Account access
Sign in with Google or email + password. Passwords are stored only as salted hashes, and sign-in/sign-up are rate-limited to resist abuse.
Private by default
Your sessions and files are visible only to you. Per-item org sharing and public read-only links are opt-in.
No training on your data
Cortexa does not use your research content or files to train models.
API keys
Keys authenticate the OpenAI-compatible API, native agent streaming, and MCP traffic. The value is shown once; Cortexa stores only a hash.
Revocation is shared
Revoking a key disables it everywhere — API clients, MCP desktop configs, remote MCP clients, and any automation using that token. Name keys per client or environment so you can revoke precisely.
Private connections are separately scoped
API and MCP keys need the
connections:usescope, and the key's user or organization must still hold a live grant to each connection. Revoking a grant takes effect without rotating the key.Your research data
It's easiest to reason about the model by separating source material, generated artifacts, and operational metadata.
Uploaded files
Private to you unless you explicitly share them with an organization workspace.
Generated outputs
Abstracts, decks, analysis, and citations stay private unless you opt into org or public-link sharing.
Private connection evidence
Connections use explicit user/role grants. Sessions that read private evidence cannot be published through an anonymous link.
Usage & pageview metadata
Cookie-free aggregate page visits plus operational usage support product improvement, billing, abuse prevention, debugging, and admin visibility. Research content is not sent to Web Analytics.
Research disclaimer
Research context only — not medical, legal, financial, or regulatory advice.
Encryption & deletion
Your data is encrypted in transit and at rest, and you can delete your account on your own terms.
Encryption
TLS 1.2+ in transit; encrypted at rest.
Delete your account
Schedule deletion in Settings → Account. You have a 30-day window to change your mind, then erasure runs on the next nightly pass — within 31 days of the request.
What deletion removes
Cascades across sessions, files, artifacts, usage, and payment identifiers.
Compliance & regulated data
What Cortexa offers today — stated plainly, with no over-claiming.
HIPAA / PHI
Not HIPAA-covered by default. No PHI without a BAA; de-identify for research.
GDPR & CCPA
Data-subject rights incl. access and deletion — support@cortexa.sh.
Enterprise reviews
Security reviews, a BAA, or compliance questions: contact support.
See also
Full legal terms live in our Privacy Policy and Terms of Service.