Legal
Privacy Policy
Last updated
How Cortex AI LLC collects, uses, and protects data when you use the Cortex platform and this website. Cortex is built privacy-first: you choose how much of your content the platform retains.
Data we collect
- Account data: name, email address, authentication identifiers from OAuth providers such as Google or GitHub, MFA and passkey registration data.
- Billing data: subscription plan, invoices, payment status. Card details are handled by Stripe and never stored by us. For crypto payments we record on-chain transaction references.
- Usage data: request counts, token usage, model selection, compute time, and rate-limit state. This metering data is required to operate and bill the service.
- Content data: prompts, code, and model responses processed through the gateway. What we retain depends on your privacy mode, described below.
- Technical data: IP address, user agent, and diagnostic logs used for security and reliability.
How we use data
- Provide the service: route requests to model providers, run agent sessions, and persist your workspaces.
- Bill accurately: aggregate metered usage and generate invoices.
- Secure the platform: detect abuse, enforce rate limits, and audit access as part of SOC 2 compliance.
- Communicate: send transactional email such as receipts and security notices.
- Improve the service: analyze aggregated, de-identified usage patterns. We do not train models on your content.
Privacy modes
Cortex offers three privacy modes that control how prompt and response content is handled:
- Standard: content may be retained to power features such as session history and replay, encrypted at rest.
- Privacy: content is processed in transit and minimized at rest. PII detection redacts sensitive values before storage.
- ZeroKnowledge: content is not persisted by the platform beyond what is strictly required to complete the request.
You can set the mode per organization or per request. Metering metadata, such as token counts, is always recorded because billing depends on it, but it contains no prompt content.
Encryption and security
- All connections use TLS 1.2 or higher.
- Data at rest is encrypted with AES-256. Encryption keys are managed in AWS KMS.
- Access follows least privilege with role-based controls and audit logging.
- The platform is operated under SOC 2 compliance requirements.
Subprocessors
We use a small set of infrastructure and payment subprocessors, including a cloud hosting provider, a payment processor, and the model providers you route requests to.
Our current subprocessors are Amazon Web Services (cloud hosting, storage, email delivery, and encryption key management), Stripe (payment processing), and the LLM inference providers your requests are routed to: OpenRouter, Anthropic, and OpenAI.
Data retention
Account and billing records are kept as long as your account exists, then for the period required by tax and accounting law. Content data follows your privacy mode. Diagnostic logs are kept for a limited rolling window.
When you close your account, we delete or de-identify personal data that we are not legally required to keep.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to certain processing, and to complain to a supervisory authority.
To exercise these rights, contact us through the contact page. We respond within the timelines required by applicable law.
Contact
Privacy questions go to Cortex AI LLC, 254 Chapman Road ste 2098, Newark, DE 19702, or through the contact page. This policy is governed by the laws of the State of Delaware, United States, where permitted.