Privacy
Cognivo is a math tutor for students, so almost everything it holds is schoolwork. This page says what we keep, where it goes, and how to get rid of it. It describes how the product is built; it is not a claim of certification under COPPA, FERPA, or any other scheme.
What we keep
- Your account — name, email address, time zone, an optional grade and course, and either a password hash or the identifier of the Google account you signed in with.
- Session work — the written transcript of the session, everything on the shared board, and any photo of your work you put on it.
- Homework — the practice set written after a session, what you turn in, and how it was marked.
- Your learning profile — how you like to be taught (pace, what should happen when you are stuck, which explanations help, a note in your own words) and what the tutor has noticed across sessions.
- Bookings — the sessions you schedule, their topics and times.
- Parent links — an invitation between a parent account and a student account, and whether it was allowed.
What we do not keep
Session audio is never recorded. Your microphone is live only while the session is, and no recording is written anywhere. The written transcript is kept, so you can read a session back afterwards.
There are no advertising trackers and no third-party analytics on this site. The cookies we set keep you signed in, remember whether you chose light or dark, and, for a few minutes while a Google sign-in completes, protect that sign-in from being hijacked.
Where it is stored
Text — accounts, transcripts, summaries, bookings, homework results — lives in a hosted Postgres database reached over TLS. Files you upload, generated worksheets, and exports live in private object storage that is not reachable by URL; a request for one goes through the same authorization as the page it belongs to.
Your learning profile is encrypted by the application with AES-256-GCM before it is written, under a key the database never holds. Transcripts and summaries are stored as ordinary text and are protected by authorization on every read, not by application-layer encryption. We do not describe any of this as end-to-end encryption, because it is not.
Who else processes it
- OpenAI — during a live session your speech and the board's contents are processed by OpenAI's realtime model. That model is the tutor's voice and its thinking.
- Anthropic — after a session ends, the transcript and the boards are sent to Anthropic to write the summary and to write and mark homework.
- Google — only if you choose to sign in with Google, which tells us the name, email address, and picture on that account.
Your work is never sold, and it is never used to train outside models. Nothing is sent to an advertiser.
What a linked parent sees
A parent sees a student only after inviting that student's verified email address and the student allowing it. Either side can end the link, and it stops working immediately.
A linked parent sees session times, session summaries, homework scores, upcoming bookings, and how many free sessions are left. A linked parent never sees transcripts, boards, uploaded photos, per-problem homework feedback, or the learning profile. More about the parent view.
Keeping and deleting
- Download your learning profile, or delete it outright, from your Profile page. Deleting it stops the tutor from using anything it held.
- Remove a single thing the tutor noticed from the same page; the tutor stops using that observation.
- Pictures the tutor takes of the board mid-session so it can look at your working are deleted as soon as it has looked.
- To delete an account and everything attached to it, write to us from the address the account uses. Contact.
If this changes
If what we keep or who processes it changes, this page changes with it before the change takes effect.