Cortex Research Workstation
Return to Search
GDPR & CCPA Regulatory Standard

Privacy Policy

Effective Date: September 13, 2026 • Version 2.4

1. Core Principles: Local-First & Zero Data Monetization

Cortex is engineered around the principle of data minimization and zero unsolicited telemetry. We do not sell, rent, monetize, or broker personal information to third parties or advertising networks. All research sessions, query history, and saved workspaces remain strictly within your browser's client-side environment (IndexedDB and LocalStorage) unless you explicitly configure remote webhook alerts.

2. Client-Side Vault & Cryptographic Security

Any API credentials (e.g., OpenRouter, OpenAI, Anthropic, or custom endpoint keys) supplied in the Cortex Settings modal are stored locally using client-side cryptographic primitives (PBKDF2 key derivation and AES-GCM encryption). Decryption keys are never transmitted to our servers. When requests are executed, calls route directly between your client browser and the designated frontier AI model provider.

3. Information We Do Not Collect

  • No Personal Identity Profiling: We do not require registration, personal names, phone numbers, or social identifiers to conduct market intelligence queries.
  • No Cross-Site Tracking: We do not deploy cross-site tracking pixels, persistent third-party advertising cookies, or browser fingerprinting scripts.
  • No Retention of Model Inputs: Search inquiries processed via the client remain ephemeral and are not indexed in any centralized surveillance repository.

4. Cookies and Local Storage

We utilize standard web storage technologies solely for technical functionality and persistent user preferences:

  • Strictly Necessary Storage: Maintains UI themes, active research desks, and client cryptographic vault state.
  • Functional Telemetry (Optional): Client-side session metrics (e.g., queries conducted) stored locally to prevent rate abuse, respecting your browser's Do-Not-Track (DNT) header.

5. User Rights Under GDPR and CCPA

Under international privacy frameworks including the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA), you retain full rights over your data:

  • Right to Eradication (Right to be Forgotten): You can wipe 100% of your search history, saved memos, and stored keys at any time via the 1-click "Clear Workspace Search History" button.
  • Right to Data Portability: Export all threads, research memos, and settings to a standard structured JSON file via the Research Library modal.
  • Right to Non-Discrimination: Cortex provides identical core research features regardless of privacy choices.

6. Contact Point & Data Protection Office

For privacy inquiries, audit verifications, or correspondence, contact our designated desk:

Cortex • Hitesh Ambulkar

https://cortex-research.org

Terms of Service ➔ System Confirmation ➔ Back to Cortex Desk ➔