Clear data practices

Privacy Policy

Effective date: July 17, 2026CognoLogEmail, calendar, meeting, and website data

No sale or ads

We do not sell personal information or use private communications for advertising.

Google Limited Use

Google Workspace data is handled under the Google API Services User Data Policy.

AI transparency

Requested AI features may send relevant content to contracted model or transcription providers.

Purpose limited

Communication data is used to deliver, secure, and support the features you choose.

Protected access

We use access controls, transport encryption, and operational safeguards designed to protect data.

User controls

You can disconnect integrations, change feature settings, and request or initiate account deletion.

1. Scope and roles

This Privacy Policy explains how CognoLog, the operator of CognoLog, collects, uses, discloses, and retains personal information through our websites, email workspace, calendar and meeting tools, artificial intelligence features, applications, and related services (the Service).

If an organization provides or manages your workspace, that organization may control your account, membership, billing, and its use of information in the workspace. In that context, we may process information on the organization's instructions, and its own privacy notices may also apply. Contact the organization for questions about its decisions or instructions.

This Policy also covers information about people who do not have a CognoLog account but communicate with a user, appear in a connected calendar, attend a recorded meeting, or receive a generated summary.

2. Information we collect

We collect information from you, connected services, other users, and your device.

Account and workspace

Name, email address, profile image, timezone, account identifiers, authentication and session information, settings, roles, invitations, and organization membership.

Connected account credentials

OAuth permissions, access and refresh tokens, provider account identifiers, connection status, and synchronization history needed to keep integrations working.

Email and contact data

Message bodies and HTML, subjects, senders, recipients, timestamps, threads, labels, folders, drafts, attachments when requested, contacts, and mailbox actions.

Calendar and meeting data

Event titles, descriptions, times, invitees, organizers, join links, bot settings, audio or video, speaker data, transcripts, summaries, recordings, and action items.

AI and derived data

Prompts, rules, user feedback, classifications such as “Needs Reply,” topics, tags, summaries, relationship graphs, vector representations, suggestions, and generated drafts.

Billing and support

Plan, seat count, customer and subscription identifiers, invoice and payment status from our payment processor, and messages or files you send to support.

Device and usage data

IP address, browser and device details, pages and features used, referral information, cookie identifiers, authentication events, performance data, and interaction events.

Diagnostics and security

Error reports, service logs, abuse signals, delivery status, and limited event or content context needed to diagnose failures and protect the Service.

Our payment processor collects payment-card details directly. We receive identifiers, billing status, invoice information, and limited payment metadata rather than full card numbers.

3. Google Workspace and connected services

When you connect Google, the Service requests the permissions shown during OAuth. These may allow it to identify your account; read, import, search, and synchronize Gmail; manage messages, labels, folders, drafts, and mailbox state; send messages you choose to send; and read or update Calendar events for meeting features.

We use and store Google data to provide visible, user-facing features, including:

  • mailbox display, synchronization, search, drafting, sending, and message actions;
  • AI classifications, including Needs Reply, topics, tags, summaries, suggested actions, and relationship analysis;
  • contact extraction, graph and vector search, automations, and workspace rules; and
  • calendar synchronization, meeting-bot scheduling, transcription, and summaries.

Stored Google data may include content and metadata, OAuth credentials, synchronization state, user-created changes, and derived tags, summaries, graphs, and embeddings. You can disconnect an integration in the Service and revoke access through your Google Account.

Google API Limited Use

CognoLog's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

In particular, we do not sell Google Workspace data, use it for advertising or credit decisions, or use it to create, train, or improve generalized artificial intelligence or machine-learning models. We transfer it only as needed to provide or improve the user-facing features you request, protect the Service, comply with law, or as otherwise permitted by the Limited Use requirements.

4. Meetings and information about non-users

Depending on a user's settings, our meeting assistant may be scheduled from a connected calendar, be added as a guest to an event, join a conferencing session, and record, transcribe, summarize, or analyze the meeting. Meeting titles, attendee names and email addresses, transcripts, recordings, summaries, and action items may be stored for the user-facing meeting experience.

The Service may send summaries, transcripts, action items, attendee-access links, or recording links to the organizer and calendar invitees, including people without an account, according to the organizer's settings and the meeting workflow. Messages or links already delivered cannot be recalled by deleting them from the Service.

If you are a correspondent, invitee, or meeting participant rather than a user, we generally receive your information because a user connected an account or enabled a meeting feature. Contact that user or the meeting organizer first to ask about their use of your information. You may also contact us at the address below.

5. How and why we use information

We use information to:

  • create, authenticate, administer, and secure accounts and workspaces;
  • connect, synchronize, display, search, and act on authorized email and calendar data;
  • record and transcribe meetings and generate requested summaries and follow-ups;
  • generate classifications, drafts, recommendations, graphs, and other AI outputs;
  • process subscriptions, seat changes, invoices, and account entitlements;
  • operate, maintain, debug, measure, and improve user-facing Service features;
  • provide support and send transactional or service communications;
  • detect fraud, abuse, security incidents, and violations of our terms; and
  • comply with legal obligations and establish, exercise, or defend legal claims.

Where a legal basis is required, we rely as appropriate on performance of a contract, your consent, our legitimate interests in operating and protecting the Service, and compliance with legal obligations. You may withdraw consent where processing relies on consent, without affecting earlier lawful processing.

6. Artificial intelligence and transcription providers

The Service uses hosted and self-managed model-routing, AI inference, embedding, and transcription systems. Depending on the feature and current configuration, relevant email text, thread context, contacts, prompts, transcript text, summaries, embedding inputs, or meeting audio may be transmitted to third-party AI or transcription providers acting on our behalf. Current configurations may route model or embedding requests to providers such as DeepSeek or Alibaba Model Studio and transcription requests to Deepgram. The provider used for a feature and its processing location may change as the Service evolves.

We limit these transfers to what is needed to provide the requested feature and require service providers to process data under applicable confidentiality, security, and data protection obligations. We do not use private communication content to train a generalized model for unrelated customers, and Google Workspace data is subject to the additional Limited Use restrictions described above.

AI-generated classifications and outputs may be incomplete or wrong. A classification such as Needs Reply is created when the Service analyzes an email; it is not a statement from the sender. Review important labels, recipients, drafts, summaries, and actions before relying on them.

Automated systems process content to operate these features. Authorized personnel may access limited information when reasonably necessary for support you request, security, incident response, legal compliance, or reliable operations, using role-based and need-to-know controls.

7. When we disclose information

We may disclose information to the following recipients:

  • Connected services, such as Google and conferencing platforms, when you direct the Service to read or make changes there.
  • Service providers for hosting, storage, databases, email delivery, AI inference, transcription, security, error monitoring, optional analytics, customer support, and payment processing.
  • Workspace participants and administrators for membership, invitations, roles, billing, and content you choose to share. Workspace access depends on the feature and assigned role.
  • Meeting recipients and link viewers when a user or workflow sends a summary, transcript, action item, attendee link, or recording link.
  • Authorities and professional advisers when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or handle a claim.
  • A successor in a merger, financing, reorganization, or sale, subject to applicable notice, consent, and Google Limited Use restrictions.

We do not sell personal information, share it with data brokers, or use private email or meeting content for targeted advertising. We do not transfer it for credit or lending decisions.

8. Cookies, analytics, and diagnostics

We use strictly necessary cookies and similar storage for authentication, security, routing, saved privacy choices, and core preferences. Without them, the Service may not function correctly.

With your analytics choice, we may use PostHog and Dub to understand page visits, referrals, feature usage, and product interactions. These tools may receive cookie or device identifiers, IP address, browser details, account identifiers, and interaction events. We do not use them to provide targeted advertising.

We use Sentry for functional error reporting and service diagnostics. It may receive error stack traces, page and device context, request metadata, and limited account or event context needed to diagnose a failure. Session replay is not enabled. We take steps to avoid sending message content or authentication credentials, but an error report may contain information present in the failing operation.

Optional analytics are disabled unless you allow them. You can change your choice below; browser controls can also block or remove cookies, although blocking necessary storage can affect the Service.

9. Retention and deletion

Retention depends on the type of information, the feature you use, workspace settings, operational needs, and legal requirements. In general:

  • account, workspace, connected-mailbox, communication, graph, vector, and generated data may be kept while the account or relevant workspace remains active;
  • some caches, generated drafts, recordings, logs, and diagnostic data have feature-specific limits;
  • billing, fraud-prevention, security, deletion-audit, and legal records may be kept for the period reasonably required for those purposes; and
  • backup copies may remain for a limited recovery period and are isolated from ordinary use until overwritten.

You can initiate account deletion from the Service or contact us. Deletion runs as a background process so connected-provider access can be revoked and data can be removed from mailbox, graph, vector, calendar, meeting, and account stores. Completion may take time and may require resolution of active billing, workspace ownership, shared meetings, or another user's continuing authorized interest.

Deletion does not recall email, summaries, or links already sent to other people, remove copies held by connected providers or recipients, or erase records we must retain for security, legal, billing, or deletion-verification purposes. We delete or de-identify remaining personal information when those purposes expire.

10. Security and international processing

We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport, access controls, credential protections, monitoring, backups, and separation of user data where appropriate. No method of storage or transmission is completely secure.

We and our service providers may process information in Canada, the United States, and other countries where we or they operate. Those countries may have different privacy laws. Where required, we use contractual and other safeguards for cross-border transfers.

11. Your rights and choices

Depending on your location and circumstances, you may have rights to:

  • request access to or a copy of personal information we hold about you;
  • correct inaccurate or incomplete information;
  • request deletion or restriction of certain processing;
  • object to certain processing or withdraw consent;
  • request portability where required by law; and
  • complain to an applicable privacy or data-protection authority.

You may also change settings, disconnect integrations, revoke Google access, manage optional analytics, or initiate account deletion in the Service. Rights are not absolute; we may need to verify your identity and may retain information where permitted or required by law.

If an organization controls your workspace or meeting, submit your request to that organization first. We will assist it with requests when required.

12. Children

The Service is designed for people who can lawfully authorize connected communication and meeting accounts and enter into these Terms. It is not directed to children, and we do not knowingly collect personal information from children in violation of applicable law. If you believe a child has provided information unlawfully, contact us.

13. Changes to this Policy

We may update this Policy to reflect changes in the Service, providers, or law. We will update the effective date and provide additional notice when required. If a change would permit a materially new use of Google user data, we will provide notice and obtain consent before using that data for the new purpose where required by Google policy or law.

14. Contact us

Contact us with privacy questions, rights requests, or complaints. Please do not send passwords, OAuth tokens, or unnecessary message content.