1. Who we are and what this policy covers
Cognito System (“Cognito,” “we,” “us,” or “our”) is operated by Aleksei Usanov. This policy applies to the Cognito iOS application, cognitosystem.com, and related support interactions.
For privacy questions or requests, email support@cognitosystem.com.
2. Information stored on your device and in iCloud
Local study data
Your cards, decks, folders, tags, scheduling state, study history, goals, app settings, and other learning data are stored locally on your device. This makes normal library access and study possible offline.
Optional iCloud sync
If you enable iCloud sync, Apple CloudKit synchronizes supported study data through the private database associated with your iCloud account. Private CloudKit data is controlled through Apple’s services and is not publicly accessible. Apple’s terms and privacy practices apply to iCloud.
Disabling iCloud sync stops future synchronization but does not necessarily delete existing local copies or data already stored in your iCloud account.
3. Content processed by AI and online features
When you choose an AI or online feature, Cognito sends the content needed to perform that request. Depending on the feature, this may include:
- topics, prompts, card text, answers, tags, language, selected exam format, and generation settings;
- documents, images, handwritten notes, audio recordings, microphone input, or extracted text;
- webpage, YouTube, or arXiv URLs and content retrieved from those sources;
- questions and conversation context used by Tutor, Voice Tutor, explanations, hints, translation, rewriting, quality review, or search-grounded generation;
- generated output returned to the app.
These requests are generally processed through Google Firebase AI Logic and Google Gemini. In supported regional routing, including certain requests from mainland China, Cognito may use DeepSeek. Search-grounded features may also use Google Search. Provider processing, security, retention, and international transfer practices may apply.
Do not submit confidential or patient-identifiable information. Cognito is a study tool, not a system for storing medical records or protected health information. Remove names, dates of birth, record numbers, faces, and other identifying details before using medical study material.
4. App, device, usage, and diagnostic information
Cognito uses Firebase services to operate, protect, understand, and improve the app. Depending on the feature and your device settings, the following information may be processed:
- Anonymous authentication and installation identifiers: a Firebase anonymous user identifier and Firebase installation identifiers used to provide cloud-backed functionality and maintain service integrity.
- Product analytics: app interactions, feature usage, subscription tier, selected exam or study context, app version, device and operating-system information, language, and coarse region. We design event payloads to avoid card text and user-created study content.
- Crash and performance data: crash traces, diagnostic logs, device/app state, and identifiers used to diagnose failures and improve stability.
- App protection: Firebase App Check tokens and related technical signals used to reduce abuse and unauthorized access.
- Notifications: APNs tokens, Firebase Cloud Messaging tokens or installation identifiers, device/app information needed for delivery, and notification interactions when notifications are enabled.
- Optional feedback and surveys: answers you submit, along with a pseudonymous identifier needed to associate or limit responses.
- Apple Ads attribution: non-content campaign, ad group, keyword, country, and placement identifiers that help us understand whether an App Store ad led to an install or app open.
Cognito does not use this information to track you across apps or websites owned by other companies.
5. Purchases and Apple services
Subscriptions and purchases are processed by Apple through StoreKit and the App Store. We receive purchase status, product identifier, entitlement, transaction, renewal, and eligibility information needed to unlock paid features and restore purchases. We do not receive your full payment card details.
If you use Sign in with Apple through a legacy or supported account flow, Apple and Firebase Authentication may process the account identifier and any information you choose to share. New users can use Cognito through silent anonymous authentication without creating a visible account.
6. Device permissions
Cognito may request access to the microphone, camera, photo library, files, notifications, or speech-related services when you use a feature that needs them. Access is controlled by iOS. You can change permissions at any time in the iOS Settings app, although the related feature may stop working.
7. How we use information and our legal bases
We process information only for defined purposes:
- Provide the app and requested features: create and study cards, generate content, synchronize data, deliver notifications, restore purchases, and provide support. Where applicable, this is necessary to perform our agreement with you.
- Secure and maintain Cognito: prevent abuse, diagnose crashes, enforce limits, and protect the service. Where applicable, this is based on our legitimate interests in operating a safe and reliable product.
- Understand and improve the product: measure feature performance, onboarding, and advertising attribution using limited analytics. Where applicable, this is based on legitimate interests or consent where local law requires it.
- Meet legal obligations: keep required transaction or compliance records and respond to valid legal requests.
8. Service providers and disclosures
| Provider | What it supports |
|---|---|
| Apple | App Store distribution and purchases, StoreKit, iCloud/CloudKit sync, APNs notifications, device permissions, and Apple Ads attribution. |
| Google Firebase | Anonymous authentication, analytics, Crashlytics, Firestore, App Check, Cloud Messaging, and Firebase AI Logic. |
| Google Gemini and Search | AI generation, tutoring, content transformation, and search-grounded responses when those features are requested. |
| DeepSeek | AI processing for supported regional routing, including certain requests from mainland China. |
| Website hosting provider | Delivery and security of cognitosystem.com, which may involve standard request logs such as IP address, browser type, and access time. |
We may also disclose information if required by law, to protect users or the service, in connection with a business reorganization, or with your direction. Providers may process data in countries other than your own under their terms and appropriate legal safeguards.
We do not sell or rent personal information. The public website does not currently install analytics or advertising cookies.
9. Retention
- Local study data remains until you delete it, remove the app, or erase the device, subject to device backups.
- iCloud data remains under your iCloud account and Apple’s controls until removed through the app, your devices, or Apple’s services.
- Crashlytics crash data is generally retained according to Google’s service settings and documentation, commonly for approximately 90 days.
- Firebase identifiers, analytics, survey responses, service records, and security logs are retained only as long as needed for the purposes described, configured retention periods, legal obligations, or dispute prevention.
- AI providers may retain or log requests and outputs according to their service terms, safety requirements, and our provider configuration.
10. Your choices and rights
You can edit or delete study content inside Cognito, disable iCloud sync, change iOS permissions and notification settings, and cancel subscriptions through your Apple ID settings.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing of, or receive a portable copy of personal information. You may also have the right to complain to your local data-protection authority.
To make a privacy request, email support@cognitosystem.com. Much of our service data is pseudonymous, so we may ask for a diagnostic or Firebase identifier and other information reasonably needed to locate and verify the relevant records. Deleting local app data does not automatically delete records held by service providers.
11. International transfers
Our providers operate globally, so information may be processed in the United States, European Economic Area, and other countries. Where required, transfers are handled using recognized safeguards such as adequacy decisions, contractual protections, or provider data-processing terms.
12. Children
Cognito is intended for users aged 13 and older. If the law where you live requires a higher age for a child to consent to an online service, a parent or legal guardian must approve the use. We do not knowingly collect personal information from children under 13. A parent or guardian who believes a child has provided information should contact us.
13. Security
We use technical and organizational safeguards appropriate to the nature of the service, including Apple platform protections, private CloudKit storage, encrypted network transport, Firebase App Check, access controls, and minimized analytics payloads. No storage or transmission method can be guaranteed completely secure.
14. Changes and contact
We may update this policy as Cognito, our providers, or legal requirements change. The current version and update date will remain available on this page. Material changes may also be communicated in the app where appropriate.
Questions or requests: support@cognitosystem.com.