Cortex
PrivacyTermsData processing

Privacy notice · last updated August 30, 2026

Company data stays tied to the work you asked Cortex to do.

This notice explains how Ben Kilby processes account, business, and connected-service data in Cortex. It covers the pre-release design-partner service and the Google Workspace access requested by the production OAuth application.

Product roleBusiness service provider

Cortex processes company data to deliver owner-visible product features.

AdvertisingNo sale or ad use

Connected-service data is not sold, brokered, or used for advertising.

AI trainingNo Cortex model training

Cortex uses approved inference routes, not partner data to train a Cortex model.

Publication statusProduction identity configured

The deployed operator name and monitored privacy mailbox are configured.

What Cortex receives

Only data needed for the selected product paths.

  • Account and company data: identity and membership references, company settings, roles, security events, product activity, and support or privacy requests.
  • Business data the company supplies or connects: invoices, payments, customers, CRM records, public-channel messages, approved web-search results, and the evidence and outputs Cortex derives from those sources.
  • Operational data: redacted request and error metadata, job and model-route status, token and cost counts, audit receipts, device or network metadata, and security signals. Cortex policy forbids tokens, OAuth payloads, or customer content in founder operations and routine diagnostic evidence.

Google user data

The five requested grants have visible product purposes.

  • Gmail read access supplies message headers, bodies, participants, and thread context from an owner-selected bounded history window for invoice context, cited knowledge, briefs, and owner questions.
  • Gmail compose access creates reviewable drafts and, only after the shipped gateway authorizes it, sends an owner-approved Invoice Chaser or Lead Responder message. New partner agents start draft-only and cannot perform a final send.
  • Calendar event read access supplies titles, descriptions, attendees, and times for customer commitments and collection timing. Cortex does not request a Calendar write scope.
  • Drive read access supplies names, types, modification times, sharing context, and supported text content from the authorized proposal library. Per-file Drive access creates a proposal or inserts approved content only in a file Cortex created or the user explicitly shared with Cortex.

Cortex uses Google user data only for prominent, user-facing Cortex features, service security, and legal compliance. It does not use Google data for ads, credit decisions, data brokerage, or personalized AI-model training. Humans do not routinely read Google content; access is limited to a user’s affirmative support request, necessary security investigation, or legal obligation.

Storage and processors

Credentials and business records take different paths.

Nango brokers the connected account and stores provider credentials; Cortex does not store Google refresh tokens. Cortex stores normalized source records, searchable memory, cited facts and relationships, drafts, audit history, and other derived product state in its company-isolated data store. Restricted Google data is therefore transmitted through and stored on Cortex-appointed server systems.

Relevant excerpts may be sent to a company-approved inference route to create embeddings, structured analysis, and agent previews. The connection disclosure names the selected processors and their current training and retention posture before ingestion. Cortex’s current technical service register is published on the data-processing page.

Retention and control

Collection limits and deletion are separate controls.

  • The owner chooses a bounded initial Gmail history window. That limit controls collection; it is not a promise that synchronized or derived data automatically expires after the same number of days.
  • Withdrawing Cortex processing consent stops dependent connection use and ingestion in Cortex. Removing Cortex under Google Account third-party connections revokes Google-side access. Neither action alone erases records already synchronized into Cortex.
  • Owners and admins can request a complete portable company export. Owners can request permanent company deletion through the shipped exact-company confirmation flow. Export objects expire on the configured short retention schedule; database backups and vendor systems follow their configured or contractual recovery periods.
  • Production backup periods and contractual request deadlines are not invented on this page. They must be confirmed in the executed customer agreement and deployed service configuration.

Security and choices

Company boundaries remain part of the privacy promise.

Company data queries use forced row-level security, mutations append redacted audit receipts, secrets stay in encrypted environment settings, and external writes cross a central approvals-aware gateway. These are implemented controls, not a claim that Cortex is SOC 2 certified. Read the security page for the current posture.

A business owner can ask to access, correct, export, or delete company data through the authenticated Cortex account path. Applicable legal rights and deadlines depend on the person, company, location, and executed agreement; Cortex does not infer them from an unauthenticated email.

Privacy contact

Use the monitored channel, never a placeholder.

Contact bkwhop@bkwhop.com. Authenticate account-specific requests through Cortex before data is disclosed or deleted.

Read the pre-release terms

Cortex