Legal

Privacy Policy

Last updated: April 15, 2026

CognitivPulse (“we”, “our”, “us”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, why we collect it, and how we use it when you use our platform at cognitivpulse.com.

1. Information We Collect

a) Information you provide directly

  • Account data: Name, email address, and password when you register.
  • Profile data: Company name, role, and profile picture if you choose to provide them.
  • Payment data: Billing details processed securely by Stripe. We never store raw card numbers.
  • Contact form submissions: Name, email, issue type, and message when you contact support.
  • Campaign content: Email copy, images, and social posts you create within the platform.

b) Information collected automatically

  • Usage data: Pages visited, features used, clicks, and session duration.
  • Device & browser data: IP address, browser type, operating system, and referring URLs.
  • Cookies & tracking: See our Cookie Policy for full details.

c) Information from third parties

  • OAuth provider data (Google) when you sign in via social login.
  • Social platform data (Facebook, LinkedIn, Twitter/X, Instagram) when you connect your accounts for scheduling.

2. How We Use Your Information

We use the data we collect to:

  • Provide, operate, and maintain the CognitivPulse platform.
  • Process payments and manage your subscription.
  • Send transactional emails (account confirmations, invoices, password resets).
  • Deliver marketing emails only if you have opted in.
  • Improve and personalise your experience, including AI-assisted content suggestions.
  • Monitor platform performance and detect / prevent fraud or abuse.
  • Comply with legal obligations.

We do not sell or rent your personal data to third parties.

3. Legal Basis for Processing (GDPR)

If you are located in the European Economic Area, we process your data under the following legal bases:

  • Contract performance: Processing necessary to deliver the service you signed up for.
  • Legitimate interests: Analytics, security monitoring, and fraud prevention.
  • Consent: Marketing emails and non-essential cookies.
  • Legal obligation: Compliance with applicable laws and regulations.

4. Data Sharing & Disclosure

We share data only with trusted service providers who help us operate the platform:

  • Supabase — database and authentication infrastructure.
  • Stripe — payment processing.
  • Resend — transactional and marketing email delivery.
  • OpenAI — AI-powered content suggestions (no personally identifiable contact data is sent).
  • Sentry — error monitoring (anonymised stack traces).
  • Google Analytics 4 — aggregated product analytics.

We may also disclose information when required by law, court order, or to protect the rights and safety of CognitivPulse or its users.

5. Data Retention

We retain your personal data for as long as your account is active or as needed to provide services. If you delete your account:

  • Profile and campaign data is deleted within 30 days.
  • Billing records are retained for 7 years for tax and legal compliance.
  • Anonymised, aggregated analytics data may be retained indefinitely.

6. Your Rights

Depending on your location, you may have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectification — correct inaccurate or incomplete data.
  • Erasure — request deletion of your personal data (“right to be forgotten”).
  • Portability — receive your data in a structured, machine-readable format.
  • Objection — object to processing based on legitimate interests or for direct marketing.
  • Restriction — request that we limit processing in certain circumstances.

To exercise any of these rights, email us at privacy@cognitivpulse.com. We will respond within 30 days.

7. Data Security

We implement industry-standard security measures including:

  • Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
  • Row-level security policies on our database to enforce multi-tenant isolation.
  • Regular security audits and penetration testing.
  • Least-privilege access controls for all team members.

No method of transmission over the internet is 100% secure. In the unlikely event of a data breach that affects your rights and freedoms, we will notify you and the relevant authorities as required by law.

8. International Transfers

Our infrastructure is primarily located in the United States. If you are located in the EEA or UK, your data may be transferred to and processed in countries with different data protection laws. Where we transfer data internationally, we rely on approved mechanisms such as Standard Contractual Clauses (SCCs).

9. Children's Privacy

CognitivPulse is not directed to individuals under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it immediately.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or a prominent notice on the platform at least 14 days before the changes take effect. Your continued use of the platform after the effective date constitutes acceptance of the updated policy.

11. Contact

For privacy-related questions or requests: