Last updated: September 1, 2026
This Privacy Policy explains how Cognardo Workbench collects, uses, stores, shares, and protects information when you use our website, Chrome extension, backend services, account features, AI features, billing features, and related support channels.
Cognardo Workbench is operated under the public trade name Cognardo. For public-facing contact, Cognardo Workbench is represented by Raven Black.
This Privacy Policy applies to:
https://workbench.cognardo.com- the Cognardo Workbench Chrome extension
- Cognardo Workbench account, sync, AI, billing, and support services
- related pages, tools, features, and communications
This is a product-specific privacy policy for Cognardo Workbench. The main Cognardo website at https://cognardo.com may have a separate general website privacy policy. Where Cognardo Workbench has different data practices because of extension, cloud sync, AI, account, or billing features, this Privacy Policy applies.
1. What Cognardo Workbench does
Cognardo Workbench is a browser-extension and web-based workspace for people who use AI tools seriously. It helps users save, organize, search, transform, summarize, compare, cite, copy, export, verify, and sync prompts, chats, AI responses, scratchpads, instruction profiles, selected text, page content, and related AI work.
Depending on the feature you use, Cognardo Workbench may process information locally in your browser, sync information to cloud storage, send information to backend services, or send user-submitted content to third-party AI, search, infrastructure, authentication, or payment providers that help provide the service.
2. Contact information
For privacy, support, billing, security, and data requests, you can contact us at:
- General contact:
contact@workbench.cognardo.com - Product support and privacy requests:
support@workbench.cognardo.com - Billing, account, refund, and subscription questions:
accounts@workbench.cognardo.com - Security and abuse reports:
security@workbench.cognardo.com
3. Important summary
This summary is provided for convenience. The full Privacy Policy below controls.
- Cognardo Workbench processes prompts, chats, AI responses, saved content, selected text, page text, scratchpads, instruction profiles, citation data, and AI feature inputs/outputs when you use features that require that data.
- Some data is stored locally in your browser or Chrome extension storage.
- Cloud Sync & Intelligence is disabled by default.
- If you enable Cloud Sync & Intelligence, supported workspace data may be synced to cloud infrastructure and used for cloud-backed features, AI-powered features, citation analysis, product improvement, and aggregated or de-identified intelligence signals.
- These intelligence signals may include things like cited URLs, source domains, brand or source mentions, citation patterns, source-quality signals, model/provider behavior trends, and claim-source support patterns.
- We do not use your raw private prompts, chats, scratchpads, or saved responses as a public dataset.
- We do not use your user content for third-party advertising.
- Optional product analytics and acquisition attribution are off until you choose to share usage information. Declining does not limit Workbench features.
- If you do not want your synced workspace data to be used for Cloud Sync & Intelligence, you should keep Cloud Sync & Intelligence disabled. Some cloud, sync, AI, and analysis features may not work without it.
- Disabling Cloud Sync & Intelligence stops future cloud sync and intelligence actions, but does not automatically delete data that was already synced.
- You can delete items, delete your account, revoke optional site access, sign out, or remove the extension.
- Account deletion starts a 30-day recovery window. After that window, cloud account data is scheduled for deletion or de-identification, subject to legal, billing, fraud-prevention, security, backup, and compliance obligations.
- Removing the Chrome extension from your browser clears local extension data from that browser.
- We do not sell your user content.
- We do not use your user content for third-party advertising.
- User-requested AI features may send submitted content to AI, search, or webpage-fetching providers depending on the feature.
- AI outputs and citation analysis may be inaccurate, incomplete, or unsafe without human review.
- You should not submit sensitive, confidential, regulated, or third-party content unless you are authorized to do so and accept the processing risk.
4. Information we collect and process
We collect and process different categories of information depending on how you use Cognardo Workbench.
4.1 Account and identity information
When you create, access, or manage an account, we may collect and process:
- account identifier or user ID
- email address
- email verification status
- display name or username
- Google profile name and profile image URL if you use Google sign-in
- uploaded avatar or profile image
- authentication provider information
- account creation and update timestamps
- account status information
- security and verification metadata
- password update metadata, where applicable
- one-time password or verification flow records
- account deletion or reactivation records
- We may collect IP addresses and related request metadata for security, authentication, fraud prevention, abuse prevention, and rate limiting.
We use this information to create and secure your account, verify identity, provide login features, manage your profile, support account recovery, and process account-related requests.
4.2 Authentication and session information
To keep you signed in and authenticate requests, Cognardo Workbench may process:
- session tokens
- API keys or account access keys
- authentication state
- login timestamps
- backend session information
- Firebase or Google authentication tokens
- browser or extension session records
The Chrome extension stores authentication information in Chrome extension storage. The website may store authenticated session information in browser local storage. These records help keep you signed in and allow the website, extension, and backend services to communicate securely.
You are responsible for keeping your account credentials, API keys, session tokens, and authenticated devices secure. Do not share them with others.
4.3 User content
Cognardo Workbench is designed to help you work with user-generated and AI-generated content. Depending on your actions and settings, we may process and store:
- saved prompts
- prompt titles, descriptions, tags, folders, models, categories, and metadata
- prompt sequences and sequence steps
- ChatGPT, Claude, or AI conversation titles
- prompts and AI responses
- chat turns, versions, model names, provider metadata, source URLs, and citation links
- pinned prompts, responses, or prompt-response pairs
- scratchpads and scratchpad content
- instruction profiles and custom instructions
- selected webpage text
- extracted page text from approved or supported pages
- generated summaries
- optimized prompts
- explanations
- flashcards
- quizzes
- tone rewrites
- expand/shorten outputs
- cross-model comparison prompts and outputs
- citation metadata, citation analysis, claims, links, evidence, and verification results
- copied or transformed content when you use copy, export, formatting, or bibliography tools
- imported or exported prompt, conversation, scratchpad, or library data
If you ask Cognardo Workbench to save, sync, analyze, summarize, transform, compare, verify, export, or copy content, that content may be processed by the extension, website, backend services, cloud database, and relevant third-party providers needed to perform the requested feature.
4.4 Webpage and selected content
When you use webpage-based features, Cognardo Workbench may process selected text or visible page text from supported or user-approved websites.
For example, this may happen when you ask Cognardo Workbench to:
- summarize selected text
- summarize a webpage
- copy selected text with custom formatting
- save selected text to a scratchpad
- explain selected text
- generate flashcards or quizzes from selected content
- rewrite, expand, or shorten selected content
- run citation-related features
- open the sidebar or floater on an approved site
When no text is selected, Cognardo Workbench may attempt to extract the main page content. The extension attempts to reduce unnecessary page elements before processing, such as scripts, styles, forms, navigation, ads, popups, cookie banners, embedded media, and other non-content elements. This minimization process is not perfect and does not guarantee that all sensitive or unnecessary information is removed.
You should not use Cognardo Workbench to process content from websites, documents, systems, or third-party sources unless you have the right and authorization to do so.
4.5 Analytics, usage, and diagnostic information
We may collect product analytics, usage, diagnostic, performance, and error-related information, such as:
- event type
- user ID
- device or installation ID
- session ID
- timestamp
- extension version
- environment
- client type
- feature used
- setting changed
- source of the action
- plan state
- usage counters
- diagnostic or runtime telemetry
We may also collect and process technical diagnostics information used to identify, troubleshoot, and resolve product issues. This information may include error events, exception details, stack traces, synchronization failures, compatibility issues, browser information, extension version information, installation identifiers, page hostnames, and related technical metadata.
Cognardo Workbench may maintain diagnostic logs locally within the extension or browser storage for troubleshooting, reliability, support, and error investigation purposes.
Automatic diagnostic and error reporting is intended to contain technical and operational information only. We do not intentionally include the contents of prompts, conversations, AI responses, scratchpads, notes, instruction profiles, copied content, or other user-generated workspace content in automatic error reports.
Product analytics are used to understand feature usage, improve performance, troubleshoot problems, detect abuse, manage entitlements, and improve the service.
Search analytics are designed not to include raw search query text. For search-related analytics, we may process metadata such as query length instead of the raw query.
We do not claim that all analytics metadata is content-free in every possible case. We use minimization practices where practical, but some diagnostic or usage records may contain contextual information needed to operate or troubleshoot the service.
Optional product analytics and acquisition attribution are separate from the account Terms and Privacy Policy acceptance required to create an account. Before optional collection begins, Workbench presents a clear choice. If you agree, we may process a random first-party visitor or installation identifier, approved campaign fields, referring hostname, landing path, browser or store details, Workbench feature events, and server-confirmed signup, activation, or payment milestones. We do not use this information for advertising.
Attribution records are designed not to contain email addresses, passwords, authentication tokens, raw prompts or chats, scratchpad content, full URLs, or full IP addresses. Campaign and referrer inputs are allowlisted, shortened, and checked before storage. Account, plan, and payment truth continues to come from the existing account and billing records rather than being duplicated in attribution records.
The optional sharing choice covers the Workbench website and extension. Before sign-in, a short-lived setup handoff may connect the permitted website visitor context to the installation in the same browser; the extension does not read the website's cookies. After sign-in, Workbench associates the current choice with the account so it can be applied on other signed-in Workbench surfaces and devices. This does not establish that one browser profile or device represents only one person, and it does not recover visits or campaign information that were not stored before permission was given.
4.6 Billing, plan, subscription, and credit information
Cognardo Workbench may process billing and plan-related information, including:
- plan name, such as Free, Pro, or Max
- plan status
- billing account ID
- subscription status
- included monthly credits
- remaining monthly credits
- top-up credit balance
- credit ledger entries
- renewal or reset dates
- invoices
- payment-provider customer or subscription identifiers
- payment failure, cancellation, refund, or account status metadata
Payments are processed by Paddle. Paddle may process buyer, payment, tax, fraud-prevention, invoice, subscription, customer, and buyer-support data as a payment provider or merchant of record.
Cognardo Workbench does not need to store full card numbers when payments are processed by a payment provider.
4.7 Settings, preferences, and consent records
We may process settings and preferences, including:
- Cloud Sync & Intelligence setting
- sidebar settings
- floater button settings
- active instruction profile setting
- shortcut settings
- custom copy settings
- permitted origins for optional site access
- extension enabled or disabled state
- theme preference
- local or cloud feature preferences
- consent version, consent scope, consent action, and consent timestamp
Consent records help us understand when you enabled or disabled cloud sync, AI-powered features, and related settings.
We may also maintain records relating to user acknowledgements, consents, and acceptance of legal agreements, including acceptance of our Terms of Service, Privacy Policy, and other applicable notices. Such records may include the date and time of acceptance, the version or last-updated date of the applicable document, and related account or device identifiers necessary to demonstrate and maintain records of such acceptance.
4.8 Profile images and avatars
If you upload or use a profile image, we may process and store that image, related metadata, and profile fields. You can delete your avatar or update your profile from your account settings where available.
5. How we collect information
We collect information in the following ways:
- directly from you when you create an account, update your profile, contact support, or use product features
- through the Chrome extension when you use Workbench features on supported or approved websites
- through the website when you sign in, manage your account, or use account features
- from Google when you use Google sign-in
- from payment providers
- from browser APIs and extension APIs needed to provide extension functionality
- from backend logs, diagnostic systems, and security systems
- from your settings, consent choices, and feature actions
6. Local storage, browser storage, and cloud storage
Cognardo Workbench uses different storage systems depending on the feature and your settings.
6.1 Chrome extension storage
The Chrome extension may use Chrome extension local or session storage to store:
- authentication state
- account cache
- local prompts, chats, scratchpads, and library data
- prompt indexes
- chat title edits
- sync metadata
- retry queues
- analytics queues
- device or installation IDs
- settings and toggles
- permitted origins
- copy formatting settings
- extension enabled or disabled state
Some Cognardo Workbench features can work locally. Other features, such as cloud backup, cross-device sync, AI actions, citation analysis, and account-based entitlements, require communication with backend or cloud services.
6.2 Website browser storage
The Cognardo Workbench website uses limited browser storage for:
workbench.auth.sessionlocalStorage after sign-in, to maintain the requested account session- Firebase-managed authentication storage after login, to authenticate account and Firestore access
workbench-themelocalStorage after you choose an appearance- a temporary, 15-minute account-summary cache in sessionStorage while signed-in account pages are in use
- short-lived checkout attempt and discount state in sessionStorage after you request those actions
- optional attribution cookies and tab-session markers only after you choose Share usage information
Google Identity Services may set g_state on signup and sign-in pages to remember Google sign-in or sign-out state. Cloudflare may set cf_clearance after a successful website security verification. Paddle may set provider-controlled cookies or storage when you request checkout, payment-method, cancellation, or subscription-management features. Optional Paddle Retain or ProfitWell initialization is limited to a signed-in Paddle customer who has chosen Share usage information. These authentication, security, and requested-payment technologies are separate from optional Workbench analytics. More detail, including normal duration and controls, is provided in the Cookie Policy.
6.3 Cloud storage
If cloud features are enabled or required for a feature you use, Cognardo Workbench may store data in cloud infrastructure, including Google Firebase, Google Cloud Firestore, Google Cloud Storage, and Google Cloud Run.
Cloud data may include:
- account profile data
- prompts
- prompt sequences
- conversations
- scratchpads
- instruction profiles
- sync metadata
- AI action history
- citation analysis results
- consent records
- billing, plan, and credit metadata
6.4 Website permission and extension product analytics
The website sharing choice controls website analytics, acquisition attribution, linking eligible website visits to an account, and optional Paddle/ProfitWell tracking. Cloud Sync does not accept that website choice or enable website tracking.
Extension product analytics is enabled when either website sharing has been accepted and made available to the extension, or Cloud Sync has been explicitly enabled with the current notice. Turning off one permission does not withdraw the other. To stop extension product analytics, turn off both website sharing in /privacy-settings and Cloud Sync in extension Settings. Supported browser privacy signals remain respected. Workspace uploads depend only on Cloud Sync, never on accepting the website banner.
Usage metadata may be used to understand activity and improve Workbench and related Cognardo products. Website-permitted referral information may be used to understand traffic, attribute visits and sign-ups, and calculate affiliate commissions. Private chats, prompts, scratchpads, and other workspace content are not used for attribution or affiliate commissions. Account services, technical diagnostics, and bug reports submitted by users remain separate from optional usage sharing.
7. Cloud Sync & Intelligence
Cloud Sync & Intelligence is disabled by default.
When you enable Cloud Sync & Intelligence, you allow Cognardo Workbench to sync supported workspace data to cloud infrastructure and use cloud-backed processing to provide features such as:
- cloud backup
- restore
- cross-device sync
- AI actions
- prompt optimization
- citation analysis
- source verification
- hallucination analysis
- AI action history
- account-based entitlements
- product improvement
- aggregated or de-identified intelligence signals
Cloud Sync & Intelligence may process supported data such as prompts, conversations, AI responses, scratchpads, instruction profiles, citation links, source URLs, model/provider metadata, AI action inputs and outputs, and related workspace metadata.
When Cloud Sync & Intelligence is enabled, Cognardo Workbench may use synced data to generate aggregated or de-identified intelligence signals. These signals may include cited URLs, source domains, brand or source mentions, citation patterns, source-quality signals, model/provider behavior trends, claim-source support patterns, and similar derived insights.
These intelligence signals may be used to improve Cognardo Workbench and to develop related Cognardo products, including products that help users understand AI citation behavior, source visibility, brand mentions, and LLM-facing content performance.
We do not use your raw private prompts, chats, scratchpads, saved responses, or account content as a public dataset. We do not publish your private workspace content. We do not use your user content for third-party advertising. We do not create third-party advertising profiles from your workspace content.
Where practical, we use aggregation, de-identification, minimization, and separation from account identifiers before using derived intelligence signals for broader product intelligence. However, de-identification is not a perfect guarantee, especially where content includes rare brand names, client names, URLs, niche topics, or other distinctive information. For this reason, you must not submit sensitive, confidential, regulated, or unauthorized third-party content to Cognardo Workbench.
If you do not want your synced workspace data to be used for Cloud Sync & Intelligence, keep Cloud Sync & Intelligence disabled. If you disable Cloud Sync & Intelligence later, future cloud sync and intelligence processing will stop where supported. Disabling the toggle does not automatically delete data that was already synced, and it may not reverse aggregated or de-identified intelligence signals that were already generated.
To delete existing cloud account data, you should delete the relevant items, delete your account where available, or contact support.
8. AI features and third-party AI processing
Cognardo Workbench includes AI-powered features, such as:
- prompt optimization
- web or selection summarization
- chat summaries
- explain-by-grade-level
- flashcards
- quizzes
- tone rewriting
- expand/shorten
- cross-model comparison
- citation metadata
- citation analysis
- hallucination and source-support checks
When you use these features, Cognardo Workbench may send the submitted content, related instructions, selected settings, URLs, citations, or feature metadata to backend services and third-party providers needed to complete the request.
Depending on the feature, provider selection, and configuration, these providers may include:
- OpenAI
- Anthropic
- Google Gemini
- Google Custom Search
- webpage-fetching or source-verification services
- Google Cloud services used to host and process backend requests
We do not make unsupported claims about how every third-party AI provider uses or retains submitted data. Their processing may be governed by their own terms, privacy policies, data processing terms, and account settings.
You should not submit sensitive, confidential, regulated, proprietary, or third-party content to AI features unless you have authorization and accept the processing risk.
AI outputs may be inaccurate, incomplete, misleading, outdated, unsafe, or unsupported by sources. Citation analysis and hallucination analysis are designed to help reduce risk, but they do not guarantee truth, completeness, legal compliance, professional accuracy, or source reliability. You are responsible for reviewing and validating outputs before relying on them.
9. Chrome extension permissions
The Cognardo Workbench Chrome extension uses Chrome permissions to provide its features.
9.1 storage
Used to store authentication state, settings, local workspace data, sync metadata, retry queues, permitted origins, analytics queues, and related extension data.
9.2 activeTab
Used to interact with the currently active tab after user action or in supported feature flows.
9.3 scripting
Used to inject extension-packaged scripts and user interface elements, such as the sidebar, floater, capture tools, copy tools, summarization tools, and citation-related tools, into supported or user-approved pages.
9.4 webNavigation
Used to detect page and navigation changes on supported AI sites and approved origins so the extension can keep the workspace context updated.
9.5 alarms
Used for background tasks such as periodic sync, queue flushing, maintenance, retries, and related scheduled extension behavior.
9.6 identity
Used for Google sign-in, authentication, and account connection features.
9.7 idle
Used to support background behavior, session optimization, sync behavior, or other low-sensitivity extension functions. It is not used to create detailed surveillance of everything you do.
10. Host permissions and site access
By default, Cognardo Workbench may operate on supported AI and chat platforms, such as:
https://chatgpt.com/*https://chat.openai.com/*https://claude.ai/*https://gemini.google.com/*https://perplexity.ai/*https://copilot.microsoft.com/*
On supported AI platforms, Cognardo Workbench may process visible prompt, chat, response, model, citation, title, page, and URL information to provide features such as saving, organizing, searching, copying, summarizing, transforming, syncing, citation support, and verification.
Cognardo Workbench may also request optional access to additional HTTPS websites. This optional access is used for features such as page capture, selection capture, summarization, scratchpad saving, citation support, and Workbench UI injection on user-approved sites.
Optional broad host permission does not mean Cognardo Workbench continuously reads all websites you visit. Access to additional sites is intended to be user-enabled, feature-specific, and revocable. You can manage or revoke approved site access through extension settings or Chrome extension controls where available.
11. Chrome Web Store Limited Use disclosure
Cognardo Workbench uses Chrome extension user data only for purposes that are necessary to provide, maintain, secure, support, analyze, bill, and improve the extension and related account features.
We use extension data for purposes such as:
- providing user-facing extension functionality
- saving and organizing prompts, conversations, scratchpads, sequences, and instruction profiles
- cloud sync and backup when enabled
- AI actions requested by the user
- citation analysis requested by the user
- account authentication
- plan, entitlement, and credit management
- security and abuse prevention
- diagnostics, reliability, and product improvement
- support and compliance
We do not sell Chrome extension user data.
We do not use Chrome extension user data for third-party advertising.
We do not use Chrome extension user data for purposes unrelated to Cognardo Workbench functionality, security, account management, billing, support, analytics, or user-requested processing.
12. How we use information
We use information to:
- provide Cognardo Workbench features
- create and manage accounts
- authenticate users and secure sessions
- save, organize, search, and sync user content
- provide local and cloud-backed workspace features
- run AI actions requested by users
- run citation, source, and hallucination analysis requested by users
- provide exports, imports, copy tools, and formatting tools
- manage plans, credits, entitlements, subscriptions, and billing
- respond to support, privacy, billing, and security requests
- improve reliability, performance, usability, and product quality
- monitor software reliability and service health
- investigate, diagnose, reproduce, and resolve software defects, extension failures, synchronization issues, compatibility problems, and operational incidents
- analyze aggregated diagnostic and error-reporting information to improve stability, performance, reliability, and user experience
- detect, prevent, and respond to fraud, abuse, unauthorized access, and security incidents
- enforce our Terms and Acceptable Use Policy
- comply with legal, tax, accounting, payment, platform, and regulatory obligations
- generate aggregated or de-identified insights to improve the product
- generate aggregated or de-identified intelligence signals when Cloud Sync & Intelligence is enabled
- understand citation patterns, source visibility, model/provider behavior, brand or source mentions, and source-quality trends
- improve Cognardo Workbench and develop related Cognardo products that help users understand AI citation behavior, LLM visibility, and source performance
We may use aggregated or de-identified metadata for product improvement, research, analysis, reporting, or public communication, provided it does not identify you or reveal your user content.
12.1 Legal reasons for processing
Depending on where you live and the activity involved, Cognardo Workbench relies on one or more of the following reasons:
- Providing the service or taking steps you request: creating and operating an account; authenticating you; saving, syncing, exporting, or processing content as directed; running requested AI or citation features; and completing or managing a purchase or subscription.
- Consent: optional acquisition attribution and product analytics; optional Paddle Retain or ProfitWell initialization; optional Cloud Sync & Intelligence where the product presents consent as the basis; and other activities for which we expressly ask permission. Consent can be refused or withdrawn without losing unrelated core functions.
- Legitimate interests: securing the website, extension, accounts, and infrastructure; preventing fraud and abuse; keeping the service available; diagnosing errors; providing support; maintaining short-lived performance caches; enforcing terms; and improving the service in ways that are proportionate and respect user rights.
- Legal obligations: tax, invoicing, accounting, recordkeeping, responding to valid legal requests, protecting rights, and maintaining records of privacy or legal choices where required.
- Protecting vital interests or carrying out a task in the public interest: only in the uncommon situations where applicable law permits or requires it.
Browser-storage rules and data-protection lawful bases are assessed separately. Storage used for authentication, security, a preference you selected, or a payment action you started may operate without the optional analytics choice because it is needed for that requested or protective function. Optional analytics, attribution, and customer-retention processing stays off until permission is given.
Where applicable law uses different terminology—for example, consent and notice requirements under India's Digital Personal Data Protection framework, or notice, opt-out, sale, sharing, and sensitive-data rules in U.S. states—we apply the relevant local rule rather than relying only on the labels above. Cognardo does not sell personal information or use Workbench data for cross-context behavioural advertising.
13. How we share information
We share information only as needed to provide, operate, secure, support, bill, improve, or comply with obligations related to Cognardo Workbench.
13.1 Service providers and subprocessors
We may share information with service providers and subprocessors, including:
- Google Firebase Authentication, for account authentication and Google sign-in support
- Google Cloud Firestore, for cloud database and sync
- Google Cloud Storage or Firebase Storage, for avatar storage and related file storage
- Google Cloud Run, for backend API hosting and processing
- Cloudflare Workers, for website hosting, routing, security, and performance
- OpenAI, for user-requested AI features
- Anthropic, for selected or configured cross-model comparison features
- Google Gemini, for selected or configured AI features
- Google Custom Search, for citation and source lookup features
- Paddle, for payment, tax, invoice, subscription, customer, buyer-support, and fraud-prevention processing
- email delivery providers, for OTPs, verification emails, account notices, deletion confirmations, and support-related messages
- Chrome, Google, and browser platform services, for extension distribution, browser APIs, and platform-level extension behavior
13.1A Diagnostics, error reporting, and support
Cognardo Workbench may process diagnostic information, error reports, support requests, and related technical information to investigate, troubleshoot, maintain, secure, and improve the service.
Certain technical errors, crashes, synchronization failures, authentication failures, compatibility issues, or operational failures may be reported automatically to our backend systems. These reports may include technical metadata such as error identifiers, exception information, browser information, extension version, installation identifiers, page hostnames, URLs, timestamps, and related diagnostic information.
Users may also voluntarily submit bug reports, support requests, screenshots, descriptions, and related diagnostic information through support channels, feedback forms, or in-product reporting tools.
Automatic diagnostic reporting is intended to contain technical information and operational metadata. We do not intentionally collect or transmit user-generated workspace content as part of automatic error reporting unless such content is necessary to provide a requested feature, is voluntarily submitted by the user as part of a support request, or is otherwise required to investigate a reported issue.
13.2 Legal, safety, and compliance reasons
We may disclose information if we believe it is reasonably necessary to:
- comply with applicable law, legal process, or government request
- enforce our Terms or Acceptable Use Policy
- protect users, the public, Cognardo Workbench, or third parties
- detect, investigate, or prevent fraud, abuse, security threats, or technical issues
- respond to chargebacks, payment disputes, billing claims, or platform review processes
- preserve or defend legal rights
13.3 Business changes
If Cognardo Workbench is involved in a merger, acquisition, reorganization, sale of assets, financing, transfer, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality and privacy protections.
14. What we do not do
We do not sell your raw private prompts, chats, scratchpads, saved responses, or account content.
We do not use your user content for third-party advertising.
We do not create third-party advertising profiles from your workspace content.
We do not publish your private workspace content as a public dataset.
We do not allow other users to view your private prompts, chats, scratchpads, saved responses, or account content unless you choose to share or export that content yourself.
We do not claim that aggregated, de-identified, or derived intelligence signals are a perfect privacy guarantee. Distinctive brands, URLs, client names, niche prompts, or rare topics can sometimes carry re-identification risk. For this reason, users must not submit sensitive, confidential, regulated, or unauthorized third-party content to Cognardo Workbench.
15. Sensitive information
Cognardo Workbench is not designed for processing highly sensitive, confidential, regulated, or restricted information. However, because users may submit free-form prompts, chats, page text, scratchpad content, or other user-generated content, such content may include health-related information if the user chooses to provide it.
You must not use Cognardo Workbench to submit, save, sync, analyze, summarize, transform, compare, or verify:
- medical records or protected health information
- financial account credentials or regulated financial records
- government ID numbers
- passwords, secrets, API keys, private keys, or authentication tokens
- children’s personal data
- confidential employer, client, customer, or third-party information without authorization
- attorney-client privileged information
- highly sensitive personal information
- regulated data that you are not authorized to process
- content you do not have the right to submit or process
If you submit sensitive or regulated information despite this policy, you are responsible for ensuring that you have the legal right, authorization, and safeguards required to do so.
16. Data retention
We keep information for as long as reasonably necessary to provide Cognardo Workbench, operate accounts, comply with legal obligations, resolve disputes, enforce agreements, maintain security, manage billing, and support the purposes described in this Privacy Policy.
16.1 Account deletion and recovery window
When you delete your account, account deletion begins a 30-day recovery window.
During this recovery window, signing in or signing up again with the same account may reactivate your account.
For paid accounts, deletion schedules subscription cancellation at the end of the current billing period. Restoring the account does not automatically restart renewal. Paid access is restored only when the existing paid period remains valid; otherwise the account returns on the Free plan.
After the 30-day recovery window, any subscription that remains open is canceled immediately before cloud account data is archived and scheduled for deletion or de-identification, subject to legal, billing, fraud-prevention, tax, security, backup, dispute, and compliance retention obligations.
Deleting your account may remove or terminate access to:
- cloud-synced data
- prompts
- conversations
- scratchpads
- instruction profiles
- AI history
- plan benefits
- credits
- account features
- billing records available through the account interface
Monthly credits and top-up credits expire when your account is deleted.
16.2 Local browser and extension data
Account deletion clears cloud account data through the account deletion process. It does not necessarily remove local data from every browser or device where the extension was installed.
To clear local extension data from a browser, remove the Cognardo Workbench Chrome extension from that browser or clear the extension’s browser storage through Chrome controls where available.
16.3 Analytics and diagnostics
Raw optional product analytics and unlinked acquisition records are generally intended to expire after approximately 90 days where configured. Raw acquisition evidence that is validly linked to an account may be retained for up to approximately 13 months to support the stated attribution lookback, audit, correction, and reporting purposes. The on-device cookie that remembers an analytics choice lasts for up to approximately six months. Server-side consent receipts may be retained for up to approximately two years to demonstrate the choice and its policy version. Bounded, de-identified daily reporting rows may be retained for up to approximately 25 months for year-over-year reporting.
Diagnostic, operational, security, and backend logs may be retained for different periods depending on infrastructure, security, troubleshooting, and compliance needs.
Aggregated or de-identified intelligence signals that have already been generated from Cloud Sync & Intelligence may be retained and used after account deletion if they are no longer reasonably linked to your account or private workspace content. Account deletion is intended to delete or de-identify cloud account data associated with your account, but it may not reverse aggregated, de-identified, or derived intelligence that has already been separated from account-level records.
Bug reports, support diagnostics, and technical error reports may be retained for longer periods where reasonably necessary to investigate issues, improve product reliability, resolve disputes, prevent abuse, comply with legal obligations, or maintain service security.
16.4 Consent records
Consent events and Cloud Sync & Intelligence records may be retained for audit, compliance, troubleshooting, or account history purposes. The website's on-device optional analytics choice expires after approximately six months, while server-side consent receipts may be retained for up to approximately two years where configured. Withdrawal stops new optional collection and triggers deletion or severing of linked optional identifiers subject to applicable legal, security, dispute, and backup obligations.
16.5 Billing and payment records
Billing, tax, invoice, payment, fraud-prevention, dispute, chargeback, and accounting records may be retained for longer periods where required or permitted by law, payment providers, tax authorities, or compliance obligations.
17. Your controls and choices
Depending on the feature and account status, you may be able to:
- sign in or sign out
- update your profile
- change your email address
- change your password
- upload, update, or delete your avatar
- enable or disable Cloud Sync & Intelligence
- delete prompts, conversations, scratchpads, instruction profiles, or other saved items
- export supported content
- revoke optional site permissions
- change extension settings
- disable the floater button
- change copy settings
- remove the Chrome extension
- review or change optional usage sharing at
/privacy-settings - delete your account
- contact support for access, correction, deletion, export, or privacy requests
Some controls may be available inside the extension, website, account settings, Chrome extension settings, or support process.
18. Your privacy rights
Depending on where you live, you may have rights to:
- request access to personal information we hold about you
- request correction of inaccurate information
- request deletion of personal information
- request export or portability of certain data
- object to certain processing
- restrict certain processing
- withdraw consent where processing is based on consent
- complain to a data protection authority
To make a privacy request, contact support@workbench.cognardo.com.
We may need to verify your identity before fulfilling a request. We may decline or limit requests where permitted by law, including where retention is needed for security, fraud prevention, billing, legal compliance, dispute resolution, or legitimate operational purposes.
Where applicable, we aim to respond to personal data requests within 30 days.
19. Security
We use technical and organizational measures designed to protect information, including:
- authenticated backend requests
- session validation
- user-scoped access checks
- rate limiting
- request validation
- input sanitization in selected workflows
- content minimization in selected workflows
- reauthentication for sensitive account actions
- OTP flows for selected verification actions
- managed cloud infrastructure
- Firebase and Google Cloud security controls
- limited extension content script behavior
- extension content security policy restrictions
- optional and revocable site permissions
- diagnostic and abuse-prevention controls
However, no system is perfectly secure. We cannot guarantee that information will always remain private, secure, available, or error-free.
You are responsible for securing your account, browser profile, devices, credentials, API keys, session tokens, exported files, and local storage.
20. International processing
Cognardo Workbench is operated from India, but the services, infrastructure, and subprocessors we use may process information in other countries.
By using Cognardo Workbench, you understand that information may be transferred to and processed in countries where we, our infrastructure providers, AI providers, payment providers, authentication providers, or other subprocessors operate. These countries may have privacy and data protection laws that differ from those in your location.
21. Children and age requirements
Cognardo Workbench is not intended for children.
You must be at least 13 years old, or old enough to manage your own Google Account in your country, whichever is higher.
If you are not old enough to use Cognardo Workbench under this policy, do not create an account or use the service.
If we learn that we have collected personal information from someone who is not old enough to use Cognardo Workbench, we may delete the account and related information.
22. Third-party websites and services
Cognardo Workbench may operate on or interact with third-party websites and services, including AI platforms, webpages you approve, authentication providers, payment providers, cloud providers, and AI providers.
This Privacy Policy does not control the privacy practices of third-party websites or services. Your use of third-party services may be governed by their own terms, privacy policies, data processing terms, and platform rules.
You are responsible for complying with third-party terms when using Cognardo Workbench on third-party websites or with third-party content.
23. Changes to this Privacy Policy
We may update this Privacy Policy from time to time.
When we make material changes, we may notify you by updating the date at the top of this page, posting a notice on the website, sending an email, showing an in-product notice, or using another reasonable method.
Your continued use of Cognardo Workbench after an updated Privacy Policy becomes effective means you accept the updated policy to the extent permitted by law.
24. Contact us
For questions or requests about this Privacy Policy or Cognardo Workbench privacy practices, contact:
- Product support and privacy requests:
support@workbench.cognardo.com - General contact:
contact@workbench.cognardo.com - Billing, account, refund, and subscription questions:
accounts@workbench.cognardo.com - Security and abuse reports:
security@workbench.cognardo.com
Public contact name: Raven Black Public trade name: Cognardo Product: Cognardo Workbench