CortexLegal

Last updated · September 16, 2026

Privacy Policy

Cortex is a personal knowledge workspace — your reading, notes, plans, goals and career pipeline in one place. This policy explains, in plain language, what we collect, why we collect it, who touches it, and the controls you have. The short version: your workspace content is yours, we never sell it, and AI features only see it at the moment you ask for help with it.

01

Who we are

Cortex (“the service”) is operated from Pakistan as part of the Scrutinies project, accessible at cortex.scrutinies.dev. For any privacy question, data request or complaint you can write to support@scrutinies.dev. Product and partnership enquiries go to hello@scrutinies.dev. We aim to acknowledge every request within 72 hours.

02

What we collect

The service stores the following categories of data, all tied to your account:

  • Account data:
  • your name, email address, a salted hash of your password (never the password itself), and whether your email is verified. If you connect Google, we additionally store the OAuth tokens and connected Gmail address needed for the import features.
  • Workspace content:
  • documents and PDFs you upload, extracted text, highlights, notes, flashcards, mind maps, goals, milestones, tasks, plans, reminders, focus sessions, reading sessions, and the jobs, scholarships and articles you save or track.
  • Derived data:
  • AI-generated summaries, takeaways and answers you request; citation positions; spaced-repetition scheduling state (SM-2); usage counters that enforce free-plan limits.
  • Operational metadata:
  • timestamps of feed syncs, your learning timezone offset (to build day windows for the morning briefing), server logs, and rough country from your IP when you start a checkout (used only to route you to the right payment provider).
03

What we deliberately do not do

  • We do not sell, rent or trade your personal data — with anyone, ever.
  • We do not run advertising or third-party tracking pixels inside the app.
  • We do not use your library content to train AI models. Model providers process your prompts ephemerally to answer your request; they receive no instruction to retain it.
  • We do not read your Gmail unless you explicitly connect it, and the connection is limited to read-only scopes used by the application-status and offer-detection import.
04

AI processing

Features such as the Copilot, document Q&A, summaries, flashcard and mind-map generation send a task-scoped snippet of your content (for example, the document you are asking about, or the highlight you selected) to a third-party large language model provider over an encrypted connection. Responses are stored in your workspace so you can revisit them. Prompts are not used to market to you, and the free daily/monthly limits are enforced with simple counters (day and month of use per feature) that contain no content.

05

Email and the morning briefing

We send transactional email — verification codes, password resets — and the optional daily morning briefing that summarises your own deadlines, reminders and upcoming horizons. The briefing is generated from your workspace each morning and sent to your account email address only. Outgoing mail is delivered through reputable email providers (currently Resend, SendGrid or SMTP relays) from our hello@scrutinies.dev address; replies and support requests are handled at support@scrutinies.dev. Every briefing links back to the app where you can adjust your agenda, and transactional email cannot be unsubscribed from while you hold an account because it authenticates critical actions.

06

Third-party processors

We rely on a small set of infrastructure providers. Each processes data only to deliver its function:

  • Vercel — application hosting, serverless functions, cron scheduling and edge network.
  • Neon — managed PostgreSQL database where workspace data lives.
  • Cloudflare — R2 object storage for uploaded PDFs; also DNS and email routing for the scrutinies.dev domain.
  • Google — optional sign-in and read-only Gmail import, activated only by you.
  • AI model providers — ephemeral processing for AI features you invoke.
  • Email delivery providers — verification codes and briefings.
  • Lemon Squeezy (Merchant of Record) and Safepay — payment processing for Pro subscriptions; they receive your billing email and payment details, never your workspace content.
07

Data retention and deletion

Your workspace data is retained for as long as your account is active. Deleting an item (a document, note, task, or mind map) removes it and, where applicable, its stored file. You can export your library data from the app at any time. When you delete your account — or ask us to delete it via support@scrutinies.dev — workspace content, AI outputs and payment linkage on our side are removed within 30 days, except records we must keep for tax, fraud-prevention or legal-defence purposes (typically minimal billing identifiers held by our payment providers under their own policies).

08

Security

Passwords are stored as salted, iterated hashes and are never recoverable by staff. Traffic is encrypted in transit (HTTPS). Session cookies are signed and HTTP-only. PDFs in object storage are served through short-lived authenticated URLs rather than public links. Access to production systems is limited to the operator. No system is perfectly secure; if a breach affecting your data ever occurs, we will notify affected users promptly and describe what happened and what we did about it.

09

Your rights and choices

  • Access & portability — export your library and data from the app, or ask us for a copy at support@scrutinies.dev.
  • Correction — edit any content in place; account email support at support@scrutinies.dev.
  • Deletion — delete items or your whole account (see section 07).
  • Objection to AI processing — AI features are opt-in per action; simply do not invoke them.
  • Disconnect Google — revoke from the app's settings and from your Google Account security page.

If you are in the EEA, UK or another jurisdiction with statutory data-protection rights, you may also lodge a complaint with your local supervisory authority. We would appreciate the chance to fix things first — write to support@scrutinies.dev.

10

Children

Cortex is intended for students and professionals and is not directed at children under 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly create accounts for children. If you believe a child has registered, contact support@scrutinies.dev and we will remove the account and its data.

11

Changes to this policy

As the product grows (new AI features, new feed sources, new payment options) this policy will be updated to match. Material changes — anything that reduces your control or adds a new data category — will be announced in the app or by email before they take effect. The “Last updated” date above always reflects the current version, and previous versions are available on request.