Privacy Policy
Last updated: July 19, 2026
This Privacy Policy describes how Cognitory ("Cognitory", "we", "us") collects, uses, and protects information in connection with our websites (including cognitory.ai) and our applications and services, including Matilda, our retirement-plan compliance platform (together, the "Services").
Information we collect
- Account information. When you sign in to the Services, we collect your name, email address, and profile picture from your identity provider.
- Content you provide. Information you or your organization submit to the Services in the course of using them.
- Connected-account data. If you connect a third-party account (such as a Google account) to the Services, we receive data from that account as described in the provider-specific sections below, and only after you explicitly grant access.
- Usage and device information. Log data such as IP address, browser type, and pages visited, collected to operate and secure the Services.
How we use information
- We use the information we collect only to provide, secure, and improve user-facing features of the Services.
- We do not use your data for advertising, and we do not sell it.
- We do not use content you provide or data from connected accounts to develop, improve, or train generalized artificial intelligence or machine learning models.
- Humans do not read your content or connected-account data except (a) with your explicit permission, (b) as necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) when the data has been aggregated and anonymized for internal operations.
How we protect your data
We protect all data we handle — and sensitive data such as email content and access credentials in particular — with the following mechanisms:
- Encryption in transit. All data transmitted between you and the Services, and between the Services and third-party APIs, is encrypted using TLS.
- Encryption at rest. All stored data, including databases and backups, is encrypted at rest using industry-standard encryption (AES-256) provided by our cloud infrastructure.
- Credential protection. OAuth tokens and other access credentials are stored encrypted in a dedicated secret-management system, are never written to logs, and are accessible only to the service components that require them.
- Access controls. Access to production systems and user data is restricted to authorized personnel on a least-privilege, need-to-know basis, and requires multi-factor authentication. Access is logged and reviewed.
- Infrastructure security. The Services run on reputable cloud providers that maintain independently audited security programs (including SOC 2 and ISO 27001).
- Monitoring and incident response. We monitor the Services for unauthorized access and other anomalies. In the event of a security incident affecting your data, we will notify affected users and applicable authorities without undue delay, as required by law.
Google user data
Parts of the Services integrate with Google APIs. We access Google user data only after you (or your organization's administrator) explicitly grant access through Google's OAuth consent flow, and only as follows:
- Google Sign-In.We use your Google account's basic profile information (name, email address, profile picture) to authenticate you and create your user account.
- Gmail.If you connect a Gmail mailbox, we access email messages, threads, and labels in that mailbox, and send email on your behalf, solely to provide the Services' email features: organizing, tracking, and responding to plan-administration correspondence between your organization and its clients. We only connect mailboxes that you explicitly authorize.
Google user data is used, protected, retained, and deleted as described in the general sections of this policy, and we do not use Google Workspace data (including Gmail content) to develop, improve, or train generalized artificial intelligence or machine learning models. You can revoke our access to your Google account at any time from your Google account security settings, after which we no longer receive data from your account.
Cognitory's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How we share information
We do not sell personal information. We share information only with service providers that help us operate the Services (such as cloud hosting and infrastructure providers), under contracts that restrict their use of the data; within your organization's workspace as directed by your organization; or when required by law.
Data retention and deletion
We retain personal data, including data from connected accounts, only for as long as needed to provide the Services. You or your organization may request deletion of stored data by contacting us at the address below; we will delete it within 30 days, except where retention is required by law. When data is deleted, it is also removed from backups on their normal rotation schedule.
Children
The Services are intended for business use and are not directed to children under 16. We do not knowingly collect personal information from children.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page and revise the "Last updated" date above.
Contact us
If you have questions about this Privacy Policy or how we handle your data, contact us at privacy@cognitory.ai.