Last updated July 16, 2026
Privacy Policy
This policy explains how Cortex collects, uses, stores, and protects personal data, including information received from Google APIs.
What Cortex is
Cortex is a personal AI assistant that helps a signed-in user understand, search, plan from, and act on their own personal information. The product is operated by Education for Equality for the Cortex project.
Cortex is designed around user control: connected data is used to help the signed-in user, and external actions such as sending email or creating calendar events require explicit user approval.
Information we collect
Account information: name, email address, profile image, subscription status, and authentication identifiers from Clerk.
Connected-source content: if you connect Gmail, Google Calendar, Instagram, WhatsApp Business, or the local iMessage bridge, Cortex may read the bounded message, calendar, and related metadata made available by the permissions and history limit you approve.
Product data: conversations with Cortex, generated plans, memory entries, spheres, open loops, pending actions, settings, your user-drawn Sphere Energy profile and preferences, usage events, and feedback you provide.
Technical data: logs, error reports, device/browser information, and deployment telemetry needed to keep the service secure and reliable.
How we use Google user data
Gmail read access covers message bodies, headers, senders and recipients, subjects, labels, timestamps, thread context, and sent messages from the exact Gmail account you choose. Cortex uses those records for inbox review, search, summaries, planning context, memory, attention detection, and review-first drafts.
Google Calendar read access covers your calendar list, calendar names and access roles, time zones and identifiers, event titles, descriptions, locations, times, attendees, recurrence, conferencing links, and free/busy availability. Cortex uses those records for day planning, scheduling options, calendar-aware answers, and Sphere Energy scheduling. If you explicitly choose private Energy calibration, Cortex analyzes at most one year and 1,500 already-synced calendar events as a weak schedule-density signal; your user-drawn curve remains in control.
OAuth tokens are encrypted before storage. Synced Gmail and Calendar records, embeddings, and exact-source derived memory or availability proposals are stored in Cortex's Supabase-backed account storage. Anthropic may process only relevant context to generate visible user-facing answers, drafts, plans, and scheduling options.
Gmail personal-model training requires a separate, optional, explicit consent and is off by default. If you opt in, messages you sent may be training targets and preceding received-message context may be processed by RunPod and Hugging Face infrastructure only for your private, user-specific model. Gmail and Calendar data are never used to train a generalized model, and Calendar records are not personal-model training examples.
Gmail sends and replies, and Google Calendar event create, update, or delete actions, are never automatic. Each exact write remains review- and approval-gated in Cortex.
Cortex does not sell Google user data, use Google user data for ads, or allow humans to read Google user data except when required for security, support, legal compliance, or abuse prevention.
Google API Limited Use
Cortex's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is used only to provide or improve user-facing Cortex features that you request or enable. It is not used to train generalized AI models that are unrelated to your own Cortex experience.
Google disconnect, revocation, and retained data
Disconnect applies to the exact Gmail or Google Calendar account you select. Cortex deactivates that integration, deletes its encrypted tokens and exact-source synchronized and normalized records, removes exact source events, unconfirmed exact-source relationship facts, unaccepted proposed commitments, and source-linked private-model artifacts, and blocks stale writers for the old integration. Pending source follow-ups are cancelled or expired without deleting their history.
Cortex attempts Google token revocation on a best-effort basis. It skips remote revocation when Gmail and Calendar may share the same Google grant and revoking it could break a sibling connection. If Google revocation is unavailable or fails, Cortex does not falsely report success: local access and exact-source deletion proceed, and you are told to remove Cortex from Google Account permissions if needed.
Disconnect preserves completed, failed, rejected, expired, and cancelled Actions and append-only Action events; chat history and global operational audit; user-confirmed people, identities, dates, and accepted commitments; generic or mixed-source memory, profiles, plans, runs, spheres, and other records that cannot safely be attributed to one account; other providers and Google accounts; and legacy personal-model artifacts without provable source attribution.
Deleting your Cortex account from Settings is the path for deleting retained user-wide data that an exact-account disconnect intentionally keeps.
How we use Instagram data
If you connect an eligible Instagram professional account through Meta's official API, Cortex may sync DMs, comments, account identifiers, timestamps, and conversation metadata made available by the permissions you approve.
Direct Instagram Login and Page/Facebook fallback integrations are bound to the exact app ID recorded during connection and are verified with their distinct configured app secrets before webhook content is processed.
Cortex uses this data to show unanswered conversations in your unified attention queue, provide planning and memory context, and prepare review-first reply drafts. Only messages you sent may be used as targets for your private personal-model adapter; received messages are context, not examples of your voice.
Cortex does not publish or send an Instagram reply without an explicit approval action. Automatic draft preparation runs only when you enable Assist mode, and a prepared draft is not treated as a sent message.
How we use WhatsApp Business and local iMessage data
WhatsApp live access uses the official Business Platform only. Cortex stores provider-confirmed phone registration and webhook-subscription state. If Cortex creates or resets a registration PIN, it stores only the encrypted value and never displays, returns, or logs the plaintext PIN. Outbound replies remain review-first actions and are not sent without explicit approval.
The foreground iMessage bridge requires explicit account-scoped consent, an immutable first-run history limit of 0 through 100, and macOS Full Disk Access. It reads an owner-only temporary SQLite snapshot, uploads bounded message text and attachment metadata but not attachment files, and cannot send through Messages.app.
Bridge logs and normal command output contain health, counts, checkpoints, and content-free replay evidence only. Pending batches are owner-only and deleted after acknowledgement or revocation; abandoned snapshot workspaces are recovered on a later run.
AI processing and service providers
Cortex may process your content with infrastructure providers such as Vercel, Supabase, Clerk, Anthropic, RunPod, Cloudflare R2, Sentry, and Google APIs so the app can authenticate you, store your data, generate responses, train or serve your personal adapter, and monitor reliability.
These providers are used as subprocessors for Cortex functionality. They are not permitted by Cortex to sell your personal data or use it for their own advertising.
Storage and security
OAuth access and refresh tokens are encrypted before storage. Cortex stores synced source content, embeddings, memory, profile data, and personal-model adapter metadata in project databases and object storage.
Cortex uses access controls, authentication, same-origin mutation checks, webhook signature checks, and usage limits to reduce the risk of unauthorized access or abuse.
No internet service can be guaranteed perfectly secure, but Cortex is built to minimize unnecessary access and to keep sensitive actions user-approved.
Retention, export, and deletion
Cortex keeps connected-source data and derived Cortex data while your account is active or until you delete it, disconnect its exact source account, or ask us to remove it, subject to the audit and user-confirmed retention described above.
You can export your Cortex data from Settings. OAuth access tokens, refresh tokens, raw API key secrets, and vector embeddings are intentionally excluded from exports.
You can delete your Cortex account and data from Settings. Deletion removes Cortex database records and attempts to delete personal-model adapter files associated with your user.
Your choices
You can choose which Google account permissions to grant and can revoke access in your Google Account permissions page at any time.
You can disconnect integrations, stop using particular features, request support, export your data, or delete your account.
Contact
For privacy questions or data requests, contact Naomi Ivie at naomi.ivie04@gmail.com.
We may update this policy as Cortex changes. The date at the top shows the latest update.