Current version: September 20, 2026
Cognee Inc. (“Cognee”, “we”) processes certain personal data through its websites (cognee.ai, docs.cognee.ai), its community channels, its managed platform Cognee Cloud (platform.cognee.ai) and through the telemetry of the open-source Cognee library. This privacy notice explains what personal data we process, why, and how we address your data protection rights.
Cognee Inc., 1288 Howard Street, Floor 5, Apartment 509, San Francisco, CA 94103, USA, is the controller for the processing described in this notice.
Our European operating company is Topoteretes UG (haftungsbeschränkt), Schönhauser Allee 163, 10435 Berlin, Germany (Amtsgericht Charlottenburg, HRB 252065 B), a wholly-owned subsidiary of Cognee Inc. and our contracting entity for customers in the EU/EEA. Topoteretes UG operates the services on behalf of Cognee Inc. as its processor under an intra-group data processing agreement. Where Topoteretes UG collects personal data independently of Cognee Inc., in particular for its own EU customer contracts, invoicing and staff, it is itself the controller of that data. Topoteretes UG is also our contact point in the European Union.
You can reach us on all data-protection matters at privacy@cognee.ai (see section 10 for details).
This section describes personal data for which Cognee is the controller when you visit and interact with our websites.
| Data | Purpose | Legal basis |
|---|---|---|
| Server log data: IP address, date/time, browser/OS/user-agent, requested URL/path/method, HTTP status, data volume, referrer, language | Deliver and secure the websites; detect and prevent abuse | Art. 6(1)(f) GDPR (legitimate interest in a secure, functioning website) |
| Error and performance diagnostics: error messages, browser/OS, page, IP address | Detect and fix technical errors | Art. 6(1)(f) GDPR (legitimate interest in a reliable website) |
| Usage/analytics data (cookieless): anonymous usage events; no cookie or device identifier is set and the events are not attributable to a person | Measure engagement and improve the websites | Art. 6(1)(f) GDPR (legitimate interest to understand the engagement of users with the websites) |
| Contact data: name, email, company, message content, communication history | Handle your enquiry; manage the business relationship | Art. 6(1)(b) GDPR (pre-contractual/contractual); Art. 6(1)(f) where no contract |
| Booking data: name, email, timezone, selected appointment | Schedule and hold the requested meeting | Art. 6(1)(b) GDPR |
| Newsletter data: email address, sign-up time, double-opt-in confirmation, open and click statistics | Send our newsletter and product announcements; measure their reach | Art. 6(1)(a) GDPR (consent, revocable at any time via the unsubscribe link) |
| Business contact data: name, business email, phone, role, company, communication and deal history (collected from you directly, from enquiry forms or from public business sources) | Sales, account management and relationship management (B2B) | Art. 6(1)(f) GDPR (legitimate interest in B2B sales); Art. 6(1)(b) GDPR where a contract is in preparation |
| Application data: CV, cover letter, contact details, qualifications and other information you submit via our careers page | Run the recruitment process | Art. 6(1)(b) GDPR; § 26(1) BDSG; Art. 6(1)(a) GDPR for a talent pool beyond the process |
We use the following service providers, who process the above data on our behalf under Art. 28 GDPR:
| Recipient | Role | Location of processing |
|---|---|---|
| Google Ireland Ltd (Google Workspace), Dublin, Ireland | Email and correspondence | Ireland (EU) / global |
| Vercel Inc., Covina, CA, USA | Website hosting and delivery | USA / global |
| Functional Software, Inc. (Sentry), San Francisco, USA | Error and performance monitoring | USA |
| Twilio Inc. (Segment), San Francisco, USA | Website analytics (cookieless) | USA |
| HubSpot Germany GmbH, Berlin, Germany | CRM — enquiries, contacts, sales pipeline | EU |
| Plus Five Five, Inc. (Resend), San Francisco, USA | Newsletter distribution | USA |
| Calendly LLC, Atlanta, GA, USA | Appointment scheduling | USA |
| Workable Software Single Member P.C., Marousi, Greece | Applicant management (careers page) | Greece (EU) |
| iubenda s.r.l., Milan, Italy | Hosting of legal pages / consent records | Italy (EU) |
We do not sell personal data collected via our websites. Our social media profiles (LinkedIn, X, YouTube, TikTok, Reddit) are referenced via external links only; no social-media tracking pixels are embedded in the websites.
Cognee Inc. is established in the USA; personal data collected through the websites is therefore processed in the USA. Transfers to Cognee Inc. as well as to its processors is safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).
We keep personal data only as long as needed for the purposes above:
The open-source Cognee library is developed publicly on GitHub (https://github.com/topoteretes/cognee) and discussed on our Discord server and social media profiles. When you open an issue, pull request or discussion, or post in our community channels, we process the profile information and content you make public on that platform (username, avatar, message content) to maintain the project, answer questions and moderate the community. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in running an open-source project and its community). GitHub, Inc., Discord Inc. and the social networks act as independent controllers for their platforms; please refer to their privacy notices for details.
When you use Cognee Cloud as a user of one of our business customers, Cognee processes personal data contained in the content of that customer’s workspace (documents, data sources, prompts, queries, resulting memories, graphs and embeddings) only as a processor on behalf of and under the documented instructions of its customer (the controller). This processing is governed by a data processing agreement (DPA) pursuant to Art. 28 GDPR, including a dedicated sub-processor list agreed between the customer and Cognee in the DPA, and is not detailed further in this notice.
For information about how your data is processed in a customer workspace and to exercise your data-protection rights, please contact the relevant customer. If you contact us directly, we will forward your request to the responsible controller without undue delay.
The subsections below describe only the processing for which Cognee is itself the controller, which is for the account, billing, support and product-usage data of registered users.
| Data | Purpose | Legal basis |
|---|---|---|
| Account data: email address, user ID (UUID), name, authentication data (via Auth0), workspace membership and role, API keys | Create, secure and administer your account and workspaces; authenticate you; provide the platform | Art. 6(1)(b) GDPR (performance of the platform contract / terms of use) |
| Billing data: billing contact, company, address, VAT ID, payment method (processed by Stripe; we do not store credit card details), token usage and invoices | Process orders, metered billing, invoicing and payment | Art. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (statutory accounting/tax obligations) |
| Support data: name, email, request content and correspondence history; for Enterprise customers, messages in a dedicated Slack channel | Respond to and manage support requests | Art. 6(1)(b) / Art. 6(1)(f) GDPR |
| Product-usage data: user ID, actions taken in the platform, API calls, token counts, feature usage, feedback ratings | Secure, maintain, meter and improve the platform | Art. 6(1)(b) GDPR (metering); Art. 6(1)(f) GDPR (legitimate interest in a secure and improving product) |
| Technical and security logs: IP address, timestamps, request metadata, error traces (metadata only, no customer content) | Operate, monitor and secure the platform; detect and investigate incidents | Art. 6(1)(f) GDPR (legitimate interest in security and reliability); Art. 32 GDPR |
Service providers that process the controller-side data listed above on our behalf under Art. 28 GDPR:
| Recipient | Role | Location of processing |
|---|---|---|
| Amazon Web Services EMEA SARL, Luxembourg | Cloud hosting of the platform (compute, object storage, secrets management) | USA (AWS region us-east-1); no EU region offered to customers today |
| Neon, Inc., San Francisco, USA | Managed Postgres database (account and application data) | USA |
| Okta, Inc. (Auth0), San Francisco, USA | Login / identity and authentication | EU (Auth0 tenant region EU-2) |
| Stripe, Inc., South San Francisco, USA | Payment processing and invoicing | USA / global |
| Dash0 Inc., New York, USA | Observability (logs, metrics, traces; metadata only) | USA |
| Vercel Inc., Covina, CA, USA | Hosting of the platform front end | USA |
| Twilio Inc. (Segment), San Francisco, USA | Product analytics | USA |
| Google Ireland Ltd (Google Workspace), Dublin, Ireland | Email and support correspondence | Ireland (EU) / global |
| Slack Technologies Limited, Dublin, Ireland | Enterprise support communication (dedicated channels) | Ireland (EU) / USA |
This notice lists only third parties that process personal data for which Cognee is the controller. Sub-processors used to process customer content on Cognee’s behalf, where Cognee acts as processor are listed in the DPA sub-processor list. Please reach out to the respective customer as controller of your data to obtain a copy of the sub-processor list if required.
Cognee Cloud is hosted in the USA and operated by Cognee Inc., a US company. If you are located in the EU/EEA, your account, billing, support and usage data is therefore transferred to the USA. The transfer to Cognee Inc. as a US company is safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.
We keep this data only as long as needed:
The self-hosted open-source Cognee library sends anonymous usage telemetry to Cognee by default (e.g. library version, operating system, the type of operation run, and an anonymous installation identifier). The telemetry does not include the content you process with Cognee. Telemetry events are sent to a Cognee-operated collection endpoint and stored in our data warehouse. You can disable telemetry at any time as described in our documentation at docs.cognee.ai. To the extent such telemetry constitutes personal data, we process it on the basis of Art. 6(1)(f) GDPR (legitimate interest in understanding how the library is used and in improving it).
When you run Cognee on your own infrastructure, Cognee does not receive the data you process. Note that, in the default configuration, the library sends content to the configured LLM and embedding provider (by default OpenAI); the provider you configure is your own processor, not Cognee’s.
Cognee Inc. and Topoteretes UG (haftungsbeschränkt) share customer, prospect and user data within the group to provide the services, for contract administration, billing, support and sales. Topoteretes UG is the contracting entity for customers in the EU/EEA; it also processes data as processor on behalf of Cognee Inc. under an intra-group data processing agreement; for the data it collects independently (its own EU customer contracts, invoicing and staff), Topoteretes UG acts as an independent controller.
You have the right to access your personal data (Art. 15 GDPR), as well as to request rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction (Art. 18 GDPR), to submit a data portability request (Art. 20 GDPR), and to object to processing based on legitimate interest (Art. 21 GDPR). Where processing is based on consent, you may withdraw it at any time with future effect. To exercise any right, contact us using the contact details below.
You can file a complaint with a supervisory authority in the EU/EEA country where you habitually reside, where you work, or where the alleged violation occurred.
The supervisory authority at the seat of our European company Topoteretes UG (haftungsbeschränkt): Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany.
Cognee Inc. is a US company. We provide the information in this notice to all users regardless of location. Cognee does not sell personal information and does not share it for cross-context behavioral advertising; we do not use personal information for targeted advertising. The categories of personal information we collect, the purposes, and the recipients are described in sections 2 to 6. If you are a resident of a US state whose privacy law grants you rights of access, deletion, correction or portability, you may exercise them by contacting privacy@cognee.ai; we will not discriminate against you for exercising them. Our services are not directed to children under 13, and we do not knowingly collect personal information from them.
For questions about this privacy notice as well as to exercise your data-protection rights, please contact us at privacy@cognee.ai or by post at the address in section 1.
Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. You can reach the data protection officer via privacy@cognee.ai.
We update this notice when our processing changes. Current version: September 20, 2026. This notice is published at https://cognee.ai/privacy-notice.