Legal · Updated July 12, 2026

Privacy Policy

Cookd holds a record of your work — so privacy isn't a footnote, it's the point. This explains what we collect, why, who helps us run the service, and the control you keep over your data.


Who we are

Eastbase Studio operates Cookd and is the controller responsible for the personal data described in this policy. You can reach us about privacy any time at support@eastbase.studio.

The short version

  • Your content is private to your account. Cookd is single-user — there’s no team sharing.
  • We don’t sell your data and we don’t use it for advertising.
  • AI features use the OpenAI API by default, with model-response storage disabled. OpenAI states that API data is not used to train its models by default.
  • You can export the documents you generate and ask us to delete your account at any time.

What we collect

We keep this to what the product needs to work:

  • Account data — your name, email, and a securely hashed password (or, if you sign in with Google, your Google account email and identifier).
  • Your content — the wins, goals, learning, projects, review cycles, rubrics, notes, and documents you create.
  • Billing data — if you subscribe, our payment processor handles your card details; we store only your subscription status, plan, renewal dates, and the card brand and last four digits. We never see or store full card numbers.
  • Technical & usage data — basic logs, device and browser information, and (where analytics are enabled) product-usage events tied to your account, to help us understand and improve the product.

How we use it

  • To provide the core product — storing and organizing your work.
  • To generate AI-assisted drafts, coaching, readiness analysis, and documents from your own content.
  • To process subscriptions and send essential account email.
  • To keep the service secure and reliable (rate limiting, abuse prevention, error monitoring).
  • To understand usage and improve the product.

We don’t sell your personal data or use it for advertising, and your content isn’t used to train AI models by our primary API provider by default (see AI processing, below).

AI processing

When you use an AI feature — capturing or strengthening your work, analyzing goals or promotion readiness, or generating a document — the content needed for that request is sent to the OpenAI API by default. Cookd sends each request with response storage disabled. OpenAI states that API data is not used to train its models by default, though limited data may be retained for abuse monitoring under OpenAI’s API data controls. Google Gemini is retained as an operator-controlled rollback provider and may process the same request data if that rollback is active. Provider terms and controls may change. Cookd grounds output in your own data, but you should always review it.

AI is optional. Where no provider is configured, Cookd uses a built-in deterministic fallback and nothing is sent out for AI processing.

Service providers (subprocessors)

We rely on a small set of trusted providers to run Cookd. Depending on configuration, these may include:

  • Vercel — application hosting and traffic/performance analytics.
  • Neon — managed PostgreSQL database where your content is stored.
  • OpenAI — the primary API provider for AI-assisted features.
  • Google — an optional Gemini rollback provider for AI features, and Google Sign-In if you choose it.
  • Resend — transactional email (verification, password reset, reminders).
  • Lemon Squeezy — payments and subscription management, as merchant of record.
  • PostHog and Sentry — product analytics and error monitoring, where enabled.
  • Upstash — rate limiting and caching, where enabled.

Each provider only receives the data needed for its function, and we choose providers with appropriate security practices.

Cookies & analytics

Cookd uses a small number of essential cookies to keep you signed in and to secure forms — these are required for the product to work. Where product analytics are enabled, we capture usage events tied to your account to understand how features are used and where they fall short. Our posture is deliberately conservative:

  • No session-recording or screen-replay tools.
  • Analytics are reverse-proxied through our own domain rather than loading third-party tracking scripts directly.
  • We identify analytics events only by your account id and email, and we don’t use this data for advertising.

You can block non-essential cookies in your browser without breaking core functionality.

Your rights and controls

  • Access & export — view your data in the app, export the documents you generate, and request a copy of your account data by email.
  • Correction — edit or update your content and account details whenever you like.
  • Deletion — you can delete individual records yourself in the app at any time; to delete your whole account and personal data, email us and we’ll action it within the windows in Data retention, below.
  • Depending on where you live, you may have additional rights under laws like the GDPR or CCPA. Email us to exercise them.

Data retention

  • While active — we keep your data for as long as your account is open.
  • Account deletion — when you ask us to delete your account, we remove or anonymize your personal data from our live systems within 30 days.
  • Backups — encrypted backups are rotated on a rolling basis, and any residual copies of deleted data are purged within 90 days.
  • Operational logs — server and security logs (for example, error and request logs) are retained for a limited period, typically up to 30 days.
  • Billing & legal exception — invoices and transaction records are kept for as long as the law requires (commonly up to 7 years for tax and accounting), even after account deletion.

Security

Passwords are stored hashed, traffic is encrypted in transit, sensitive actions are rate-limited, and access to your content is scoped to your account. No system is perfectly secure, but we take reasonable, layered measures to protect your data. Please also help us keep it safe — don’t store other people’s confidential information in Cookd (see the Terms of Service).

Changes to this policy

We’ll update this policy as the product evolves. When we do, we’ll change the “Updated” date above and, for material changes, give notice in-app or by email.

Contact

Questions, or want to exercise a privacy right? Email support@eastbase.studio. See also our Terms of Service.