Cogently Back to App

Effective Date: July 29, 2026

Cogently Privacy Policy

This policy explains how Cogently ("Cogently", "we", "us"), operated by Stryker Capital LLC, 7995 Blue Diamond Rd, Las Vegas, NV 89178, collects, uses, shares and protects information when you use cogently.app and related services (the "Service"). It is written to align with the EU and UK GDPR and the California Consumer Privacy Act as amended by the CPRA.

1. The Short Version

  • Your pitch deck is sent to third-party AI providers to produce your audit. We do not permit them to train their models on it. See §4.
  • You can get a preview audit without an account. We do not store that deck. See §3.1.
  • We never see your card number — Stripe handles payment.
  • We run advertising pixels. Under California law that counts as "sharing" personal information, and you can opt out. See §7 and §9.
  • We do not sell your personal information for money.

2. Who We Are

Stryker Capital LLC is the data controller for the Service. Contact: privacy@cogently.app. We have not appointed a Data Protection Officer, as we are not required to.

3. What We Collect

3.1 Deck content you submit

  • Signed-in audits. Pitch text, uploaded PDF/PPTX files, Google Slides links, deal parameters (ask, valuation, terms, stage), coaching messages and any drafts. This may contain confidential business information — treat it as you would any document you share with an outside adviser.
  • Anonymous preview audits. If you use the preview scorer on the home page without an account, the text you paste is sent to our AI provider to generate a score and is not written to our database. It exists only for the lifetime of that request. We log no copy of it.
  • Files you upload are stored in Google Cloud Storage so your audits remain viewable in your history.

3.2 Account and identity

  • Name, email address and the sign-in method you chose (Google, Apple, or email and password), handled by Firebase Authentication.
  • If you sign in with Apple using Hide My Email, we receive only the relay address and never your real one.
  • Acceptance records. When you accept these terms we store the timestamp, the document versions, your sign-up method, your IP address and your browser user-agent. This is kept as evidence of agreement and for no other purpose.

3.3 Payment

Payments are processed by Stripe. We receive your subscription status, plan, and limited billing metadata. We do not collect, see or store your full card number. If you join our affiliate programme, Stripe Connect additionally collects your tax identity (W-9 or W-8BEN) directly — that information goes to Stripe and never reaches us. See §5.

3.4 Usage, device and analytics

  • Pages viewed, features used, audit scores, approximate location inferred from IP, browser and device type.
  • Server logs including IP address, retained for security and abuse prevention.
  • Article view counts on our blog — aggregate only, with no visitor identifier attached.

3.5 Communications

  • Newsletter. Your email address, on double opt-in only: we send one confirmation email and nothing further unless you click the link in it. Delivery is handled by Resend. Every email carries a working unsubscribe link.
  • Support correspondence you send us.

4. AI Processing — Read This One

Producing an audit requires sending your deck content to third-party AI providers. This is the core of how the Service works and cannot be turned off while still using it.

  • Providers currently used: Google (Gemini) and Anthropic (Claude).
  • We use these providers under terms that prohibit training their models on your content. We do not train any model on your deck, and we do not use one customer's deck to inform another's audit.
  • Providers may retain content briefly for abuse monitoring under their own policies. We do not control that retention.
  • AI output can be wrong. Scores, red flags and rewrites are generated text, not verified fact and not professional advice. See our Terms of Use.
  • Do not paste anything you are not free to disclose — material under a strict NDA, personal data about third parties, or regulated data such as health or payment-card information.

5. Who We Share With

We do not sell your personal information. We share it with service providers who process it on our behalf:

ProviderPurposeWhat it receives
Google Cloud / FirebaseHosting, database, authentication, file storageEssentially all Service data
Google (Gemini)AI audit generationDeck content
Anthropic (Claude)AI audit generationDeck content
StripePayments, affiliate payouts, tax formsEmail, billing data, tax identity
ResendTransactional and newsletter emailEmail address, message content
PromoteKitAffiliate referral trackingReferral identifier, purchase events
Google AnalyticsProduct and campaign analyticsUsage events, device, approximate location
Meta, LinkedInAdvertising measurementPage views, conversion events
LinkedIn (publishing)Only if you connect your accountYour access token and posts you publish

We may also disclose information where required by law, to enforce our terms, to investigate fraud, or in connection with a merger or sale of assets — in which case we will give notice before your information becomes subject to a different policy.

6. Why We Are Allowed To (GDPR Legal Bases)

  • Contract — creating your account, running audits, taking payment.
  • Legitimate interests — security, fraud prevention, service improvement, keeping records of your agreement to our terms.
  • Consent — newsletter subscription and non-essential advertising cookies. Withdrawable at any time.
  • Legal obligation — tax and accounting records.

7. Cookies, Pixels and Local Storage

  • Strictly necessary — your login session. The Service cannot work without it.
  • Analytics — Google Analytics 4, to understand which features are used and which campaigns work.
  • Advertising — the Meta Pixel and LinkedIn Insight Tag measure ad conversions and enable retargeting.
  • Local storage — we store a flag in your browser recording that you have seen or dismissed our email prompt, so you are not shown it repeatedly. It contains no personal information.

California residents: use of the advertising pixels above constitutes "sharing" for cross-context behavioural advertising under the CPRA. See §9 to opt out. You can also block these with browser privacy settings or an ad blocker, which we do not attempt to circumvent.

8. How Long We Keep It

  • Account and audits — while your account is open, then deleted within 90 days of account deletion.
  • Anonymous preview decks — not stored at all.
  • Payment and tax records — as long as tax law requires, typically seven years.
  • Acceptance records — for as long as the account exists plus any applicable limitation period, because their purpose is evidential.
  • Newsletter — until you unsubscribe, plus a suppression record so we do not email you again by mistake.
  • Server logs — typically 30 to 90 days.

9. Your Rights

If you are in the EEA or UK: you have the right to access, correct, delete, restrict or object to processing, to data portability, and to withdraw consent. You may also lodge a complaint with your supervisory authority.

If you are in California: you have the right to know, delete, correct, and to opt out of sale or sharing, and not to be discriminated against for exercising those rights. We do not sell personal information for money, but we do "share" it for advertising as described in §7.

To exercise any right, or to opt out of advertising sharing, email privacy@cogently.app. We respond within 30 days (45 for California requests, extendable where permitted). We will ask you to verify control of your account email before acting.

10. International Transfers

We are based in the United States and our providers are largely US-based, so data about EEA and UK users is transferred to the US. Where required we rely on the European Commission's Standard Contractual Clauses, the UK Addendum, or a provider's certification under the EU-US Data Privacy Framework.

11. Security

Encryption in transit and at rest, access controls on production systems, and authentication managed by Firebase. Payment card data never touches our servers. No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal data we will notify you and any regulator as required by law.

12. Children

The Service is not directed to anyone under 18 and we do not knowingly collect their data. If you believe a child has provided us information, email us and we will delete it.

13. Changes

We may update this policy. The effective date above changes, and material changes will be notified in-product or by email before taking effect. Continued use afterwards means acceptance.

14. Contact

Privacy: privacy@cogently.app · General: hello@cogently.app
Stryker Capital LLC, 7995 Blue Diamond Rd, Las Vegas, NV 89178, USA.