On this page
- 1. Who We Are
- 2. Personal Information We Collect
- Information you provide to us
- Information we collect automatically
- Information from third parties
- 3. How We Use Personal Information
- 4. AI Workloads and Customer Content
- 5. How We Disclose Personal Information
- 6. Cookies and Similar Technologies
- 7. International Data Transfers
- 8. Data Retention
- 9. Security
- 10. Your Choices and Rights
- 11. Notice for California Residents
- Categories Collected
- Sources
- Purposes
- Disclosure
- Sale or Sharing
- Sensitive Personal Information
- California Rights
- 12. Children
- 13. Third-Party Links and Services
- 14. Changes to This Privacy Policy
- 15. Contact Us
This Privacy Policy explains how CogFoundry Pte. Ltd. (Singapore UEN 202603662E, “CogFoundry”, “we”, “us”) collects, uses, discloses, and protects personal information when you use CogFoundry websites, the CogFoundry console, Model Center, LoomLoom, SkillBot Marketplace, APIs, documentation, support channels, and related services (together, the “Services”). At launch, this single Privacy Policy is intended to apply to all of the Services listed above.
By using the Services, you acknowledge that we process personal information as described in this Privacy Policy. If you use the Services on behalf of an organization, you are responsible for making sure that your organization has the rights and notices needed to provide personal information and Customer Content to CogFoundry.
1. Who We Are
- Controller / business: CogFoundry Pte. Ltd. (Singapore UEN 202603662E)
- Privacy contact / data protection contact: [email protected]
For account administration, billing, website activity, support, and marketplace participation, CogFoundry generally acts as the controller or business responsible for the personal information described in this Privacy Policy.
For Customer Content that you submit for execution through APIs, LoomLoom, SkillBot Marketplace, or other AI Workloads, CogFoundry may act as a service provider or processor on behalf of the customer, depending on the applicable agreement and product configuration.
For the current launch, CogFoundry uses the privacy contact above as its public data protection contact. CogFoundry does not list a separate EU or UK representative in this Privacy Policy. If the Services are later offered in a way that requires an EU or UK representative, a formally appointed DPO, or another local representative under applicable law, CogFoundry will update this Privacy Policy and related notices as required.
2. Personal Information We Collect
We collect the following categories of personal information, depending on how you use the Services.
Information you provide to us
You share this information directly when you create an account, complete payment onboarding, run workloads, or contact us.
| Category | Examples |
|---|---|
| Account information | Name, email address, password or login method, organization, role, profile settings, account status |
| Business verification information | Legal company name, UEN or business registration number, business structure, incorporation date, registered business address, company tax ID, business phone number, business website, business description, products or services sold, target customers, expected processing volume, average transaction amount, refund policy, and delivery timeline where required for payment onboarding or compliance |
| Identity and ownership verification information | Full legal name, date of birth, nationality, residential address, role in the company, percentage ownership, government-issued ID, and related verification materials for directors, beneficial owners, or company representatives where required for payment onboarding, sanctions screening, fraud prevention, or legal compliance |
| Payment and billing information | Billing profile, payment amount, currency, transaction identifiers, invoice or receipt details, payment status, refund status. Card details are processed by our payment processor and are not intended to be stored directly by CogFoundry |
| Customer Content | Prompts, inputs, uploaded files, workflow specifications, tool calls, API payloads, generated outputs, artifacts, and related execution metadata submitted through the Services |
| Marketplace and creator information | SkillBot listings, template metadata, pricing settings, creator earnings records, review requests, usage records |
| Communications | Support messages, contact form submissions, survey responses, sales or onboarding communications |
Information we collect automatically
We generate or observe this information as you use the Services, largely to keep them running, secure, and billable.
| Category | Examples |
|---|---|
| Authentication information | Login tokens, session identifiers, OAuth provider identifiers, multi-factor or verification status if enabled |
| API and usage information | API key metadata, request timestamps, model or service selected, token or credit usage, rate-limit settings, execution status, error logs |
| Device, log, and network information | IP address, browser type, device identifiers, operating system, referring pages, pages viewed, approximate location inferred from IP, diagnostic logs |
| Cookies and similar technologies | Session cookies, preference cookies, security cookies, and, if enabled, analytics cookies |
Information from third parties
When you choose to connect an external provider, we receive the information that provider returns.
| Category | Examples |
|---|---|
| Third-party login information | Information returned by Google, GitHub, or another login provider when you choose to sign in through that provider |
We do not intentionally request sensitive personal information such as precise geolocation, biometric information, health information, or payment card numbers as part of normal product use. Government-issued identity documents may be requested only where required for payment onboarding, identity verification, sanctions screening, fraud prevention, or legal compliance, and may be processed directly by a payment or identity verification provider such as Stripe or Stripe Identity. You should not submit sensitive personal information in Customer Content unless your organization has authorized it and the applicable product configuration and agreement permit it.
3. How We Use Personal Information
| Purpose | Examples | Legal basis where GDPR/UK GDPR applies |
|---|---|---|
| Provide and operate the Services | Create accounts, authenticate users, issue API keys, execute AI Workloads, route model requests, deliver results and artifacts | Contract; legitimate interests |
| Process payments and credits | Create payment sessions, apply credits, generate bills, process refunds, prevent payment abuse | Contract; legal obligation; legitimate interests |
| Complete payment onboarding and compliance verification | Verify company registration information, business profile, directors, beneficial owners, bank account eligibility, refund policy, delivery timeline, and transaction volume where required by payment providers or law | Contract; legal obligation; legitimate interests |
| Secure the Services | Detect abuse, enforce rate limits, prevent credential misuse, investigate incidents, maintain audit logs | Legitimate interests; legal obligation |
| Support users | Respond to support requests, diagnose errors, communicate service updates | Contract; legitimate interests |
| Improve reliability and performance | Debug failures, measure latency and availability, improve routing, caching, and workload execution quality | Legitimate interests |
| Manage marketplace activity | Review SkillBot listings, calculate creator earnings, maintain transaction and usage records | Contract; legitimate interests |
| Send administrative communications | Account notices, billing notices, policy updates, security alerts | Contract; legal obligation; legitimate interests |
| Send optional marketing communications | Product updates, events, newsletters, or promotional messages where permitted | Consent or legitimate interests, depending on jurisdiction |
| Comply with law | Tax, accounting, sanctions, lawful requests, dispute resolution | Legal obligation; legitimate interests |
4. AI Workloads and Customer Content
CogFoundry is an AI Workload production system. An AI Workload may include prompts, model calls, API calls, tool execution, files, workflow steps, logs, generated outputs, and artifacts.
We process Customer Content to:
- execute the AI Workload you request;
- route requests to selected model, API, infrastructure, or tool providers;
- return outputs and artifacts;
- provide billing, usage, debugging, security, and support functions;
- improve service reliability, observability, and abuse prevention.
Unless you or your organization explicitly authorizes it, CogFoundry does not use Customer Content to train CogFoundry models or third-party models. If you configure the Services to use a third-party model or API provider, that provider may process Customer Content according to its own terms, data processing agreement, and product configuration.
5. How We Disclose Personal Information
We disclose personal information only as needed for the purposes described in this Privacy Policy.
| Recipient category | Purpose |
|---|---|
| Cloud infrastructure and hosting providers | Host the Services, databases, logs, files, and execution environments |
| Model, API, and tool providers | Execute requested AI Workloads and return outputs |
| Payment processors, including Stripe where enabled | Process payments, refunds, fraud checks, payment onboarding, invoices, tax and transaction records. CogFoundry does not intentionally store full payment card numbers |
| Identity verification providers, including Stripe Identity or Singpass MyInfo where enabled | Verify directors, beneficial owners, company representatives, or related identity materials where required. CogFoundry normally receives verification status, provider identifiers, limited metadata, and compliance records, not raw identity documents unless required |
| Authentication providers | Support login through Google, GitHub, or other providers selected by the user |
| Email, support, and communication providers | Send account notices, support replies, and service communications |
| Professional advisors | Accounting, legal, compliance, security, and audit support |
| Authorities or third parties when legally required | Comply with law, enforce agreements, protect rights, prevent abuse or security incidents |
| Business transaction counterparties | Support a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate protections |
At launch, CogFoundry does not enable optional analytics providers or advertising trackers. If optional analytics, advertising, or similar tracking is enabled later, CogFoundry will update this Privacy Policy and implement applicable notice, consent, and opt-out controls before use.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use sensitive personal information to infer personal characteristics.
6. Cookies and Similar Technologies
We use cookies and similar technologies to operate the Services, keep you signed in, remember preferences, and protect accounts. At launch, optional analytics cookies and advertising cookies are not enabled.
Types of cookies may include:
- Strictly necessary cookies for login, security, routing, and session management.
- Preference cookies for language and interface settings.
- Optional analytics or advertising cookies are not enabled at launch. If enabled later, they will be used only with required notice, consent, or opt-out controls.
You can control cookies through your browser settings. Some Services may not function correctly if strictly necessary cookies are disabled.
7. International Data Transfers
CogFoundry is based in Singapore. We and our service providers may process and store personal information in Singapore, the United States, the EEA/UK, and other locations where we or our service providers operate. These countries may have data protection laws that differ from those in your jurisdiction.
Where required, we use appropriate safeguards for international transfers, such as data processing agreements, standard contractual clauses, the UK Addendum, adequacy decisions, the EU-U.S. Data Privacy Framework where applicable, or other lawful transfer mechanisms. We also take reasonable steps to require service providers to protect transferred personal information consistently with this Privacy Policy and applicable law.
8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, unless a longer period is required or permitted by law.
| Data category | Retention approach |
|---|---|
| Account information | Retained while the account is active. After account deletion or deactivation, account personal information is deleted or de-identified within 90 days where technically feasible, except where retention is needed for security, billing, legal compliance, dispute resolution, anti-fraud, or service integrity |
| Customer Content and artifacts | By default, retained for up to 30 days after AI Workload completion for delivery, retry, debugging, abuse prevention, and service reliability, unless you delete it earlier or a product setting, enterprise agreement, or legal requirement provides a different period |
| Business verification and identity verification records | Original identity documents are generally retained by Stripe, Stripe Identity, Singpass MyInfo, or other verification providers according to their rules. CogFoundry retains limited verification status, provider identifiers, compliance metadata, and related records while needed for payment, anti-fraud, sanctions, tax, accounting, audit, disputes, and legal compliance |
| API usage and operational logs | Up to 180 days for operations, billing, debugging, reliability, and abuse prevention, unless longer retention is needed for security, fraud, legal compliance, or dispute purposes |
| Security logs | Up to 1 year, and longer if needed to investigate abuse, fraud, security incidents, legal claims, or compliance matters |
| Billing, tax, and transaction records | At least 5 years for billing, audit, tax, accounting, anti-fraud, and dispute purposes, and longer where required or permitted by applicable law |
| Support communications | Up to 3 years after the request is closed unless longer retention is needed for dispute or compliance purposes |
| Marketing preferences | Until you unsubscribe or the data is no longer needed |
We may retain de-identified or aggregated information that no longer reasonably identifies an individual.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, or disclosure. These measures may include access controls, encryption in transit, secret management, logging, monitoring, and review of production access.
No online service can guarantee absolute security. You are responsible for protecting your account credentials, API keys, and any systems that connect to CogFoundry. If you believe your account or API key has been compromised, contact us promptly at [email protected] and revoke or rotate affected credentials.
10. Your Choices and Rights
Depending on where you live, you may have rights to:
- access personal information we hold about you;
- correct inaccurate personal information;
- delete personal information;
- restrict or object to certain processing;
- receive a portable copy of certain personal information;
- withdraw consent where processing is based on consent;
- opt out of certain marketing communications;
- lodge a complaint with a data protection authority.
To exercise these rights, contact [email protected]. We may need to verify your identity before responding, and authorized agents may need to provide proof of authority where applicable. We target an initial response within 30 days and will complete requests within the period required by applicable law. Some information may be retained or request scope may be limited if required for security, billing, legal compliance, dispute resolution, anti-fraud, or service integrity.
11. Notice for California Residents
This section supplements the rest of this Privacy Policy for California residents.
Categories Collected
In the last 12 months, we may have collected the following categories of personal information:
| CCPA category | Examples in CogFoundry Services |
|---|---|
| Identifiers | Name, email address, account ID, IP address, OAuth identifier |
| Customer records information | Billing contact details, transaction records |
| Commercial information | Credits purchases, usage records, invoices, refunds, SkillBot Marketplace activity |
| Internet or network activity | Log data, API usage, pages viewed, device and browser information |
| Approximate geolocation | Approximate location inferred from IP address |
| Professional or employment-related information | Organization name, role, team information, director or company representative role if provided |
| Inferences | Product preferences or account status inferred from usage, where applicable |
| Sensitive personal information | We do not intentionally collect sensitive personal information as part of normal product use. Government-issued identity documents may be processed where required for payment onboarding or compliance through verification providers, and users may submit sensitive data in Customer Content only if authorized |
Sources
We collect personal information from you, your organization, your use of the Services, third-party login providers you choose to use, payment processors, verification providers, and service providers that help operate the Services.
Purposes
We use personal information for the purposes described in Section 3, including providing the Services, processing payments, securing accounts, supporting users, improving reliability, managing marketplace activity, preventing fraud and abuse, and complying with law.
Disclosure
We may disclose the categories above to the recipient categories described in Section 5.
Sale or Sharing
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We have not sold or shared personal information for those purposes in the last 12 months.
Sensitive Personal Information
We do not use or disclose sensitive personal information to infer personal characteristics.
California Rights
California residents may have the right to know, access, correct, delete, and receive information about certain disclosures of personal information. They may also have the right to opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising their privacy rights.
To exercise these rights, contact [email protected]. If we later sell or share personal information as defined by California law, we will provide a “Do Not Sell or Share My Personal Information” link.
12. Children
The Services are intended for business and developer use and are not directed to children under 13, or under any higher age threshold for parental consent that applies where the Services are offered. We do not knowingly collect personal information from children. If you believe a child has provided personal information to CogFoundry, contact us at [email protected] and we will take appropriate steps to delete it.
13. Third-Party Links and Services
The Services may link to third-party websites, model providers, documentation, repositories, OAuth providers, or payment pages. Their privacy practices are governed by their own policies. You should review those policies before using third-party services.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will take reasonable steps to notify users, such as posting an updated version on our website, updating the “Last updated” date, or sending an account notice where appropriate.
15. Contact Us
If you have questions about this Privacy Policy or want to exercise privacy rights, contact:
CogFoundry Pte. Ltd. (Singapore UEN 202603662E) Email: [email protected]