Privacy Policy
Last Updated: May 29, 2026
Cogniself LLC d/b/a Cogniself ("Cogniself," "Company," "we," "our," or "us") values privacy and data protection. This Privacy Policy describes how we handle personal information across Cogniself's consumer, Delta, Jung, Growth Hub, shared-report, invite, billing, and Pro services.
Last updated: July 17, 2026.
We do not promise clinical confidentiality, HIPAA coverage, or employment-law compliance for customer workflows unless a separate written agreement expressly says so. If you use Cogniself through an organization, that organization may have its own privacy obligations and notices.
Our Privacy Commitments
Cogniself is designed to align with European Union and United Kingdom data-protection standards, including transparency, purpose limitation, data minimization, security, accountability, and privacy rights. That means:
- We use your assessment responses, scores, reports, Jung context, Delta responses, Growth Hub data, and Pro participant data to provide the Cogniself results, tools, and services you request, and for the limited operational, security, legal, and support purposes described in this Policy.
- We do not sell your personal information.
- We do not use assessment responses, scores, Delta responses, Jung chats, Growth Hub data, or Pro participant data for cross-context behavioral advertising.
- We do not disclose your identifiable assessment results to a Cogniself Pro organization, recruiter, manager, team lead, observer, partner, or shared-link recipient unless you choose a sharing flow, accept an invite, link an assessment, or otherwise consent to that disclosure.
- Cogniself personnel do not routinely view identifiable assessment responses or results. Access is restricted to authorized personnel and systems where needed to operate the Services, provide support you request, debug technical issues, protect security, prevent abuse, comply with law, enforce terms, or handle a privacy request.
- We protect personal information with administrative, technical, and organizational safeguards, including encryption in transit, provider-supported encryption at rest, role-based access controls, logging, and separation or pseudonymization of identifiers where practical.
- We use aggregated, de-identified, or anonymized data where practical for product analytics and service improvement. If data can still reasonably identify you or be linked back to your account, we treat it as personal information.
Scope and Roles
This Privacy Policy explains how Cogniself collects, uses, discloses, retains, and protects personal information when you use Cogniself websites, applications, assessments, reports, Jung AI assistant, Cogniself Delta, Growth Hub, shared links, invite flows, Cogniself Pro workspaces, billing, support, and related services. It should be read with our Terms and Conditions.
- For consumer users, Cogniself generally acts as the business, controller, or similar responsible party for personal information we collect directly.
- For Cogniself Pro, an organization may act as controller, business, employer, deployer, or similar responsible party for candidate, team-member, employee, participant, or workspace data. Cogniself may process data on behalf of the organization under its instructions and any data-processing agreement.
- If you were invited by an organization, recruiter, manager, team lead, partner, or observer, that inviter may receive the information and outputs described in the invite or consent flow.
- If an organization configures Cogniself for regulated employment, workplace, healthcare, education, public-sector, or high-risk AI use, that organization is responsible for giving the required notices and instructions before Cogniself processes participant data for that use.
Information We Collect
The information we collect depends on how you use Cogniself. Categories may include account and contact data; assessment and report data; Delta and neurodivergence-screening data; Jung, voice, and Growth Hub data; Cogniself Pro organization, project, participant, consent, invite, and report data; payment and commercial data; device, usage, log, cookie, analytics, approximate location, and security data; communications and support data; and information from authentication providers, payment processors, organization administrators, invite senders, observers, partners, analytics providers, fraud-prevention services, and public or licensed research databases.
Assessment responses, scores, and generated reports are account-linked when needed to show your results, maintain your report history, support paid features, provide account export, honor deletion or revocation requests, and secure the Services. For participant, invite, shared-report, and consent flows, we may record evidence needed to administer and prove the decision later, such as notice version, locale, consent status, consent or revocation time, participant email or account identifier, project and organization identifiers, approximate country from request metadata, user-agent metadata, and a summary of the notice shown.
Sensitive Information
Some Cogniself features can involve sensitive information or inferences, including personality traits, neurodivergence-related screening responses, workplace context, relationship context, participant consent records, and other information that may reveal health-related, employment-related, psychological, or protected-class implications depending on use.
- We do not require sensitive information unless needed for a feature you choose.
- We do not use assessment responses, Delta responses, Jung chats, Pro participant data, or other sensitive personal information for cross-context behavioral advertising.
- Do not submit protected health information as a HIPAA covered entity or business associate unless we have signed a separate business associate agreement.
- If you submit sensitive information about another person, you are responsible for the legal basis, notice, consent, and authority.
- If GDPR or similar law treats information as special-category data, Cogniself processes it only where a valid Article 9 condition or similar exception applies, such as explicit consent for an optional feature or another basis established by the responsible controller.
How We Use Information
We use personal information to provide, operate, authenticate, localize, secure, and maintain the Services; administer assessments and generate reports; provide Jung assistant context and Delta outputs; manage Growth Hub actions and Pro workspaces; process purchases and subscriptions; send service, security, consent, invite, transactional, product, and lawful marketing communications; monitor performance; debug errors; prevent abuse; enforce terms; protect users; investigate fraud or security incidents; respond to privacy requests; maintain data-protection records; comply with law; improve features through aggregate, de-identified, anonymized, or privacy-preserving analysis where practical; and fulfill legal, accounting, tax, audit, dispute, regulatory, and record-keeping obligations.
We do not use your identifiable assessment responses or results for unrelated purposes. In particular, we do not sell them, do not use them for cross-context behavioral advertising, do not make final employment or clinical decisions with them, and do not share them with Pro organizations or other recipients unless the relevant sharing, invite, consent, or legal basis applies.
Access to Assessment Results
Your assessment responses and results are private by default. Cogniself systems process them to calculate scores, generate reports, show your history, provide Jung or Growth Hub context where you enable those features, and operate account export and deletion tools.
Cogniself personnel do not routinely access identifiable assessment responses or results. Limited access may occur only for authorized operational reasons, such as support you request, security investigation, fraud or abuse prevention, technical debugging, legal compliance, data-protection requests, or enforcing these Terms. Access is role-restricted and logged where supported by the underlying systems.
For Cogniself Pro, a participant's assessment results are not linked to a Pro project and not made available for Pro report generation unless the participant accepts the invite or otherwise gives the relevant consent. Declining or revoking consent prevents future Pro report generation from the linked assessment, subject to the retention limits described below.
AI Processing
Cogniself uses AI and model providers to help generate reports, assistant replies, summaries, voice features, research-supported content, and product recommendations. We may send prompts, user messages, assessment context, report context, transcript text, metadata, and safety instructions to AI providers as needed for the requested feature. We limit these transfers to what is reasonably needed for the feature you requested or enabled. When you use Jung or another conversational AI feature, you are interacting with software-assisted output rather than a human professional.
Cogniself does not use AI outputs as final hiring, rejection, diagnosis, treatment, legal, financial, credit, insurance, housing, or similarly significant decisions. We do not knowingly use identifiable assessment responses, Delta data, Jung chats, or Pro participant data to train publicly available third-party foundation models unless we tell you and obtain legally required consent.
Cogniself Pro outputs are designed for advisory human review. If an organization deploys Cogniself in a context that is regulated as a high-risk AI system, automated employment decision tool, employment test, or consequential-decision system, the organization is responsible for deployer, employer, or controller obligations unless a separate written agreement says otherwise.
How We Share Information
We disclose personal information only as needed for the purposes described here, as directed by you or an authorized organization, or as required by law. We do not sell personal information. Recipients may include service providers, processors, and subprocessors; payment processors such as Stripe; AI and model providers; organization administrators and workspace members according to role and permissions; invite senders, observers, partners, report recipients, or shared-link viewers; legal, safety, and compliance recipients; business transaction recipients; and aggregate, de-identified, or anonymized recipients where permitted by law.
We do not share identifiable assessment responses or results with advertisers or data brokers. We do not share them with a Cogniself Pro organization unless the participant accepts the relevant invite, links an assessment, uses a sharing feature, or another legal basis requires disclosure.
For Cogniself Pro, an organization may export, download, copy, or otherwise handle participant and workspace information outside Cogniself. That organization is responsible for its own access controls, retention, onward sharing, employment records, and responses to data-subject requests for information it controls.
Cookies, Analytics, and Advertising Choices
We use cookies, local storage, pixels, SDKs, server logs, and similar technologies to keep you signed in, remember preferences, secure the Services, understand performance, measure campaigns, and improve the product. Some pages may use analytics or advertising tools if enabled.
You can control cookies through your browser settings. Where legally required, we honor applicable opt-out signals or consent choices for targeted advertising, sale, sharing, and sensitive personal information. We do not sell personal information for money, and we do not use assessment responses, assessment results, Delta responses, Jung chats, Growth Hub data, or Pro participant data for cross-context behavioral advertising.
California Notice at Collection
If you are a California resident, we may collect identifiers, customer records, commercial information, internet or electronic network activity, approximate geolocation, audio or sensory information if you use voice features, professional or employment-related information in Pro contexts, inferences and assessment profiles, and sensitive personal information where you choose to provide it or where required for a feature.
We collect, use, disclose, and retain these categories for the purposes and recipient categories described in this Privacy Policy. We do not knowingly sell or share assessment responses, assessment results, Delta responses, Jung chats, Growth Hub data, Pro participant data, payment data, or sensitive personal information for cross-context behavioral advertising.
Legal Bases for EEA, UK, and Similar Regions
Where GDPR, UK GDPR, or similar law applies, Cogniself is designed to meet applicable controller or processor obligations for the relevant feature and relies on the legal basis that fits the product feature and context:
- Account, authentication, assessment delivery, report generation, purchases, subscriptions, support, security, and core product operation: performance of a contract, legitimate interests, or legal obligation.
- Optional Jung assistant, Growth Hub actions, shared report links, voice features, and optional profile context: performance of a contract, consent where required, or legitimate interests depending on the feature and your choices.
- Delta neurodivergence-screening intake, neurodivergence-related responses, medical-history fields you choose to provide, and health-related inferences: explicit consent or another permitted Article 9 basis where applicable, plus contract necessity for the feature you requested.
- Cogniself Pro participant workflows: the inviting organization may be the controller for project use; Cogniself processes the invite, assessment link, consent record, report generation, security logs, and support functions under the organization’s instructions and any applicable data-processing agreement. Participant consent is recorded before assessment data is linked to a Pro project.
- Analytics, marketing cookies, advertising technologies, and lifecycle marketing: consent where required, opt-out where allowed, and legitimate interests for strictly necessary security, fraud-prevention, and service communications.
- Tax, accounting, payment, fraud prevention, dispute, legal, regulatory, audit, and safety records: legal obligation and legitimate interests.
You may withdraw consent where processing depends on consent. Withdrawal does not affect processing that already occurred lawfully, and it may not remove records we must retain for legal, security, billing, audit, dispute, compliance-evidence, or organization-controller obligations.
Automated Decision-Making and Profiling
Cogniself generates personality, growth, Delta, and Pro insights using software and AI-assisted processing, but Cogniself does not make final clinical, employment, credit, insurance, housing, legal, financial, or similarly significant decisions about you.
If an organization uses Cogniself in a way that creates automated decision-making, profiling, employment testing, high-risk AI, or a consequential decision under applicable law, that organization is responsible for notices, lawful basis, impact assessments, audits, human review, appeals, accommodations, and data rights. Cogniself Pro outputs are designed as advisory material for human review and must not be used as a final hiring, rejection, firing, promotion, diagnosis, protected-class, or automated employment decision.
Where GDPR Article 22 or similar law applies, you may request human review, contest a decision, and request meaningful information about the logic, significance, and expected consequences of relevant profiling. Where the decision was made by a Cogniself Pro organization, Cogniself may direct the request to that organization or act on its instructions.
Data Retention
We keep personal information as long as reasonably necessary for the purposes described here unless a longer period is required or permitted by law. Current retention buckets include:
- Account, profile, assessment, report, Jung, Delta, Growth Hub, and share data: generally while your account, report, share, subscription, or requested feature remains active, unless you delete it or request deletion.
- Jung coaching memory: visible and clearable in privacy settings, included in account export, and removed when the account is deleted unless legal or security retention applies.
- Cogniself Pro participant links: retained while the organization project or workspace remains active. If you revoke consent or delete your account, Cogniself unlinks your assessment from future Pro report generation; the organization may retain project records where it is the controller or where legal, audit, employment, billing, or dispute obligations apply.
- Billing, tax, payment, subscription, affiliate, payout, fraud-prevention, chargeback, accounting, audit, and legal records: retained for the period required or reasonably needed for those obligations.
- Consent, consent-evidence, unsubscribe, security, system, diagnostic, abuse-prevention, and audit logs: retained for the period reasonably needed to prove compliance, protect the Services, investigate incidents, and honor preferences.
- Backups: removed or overwritten on the normal backup lifecycle rather than immediately edited in place.
Deletion requests may not remove de-identified data, aggregate data, backup copies before normal expiration, legal records, fraud-prevention records, or organization records that must be preserved.
Your Privacy Rights
Depending on where you live and how you use Cogniself, you may have rights to access, know, correct, delete, port, restrict, object, withdraw consent, opt out of sale or sharing, opt out of targeted advertising, limit sensitive personal information, appeal a rights decision, or complain to a regulator.
You can make requests through available account settings or by emailing help@cogniself.co. We may need to verify identity and authority. We respond within the period required by applicable law. If your information is controlled by a Cogniself Pro organization, we may direct your request to that organization or act on its instructions. Account export is designed to include account, assessment, report, Delta, Jung, Growth Hub, sharing, subscription, email-preference, affiliate, consent, and relevant Pro records associated with your account, subject to the rights and freedoms of other people.
International Transfers
Cogniself is based in the United States, and personal information may be processed in the United States and other countries where we or our service providers operate. Where required, we use appropriate safeguards such as contractual protections, data-processing agreements, standard contractual clauses, transfer impact assessments, adequacy decisions, or other lawful transfer mechanisms.
Service-provider categories may include hosting and infrastructure providers, database and storage providers, authentication providers, payment processors, email providers, analytics providers, AI and model providers, voice/audio providers, fraud-prevention and security providers, support tools, professional advisers, and organization-selected recipients in Pro workflows. Cogniself maintains internal records of processors and subprocessors for launch governance and customer contracting, and may make subprocessor information available through a separate register, data-processing agreement, or customer notice.
If Cogniself is required to appoint an EU/UK representative or Data Protection Officer for a particular offering or customer workflow, the representative or DPO contact will be listed here or in the applicable product, checkout, workspace, or data-processing agreement notice. Until then, privacy requests should be sent to help@cogniself.co.
Security, Encryption, and De-Identification
We use administrative, technical, and organizational safeguards designed to protect personal information, including access controls, encryption in transit, provider-supported encryption at rest, role-based permissions, logging, and security monitoring. We separate or pseudonymize identifiers where practical and use aggregated, de-identified, or anonymized data where practical for analytics, diagnostics, and service improvement.
Because Cogniself must link some information to your account to provide your results, subscriptions, reports, exports, and deletion controls, not all product data is anonymous while your account or report remains active. Where data remains identifiable or reasonably linkable to you, we handle it as personal information under this Policy.
We maintain an incident-response process intended to support legally required breach assessment, documentation, and notification. No system is perfectly secure, so we cannot guarantee absolute security. Contact help@cogniself.co if you believe your account or information has been compromised.
Children and Minors
Cogniself is intended for adults. We do not knowingly collect personal information from children under thirteen (13), and the Services are not intended for users under eighteen (18) unless a specific product flow expressly allows a different age gate and all required consents are satisfied.
Healthcare and HIPAA
Cogniself is not a healthcare provider, health plan, healthcare clearinghouse, HIPAA covered entity, or HIPAA business associate by default. The Services are not designed for diagnosis, treatment, clinical monitoring, or emergency care. Covered entities and business associates should not submit protected health information unless a separate written business associate agreement is in place.
Changes to This Policy
We may update this Privacy Policy from time to time. The updated policy will be effective when posted unless a later effective date is stated. If changes are material, we may provide additional notice as required by law.
Contact Us
If you have questions about this Privacy Policy or want to exercise privacy rights, contact Cogniself LLC at help@cogniself.co.
© 2026 Cogniself LLC