CognabySign in

Privacy Policy

Last updated 2 August 2026

This policy explains what personal data Cognaby (“we”, “us”) collects, why, and your rights over it. We are the data controller for the personal data described here. Questions or requests? Email privacy@cognaby.com.

What we collect

  • Account details: your email address, a display name you choose, and the year of birth you give at signup (for our age requirement).
  • Study material you upload: the notes, documents, photos or text you add. Your file is read in your own browser, and the text taken out of it is what your cards are written from. Document text is never written to our logs.
  • The file itself: we keep your original upload so Source can show you the page a card came from, exactly as you gave it to us. That means the document or photo you chose, the text you pasted or dictated, and the address of any link you added. It is stored in a private bucket that is not reachable from the open web: every view goes through the app and checks it is you first. It is kept for as long as the set is, deleted with the set, and deleted with your account. It is included in your export.
  • The passages your cards came from: we keep the extracted text, in short passages, for as long as the deck exists. This is what lets a card show you the exact part of your notes it was written from. It is a copy of your own material, held with your deck and visible only to you, and it is included when you export or delete your data.
  • Photos and scans: if you add a photo of your notes, or a scanned PDF with no readable text in it, the page images are sent to our AI providers to be transcribed into text. We do not keep the images afterwards.
  • What you write: when you explain an idea in your own words, or answer in writing, we store what you wrote and the feedback given on it. This is your work and it is part of your export.
  • Study data: the decks and cards created for you, how you group them into courses, your reviews, sessions and progress, and preferences such as timezone, reminders and accessibility settings.
  • Usage data: a record of things that happen in the app, such as a deck being built or a daily limit being reached, so we can see what is working and what is breaking.
  • Technical data: basic information needed to run the Service securely (for example, to sign you in, prevent abuse and keep the app working).

How we use it

  • to provide the Service, creating cards from your material and scheduling your reviews;
  • to mark written answers you choose to have marked, to rewrite a card that is not landing, and to build warm-up questions from cards you already have;
  • to sign you in and keep your account secure;
  • to prevent abuse and stay within cost limits;
  • to fix problems and improve the Service.

Our lawful bases (UK GDPR) are: performance of our contract with you (to run the Service), our legitimate interests (security, preventing abuse, improving the product), consent where we ask for it, and legal obligation where the law requires. We do not use your content for advertising, and we do not sell your data.

Who processes your data (sub-processors)

We use a small number of trusted providers to run the Service. They process your data only on our instructions and only to provide their part of the Service. By category of recipient:

  • Cloud hosting & database provider: stores and runs your account and study data, and handles sign-in/authentication.
  • Content delivery & bot-protection provider: serves the app and protects the sign-in form.
  • AI model providers (via an AI gateway): process the study text you upload to generate your cards, transcribe photos and scans you add, mark written answers you ask to have marked, and rewrite cards you flag. This is how your uploads become cards.
  • Email delivery provider: sends your sign-in codes and other transactional emails.
  • Payment processor: handles payments (only if and when paid plans are enabled).

Some of these providers process data outside the UK/EEA; where they do, appropriate safeguards (such as standard contractual clauses) apply.

How long we keep it

We keep your data for as long as your account is active. When you delete your account (from Settings), your account and the data linked to it are erased: your decks and cards, the passages they were written from, your courses, your reviews and sessions, everything you wrote and the feedback on it, and the connections between your cards. Any residual copies in backups clear on their normal cycle.

The one thing we keep is the usage record described above, with your account removed from it so it is no longer about you: a count of decks built or limits reached, with nobody attached. We do that so deleting an account does not distort what we know about whether the app works.

Your rights

Under UK GDPR you have the right to:

  • access your data, and export it: download a full copy any time from Settings;
  • correct inaccurate data;
  • erase your data: delete your account any time from Settings;
  • object to or restrict certain processing, and withdraw consent where processing relies on it;
  • complain to the UK Information Commissioner's Office (ICO) at ico.org.uk.

Children

Cognaby is not for children under 16. We ask for your year of birth at signup and do not permit accounts below that age. If you believe a younger child has created an account, contact us and we will remove it.

Security

We protect your data with row-level access controls (so it's only ever accessible to you), encrypted connections, least-privilege access to our systems, and reasonable, industry-standard security measures.

Changes

We may update this policy as the Service evolves. We'll change the “last updated” date above and, for material changes, tell you in the app.

Contact

For any privacy question or to exercise your rights, email privacy@cognaby.com.

© 2026 CognabyTermsPrivacyHome