Privacy Policy
Last updated 30 August 2026. This notice describes how Cognivault handles personal data. It reflects what the software actually does; it is not legal advice and should be reviewed by a qualified adviser before publication.
Who is responsible for your data
The data controller for Cognivault is Nikah AI Ltd, registered at Office 1216, 60 Tottenham Court Road, Fitzrovia, London, W1T 2EW, United Kingdom (company number 17199968, ICO registration C1961639). Privacy questions and data-rights requests go to support@cognivault-ai.com.
What we collect
- Account data. Your name, email address, profile image if you supply one, your role, whether you have completed onboarding, and the date the account was created. If you sign in with a password, a hashed credential is stored; we never hold the password itself.
- Workspace content. Everything you choose to put into a workspace: decision briefs and their sources, reasoning-profile sessions, answers and entries, operating-memory records and their revisions, outcome reviews, and Ask threads and messages. This content is yours and may contain whatever you type into it, so avoid entering personal data you do not need to record.
- Team data. Workspace names, membership and roles, and the email addresses you invite.
- Billing status. The plan, subscription status and trial end date held against your workspace. Card details are never entered on this site — see billing terms.
- Analytics, only if you accept it. See the next section.
Cookies and analytics
The only analytics SDK loaded by this site is PostHog. When — and only when — you accept it on the banner, PostHog is initialised and will:
- set a first-party PostHog cookie and a matching entry in your browser’s local storage, holding a randomly generated analytics identifier and session identifier;
- record a page view for each page you open, and autocapture interactions such as clicks on links and buttons, with the page URL and element details;
- store any
utm_source,utm_mediumandutm_campaignvalues from your arriving link in session storage, and attach them plus your analytics identifiers to the checkout link if you start a purchase, so the order can be matched to its source.
If you reject, or have not answered, none of that runs: no PostHog request is made and nothing is written to your device beyond the record of your own choice, which is strictly necessary and stored in local storage under cognivault.analytics-consent. Your session cookie for signing in is also strictly necessary and is not covered by the banner. You can change your mind at any time:
Why we use it, and on what basis
- To provide the service you signed up for — accounts, workspaces, briefs, memory and Ask. Lawful basis: performance of a contract.
- To keep the service secure and working, and to answer support requests. Lawful basis: legitimate interests.
- To understand how the site is used and where sign-ups come from. Lawful basis: consent, which you give or withhold on the banner.
- To meet accounting and tax obligations on paid accounts. Lawful basis: legal obligation.
Who we share it with
- OVH — provides the server this application runs on. We rent a virtual private server from OVH and operate it ourselves; OVH supplies the machine and the network, and its infrastructure handles the traffic and connection logs that come with that.
- Our own Convex backend — the application database and the authentication system run on a self-hosted Convex deployment on that same server. All account data and workspace content is stored there, under our control. It is not sent to Convex’s hosted service, and Convex the company does not receive it.
- Stripe — handles payment for a paid plan. When you start an upgrade, this application asks Stripe to create a Checkout Session and sends you to Stripe’s own hosted checkout page, so your card details are given to Stripe and never reach us or this server. Stripe returns the plan, the subscription status and an identifier for the subscription, which we store to know what your workspace is entitled to. Stripe also hosts the billing portal where an existing subscriber changes seats or cancels.
- OpenAI — when the Ask and Decision Brief analysis features run, the workspace context relevant to your question, and the question itself, are sent to the OpenAI chat completions API for analysis. If the operator has not configured an OpenAI key, those features fall back to a local, non-AI summary and nothing leaves the system.
- PostHog — receives the analytics events described above, and only with your consent.
Some of these providers process data outside the UK. The transfer safeguard relied on for this deployment is the UK International Data Transfer Addendum to the EU Standard Contractual Clauses. We do not sell personal data and we do not use it for advertising.
How long we keep it
Account data and workspace content are kept for as long as the account exists. When you delete your account, deletion is immediate and is described in full on the account deletion page. Analytics records are kept for as long as the PostHog project retains them. Billing records connected to a paid plan are kept for six years from the end of the accounting period the record falls in, which is the retention HMRC requires of a UK limited company to meet accounting and tax obligations.
Your rights
If you are in the UK or the EEA you have the right to access, correct, delete, restrict or object to the processing of your personal data, the right to data portability, and the right to withdraw consent at any time — withdrawing analytics consent takes effect immediately using the control above. Deletion can be exercised yourself, in the app, without contacting us. For anything else, write to support@cognivault-ai.com. You also have the right to complain to the Information Commissioner’s Office at ico.org.uk/make-a-complaint.
Children
Cognivault is a workplace tool and is not directed at children. We do not knowingly collect data from anyone under 16.