Legal · Privacy
Privacy Policy.
This policy explains what data CogniLead collects about you when you use cognilead.ai, why we collect it, how long we keep it, and what rights you have over it. CogniLead is a managed cold-email deliverability engine: you supply the lead data (via the dashboard or the /api/v1/leads API) and CogniLead runs email outbound on your behalf. It also generates AI content scaffolding. The recipient addresses you reach with outbound are covered by our outbound hygiene commitments below, not a separate data agreement.
1. Who we are
CogniLead is a product operated by Medishift (a Switzerland-based entity; CogniLead GmbH is in formation). The service is offered at cognilead.ai. The controller for the personal data described in this policy is the operating entity above.
For any privacy-related question, write to privacy@cognilead.ai. For data-protection matters specifically, write to dpo@cognilead.ai.
2. What we collect
We collect three categories of personal data about our users:
a. Account data
- Email address
- Display name
- OAuth provider identifier when you sign in with Github or Google
- Workspace name you choose during onboarding
- Plan and billing identifiers when you subscribe to a paid tier
b. Operational data
- API request logs: HTTP method, path, status code, source IP, user-agent — persisted to the
api_callstable for debugging and abuse prevention - Session cookies necessary to keep you signed in
- CSRF tokens used to protect form submissions
c. Outbound campaign data
When you run outbound campaigns, CogniLead handles the recipient addresses you supply (through the dashboard or the /api/v1/leads API), the messages you send, and the resulting delivery, bounce, reply, suppression, and unsubscribe records. We process this data only to operate your campaigns and to enforce outbound hygiene: honouring suppression lists and RFC 8058 one-click unsubscribe. We do not build, enrich, or rank a company universe ourselves, and we do not source recipient addresses for you — you supply the leads.
3. Legal basis
We rely on two grounds for processing the personal data described above:
- Contract performance. Account data and session cookies are necessary to provide the SEO generation and outbound service you have asked us to provide.
- Legitimate interest. Operational logs, abuse prevention, security monitoring, and limited outbound communications to our own business prospects rely on our legitimate interest in operating the service safely and reaching relevant contacts. Every outbound message carries a working one-click unsubscribe, and you can object at any time using the contact details below.
We do not use consent (Article 6(1)(a)) as the primary lawful basis for any of the categories above; we do not run any consent-based tracking. If we ever introduce a feature that requires consent, you will be asked explicitly and may withdraw at any time.
4. Retention
- Account data: kept until your account is deleted, then a 30-day grace window for recovery before hard deletion.
- API request logs: 90 days, after which they are aggregated for security analytics and the raw rows are dropped.
- Financial records: 7 years, as required by Swiss accounting and tax law (CO 958f). This is the only retention period that survives account deletion.
- Outbound campaign records: kept while the campaign is active and for analytics afterward; suppression and unsubscribe entries are kept indefinitely so we never re-contact someone who opted out.
- Backups: 30-day rolling snapshots (see Security). A deletion request propagates to backups within one full rotation cycle.
5. Sub-processors
We use the following sub-processors to deliver the service. We share only the data each one needs to perform its function.
- Supabase — authentication, multi-tenant Postgres database, and row-level security.
- Resend — outbound and transactional email delivery, plus inbound reply and bounce webhooks.
- Cloudflare — application hosting and edge network.
- Stripe — billing (activated only when paid plans are enabled).
- phi-cloud — our LLM provider. It powers AI content scaffolding and the personalisation of outbound messages. CogniLead does not use phi-cloud's HIPAA / patient-data tier and sends it no health data.
6. International transfers
Account data, operational logs, and outbound campaign records are stored in our primary database region. To run the service we share the minimum necessary data with the sub-processors listed above, some of which operate globally distributed infrastructure.
When SEO content is generated or an outbound message is personalised, the relevant prompt and context are sent to our LLM provider, phi-cloud. Where personal data crosses a border to reach a sub-processor, we rely on appropriate safeguards such as Standard Contractual Clauses.
7. Your rights
Depending on where you live, you may have the following rights over your personal data:
- Access — request a copy of what we hold about you.
- Rectification — correct anything that is wrong.
- Erasure — ask us to delete your data.
- Portability — receive your data in a machine-readable format.
- Restriction — limit how we use your data.
- Objection — object to processing based on legitimate interest.
- Withdrawal — withdraw any consent you may have given.
We honor these requests within 30 days. To exercise any of them, email privacy@cognilead.ai. If you received an outbound message from us and simply want it to stop, use the one-click unsubscribe in that message and you will be added to our permanent suppression list. Where applicable, you also have the right to lodge a complaint with your data-protection authority.
8. Cookies
We use strictly necessary cookies only: a session cookie that keeps you signed in, and a CSRF token that protects form submissions. We do not use analytics cookies, marketing cookies, advertising pixels, third-party tracking tags, or fingerprinting. There is no cookie banner because there is nothing to opt out of.
9. Security
We treat security as part of the product. TLS 1.3 for all traffic, MFA enforced on the dashboard, Postgres Row Level Security keyed on tenant identifier, and daily encrypted backups in a separate region. The full posture is documented at /legal/security.
10. Changes
We will give you at least 30 days notice for any material change to this policy, by email to the address on your account and by a visible notice on the dashboard. Non-material changes (typos, clarifications) are published silently with an updated date at the top of this page.
11. Contact
Privacy questions: privacy@cognilead.ai.
Data-protection matters: dpo@cognilead.ai.