Privacy Notice — cognee.ai

Current version: September 20, 2026

Cognee Inc. (“Cognee”, “we”) processes certain personal data through its websites (cognee.ai, docs.cognee.ai), its community channels, its managed platform Cognee Cloud (platform.cognee.ai) and through the telemetry of the open-source Cognee library. This privacy notice explains what personal data we process, why, and how we address your data protection rights.

1. Who is responsible

Cognee Inc., 1288 Howard Street, Floor 5, Apartment 509, San Francisco, CA 94103, USA, is the controller for the processing described in this notice.

Our European operating company is Topoteretes UG (haftungsbeschränkt), Schönhauser Allee 163, 10435 Berlin, Germany (Amtsgericht Charlottenburg, HRB 252065 B), a wholly-owned subsidiary of Cognee Inc. and our contracting entity for customers in the EU/EEA. Topoteretes UG operates the services on behalf of Cognee Inc. as its processor under an intra-group data processing agreement. Where Topoteretes UG collects personal data independently of Cognee Inc., in particular for its own EU customer contracts, invoicing and staff, it is itself the controller of that data. Topoteretes UG is also our contact point in the European Union.

You can reach us on all data-protection matters at privacy@cognee.ai (see section 10 for details).

2. Websites (cognee.ai, docs.cognee.ai)

This section describes personal data for which Cognee is the controller when you visit and interact with our websites.

2.1 What we process, why, and on what legal basis

DataPurposeLegal basis
Server log data: IP address, date/time, browser/OS/user-agent, requested URL/path/method, HTTP status, data volume, referrer, languageDeliver and secure the websites; detect and prevent abuseArt. 6(1)(f) GDPR (legitimate interest in a secure, functioning website)
Error and performance diagnostics: error messages, browser/OS, page, IP addressDetect and fix technical errorsArt. 6(1)(f) GDPR (legitimate interest in a reliable website)
Usage/analytics data (cookieless): anonymous usage events; no cookie or device identifier is set and the events are not attributable to a personMeasure engagement and improve the websitesArt. 6(1)(f) GDPR (legitimate interest to understand the engagement of users with the websites)
Contact data: name, email, company, message content, communication historyHandle your enquiry; manage the business relationshipArt. 6(1)(b) GDPR (pre-contractual/contractual); Art. 6(1)(f) where no contract
Booking data: name, email, timezone, selected appointmentSchedule and hold the requested meetingArt. 6(1)(b) GDPR
Newsletter data: email address, sign-up time, double-opt-in confirmation, open and click statisticsSend our newsletter and product announcements; measure their reachArt. 6(1)(a) GDPR (consent, revocable at any time via the unsubscribe link)
Business contact data: name, business email, phone, role, company, communication and deal history (collected from you directly, from enquiry forms or from public business sources)Sales, account management and relationship management (B2B)Art. 6(1)(f) GDPR (legitimate interest in B2B sales); Art. 6(1)(b) GDPR where a contract is in preparation
Application data: CV, cover letter, contact details, qualifications and other information you submit via our careers pageRun the recruitment processArt. 6(1)(b) GDPR; § 26(1) BDSG; Art. 6(1)(a) GDPR for a talent pool beyond the process

2.2 Recipients (processors)

We use the following service providers, who process the above data on our behalf under Art. 28 GDPR:

RecipientRoleLocation of processing
Google Ireland Ltd (Google Workspace), Dublin, IrelandEmail and correspondenceIreland (EU) / global
Vercel Inc., Covina, CA, USAWebsite hosting and deliveryUSA / global
Functional Software, Inc. (Sentry), San Francisco, USAError and performance monitoringUSA
Twilio Inc. (Segment), San Francisco, USAWebsite analytics (cookieless)USA
HubSpot Germany GmbH, Berlin, GermanyCRM — enquiries, contacts, sales pipelineEU
Plus Five Five, Inc. (Resend), San Francisco, USANewsletter distributionUSA
Calendly LLC, Atlanta, GA, USAAppointment schedulingUSA
Workable Software Single Member P.C., Marousi, GreeceApplicant management (careers page)Greece (EU)
iubenda s.r.l., Milan, ItalyHosting of legal pages / consent recordsItaly (EU)

We do not sell personal data collected via our websites. Our social media profiles (LinkedIn, X, YouTube, TikTok, Reddit) are referenced via external links only; no social-media tracking pixels are embedded in the websites.

2.3 International transfers

Cognee Inc. is established in the USA; personal data collected through the websites is therefore processed in the USA. Transfers to Cognee Inc. as well as to its processors is safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914).

2.4 Retention

We keep personal data only as long as needed for the purposes above:

  • Server logs and error diagnostics: deleted or anonymised once no longer required for technical operation and security.
  • Analytics data: anonymous; aggregated statistics are kept without personal reference.
  • Contact and booking data: at latest 2 years after the communication or appointment ends, unless a contract or further communication follows.
  • Business contact data (CRM): for the duration of the business relationship and at latest 3 years after our last interaction.
  • Newsletter data: until you unsubscribe; proof of consent for 3 years thereafter (§ 195 BGB limitation period).
  • Application data: 6 months after the end of the recruitment process (§ 15 AGG), longer only with your consent.

3. Community and developer channels

The open-source Cognee library is developed publicly on GitHub (https://github.com/topoteretes/cognee) and discussed on our Discord server and social media profiles. When you open an issue, pull request or discussion, or post in our community channels, we process the profile information and content you make public on that platform (username, avatar, message content) to maintain the project, answer questions and moderate the community. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in running an open-source project and its community). GitHub, Inc., Discord Inc. and the social networks act as independent controllers for their platforms; please refer to their privacy notices for details.

4. Cognee Cloud (platform.cognee.ai)

When you use Cognee Cloud as a user of one of our business customers, Cognee processes personal data contained in the content of that customer’s workspace (documents, data sources, prompts, queries, resulting memories, graphs and embeddings) only as a processor on behalf of and under the documented instructions of its customer (the controller). This processing is governed by a data processing agreement (DPA) pursuant to Art. 28 GDPR, including a dedicated sub-processor list agreed between the customer and Cognee in the DPA, and is not detailed further in this notice.

For information about how your data is processed in a customer workspace and to exercise your data-protection rights, please contact the relevant customer. If you contact us directly, we will forward your request to the responsible controller without undue delay.

The subsections below describe only the processing for which Cognee is itself the controller, which is for the account, billing, support and product-usage data of registered users.

4.1 What we process, why, and on what legal basis

DataPurposeLegal basis
Account data: email address, user ID (UUID), name, authentication data (via Auth0), workspace membership and role, API keysCreate, secure and administer your account and workspaces; authenticate you; provide the platformArt. 6(1)(b) GDPR (performance of the platform contract / terms of use)
Billing data: billing contact, company, address, VAT ID, payment method (processed by Stripe; we do not store credit card details), token usage and invoicesProcess orders, metered billing, invoicing and paymentArt. 6(1)(b) GDPR; Art. 6(1)(c) GDPR (statutory accounting/tax obligations)
Support data: name, email, request content and correspondence history; for Enterprise customers, messages in a dedicated Slack channelRespond to and manage support requestsArt. 6(1)(b) / Art. 6(1)(f) GDPR
Product-usage data: user ID, actions taken in the platform, API calls, token counts, feature usage, feedback ratingsSecure, maintain, meter and improve the platformArt. 6(1)(b) GDPR (metering); Art. 6(1)(f) GDPR (legitimate interest in a secure and improving product)
Technical and security logs: IP address, timestamps, request metadata, error traces (metadata only, no customer content)Operate, monitor and secure the platform; detect and investigate incidentsArt. 6(1)(f) GDPR (legitimate interest in security and reliability); Art. 32 GDPR

4.2 Recipients (processors)

Service providers that process the controller-side data listed above on our behalf under Art. 28 GDPR:

RecipientRoleLocation of processing
Amazon Web Services EMEA SARL, LuxembourgCloud hosting of the platform (compute, object storage, secrets management)USA (AWS region us-east-1); no EU region offered to customers today
Neon, Inc., San Francisco, USAManaged Postgres database (account and application data)USA
Okta, Inc. (Auth0), San Francisco, USALogin / identity and authenticationEU (Auth0 tenant region EU-2)
Stripe, Inc., South San Francisco, USAPayment processing and invoicingUSA / global
Dash0 Inc., New York, USAObservability (logs, metrics, traces; metadata only)USA
Vercel Inc., Covina, CA, USAHosting of the platform front endUSA
Twilio Inc. (Segment), San Francisco, USAProduct analyticsUSA
Google Ireland Ltd (Google Workspace), Dublin, IrelandEmail and support correspondenceIreland (EU) / global
Slack Technologies Limited, Dublin, IrelandEnterprise support communication (dedicated channels)Ireland (EU) / USA

This notice lists only third parties that process personal data for which Cognee is the controller. Sub-processors used to process customer content on Cognee’s behalf, where Cognee acts as processor are listed in the DPA sub-processor list. Please reach out to the respective customer as controller of your data to obtain a copy of the sub-processor list if required.

4.3 International transfers

Cognee Cloud is hosted in the USA and operated by Cognee Inc., a US company. If you are located in the EU/EEA, your account, billing, support and usage data is therefore transferred to the USA. The transfer to Cognee Inc. as a US company is safeguarded by the EU–US Data Privacy Framework and/or the EU Standard Contractual Clauses.

4.4 Retention

We keep this data only as long as needed:

  • Account data: for the duration of the contract; the workspace content is deleted 30 days after the subscription period is terminated.
  • Billing and invoicing data: retained for statutory periods (10 years for invoices issued by Topoteretes UG (§ 147 AO, § 257 HGB, § 14b UStG) and 7 years for Cognee Inc.
  • Support data: at most for the duration of the contract, then anonymised (for statistical purposes) or deleted.
  • Product-usage data: for 24 months; then aggregated or deleted.
  • Technical and security logs: from 30 days to 12 months (depending on log type).

5. Telemetry of the open-source Cognee library

The self-hosted open-source Cognee library sends anonymous usage telemetry to Cognee by default (e.g. library version, operating system, the type of operation run, and an anonymous installation identifier). The telemetry does not include the content you process with Cognee. Telemetry events are sent to a Cognee-operated collection endpoint and stored in our data warehouse. You can disable telemetry at any time as described in our documentation at docs.cognee.ai. To the extent such telemetry constitutes personal data, we process it on the basis of Art. 6(1)(f) GDPR (legitimate interest in understanding how the library is used and in improving it).

When you run Cognee on your own infrastructure, Cognee does not receive the data you process. Note that, in the default configuration, the library sends content to the configured LLM and embedding provider (by default OpenAI); the provider you configure is your own processor, not Cognee’s.

6. Sharing within the Cognee group

Cognee Inc. and Topoteretes UG (haftungsbeschränkt) share customer, prospect and user data within the group to provide the services, for contract administration, billing, support and sales. Topoteretes UG is the contracting entity for customers in the EU/EEA; it also processes data as processor on behalf of Cognee Inc. under an intra-group data processing agreement; for the data it collects independently (its own EU customer contracts, invoicing and staff), Topoteretes UG acts as an independent controller.

7. Your rights

You have the right to access your personal data (Art. 15 GDPR), as well as to request rectification (Art. 16 GDPR), erasure (Art. 17 GDPR), restriction (Art. 18 GDPR), to submit a data portability request (Art. 20 GDPR), and to object to processing based on legitimate interest (Art. 21 GDPR). Where processing is based on consent, you may withdraw it at any time with future effect. To exercise any right, contact us using the contact details below.

8. Right to complain

You can file a complaint with a supervisory authority in the EU/EEA country where you habitually reside, where you work, or where the alleged violation occurred.

The supervisory authority at the seat of our European company Topoteretes UG (haftungsbeschränkt): Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, Germany.

9. Information for residents of the United States

Cognee Inc. is a US company. We provide the information in this notice to all users regardless of location. Cognee does not sell personal information and does not share it for cross-context behavioral advertising; we do not use personal information for targeted advertising. The categories of personal information we collect, the purposes, and the recipients are described in sections 2 to 6. If you are a resident of a US state whose privacy law grants you rights of access, deletion, correction or portability, you may exercise them by contacting privacy@cognee.ai; we will not discriminate against you for exercising them. Our services are not directed to children under 13, and we do not knowingly collect personal information from them.

10. Contact details

For questions about this privacy notice as well as to exercise your data-protection rights, please contact us at privacy@cognee.ai or by post at the address in section 1.

Our data protection officer is heyData GmbH, Schützenstraße 5, 10117 Berlin, Germany. You can reach the data protection officer via privacy@cognee.ai.

11. Changes

We update this notice when our processing changes. Current version: September 20, 2026. This notice is published at https://cognee.ai/privacy-notice.