Legal

Terms & Privacy

How we operate, what we protect, and your rights as a Cogna8 user.

Last updated: February 10, 2026

Terms of Service

Cogna8 Terms of Service

Effective date: February 10, 2026

1. Acceptance of Terms

By accessing or using the Cogna8 platform ("Service"), you agree to be bound by these Terms of Service ("Terms"). If you are using the Service on behalf of an organisation, you represent and warrant that you have the authority to bind that organisation to these Terms, and "you" refers to both you individually and the organisation.

If you do not agree to these Terms, you must not access or use the Service. Your continued use of the Service after any modifications to these Terms constitutes acceptance of those modifications.

2. Description of Service

Cogna8 is a State Integrity platform for AI systems. The Service provides a control plane for governing AI actions through:

  • A State Engine that maintains a canonical record of what AI agents know and believe, detecting contradictions in real time.
  • Conflict Detection that surfaces contradictions between agents, data sources, or temporal states before any action is taken.
  • An immutable Audit Trail that records every state change, conflict, gate evaluation, and resolution for full decision traceability.
  • Policy Gates that enforce deterministic rules about which actions may proceed based on the current state of knowledge — blocking actions when required state keys are missing, conflicted, or policy conditions are unmet.
  • REST APIs, SDKs (Python, TypeScript), and integrations with third-party AI frameworks including LangChain, LlamaIndex, and others.
  • A web-based development environment for exploring and testing State Integrity concepts.

The Service is designed to ensure that AI systems never act on contradicted, stale, or incomplete State — providing deterministic governance, not probabilistic filtering.

3. Eligibility

You must be at least 18 years old (or the age of majority in your jurisdiction) to use the Service. By using the Service, you represent that you meet this requirement. If you are under 18, you may not create an account or use the Service.

4. Account Registration & Security

To access certain features of the Service, you must register for an account. You agree to:

  • Provide accurate, current, and complete information during registration.
  • Maintain and promptly update your account information to keep it accurate and complete.
  • Maintain the security and confidentiality of your login credentials and API keys.
  • Accept responsibility for all activities that occur under your account.
  • Notify Cogna8 immediately at admin@cogna8.io if you suspect any unauthorised use of your account.

Cogna8 reserves the right to suspend or terminate accounts that violate these Terms or that we reasonably believe have been compromised.

5. Acceptable Use

You agree not to use the Service to:

  1. Violate any applicable law, regulation, or third-party right.
  2. Transmit any malware, virus, or other harmful code.
  3. Attempt to gain unauthorised access to any part of the Service, other accounts, or connected systems.
  4. Interfere with or disrupt the integrity or performance of the Service.
  5. Use the Service to develop a competing product or service.
  6. Reverse engineer, decompile, or disassemble any aspect of the Service except as permitted by applicable law.
  7. Scrape, crawl, or use automated means to access the Service beyond the provided APIs.
  8. Circumvent any rate limits, access controls, or security measures.
  9. Store or transmit content that is unlawful, defamatory, or infringes intellectual property rights.
  10. Use the Service in any manner that could damage, disable, overburden, or impair the Service.

Cogna8 reserves the right to investigate and take appropriate action against anyone who, in Cogna8's sole discretion, violates this section, including removing content, suspending or terminating accounts, and reporting to law enforcement.

6. API Usage & Rate Limits

Access to the Cogna8 API is subject to rate limits and usage quotas as described in the API documentation. You agree to:

  • Comply with all documented rate limits and usage restrictions.
  • Implement appropriate retry logic and backoff strategies in your integrations.
  • Not share API keys or access tokens with unauthorised parties.
  • Rotate API keys periodically and immediately revoke compromised keys.

Cogna8 may modify rate limits or usage quotas at any time. We will provide reasonable notice of material changes via the API documentation or email.

7. Intellectual Property

The Service, including all software, algorithms, designs, text, graphics, and documentation, is owned by Cogna8 and is protected by copyright, trademark, and other intellectual property laws. "Cogna8", the Cogna8 logo, "State Integrity", and related marks are trademarks of Cogna8.

Subject to these Terms, Cogna8 grants you a limited, non-exclusive, non-transferable, revocable licence to access and use the Service for your internal business purposes. This licence does not include the right to sublicence, modify, adapt, or create derivative works of the Service.

8. Customer Data & State Ownership

Your State data belongs to you. Cogna8 makes the following commitments regarding your data:

  1. Ownership: You retain all rights, title, and interest in your State data, audit trail entries, policy configurations, and any other data you submit to the Service ("Customer Data").
  2. Limited licence: You grant Cogna8 a limited licence to process Customer Data solely to provide and improve the Service.
  3. No training: Cogna8 will not use your Customer Data to train machine learning models or for any purpose unrelated to providing the Service to you.
  4. Portability: You may export your Customer Data at any time through the API or by contacting admin@cogna8.io.
  5. Deletion: Upon account termination, Customer Data will be made available for export for 30 days, after which it will be permanently deleted from production systems within 90 days (backup purge cycle).

9. Service Levels & Availability

Cogna8 strives to maintain high availability of the Service. However, the Service is provided on an "as available" basis. We do not guarantee uninterrupted or error-free operation. Scheduled maintenance windows will be communicated in advance where practicable.

Enterprise customers with a separate Service Level Agreement (SLA) are governed by the terms of that agreement with respect to uptime commitments and remedies.

10. Fees & Payment

Certain features of the Service may require payment of fees. All fees are stated in Australian Dollars (AUD) unless otherwise specified. You agree to pay all applicable fees in accordance with the pricing plan you select. Fees are non-refundable except as required by law or as expressly stated in these Terms.

Cogna8 may change pricing at any time upon 30 days' written notice. Continued use of the Service after a pricing change constitutes acceptance of the new pricing.

11. Confidentiality

Each party agrees to hold in confidence and not disclose to any third party any Confidential Information of the other party, except as expressly permitted in these Terms. "Confidential Information" means any non-public information disclosed by one party to the other that is designated as confidential or that reasonably should be understood to be confidential, including Customer Data, API keys, security configurations, and business plans.

Confidential Information does not include information that: (a) is or becomes publicly known through no fault of the receiving party; (b) was known to the receiving party prior to disclosure; (c) is independently developed by the receiving party without reference to the disclosing party's Confidential Information; or (d) is lawfully received from a third party without restriction.

12. Warranties & Disclaimers

Cogna8 warrants that the Service will perform materially in accordance with the applicable documentation. If the Service does not conform to this warranty, your exclusive remedy is for Cogna8 to use commercially reasonable efforts to correct the non-conformity.

EXCEPT FOR THE EXPRESS WARRANTY ABOVE, THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE" WITHOUT WARRANTY OF ANY KIND, WHETHER EXPRESS, IMPLIED, STATUTORY, OR OTHERWISE. COGNA8 SPECIFICALLY DISCLAIMS ALL IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. COGNA8 DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR COMPLETELY SECURE. NO ADVICE OR INFORMATION, WHETHER ORAL OR WRITTEN, OBTAINED FROM COGNA8 SHALL CREATE ANY WARRANTY NOT EXPRESSLY STATED IN THESE TERMS.

13. Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW, IN NO EVENT SHALL COGNA8, ITS DIRECTORS, EMPLOYEES, AGENTS, OR LICENSORS BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, INCLUDING BUT NOT LIMITED TO LOSS OF PROFITS, DATA, BUSINESS OPPORTUNITIES, OR GOODWILL, ARISING OUT OF OR RELATED TO YOUR USE OF OR INABILITY TO USE THE SERVICE, REGARDLESS OF THE CAUSE OF ACTION OR THE THEORY OF LIABILITY, EVEN IF COGNA8 HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

COGNA8'S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATED TO THESE TERMS OR THE SERVICE SHALL NOT EXCEED THE GREATER OF: (A) THE AMOUNTS PAID BY YOU TO COGNA8 IN THE TWELVE (12) MONTHS PRECEDING THE CLAIM; OR (B) ONE HUNDRED AUSTRALIAN DOLLARS (AUD $100).

Some jurisdictions do not allow the exclusion or limitation of incidental or consequential damages, so the above limitations may not apply to you. In such jurisdictions, Cogna8's liability is limited to the fullest extent permitted by law.

14. Indemnification

You agree to indemnify, defend, and hold harmless Cogna8, its officers, directors, employees, and agents from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable legal fees) arising out of or related to: (a) your use of the Service; (b) your violation of these Terms; (c) your violation of any third-party rights; or (d) your Customer Data.

15. Term & Termination

These Terms are effective from the date you first access the Service and continue until terminated. Either party may terminate these Terms at any time by providing written notice to the other party.

Upon termination:

  • Your right to access and use the Service will cease immediately.
  • You will have a 30-day export window to retrieve your Customer Data via the API or by contacting admin@cogna8.io.
  • After the export window, Customer Data will be permanently deleted from production systems. Backup copies will be purged within 90 days.
  • Sections that by their nature should survive termination (including Intellectual Property, Limitation of Liability, Indemnification, and Governing Law) will survive.

Cogna8 may suspend or terminate your access immediately if you breach these Terms or if required by law.

16. Modifications to the Service

Cogna8 reserves the right to modify, suspend, or discontinue the Service (or any part thereof) at any time, with or without notice. We will use reasonable efforts to provide advance notice of material changes. Cogna8 shall not be liable to you or any third party for any modification, suspension, or discontinuation of the Service.

17. Modifications to Terms

Cogna8 may modify these Terms at any time by posting the updated Terms on the Service. Material changes will be communicated via email or a prominent notice on the Service at least 30 days before they take effect. Your continued use of the Service after the effective date of any modification constitutes acceptance of the modified Terms.

18. Governing Law & Dispute Resolution

These Terms shall be governed by and construed in accordance with the laws of New South Wales, Australia, without regard to its conflict of law provisions. Any dispute arising out of or in connection with these Terms shall be resolved as follows:

  1. Negotiation: The parties shall first attempt to resolve the dispute through good-faith negotiation for a period of 30 days.
  2. Mediation: If negotiation fails, the dispute shall be submitted to mediation administered by the Australian Disputes Centre (ADC) in Sydney, Australia.
  3. Litigation: If mediation fails, the dispute may be brought before the courts of New South Wales, Australia, and each party irrevocably submits to the exclusive jurisdiction of those courts.

19. General Provisions

Entire Agreement. These Terms, together with any applicable SLA or order form, constitute the entire agreement between you and Cogna8 regarding the Service and supersede all prior agreements and understandings.

Severability. If any provision of these Terms is held to be invalid or unenforceable, the remaining provisions shall continue in full force and effect.

Waiver. The failure of Cogna8 to enforce any right or provision of these Terms shall not constitute a waiver of such right or provision.

Assignment. You may not assign or transfer these Terms without Cogna8's prior written consent. Cogna8 may assign these Terms without restriction.

Force Majeure. Cogna8 shall not be liable for any failure or delay in performance due to causes beyond its reasonable control, including natural disasters, acts of government, pandemic, war, terrorism, labour disputes, power failures, or internet disruptions.

Notices. Notices to Cogna8 should be sent to admin@cogna8.io. Notices to you will be sent to the email address associated with your account.

No Third-Party Beneficiaries. These Terms do not confer any rights or remedies on any third party.

20. Contact

If you have any questions about these Terms, please contact us:

admin@cogna8.io

Privacy Policy

Cogna8 Privacy Policy

Effective date: February 10, 2026

1. Introduction & Scope

Cogna8 ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Cogna8 platform and related services (the "Service").

This policy applies to all users of the Service, including visitors to our website, registered account holders, API consumers, and anyone who interacts with our platform. By using the Service, you consent to the practices described in this Privacy Policy.

2. Information We Collect

2.1 Information You Provide Directly

  • Account registration data: name, email address, organisation name, role.
  • Authentication credentials: OAuth tokens (via Google or other providers), API keys.
  • Payment information: billing address, payment method details (processed by our payment provider; we do not store full card numbers).
  • Communications: emails, support tickets, feedback, and survey responses you send to us.
  • Partner inquiry data: name, email, company, partnership type, and messages submitted through our partner contact form.

2.2 Information Collected Automatically

  • Usage data: features used, actions performed, timestamps, session duration.
  • Device information: browser type, operating system, screen resolution, device identifiers.
  • Network data: IP address, approximate location (city/country level), referring URL.
  • Performance data: page load times, error logs, API response times.

2.3 State Data

When you use the Cogna8 platform, you may submit State data — including state keys, values, metadata, conflict records, gate evaluations, policy configurations, and audit trail entries. This data is Customer Data as defined in our Terms of Service. We process State data solely to provide the Service to you. We do not access, analyse, or use your State data for any other purpose, including training machine learning models or building aggregate datasets.

3. Legal Basis for Processing

We process your personal information on the following legal bases:

  • Contract: Processing necessary to provide the Service you have requested and to fulfil our contractual obligations.
  • Legitimate interests: Processing necessary for our legitimate business interests, such as improving the Service, preventing fraud, and ensuring security — provided these interests are not overridden by your rights.
  • Consent: Where you have given specific consent for certain processing activities, such as receiving marketing communications.
  • Legal obligation: Processing necessary to comply with applicable laws, regulations, or legal proceedings.

4. How We Use Your Information

4.1 Providing the Service

  • Authenticating your identity and managing your account.
  • Processing State data, evaluating gates, detecting conflicts, and maintaining audit trails.
  • Delivering API responses and SDK functionality.
  • Providing customer support and responding to inquiries.

4.2 Improving the Service

  • Analysing aggregate usage patterns to improve features and performance (using anonymised, aggregated data only — never your State data).
  • Conducting internal research and development.
  • Monitoring and improving infrastructure reliability and security.

4.3 Communication

  • Sending service-related notifications (e.g., security alerts, maintenance windows, account changes).
  • Responding to your support requests and inquiries.
  • Sending product updates and feature announcements (with opt-out available).

4.4 Security & Compliance

  • Detecting, investigating, and preventing fraudulent or unauthorised activity.
  • Enforcing our Terms of Service and other policies.
  • Complying with applicable legal requirements and responding to lawful requests.

What we do NOT do:

  • We do NOT sell your personal information to third parties.
  • We do NOT use your State data to train machine learning models.
  • We do NOT share your State data with other customers.
  • We do NOT create advertising profiles from your usage data.
  • We do NOT use your data for any purpose unrelated to providing and improving the Service.

5. Data Storage, Security & Infrastructure

5.1 Encryption

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256). API keys and authentication tokens are hashed and salted before storage.

5.2 Access Controls

Access to Customer Data is restricted to authorised personnel who require access to perform their duties. We employ role-based access controls, multi-factor authentication, and audit logging for all internal access.

5.3 Infrastructure

The Service is hosted on enterprise-grade cloud infrastructure with redundancy across multiple availability zones. We employ automated monitoring, alerting, and incident response procedures.

5.4 Audit Trail Integrity

Cogna8's audit trail is designed to be immutable. Once an event is recorded, it cannot be modified or deleted. This ensures the integrity and reliability of your compliance and governance data.

5.5 Incident Response

In the event of a data breach, Cogna8 will notify affected users within 72 hours of becoming aware of the breach, in accordance with applicable data protection laws. We will provide details of the nature of the breach, the data affected, and the steps being taken to mitigate the impact.

6. Data Sharing & Third Parties

We may share your information in the following limited circumstances:

6.1 Service Providers

We engage trusted third-party service providers to assist in delivering the Service (e.g., cloud hosting, payment processing, email delivery, analytics). These providers are contractually obligated to protect your data and may only process it on our behalf.

6.2 Legal Requirements

We may disclose your information if required by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

6.3 Business Transfers

If Cogna8 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your personal information is transferred and becomes subject to a different privacy policy.

6.4 With Your Consent

We may share your information with third parties when you have given explicit consent for us to do so.

7. Cookies & Tracking Technologies

7.1 Essential Cookies

We use essential cookies to maintain your session, remember your authentication state, and ensure the Service functions correctly. These cookies are strictly necessary and cannot be disabled.

7.2 Preference Cookies

We use preference cookies to remember your settings, such as theme preference (light/dark mode), language, and display options.

7.3 Analytics Cookies

We may use analytics cookies to understand how the Service is used, identify popular features, and improve the user experience. Analytics data is aggregated and anonymised.

7.4 What We Do NOT Use

  • We do NOT use third-party advertising cookies.
  • We do NOT use tracking pixels for advertising purposes.
  • We do NOT use cross-site tracking technologies.
  • We do NOT sell cookie data to data brokers or advertisers.
  • We do NOT use fingerprinting technologies to identify users.

8. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

  1. Right of Access: You may request a copy of the personal information we hold about you.
  2. Right to Rectification: You may request correction of inaccurate or incomplete personal information.
  3. Right to Erasure: You may request deletion of your personal information, subject to legal retention requirements.
  4. Right to Restriction: You may request that we restrict processing of your personal information in certain circumstances.
  5. Right to Data Portability: You may request your personal information in a structured, commonly used, machine-readable format.
  6. Right to Object: You may object to processing of your personal information based on legitimate interests.
  7. Right to Withdraw Consent: Where processing is based on consent, you may withdraw consent at any time.
  8. Right to Complain: You have the right to lodge a complaint with your local data protection authority.

To exercise any of these rights, please contact us at admin@cogna8.io. We will respond within 30 days (or as required by applicable law).

9. Data Retention

We retain your information for the following periods:

  • Account data: Retained for the duration of your account, plus 30 days after account closure for export purposes.
  • Backup copies: Purged within 90 days of account closure.
  • Usage logs: Retained for up to 12 months for security and performance analysis, then anonymised or deleted.
  • Billing records: Retained for 7 years to comply with tax and accounting obligations.
  • Support correspondence: Retained for 3 years after resolution, then deleted.

You may request early deletion of your data by contacting admin@cogna8.io, subject to any legal retention requirements.

10. International Data Transfers

Cogna8 is based in Australia. Your information may be processed in Australia, the United States, and other countries where our service providers operate. When we transfer data outside your jurisdiction, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs) approved by the European Commission for transfers from the EU/EEA.
  • Adequacy decisions where applicable.
  • Binding corporate rules or equivalent mechanisms.
  • Your explicit consent where required.

11. Children's Privacy

The Service is not directed at children under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information promptly. If you believe a child under 18 has provided us with personal information, please contact us at admin@cogna8.io.

12. Jurisdiction-Specific Provisions

12.1 Australian Privacy Act

If you are an Australian resident, your personal information is handled in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12.2 GDPR (European Economic Area)

If you are located in the EEA, you have additional rights under the General Data Protection Regulation (GDPR), including the rights described in Section 8 above. Our legal basis for processing is described in Section 3. For GDPR-related inquiries, contact our Data Protection team at admin@cogna8.io. You may also lodge a complaint with your local Data Protection Authority (DPA).

12.3 CCPA/CPRA (California)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the right to know what personal information is collected, the right to delete, the right to opt out of the sale of personal information, and the right to non-discrimination. We do not sell personal information as defined by the CCPA/CPRA.

12.4 Other Jurisdictions

We are committed to complying with applicable data protection laws in all jurisdictions where we operate. If you have questions about how the laws of your jurisdiction apply, please contact us at admin@cogna8.io.

13. Third-Party Links & Integrations

The Service may contain links to third-party websites, services, or integrations (e.g., LangChain, OpenAI, GitHub). We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party service before providing personal information. Our integration with third-party services is limited to the functionality described in our documentation and does not grant those services access to your State data unless you explicitly configure such access.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to the address associated with your account, or by posting a prominent notice on the Service, at least 30 days before the changes take effect. We encourage you to review this Privacy Policy periodically. The "Effective date" at the top of this policy indicates when it was last revised.

15. Contact & Data Protection Enquiries

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

admin@cogna8.io

You may also contact the relevant supervisory authority in your jurisdiction:

  • Australia: Office of the Australian Information Commissioner (OAIC) — oaic.gov.au
  • EU/EEA: Your local Data Protection Authority (DPA)
  • UK: Information Commissioner's Office (ICO) — ico.org.uk