Last updated: February 10, 2026
At Cogniso, we believe your learning journey should be private and secure. This policy explains how we collect, use, and protect your data across our AI-powered learning platform, including our document management system (Cortex), study rooms, live lectures, assessments, and all collaborative features.
1. Information We Collect
1.1 Account Information
- Name, email address, and profile photo (via Google Sign-In or email registration)
- Password (encrypted, for email-based accounts)
- Institution affiliation and role (student, instructor, admin)
- Multi-factor authentication settings and recovery options
1.2 Learning & Study Data
- Course enrollments, progress, and completion status
- Assessment submissions, quiz answers, and AI-generated feedback
- Practical assessment work including essays, code submissions, case studies, and design tasks
- Study session data from Focus, Discussion, Collaborative, and Practice rooms
- Pomodoro timer usage and productivity patterns
- Learning analytics, weakness analysis, and personalized recommendations
1.3 Documents & Files (Cortex)
- PDF documents you upload for AI analysis and study
- Highlights, annotations, bookmarks, and notes you create
- Document chat conversations with our AI assistant
- Drawings and canvas submissions for assessments
- File uploads for assignments and practical assessments
1.4 Real-Time Collaboration Data
- Video and audio streams during live lectures and discussion rooms (not permanently stored)
- Chat messages in study rooms and live lecture Q&A
- Whiteboard drawings and collaborative document edits
- Presence indicators and participation data (raise hand, reactions)
- Screen sharing content during collaborative sessions
1.5 Technical & Usage Data
- Device information, browser type, and operating system
- IP address and approximate location
- Feature usage patterns and navigation paths
- Error logs and performance metrics
2. How We Use Your Information
2.1 AI-Powered Learning Features
- Generate personalized assessments and practice questions using GPT-4
- Create educational images and diagrams using DALL-E 3
- Analyze your documents to provide intelligent Q&A via Cortex
- Evaluate your submissions and provide detailed AI feedback
- Identify learning weaknesses and recommend study materials
- Personalize difficulty levels and content recommendations
2.2 Platform Operations
- Authenticate your identity and maintain account security
- Enable real-time collaboration in study rooms and live lectures
- Process WebRTC connections for video conferencing
- Sync your data across devices in real-time
- Send notifications about courses, assignments, and deadlines
- Track gamification points, achievements, and leaderboard rankings
2.3 Institutional Features
- Provide progress reports to your institution (if enrolled through one)
- Enable instructors to view student submissions and provide grades
- Generate analytics for department heads and administrators
- Facilitate early warning systems for at-risk students
3. AI Processing & Third-Party Services
To provide our AI-powered features, we use the following services:
- OpenAI (GPT-4, GPT-4o-mini, DALL-E 3): For assessment generation, document analysis, AI evaluation, and educational image creation. Your content is processed according to OpenAI's data usage policies.
- Supabase: For database storage, authentication, file storage, and real-time synchronization. Data is encrypted at rest and in transit.
- Resend: For transactional emails including notifications and password resets.
- Vercel: For hosting and content delivery.
We do not use your learning data to train AI models. Your submissions and documents are processed only to provide immediate features and are not retained by AI providers for model training.
4. Data Storage & Security
- All data is stored on Supabase infrastructure with encryption at rest (AES-256)
- Data in transit is protected using TLS 1.3 encryption
- Passwords are hashed using bcrypt with salting
- Multi-factor authentication (MFA) available for enhanced security
- Row-Level Security (RLS) ensures users can only access their own data
- Regular security audits and vulnerability assessments
- Video/audio streams are peer-to-peer (WebRTC) and not stored on our servers
5. Data Sharing
We do not sell your personal information. We share data only in these circumstances:
- With your institution: If you're enrolled through a school or organization, administrators and instructors can view your progress, grades, and submissions.
- With collaborators: Other users in your study rooms can see shared content, chat messages, and collaborative work.
- With service providers: As described in Section 3, to operate our platform.
- For legal compliance: When required by law or to protect rights and safety.
6. Your Rights & Controls
You have control over your data:
- Access: View all your data through Settings > Privacy
- Export: Download your learning data, documents, and submissions
- Correct: Update your profile and account information anytime
- Delete: Request deletion of your account and associated data
- Notifications: Manage email and push notification preferences
- Visibility: Control what appears on leaderboards and to other users
To exercise these rights, visit your Settings page or contact us at privacy@cogniso.io.
7. Data Retention
- Account data is retained while your account is active
- Learning progress and submissions are kept for your reference and institutional records
- Chat messages in study rooms are retained for 90 days
- Video/audio streams are not recorded or stored (real-time only)
- Deleted documents are removed from storage within 30 days
- After account deletion, data is purged within 90 days (except where legally required)
8. Cookies & Tracking
We use cookies for:
- Authentication: Keeping you logged in across sessions
- Preferences: Remembering your theme, language, and settings
- Analytics: Understanding feature usage to improve the platform
We do not use third-party advertising cookies or sell data to advertisers.
9. Children's Privacy
Cogniso is designed for users aged 13 and older. For users under 18, we recommend parental guidance. If an institution enrolls students under 13, additional parental consent and COPPA compliance measures apply. Contact us for institutional arrangements.
10. International Users
Cogniso operates globally. Your data may be processed in countries outside your residence. We ensure appropriate safeguards are in place for international transfers, including standard contractual clauses where applicable.
11. Changes to This Policy
We may update this policy to reflect changes in our practices or legal requirements. We'll notify you of significant changes via email or in-app notification. Continued use after changes constitutes acceptance.
12. Contact Us
Questions about this Privacy Policy or your data?