Privacy Policy
Effective date: May 1, 2025 · Last updated: May 1, 2025
1. Who we are
CogniFetch Ltd. ("CogniFetch", "we", "us", or "our") is a software company incorporated in Jamaica, providing an AI-powered knowledge management platform for enterprises. Our registered address is Kingston, Jamaica.
This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use the CogniFetch platform, including our website at cognifetch.com and any related services (collectively, the "Service").
Under applicable data protection law, CogniFetch acts as a data controller for account and usage data, and as a data processor for the documents and content you upload into the platform on behalf of your organization.
2. Information we collect
Account information — When you create an account, we collect your name, email address, password (hashed using bcrypt — we never store plaintext passwords), organization name, and industry.
Document content — Documents, text, files, and URLs you upload or ingest into the platform. This content is chunked, embedded as vector representations, and stored in your organization's private knowledge base. This is the core data of the Service.
Query data — Questions your team asks the system, the number of document chunks retrieved, response times, and timestamps. This is stored in your organization's query log for your own analytics.
Usage and technical data — IP addresses, browser type, operating system, pages visited, and timestamps. Collected automatically for security, debugging, and rate limiting purposes.
Billing data — Payment is processed by PayPal. We store your subscription plan, status, and PayPal subscription ID. We never see or store your full payment card details.
Communications — Emails you send us, support requests, and feedback.
3. How we use your information
We use the information we collect to:
- Provide, operate, and maintain the CogniFetch platform
- Process your documents and respond to queries using AI retrieval and generation
- Authenticate users and enforce organization-level access controls
- Send transactional emails (account creation, password resets, invitations, billing receipts)
- Display analytics dashboards to your organization administrators
- Enforce subscription plan limits (query counts, document limits, user counts)
- Detect and prevent security threats, fraud, and abuse
- Comply with legal obligations
- Improve the reliability, performance, and security of the Service
We do not use your data for advertising, sell your data to third parties, or use your document content for any purpose other than providing the Service to your organization.
4. AI and document processing
CogniFetch uses artificial intelligence to process your documents. Here is exactly what happens when you ingest a document:
- Your document is split into text chunks of approximately 512 tokens each
- Each chunk is sent to Voyage AI's embedding API to generate a numerical vector representation (1,024 dimensions)
- These vectors and the original text are stored in your organization's private database partition on Supabase (PostgreSQL with pgvector)
- When a user asks a question, the question is also embedded by Voyage AI, and your database is searched for the most semantically relevant chunks
- The retrieved chunks are sent to Anthropic's Claude API as context, along with the user's question, to generate a grounded answer
- Claude's response is streamed back to your user
Your document content is transmitted to Voyage AI and Anthropic's APIs during this process. Both providers are contractually bound not to use your content for model training. See Section 5 for details.
5. We do not train AI on your data
This is our most important commitment: CogniFetch does not use your documents, queries, or any content you upload to train, fine-tune, or improve any AI model — including our own systems or those of our AI providers.
Our AI providers are bound by the following commitments under their enterprise APIs:
- Anthropic (Claude): API inputs and outputs are not used to train Anthropic's models by default under their API terms
- Voyage AI: Embedding API inputs are not retained or used for model training
- Your data is used only to generate responses for your users in real time
If this ever changes — it won't without your explicit consent and an update to this policy.
6. Third-party sub-processors
We use the following sub-processors to deliver the Service. Each is bound by data processing agreements consistent with applicable privacy law:
| Processor | Purpose | Data location |
|---|---|---|
| Supabase Inc. | Database hosting, vector storage, authentication infrastructure | US (AWS us-east-1) |
| Anthropic PBC | AI text generation (Claude API) | US |
| Voyage AI Inc. | Document and query embedding | US |
| Vercel Inc. | Application hosting and edge delivery | US / Global CDN |
| PayPal Holdings Inc. | Subscription payment processing | US / Global |
| Resend Inc. | Transactional email delivery | US |
| Cohere Inc. | Optional reranking (if enabled) | US |
We will update this list when we add new sub-processors and will notify you by email at least 14 days in advance of material changes.
7. Data retention
Account data — Retained for the duration of your subscription plus 90 days after cancellation, then permanently deleted.
Document content and vectors — Retained until you delete the document from your knowledge base, or until your organization account is deleted. Deletion is permanent and irreversible — we do not keep backups of deleted documents beyond 7 days for disaster recovery purposes.
Query logs — Retained for 12 months on Professional and Enterprise plans, 90 days on Starter, then permanently deleted.
Audit logs — Retained for 12 months and cannot be deleted by users (required for compliance integrity).
Billing records — Retained for 7 years as required by applicable financial regulations.
Security logs — IP addresses and access logs retained for 90 days.
8. Your rights
Depending on your jurisdiction, you have the following rights regarding your personal data:
- Right to access — request a copy of the personal data we hold about you
- Right to rectification — correct inaccurate or incomplete personal data
- Right to erasure — request deletion of your personal data (subject to legal retention requirements)
- Right to restriction — request we limit how we process your data
- Right to portability — receive your data in a machine-readable format
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — where processing is based on consent, withdraw it at any time
To exercise any of these rights, email us at privacy@cognifetch.com. We will respond within 30 days. We may need to verify your identity before processing your request.
Organization owners can delete all documents, members, and organization data directly from the Settings dashboard without contacting us.
9. Security measures
We implement the following technical and organizational measures to protect your data:
- AES-256 encryption for all data at rest
- TLS 1.3 for all data in transit
- bcrypt password hashing (cost factor 12)
- Role-based access control — users only access data their organization owns
- API key hashing — API keys are stored as SHA-256 hashes, never in plaintext
- File scanning on upload — magic byte checking, content pattern analysis, and optional VirusTotal integration
- Rate limiting on all authentication and AI endpoints
- Middleware security headers (CSP, HSTS, X-Frame-Options, X-Content-Type-Options)
- CVE-2025-29927 middleware bypass protection
- Separate database schemas isolating RAG data from application data
No system is perfectly secure. In the event of a data breach affecting your personal data, we will notify you and relevant authorities within 72 hours as required by applicable law.
10. International data transfers
CogniFetch is incorporated in Jamaica. Our infrastructure is hosted primarily in the United States through Supabase (AWS us-east-1) and Vercel. If you are located in the European Economic Area, United Kingdom, or another jurisdiction with data transfer restrictions, be aware that your data is transferred to and processed in the United States.
We rely on the following transfer mechanisms:
- Standard Contractual Clauses (SCCs) with EU-based customers
- Sub-processor Data Processing Agreements with all third-party providers listed in Section 6
- Contractual commitments to data minimization and purpose limitation with all providers
Enterprise customers requiring specific data residency commitments should contact us to discuss custom deployment options.
12. Children's privacy
CogniFetch is an enterprise B2B platform and is not directed to individuals under the age of 18. We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected data from a minor, we will delete it immediately. Contact us at privacy@cognifetch.com if you believe we have done so.
13. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the 'Last updated' date at the top of this page
- Send an email notification to all registered organization owners
- Post a notice in the CogniFetch dashboard for 30 days
Your continued use of the Service after changes take effect constitutes acceptance of the updated policy. If you disagree with material changes, you may terminate your account within 30 days of notification for a pro-rated refund of any prepaid fees.
14. Contact us
For privacy-related questions, data subject requests, or to report a concern:
We aim to respond to all privacy inquiries within 5 business days and to complete data subject requests within 30 days.