1. Introduction
This Privacy Policy describes how Cortex ("Cortex," "we," "us," or "our") collects, uses, and shares your personal data, and what choices you have, when you use the Cortex mobile app, our website at cortexdesks.com, and related services (together, the "Services"). Cortex is built to collect as little as possible beyond what it needs to sync your notes and habits across your devices. By using the Services you agree to the practices in this policy. If you do not agree, please do not use the Services. Capitalized terms not defined here have the meaning given in our Terms of Service.
2. Information We Collect
A. Account information. Cortex requires an account, created with Google, Apple, or an email and password. At sign-up we collect an email address and, depending on the sign-in method you choose and whether you grant it, a name. Google and Apple each share only what their own sign-in flow discloses to you at the time. We never see your Google or Apple password.
B. Content you provide. The text of your notes, their category and priority, due dates, completion status, your habits, your habit check-ins, and any custom words you add to help transcription. This syncs to your account and is stored with Firebase (a Google Cloud service), which is what lets a note captured on one device show up on another. When you capture by voice, your speech is turned into text as described in section 4. We never store your voice recordings ourselves.
C. Usage and device data. We collect limited, content-free data about how the app is used and how it performs, using Firebase Analytics and Firebase Crashlytics. This includes events such as finishing onboarding, capturing a note (and whether it was by voice or text), creating or checking in a habit, viewing the paywall, and starting a trial. It also includes crash reports and error details, device model, operating system version, app version, language, and a random app-instance identifier. We tie this data to your account ID so we can count active users and measure crash rates. These events never contain the text of your notes or habits.
D. Purchase information. Premium purchases run through Apple's In-App Purchase system. We use RevenueCat to manage subscriptions, so RevenueCat receives purchase and subscription data, such as your subscription status and purchase history, tied to an anonymous or account identifier. We never receive or store your payment card or Apple ID payment details. Apple handles those.
E. Website and waitlist. If you join the waitlist on our website, we collect the email address you enter. If you sign in to the web dashboard, we process your account information through Firebase Authentication. If you set a name in the dashboard's Settings, it is saved to your account with Firebase Authentication so the app and the website can greet you by it. The Library's word suggestions are worked out inside your browser from notes it has already loaded, and nothing extra is sent anywhere to produce them. The website stores a theme preference (light or dark) in your browser's local storage. We do not use advertising cookies or third-party advertising trackers on the website.
F. Information you send us. If you email us for support or to make a privacy request, we keep that correspondence and any information you include in it.
G. What stays on your device. Your app settings (notification and lock preferences, theme, and a display name you set inside the app) and your Premium entitlement status are stored locally on your device. A name you set on the website is stored with your account instead, as described in E above.
3. How We Use Data
We use personal data to:
- Operate the Services. Create your account, store and sync your notes and habits, turn speech into text, sort captures, and send the reminders you turn on.
- Provide Premium. Unlock Premium features and manage your subscription.
- Understand and improve the app. Measure usage in aggregate, find and fix crashes, and decide what to build.
- Support you. Answer your questions and requests.
- Protect the Services. Detect and prevent fraud, abuse, and violations of our Terms.
- Comply with the law. Meet legal obligations and respond to lawful requests.
Where GDPR or similar laws apply, we process account and sync data on the basis of contract performance, analytics and diagnostics on the basis of our legitimate interest in maintaining and improving the app, and anything else with your consent or to comply with legal obligations.
4. Speech Recognition, AI, and Your Content
The app uses your microphone to let you capture notes by voice, and turns that speech into text in one of two ways depending on how you captured it.
In-app capture (the record button) stays on your device. Speech you capture by tapping the record button in the app is transcribed by Apple's Speech Recognition framework with on-device recognition required. The audio is never uploaded to Apple, to us, or to anyone else. If your device has not downloaded on-device recognition for your selected language, capture stops and asks you to download it rather than falling back to a network service. You can add languages under Settings → General → Keyboard → Dictation Languages.
Action Button and Shortcuts captures are transcribed in the cloud. When you capture with the Action Button or a Shortcut, the app records short audio and sends that recording to Groq, Inc., which runs a speech-to-text model on our behalf and returns the text. Along with the audio, the app sends the words you have added to your Library, so names and terms you use come back spelled your way. We use Groq because it transcribes multilingual and mixed-language speech far more accurately than on-device recognition. Groq acts as our service provider for this: it processes the audio only to produce the transcript, does not use it to train models, and retains it only transiently. Groq's handling is additionally governed by Groq's Privacy Policy.
Text cleanup. After a voice capture is saved, the app sends the text of that note (never audio) to Anthropic, PBC to correct transcription errors and classify it. With the text it sends the names of your habits and the words in your Library, so the cleanup can match a capture to a habit and leaves your own terms exactly as you spell them. Anthropic acts as our service provider for this, does not use the text to train models, and retains it only transiently. Anthropic's handling is additionally governed by Anthropic's Privacy Policy.
Dictation on the web dashboard. If you use the microphone button on the web dashboard, speech is turned into text by your web browser's own speech recognition, not by us. Depending on your browser, the browser sends that audio to its maker's speech service to transcribe it (for example Google for Chrome, Microsoft for Edge, or Apple for Safari), under that company's own privacy policy. We never receive the audio. Only the resulting text reaches the dashboard, where you can edit it before saving it as a note. The browser asks for your permission before it uses the microphone, and you can turn that permission off at any time in its settings.
We never store your voice recordings ourselves. A recording is discarded once it has been turned into text. The resulting text is a note like any other, and syncs to your account per section 2.
We never use your notes, voice transcripts, habits, or any other content to train artificial intelligence models, and we do not allow our service providers to.
5. Device Features and Permissions
Face ID. If you turn on "Lock Notes," the app asks iOS to verify your identity with Face ID before revealing that content. This uses Apple's on-device biometric system: the app receives only a yes or no result and never sees your face, fingerprint, or any biometric data.
Notifications. Reminders (urgent tasks, habit check-ins, and any digests you turn on) are scheduled locally on your device. No notification content is sent to us or to any third party, and no push notification server is involved.
Shortcuts and the Action Button. Capturing a note via Siri, the Action Button, or the Shortcuts app passes your text or recording from iOS to this app on your device via an iOS App Group. A recording captured this way is then sent to Groq for transcription, as described in section 4. Text captured this way is filed directly and does not leave your device except to sync to your account.
Calendar. If you choose to connect your calendar, the app reads and writes calendar items on your device using iOS's calendar permission, and only as you request.
6. Analytics, Diagnostics, and Tracking
We use Firebase Analytics and Firebase Crashlytics (Google Cloud services) for the usage and crash data described in section 2C. Google processes this data for us, and its handling is governed by Google's Privacy Policy in addition to this one.
We do not run advertising, we do not use advertising networks, we do not use your data for targeted advertising, and we do not track you across other companies' apps or websites. We do not access your device's advertising identifier.
7. Retention of Data
- Account and sync data. We keep your notes, habits, and check-ins for as long as your account exists. If you delete your account (Settings → Delete account), they are permanently deleted from our servers along with your account itself. This is irreversible. Encrypted backups maintained by our infrastructure provider may persist for a limited period under its standard backup procedures before they are overwritten.
- Usage and crash data. Kept by Google under the retention settings of Firebase, and used in aggregate.
- Voice recordings. Not retained by us. Groq retains audio only transiently to produce the transcript, and Anthropic retains text only transiently.
- Waitlist emails. Kept until we have contacted you about the launch, or until you ask us to delete them.
- Support emails. Kept for as long as needed to help you and to keep a record of the request.
- Legal reasons. We may keep information longer where required by law, to resolve disputes, or to enforce our agreements.
8. Transfer of Data
Cortex is operated from the United States and our service providers process data in the United States and other countries where they or their subprocessors operate. If you use the Services from outside the United States, your data will be transferred to and processed in the United States, where data protection laws may differ from those where you live. We take steps reasonably necessary to make sure your data is treated securely and in line with this policy, including using providers that maintain appropriate transfer safeguards.
9. Sharing With Others
We do not sell your personal data. We share it only in these cases:
- Service providers acting on our behalf. Firebase and Google (storage, sync, sign-in, analytics, crash reports), RevenueCat (subscriptions), Apple (sign-in and in-app purchases), Groq (transcription of Action Button and Shortcut recordings, with your Library words), and Anthropic (text cleanup of captures, with your habit names and Library words). They may use your data only to provide services to us, and AI providers are prohibited from training on it.
- Legal and safety. To comply with law, a court order, or a government request, and to protect the rights, property, or safety of Cortex, our users, or the public.
- Business transfers. In connection with a merger, sale of assets, financing, or acquisition, in which case the recipient would be bound to honor this policy.
- With your consent. When you ask us to or agree to it.
10. What We Don't Do
- No advertising, no ad networks
- No selling of your data, and no sharing it beyond the service providers named in this policy, who act on our behalf to run the app
- No access to your contacts, photos, or other apps
- We never use your content to train AI models
11. How We Secure Your Information
Your synced data is encrypted in transit (TLS) and at rest by Firebase. Local data on your device is protected by iOS system encryption and, if you enable Lock Notes, by Face ID or your device passcode. We do not have access to your payment details. No method of transmission or storage is 100% secure, so we cannot guarantee absolute security.
12. Your Rights
Everyone can:
- Delete a note or habit in the app or on the web dashboard, any time, including several habits at once.
- Delete your account from Settings → Delete account, which permanently removes your account and everything synced to it from our servers.
- Get a copy of your data: email us at cortexapp.support@gmail.com and we will send you what we hold for your account.
- Turn off notifications, Face ID lock, and the microphone at any time in the app or in iOS Settings.
If you are in the European Economic Area, the United Kingdom, or Switzerland, you also have the right to access, correct, or delete your personal data, to object to or ask us to restrict our processing of it, to receive it in a structured, machine-readable format, and to withdraw consent where we rely on it. You have the right to complain to your local data protection authority. Email us to exercise these rights. We may ask you to verify your identity first, and we will respond within 30 days.
13. Privacy Notice for California Residents
If you are a California resident, the California Consumer Privacy Act (CCPA) gives you the right to know what personal information we collect, use, and disclose, to request deletion or correction of it, and not to be discriminated against for exercising your rights.
- Categories we collect (see section 2): identifiers such as email address and account ID; commercial information such as subscription status; internet or app activity such as usage events and crash data; and the content you create in the app.
- Sources: you, your device, and the sign-in and purchase providers you use.
- Purposes: those in section 3.
- Sale and sharing: we do not sell personal information, and we do not share it for cross-context behavioral advertising.
- How to make a request: email cortexapp.support@gmail.com. We will verify your identity and respond within 45 days. You may use an authorized agent, and we may ask for proof of their authority.
14. Children
The Services are not directed at children under 13, and we do not knowingly collect data from children under 13. If you are a parent or guardian and believe your child gave us personal data, contact us at cortexapp.support@gmail.com and we will delete it.
15. Links to Third-Party Websites
The Services may link to third-party websites or services, such as Apple's subscription pages or our providers' privacy policies. We are not responsible for their content or practices, and their privacy policies, not this one, govern what they collect.
16. Changes to This Privacy Policy
If this policy changes, we will update the date at the top. If a change meaningfully reduces your rights, we will tell you, for example by email or a notice in the app. Changes are not retroactive. Continued use of the Services after a change means you accept the update.
17. Contact Us
Questions about this policy, or requests to exercise your privacy rights: cortexapp.support@gmail.com