Privacy Policy

Last updated: March 20, 2026

1. Introduction

We are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Cognivio AI (the “Service”).

By using the Service, you consent to the practices described in this policy. If you do not agree, please discontinue use of the Service.

2. Information We Collect

2.1 Information You Provide

  • Account information — name, email address, and profile picture (provided directly or via Google Sign-In).
  • Uploaded content — documents, PDFs, and other study materials you upload for processing.
  • Communications — messages you send to us via the contact form or email.

2.2 Information Collected Automatically

  • Usage data — pages viewed, features used, timestamps, and interaction patterns.
  • Device information — browser type, operating system, screen resolution, and IP address.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and improve the Service.
  • Process your uploaded documents using AI to generate summaries, flashcards, quizzes, audio, and video content.
  • Manage your account and subscription.
  • Send transactional emails (e.g., password reset, billing notifications).
  • Detect and prevent fraud, abuse, and security incidents.
  • Comply with legal obligations.

We do not sell your personal information to third parties. We do not use your uploaded documents to train our AI models.

4. Third-Party Services

We work with trusted third-party providers to deliver the Service. These providers have access only to the information necessary to perform their specific functions:

Paddle

Payment processing, tax collection, and invoicing as our Merchant of Record

View their privacy policy →

Google OAuth

Account authentication via Google Sign-In

View their privacy policy →

Google Gemini

AI-powered content generation (summaries, flashcards, quizzes, explanations)

View their privacy policy →

Cloudinary

Cloud storage for generated media files (audio overviews, podcast audio, video content, and profile images)

View their privacy policy →

ElevenLabs

AI text-to-speech for voice overviews, podcast narration, and video explanations

View their privacy policy →

Gamma

Slide rendering and visual presentation generation for AI video overviews

View their privacy policy →

Vapi

Real-time voice interaction and viva-mode speech processing

View their privacy policy →

MongoDB Atlas

Cloud database for storing user accounts, documents, and generated content metadata

View their privacy policy →

We encourage you to review the privacy policies of these providers.

5. Generated Content & Public URLs

Certain content generated by the Service — including voice overviews, podcast audio, and video explanations — is stored on Cloudinary, a third-party cloud storage provider. Each piece of generated content is assigned a unique, cryptographically secure URL (a “secure_url”) that cannot be guessed by anyone.

However, these URLs are publicly accessible, meaning that anyone who has the URL can view or listen to the content without logging in. If you copy and share a content URL, the recipient will be able to access it.

We are not responsible for content that is shared by you through these URLs. If you wish to remove generated content, you can delete it from within the Service, and the corresponding Cloudinary URL will also be removed.

6. Data Retention

We retain your personal information and uploaded content for as long as your account is active or as needed to provide you with the Service. If you delete your account, we will delete or anonymize your data within 30 days, unless retention is required by law.

AI-generated outputs (summaries, flashcards, audio, video, etc.) are stored alongside your account and are deleted when the associated document or account is deleted.

7. Data Security

We implement industry-standard security measures to protect your information, including:

  • HTTPS encryption for all data in transit.
  • Encrypted storage for sensitive data at rest.
  • Secure password hashing (bcrypt).
  • JWT-based authentication with no cookie storage.
  • Rate limiting and HTTP parameter pollution prevention.

While we take reasonable precautions, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — request a copy of the personal data we hold about you.
  • Correction — request corrections to inaccurate or incomplete data.
  • Deletion — request that we delete your personal data and uploaded content.
  • Data portability — request your data in a structured, machine-readable format.
  • Objection — object to certain types of processing.

To exercise any of these rights, contact us at cognivioai.app@gmail.com. We will respond within 30 days.

9. Cookies

Cognivio AI does not use cookies. We use token-based authentication (JWT) stored in your browser's local storage to maintain your session. No tracking cookies or third-party advertising cookies are placed on your device.

10. Changes to This Policy

We may update this Privacy Policy periodically. When we make material changes, we will notify you by updating the “Last updated” date at the top of this page and, where appropriate, by providing additional notice (such as an email or in-app notification).

11. Contact Us

If you have questions about this Privacy Policy or how we handle your data, please contact us:

Cognivio AI

Email: cognivioai.app@gmail.com