Support

Privacy Policy

Effective Date: May 14, 2026 Last Updated: August 24, 2026

Changelog (August 24, 2026): Updated "Cookies and Tracking Technologies" for our region-aware consent model: visitors in regions whose law requires opt-in consent (EU/EEA, United Kingdom, Switzerland, China, Canada, South Korea) see a consent banner and analytics stays off until they accept; visitors elsewhere are not interrupted by a banner: analytics runs by default and can be turned off at any time via the "Cookie preferences" control in the page footer or in account settings. Added: we honor the Global Privacy Control (GPC) browser signal as an opt-out everywhere; and for signed-in users, a consent choice is saved to the account so it applies across all your devices.

Changelog (August 21, 2026): Updated the "Product Analytics and Session Replay (PostHog)" section: signed-in product usage is now measured as interaction events associated with your account (identified product analytics) to improve the product; what you type is never collected as analytics; session replay of signed-in usage remains off by default outside limited, time-boxed study periods; and deleting your account also deletes the associated analytics person record.

Changelog (August 14, 2026): Added the "Product Analytics and Session Replay (PostHog)" section disclosing our use of PostHog for product analytics and session replay, including input masking, internal-account exclusion, our posture on signed-in usage capture (time-boxed study periods), and the 30-day recording retention default.

Changelog (August 9, 2026): Added the "Google User Data (Gmail)" and "Google User Data (Google Analytics — your connected account)" sections disclosing our use of the Gmail, Google People, and Google Analytics APIs — for dedicated outreach mailboxes and for your own optionally-connected Gmail account (the Gmail mail scope https://mail.google.com/ plus read-only contact-lookup scopes) and your own optionally-connected Google Analytics account (analytics.readonly, analytics, analytics.edit) — including our compliance with the Google API Services User Data Policy's Limited Use requirements, and corresponding entries under "Your Rights and Choices."

Changelog (June 20, 2026): Added disclosures for AI Employees — dedicated employee email addresses; our processing, on your behalf, of the personal data of the people your AI Employee corresponds with (most of whom are not CellCog users); the non-removable human-supervisor identity disclosure on every outbound email; autonomous actions on connected accounts via Personal Tools; and the email-delivery (SendGrid/Twilio) and integration (Composio) sub-processors.

Changelog (May 14, 2026): Added disclosures for Browse my Chrome (Chrome extension), CellCog Desktop (Cowork), and the LLM providers we transmit chat content to for processing. Updated children's-privacy age threshold to align with GDPR member-state defaults.


Introduction

CellCog AI ("CellCog", "we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered chat service at cellcog.ai (the "Service").

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with the terms of this policy, please do not access or use the Service.


Information We Collect

Information You Provide

  • Account Information: When you create an account, we collect your email address, name, and authentication credentials through Firebase Authentication.
  • Profile Information: You may optionally provide additional profile information such as a profile picture or description.
  • Chat Content: We store the messages and content you create within our Service to provide you with chat history and continuity.
  • Uploaded Files: Any documents, images, or files you upload to the Service for processing or analysis.
  • Project Information: If you create or join a project workspace, we collect project name and your role within that organization.
  • Google Drive Integration: If you connect your Google Drive, we access only the files you explicitly select for import, using read-only permissions.
  • AI Employee Data: If you create an AI Employee, we collect and store its configuration (name, role, schedule, and the business name shown in its signature), its mailbox (sent and received email and attachments, including the personal data of the people it corresponds with), its memory and work artifacts, and records of actions it takes on your connected accounts.

Browse my Chrome (Chrome Extension)

If you install the CellCog Browse Chrome extension and connect it to the CellCog Desktop app, your CellCog AI agent can drive a designated tab group inside your Chrome browser. While Browse my Chrome is enabled for a chat:

  • What the agent can access: The contents of pages inside the "CellCog" tab group only — this includes page text, the accessibility tree, form values, and the URL of each tab. The agent acts on tabs you have explicitly brought into the workspace.
  • What the agent never accesses on its own: Tabs outside the CellCog tab group, browsing history, bookmarks, saved passwords, or any tab the user has not adopted into the workspace.
  • Sensitive data redaction: Password fields and credit-card fields are automatically redacted before any page content is read by the agent.
  • Cookies, localStorage, and session data: These are NOT auto-redacted. If the agent's script explicitly reads them (e.g., to authenticate an API call on your behalf), the data is included in the chat session and visible to the AI. The CellCog Browse skill instructs agents to treat such values as sensitive and not to log them unnecessarily.
  • Screenshots: When the agent captures a page screenshot, the image is saved to a temporary directory on your machine and made available to the chat. Screenshots may include any content visible in your browser, including private surfaces like email or banking pages.
  • Where the data flows: Locally between Chrome and CellCog Desktop via Native Messaging (no remote transmission for the extension itself). Once the agent reads page content as part of completing your task, that content becomes part of your chat session and is transmitted to the LLM provider serving that chat (see "Data Sharing and Disclosure" below).
  • User control: Chrome shows a yellow "CellCog Browse started debugging this browser" banner on every controlled tab. You can revoke control at any time by clicking "Cancel" on that banner. You can set an auto-approval threshold to require explicit approval for actions above a chosen risk level.
  • What the extension stores: Nothing of its own. The extension has no storage permission; all state lives in Chrome's own tab-group system and in CellCog Desktop.

CellCog Desktop (Cowork)

If you install the CellCog Desktop app and grant it access to a working directory on your machine (Cowork), your CellCog AI agent can read files, write files, and run terminal commands inside that directory:

  • What the agent can access: Files and directories inside the working directory you explicitly chose. The agent identifies each file or command's permission level (read, write, execute) and either auto-runs it or requests your approval, based on the auto-approval settings you configured.
  • What the agent does NOT access on its own: Files outside your chosen working directory, system credentials (e.g., SSH keys, browser cookie stores), or any blocked path. Certain sensitive paths are kernel-enforced as off-limits and credentials in command output are automatically redacted.
  • Where the data flows: Locally between the Desktop app and CellCog's servers over your authenticated session. File contents and command outputs that the agent reads as part of completing your task become part of your chat session and are transmitted to the LLM provider serving that chat (see "Data Sharing and Disclosure" below).
  • User control: You see every command and file change in an approval card before it runs (unless you have explicitly auto-approved that category). You can revoke working-directory access at any time from the CellCog Desktop app.

AI Employees

An AI Employee is a standing AI agent you create that works on a recurring schedule (or on demand), has its own email address, its own memory, and can take actions on your behalf. Two points matter most up front: (1) every email your AI Employee sends names you, the human supervisor, with your email address, so recipients always know who is accountable; and (2) because your AI Employee corresponds with other people, we process the personal data of those people — most of whom are not CellCog users — on your behalf. When you create and run an AI Employee, the following additional data practices apply.

  • Its own email address. Each AI Employee is assigned an address at @cellcog.com and can send and receive email there. We store the email it sends and receives — including message content, headers, recipients, timestamps, and attachments — to provide threading, history, and continuity across its work sessions, in the same way we store your chat history.
  • Email from and to other people. Because your AI Employee sends and receives email, we necessarily process the personal data of the people it corresponds with (their email address, name, message content, and anything they choose to include). Most of these people are not CellCog users. You direct who your AI Employee contacts and you are the party with the relationship to those recipients (see "Your Responsibilities for People Your AI Employee Contacts" below). We process this correspondence solely to operate your AI Employee's mailbox on your behalf; we do not use it to build independent profiles of those individuals or for our own marketing.
  • Your identity is shown on every email (by design). Every email your AI Employee sends carries a signature identifying it as an AI Employee and naming you, the human supervisor, with your account email address. This is intentional and cannot be removed: a recipient must always be able to see that there is an accountable human behind the AI and to reach that human directly. By running an AI Employee, you consent to your name and account email being disclosed to the recipients (and repliers) of its email. If this is not appropriate for your use case, do not use the AI Employee email feature.
  • Actions on your connected accounts. If you enable Personal Tools or other integrations for an AI Employee, it can take actions on the third-party accounts you connect (for example posting, messaging, or reading data) on your behalf, autonomously, within the permissions you granted. Those actions and their data are governed by this Policy and by the third party's own terms. You can disconnect any integration at any time.
  • Autonomous, scheduled processing. An AI Employee may process data and take actions while you are not present — on its schedule, or when woken by an inbound email or a trigger you configured (for example a new message in a connected app). Content it reads to do its work (emails, files, connected-app data) becomes part of its session and is transmitted to the LLM provider serving it, as described in "Data Sharing and Disclosure."
  • Retention & deletion. An AI Employee's mailbox, memory, and workspace are retained until you delete the AI Employee or your account. Deleting an AI Employee deletes its associated data on the same basis as deleting a chat (see "Data Retention").

Google User Data (Gmail)

CellCog connects to Google's Gmail API using OAuth, with your explicit authorization, in two situations. Both use the Gmail mail scope (https://mail.google.com/); what we actually do under it in each situation is described below.

1. Dedicated outreach mailboxes. If you use CellCog's cold-outreach feature, your AI Employee sends and receives email through dedicated outreach mailboxes — Google Workspace mailboxes on separate sending domains provisioned specifically for your outreach (never the Gmail account of any recipient). For these mailboxes:

  • Read: We read messages arriving at your outreach mailboxes so your AI Employee can see and respond to replies from the people you contacted. We poll each connected mailbox for new messages and store the correspondence in your AI Employee's mailbox history, exactly as described in the "AI Employees" section above.
  • Send: We send email from your outreach mailboxes on your behalf — the outreach messages and replies your AI Employee composes under your direction and within the sending limits and approvals you configured.

2. Your own Gmail account (optional). If you choose to connect your own Gmail account to your AI assistant, it can manage that mailbox at your direction: reading and triaging mail, sending and replying, organizing messages with labels and filters, managing drafts, deleting messages you ask it to remove, and looking up your own contacts (read-only, via Google People API scopes you approve at connection time) to resolve recipients. Automated actions are governed by the permissions and approval settings you configure; deletion only ever occurs at your explicit direction. You can disconnect your Gmail account at any time from CellCog or from your Google account's security settings, which revokes our access.

What we do with this Gmail data — and what we don't:

  • We use Gmail message data solely to provide these features to you: reading and triaging mail, threading conversations, sending mail you directed, and managing your mailbox at your direction. Message content your AI assistant reads to do its work is transmitted to the LLM provider serving it under zero-data-retention API terms, as described in "Data Sharing and Disclosure."
  • We do not use Gmail data for advertising. We do not sell it. We do not use it to train machine-learning or AI models. Humans do not read it, except with your explicit permission, where necessary for security or abuse investigation, to comply with applicable law, or where the data has been aggregated and anonymized for internal operations.
  • OAuth access tokens for connected mailboxes are encrypted at rest, and access is limited to the systems that operate the mailbox on your behalf.
  • You can disconnect any connected mailbox at any time (or delete your outreach domains), which revokes our access; you can also revoke access directly from your Google account security settings or Google Workspace admin console. Stored correspondence follows the retention rules above.

Limited Use disclosure: CellCog's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Google User Data (Google Analytics — your connected account)

Separately from the analytics cookies on our own website (described under "Cookies" below), you can optionally connect your own Google Analytics account to your AI assistant using OAuth, with your explicit authorization. When you do:

  • Read (analytics.readonly): Your AI assistant reads reports and metrics from your connected Google Analytics properties to answer the questions you ask about your website traffic and marketing performance.
  • Manage (analytics, analytics.edit): At your explicit direction, your AI assistant can manage your Google Analytics configuration — for example creating or updating properties, data streams, custom dimensions, and conversion events as part of analytics setup you requested. Every configuration change is initiated by your instruction and governed by the permissions and approval settings you configure.

We use your Google Analytics data solely to provide these features to you. Report data your AI assistant reads to do its work is transmitted to the LLM provider serving it under zero-data-retention API terms, as described in "Data Sharing and Disclosure." We do not use your Google Analytics data for advertising, do not sell it, and do not use it to train machine-learning or AI models; humans do not read it except with your explicit permission, where necessary for security or abuse investigation, or to comply with applicable law. OAuth tokens are encrypted at rest. You can disconnect your Google Analytics account at any time from CellCog or from your Google account's security settings, which revokes our access.

The Limited Use disclosure above applies equally to Google Analytics data received through Google APIs.

Your Responsibilities for People Your AI Employee Contacts

When you direct an AI Employee to contact people (for example, outreach emails), you are responsible for having a lawful basis to contact them and for complying with applicable anti-spam and data-protection laws — such as the U.S. CAN-SPAM Act, Canada's CASL, and the EU/UK GDPR and e-Privacy rules — including honoring opt-out and unsubscribe requests. For this correspondence, you determine the purpose and means of contacting your recipients (you act as the data controller for your outreach), and CellCog processes the correspondence on your behalf to operate the mailbox. A recipient who wishes to stop hearing from your AI Employee, or to exercise data-protection rights, can reply to the email or contact the human supervisor named in the signature; such requests are directed to you as the responsible party, and we will reasonably assist and, where we act as a processor, act on your documented instructions. See the Acceptable Use and AI Employees sections of our Terms of Service.

Information Collected Automatically

  • Usage Data: We collect information about how you interact with our Service, including features used, time spent, and actions taken.
  • Device Information: We may collect information about your device, including browser type, operating system, and device identifiers.
  • Log Data: Our servers automatically record information including IP address, browser type, referring/exit pages, and timestamps.

Cookies and Tracking Technologies

What Are Cookies?

Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience and understand how you use our service.

Types of Cookies We Use

1. Essential Cookies (No Consent Required)

These cookies are necessary for the website to function and cannot be switched off.

  • Cookie Name: session
  • Purpose: Authentication and session management
  • Provider: Firebase (Google)
  • Duration: Session-based (deleted when you close your browser)
  • Legal Basis: Strictly necessary for service provision (GDPR Article 6(1)(b))

2. Analytics Cookies

These cookies help us understand how visitors interact with our website. Whether we ask for consent before setting them depends on where you are (see "Managing Your Cookie Preferences" below): in regions whose law requires opt-in consent — the EU/EEA, United Kingdom, Switzerland, China, Canada, and South Korea — these cookies are set only after you accept; elsewhere they are used by default and you can turn them off at any time.

  • Cookie Names: _ga, _ga_* (Google Analytics 4)
  • Purpose: Measure website traffic, user behavior, and feature usage
  • Data Collected:
    • Pages visited and time spent
    • Click patterns and navigation paths
    • Device type, browser, and operating system
    • Geographic location (country/city level)
    • Referral source (how you found us)
    • User interactions (signups, logins, feature usage)
  • Provider: Google LLC
  • Duration: Up to 2 years
  • Data Transfers: To Google servers in the United States
  • Legal Basis: Your explicit consent (e.g., GDPR Article 6(1)(a)) in opt-in regions; our legitimate interest in understanding and improving our service (with a working opt-out at all times) elsewhere

Google Analytics 4 Details

  • Data Processing Agreement: We have a Data Processing Agreement with Google LLC
  • IP Anonymization: Enabled by default to protect your privacy
  • Data Retention: 2 months for event-level data, 14 months for user-level data (automatically deleted after)
  • Google Signals: Disabled (no cross-device tracking)
  • Advertising Features: Disabled (we don't use GA4 for advertising)

Product Analytics and Session Replay (PostHog)

In addition to Google Analytics, we use PostHog (PostHog Inc., a US provider) for product analytics and session replay on our website, to understand how visitors and new users interact with CellCog and to improve the product experience.

  • What is collected: page views, clicks, and interaction events; and for some sessions, a session replay — a reconstruction of how the page was used (mouse movement, scrolling, elements clicked).
  • What is NOT collected: anything you type into input fields is masked at the source and never leaves your browser (passwords, form fields). CellCog team and internal accounts are excluded from collection.
  • Logged-in usage: for signed-in users, we collect product interaction events (pages viewed and product controls clicked, such as navigation items), associated with your account, to understand feature usage and improve the product. What you type into the product (messages, documents, form fields) is never collected as analytics. Session replay of signed-in usage remains off by default; for limited, time-boxed periods we may enable session capture for signed-in usage to study onboarding and first-use friction; input masking always applies, and recordings from such periods are reviewed for product-improvement purposes only and deleted when no longer needed.
  • Account deletion: when you delete your CellCog account, the analytics person record associated with your account is deleted as well.
  • Retention: session recordings are retained for up to 30 days by default, then deleted automatically.
  • Your rights: you can request deletion of your analytics data or recordings by contacting us at the address in the Contact section.

Your Rights Regarding Analytics

  • Access your analytics data via Google's privacy dashboard
  • Request deletion of your analytics data by contacting us
  • Opt-out using the Google Analytics Opt-out Browser Add-on
  • Opt out or withdraw consent at any time via "Cookie preferences" in the page footer, or in your account under Privacy & Data (any region)
  • Global Privacy Control (GPC): if your browser sends the GPC signal, we treat it as an opt-out of analytics cookies automatically, everywhere, with no banner interaction needed

Managing Your Cookie Preferences

In regions whose law requires opt-in consent (EU/EEA, United Kingdom, Switzerland, China, Canada, South Korea): When you first visit our site, you'll see a cookie consent banner. You can:

  • Accept all cookies
  • Reject all non-essential cookies
  • Customize your preferences

Analytics cookies are not set until you accept. If you don't interact with the banner, analytics stays off and we won't show the banner again for a while rather than asking on every visit.

Everywhere else (including the United States): We don't interrupt your visit with a banner. Analytics cookies are used by default to improve our service, and you can opt out at any time through:

  • "Cookie preferences" (page footer), which opens the full consent panel
  • Your account settings, under Privacy & Data (for signed-in users)
  • The Global Privacy Control (GPC) browser signal, honored automatically as an opt-out
  • Your browser settings, or the Google Analytics Opt-out Add-on

Signed-in users: your cookie-consent choice is saved to your CellCog account, so it applies across all your browsers and devices and you won't be asked again.

List of Cookies

table
SourceNamePurposeDurationType
CellCog (Firebase)sessionAuthentication and session managementSessionEssential
CellCogcellcog_cookie_consentRemembers your cookie-consent choice1 yearEssential
CellCogcellcog_geo_cacheCaches region detection for the consent model24 hoursEssential
Google (GA4)_ga, _ga_*Analytics: traffic and usage measurementUp to 2 yearsNon-essential (analytics)
PostHogph_*Product analytics and session replay (see PostHog section)Up to 1 yearNon-essential (analytics)

We do not use any advertising, targeting, or cross-site tracking cookies.

Browser Controls

Most browsers allow you to control cookies through settings:

  • Chrome: Settings → Privacy and Security → Cookies
  • Safari: Preferences → Privacy → Manage Website Data
  • Firefox: Options → Privacy & Security → Cookies and Site Data

Learn more at: www.allaboutcookies.org

Note: Disabling cookies may affect your ability to use certain features of our Service.


How We Use Your Information

We use the collected information for the following purposes:

  • To provide, maintain, and improve our Service
  • To process and respond to your chat queries using AI technology
  • To manage your account and provide customer support
  • To send you important updates about the Service (Auto enabled on signup)
  • To analyze usage patterns and improve user experience
  • To detect, prevent, and address technical issues or abuse
  • To comply with legal obligations and enforce our Terms of Service
  • To facilitate collaboration features within project workspaces

Data Storage and Security

  • Storage Location: Your data is stored on Google Cloud Platform servers located in the United States.
  • Encryption: We use industry-standard encryption for data in transit (HTTPS/TLS) and at rest.
  • Access Controls: We implement strict access controls and authentication mechanisms to protect your data.
  • Third-Party Services: We use Firebase for authentication, Google Cloud Storage for file storage, MongoDB for database services, and Google Analytics for usage analytics.

Data Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

  • With Your Consent: We may share information when you give us explicit permission.
  • Within Your Organization: Content within project workspaces may be visible to other authorized members.
  • Service Providers: We share information with trusted third-party service providers who help us operate the Service. These include Google Cloud Platform (hosting and storage), Firebase (authentication), MongoDB Atlas (database), and Google Analytics (usage analytics).
  • Email Delivery (AI Employees): We use SendGrid (Twilio) to send and receive your AI Employee's email. SendGrid processes the message content, recipients, and attachments of that email as necessary to deliver and receive it on your behalf.
  • Integration Provider (Composio): For Personal Tools and connected-app triggers (the "wake conditions" that can start an AI Employee), we use Composio to broker authorized access to the third-party services you connect. Composio processes the connection and the data passed to and from those tools to execute the actions you authorize.
  • LLM Providers: To respond to your chat queries and complete agent tasks, we transmit your chat content — including messages, uploaded files, page content the agent reads (via Browse my Chrome), file/command output the agent reads (via Cowork), and the email content and connected-app data an AI Employee reads to do its work — to large language model providers. Current providers include Anthropic (Claude), OpenAI (GPT), and Google (Gemini). Each provider has agreed to zero data-retention for inference content via their API terms (i.e., they do not train on or retain your content beyond the immediate request). The specific provider used for a given chat depends on the model selected for that chat.
  • Analytics Provider (Google): When you consent to analytics cookies, anonymized usage data is shared with Google LLC for analytics purposes.
  • Legal Requirements: We may disclose information if required by law or in response to valid legal requests.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, your information may be transferred.

Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: You can request access to the personal information we hold about you.
  • Correction: You can update or correct your account information at any time.
  • Deletion: You can request deletion of your account and associated data.
  • Portability: You can request a copy of your data in a portable format.
  • Opt-out: You can opt-out of marketing communications at any time.
  • Cookie Preferences: You can manage your cookie preferences at any time.
  • Google Drive: You can disconnect Google Drive integration and revoke access at any time.
  • Gmail: You can disconnect outreach mailboxes or your own connected Gmail account at any time; this revokes CellCog's Gmail API access. You can also revoke access from your Google account security settings or Google Workspace admin console.
  • Google Analytics (connected account): You can disconnect your Google Analytics account at any time; this revokes CellCog's Google Analytics API access. You can also revoke access from your Google account security settings.

Additional Rights for EU/EEA Users

If you are located in the European Economic Area, you have additional rights including:

  • Right to Object: You can object to processing of your personal data
  • Right to Restrict: You can request restriction of processing
  • Right to Withdraw Consent: You can withdraw consent at any time (without affecting prior processing)
  • Right to Lodge a Complaint: You can file a complaint with your local data protection authority

List of EU Data Protection Authorities: EDPB Members


Data Retention

We retain your personal information for as long as necessary to provide our Service and fulfill the purposes described in this Privacy Policy. Specifically:

  • Account information is retained until you delete your account
  • Chat history is retained until you explicitly delete it
  • Uploaded files are retained until you delete them or your account
  • Usage logs are retained for up to 90 days
  • Analytics data: Event-level data retained for 2 months, user-level data for 14 months (Google Analytics 4)

Children's Privacy

Our Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. Some EU member states have set lower digital-consent ages (e.g., 13 in the UK and Ireland) — in those jurisdictions the local age applies, but our default policy is 16 to provide the strongest protection across the EU. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at privacy@cellcog.ai.


International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.

Analytics Data Transfers

When you consent to analytics cookies, your anonymized usage data may be transferred to and processed on Google servers located in the United States.

Legal Safeguards

  • Standard Contractual Clauses (EU Commission approved)
  • EU-US Data Privacy Framework participation (Google)
  • Data Processing Agreements with our sub-processors, including Google LLC, SendGrid (Twilio), and Composio
  • IP anonymization to minimize personal data collection

EU/EEA users have the right to object to international transfers. Contact us at privacy@cellcog.ai to exercise this right.


Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. For material changes, we will provide additional notice via email or through the Service.


Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

CellCog AI Email: privacy@cellcog.ai Website: https://cellcog.ai

Response Time: We aim to respond to all privacy requests within 30 days as required by GDPR.


© 2026 CellCog AI. All rights reserved.