Skip to content

Privacy policy

This policy explains which personal data Cortex Foundation collects, why, on which legal basis, for how long it is kept, and how you exercise your rights over it. It covers the site and every Cortex service reachable from it.

Last updated: [À REMPLIR PAR MATHIS : date de cette version]

This is the version in force since [À REMPLIR PAR MATHIS : date de cette version]. Earlier versions are available on request; the date at the top of this page is the one that applies.

1 Data we collect

  • Category
    Account data
    What it contains
    e-mail address, hashed password or identity-provider identifier, display name
    Collected when
    you create an account
  • Category
    Service data
    What it contains
    conversation text, prompts, uploaded files, generated outputs
    Collected when
    you use a service
  • Category
    Technical data
    What it contains
    IP address, user agent, request timestamps, error traces
    Collected when
    every request
  • Category
    Billing data
    What it contains
    billing name, address, tax identifier, payment-provider token
    Collected when
    you subscribe to a paid plan
  • Category
    Support data
    What it contains
    the content of your messages to us, and any attachment
    Collected when
    you contact support
  • Category
    Site measurement
    What it contains
    page views and events, without cross-site identifiers
    Collected when
    you visit the site, unless you refuse

We do not collect special-category data, and we ask you not to put it in a prompt. We do not buy personal data from data brokers. We do not sell it, and we do not share it for cross-context behavioural advertising.

2 Purposes

We process personal data to: provide the services and keep you signed in; produce the response you asked for; enforce the rate limits and the acceptable-use rules; bill paid subscriptions; answer support requests; measure whether the site works; detect, investigate and prevent abuse and security incidents; meet our legal and accounting obligations; and improve our models where — and only where — the legal basis below permits it.

4 Retention periods

  • Data
    Account data
    Retention
    life of the account, then [À REMPLIR PAR MATHIS : délai de purge, 30 jours par défaut]
    Starting point
    account deletion
  • Data
    Conversation content and prompts
    Retention
    [À REMPLIR PAR MATHIS : durée — voir la section 3 sur la rétention des prompts]
    Starting point
    the request
  • Data
    Generated outputs kept by you
    Retention
    life of the account
    Starting point
    creation
  • Data
    Technical logs
    Retention
    [À REMPLIR PAR MATHIS : durée, 12 mois par défaut]
    Starting point
    the request
  • Data
    Security and abuse logs
    Retention
    [À REMPLIR PAR MATHIS : durée, 12 mois par défaut]
    Starting point
    the incident
  • Data
    Invoices and accounting records
    Retention
    [À REMPLIR PAR MATHIS : durée légale, 10 ans par défaut en France]
    Starting point
    the invoice date
  • Data
    Support tickets
    Retention
    [À REMPLIR PAR MATHIS : durée, 3 ans par défaut]
    Starting point
    the last exchange
  • Data
    Consent records (cookies, training)
    Retention
    [À REMPLIR PAR MATHIS : durée, durée de la campagne + 6 mois par défaut]
    Starting point
    withdrawal or expiry

When a period ends the data is deleted or irreversibly anonymised. Backups follow a [À REMPLIR PAR MATHIS : durée de rotation des sauvegardes, 35 jours par défaut] rotation and roll off on their own schedule.

5 Processors and recipients

  • Processor
    [À REMPLIR PAR MATHIS : hébergeur]
    Role
    hosting of the site and the services
    Location
    [À REMPLIR PAR MATHIS]
    Safeguard
    [À REMPLIR PAR MATHIS : CCT / décision d'adéquation]
  • Processor
    [À REMPLIR PAR MATHIS : prestataire de paiement]
    Role
    payment processing
    Location
    [À REMPLIR PAR MATHIS]
    Safeguard
    [À REMPLIR PAR MATHIS]
  • Processor
    [À REMPLIR PAR MATHIS : prestataire e-mail]
    Role
    transactional e-mail
    Location
    [À REMPLIR PAR MATHIS]
    Safeguard
    [À REMPLIR PAR MATHIS]
  • Processor
    [À REMPLIR PAR MATHIS : mesure d'audience]
    Role
    site measurement
    Location
    [À REMPLIR PAR MATHIS]
    Safeguard
    [À REMPLIR PAR MATHIS]
  • Processor
    [À REMPLIR PAR MATHIS : fournisseur d'accès à un modèle tiers], le cas échéant
    Role
    inference on a subcontracted model
    Location
    [À REMPLIR PAR MATHIS]
    Safeguard
    [À REMPLIR PAR MATHIS]

Each processor is bound by a data-processing agreement under Article 28 GDPR. We do not authorise a processor to use your data for its own purposes. Beyond processors, we disclose data only where the law compels it, and we challenge a request we consider excessive.

6 International transfers

Where a processor is established outside the European Economic Area, the transfer relies on [À REMPLIR PAR MATHIS : mécanisme — décision d'adéquation, clauses contractuelles types, ou règles d'entreprise contraignantes], together with the supplementary measures required by the case law — typically encryption in transit and at rest, with keys held in the EEA.

A transfer impact assessment is carried out for each destination and reviewed [À REMPLIR PAR MATHIS : fréquence, annuelle par défaut]. You may obtain a copy of the applicable safeguard by writing to the Data Protection Officer.

7 Your rights

You have the right to access your data, to rectify it, to erase it, to restrict its processing, to object to it, and to receive it in a portable, machine-readable format. Where processing rests on consent, you may withdraw that consent at any time, without affecting the lawfulness of what was done before.

Exercise these rights from your account settings, or by writing to the Data Protection Officer at the address in 2.3.9. We answer within one month; where a request is complex we may extend that by two months and we will tell you within the first month.

In France you may also lodge a complaint with the CNIL; elsewhere in the European Union, with your national supervisory authority. We would rather you came to us first, and we will not treat a complaint as a reason to close your account.

You have the right not to be subject to a decision based solely on automated processing that produces a legal effect or a similarly significant effect. Cortex does not make such decisions about users' accounts. Where a model produces a recommendation that a human then acts on, the human is accountable for the decision — see the AI disclosure.

8 Cookies and local storage

The site sets cookies in three categories.

  • Category
    Strictly necessary
    Purpose
    session, authentication, security, load balancing, cookie-consent record
    Requires consent
    no
    Lifetime
    session or [À REMPLIR PAR MATHIS : durée]
  • Category
    Measurement
    Purpose
    aggregate page views and events, no cross-site identifier
    Requires consent
    yes
    Lifetime
    [À REMPLIR PAR MATHIS : durée, 13 mois maximum]
  • Category
    Preference
    Purpose
    interface language, theme
    Requires consent
    yes, where it is not strictly necessary to deliver the requested service
    Lifetime
    [À REMPLIR PAR MATHIS : durée, 6 mois par défaut]

There is no advertising or retargeting cookie on this site, and no cookie placed by a third party for its own purposes. Refusing consent is as easy as giving it: the consent banner offers both choices at the same level. You can change your choice at any time from the "Cookie settings" link in the footer. Withdrawing consent does not affect the lawfulness of processing carried out before.

The application services store a session token in local storage. It is strictly necessary and is removed when you sign out.

9 Contact — Data Protection Officer

Data Protection Officer: [À REMPLIR PAR MATHIS : nom du DPO, ou « the Data Protection Officer of Cortex Foundation » si la fonction est assurée sans nommer de personne] Address: [À REMPLIR PAR MATHIS : adresse postale du DPO, ou celle du siège] E-mail: [À REMPLIR PAR MATHIS : adresse e-mail du DPO]

Put "GDPR request" in the subject line. We may ask for proof of identity where a request is made by someone other than the account holder, and we will ask for the minimum needed.

This policy is reviewed at least once a year. Material changes are announced on this page with a new "last updated" date.

No, not by default. Training on user conversations is off, and it stays off until you enable it for a conversation or for your account. Enabling it is a consent you can withdraw, and withdrawing it stops future training without affecting what was already learned.

The other documents

Each one is dated at the top; the version in force is the one you are reading.

  • Legal notice

    Who publishes this site, who is responsible for what it says, and under which licences the models are released.

  • Terms of service

    These terms govern your use of cortex.foundation and of the Cortex services reachable from it.

  • AI disclosure

    Cortex Foundation trains and publishes its own models, and serves them in products. This page states plainly what those models do, what they do not do, what happens to the text you send them, and which uses we refuse.