Privacy Policy

Version 2026-08-02 · Last updated August 2, 2026

Need to report something? To object to the use of your name, image, or likeness, or to report infringement, use our notice form. For privacy requests about your own data, see “Your Rights” below.

Overview

DRAFT — REQUIRES REVIEW BY LICENSED COUNSEL BEFORE USE. This text is provided for attorney review and is not legal advice. Effective date: June 21, 2026 Last updated: August 2, 2026 This Privacy Policy explains how The Cognitive Muse, Inc., a Delaware corporation ("Company," "we," "us," or "our") collects, uses, shares, and protects information in connection with The Cognitive Muse platform and all related websites, applications, tools, features, APIs, and AI models (collectively, the "Service"). The Service is an AI creative-generation tool built for outdoor-advertising and other sales and marketing teams to generate billboard and campaign artwork, copy, and related materials. The Service is designed for business and professional use. In many cases the information we process on your behalf includes personal information about THIRD PARTIES that you choose to upload — for example, your CRM clients and contacts, sales leads, and people whose faces, headshots, signatures, names, logos, or brands appear in images you provide. For that information, you are the controller (or "business") and we act as your processor (or "service provider"). See "Roles: Controller and Processor" below. You are responsible for having a lawful basis and any required notices or consents before you provide third-party personal information to the Service. This Policy works together with our Terms of Service and our AI Art User Agreement. Capitalized terms not defined here have the meaning given in the Terms of Service.

Roles: Controller and Processor

The Service handles two broad categories of personal information, and our role differs for each: (a) Account and operational data. For the personal information of you and your authorized users — account, billing, login, device, and consent records — we act as a data controller (and, under U.S. state laws, a "business"). This Policy describes how we handle that data. (b) Customer-uploaded data about third parties. For personal information you upload or generate about other people and businesses — including CRM clients and contacts, sales-lead records, deal and placement data, and any faces, headshots, signatures, names, likenesses, logos, or brands contained in images or briefs you provide — we act as a data processor (and, under U.S. state laws, a "service provider") that processes that data on your behalf and under your instructions to provide the Service. You are the controller/business for that data. As the controller of customer-uploaded third-party data, you are responsible for: providing any privacy notices required to those individuals; establishing a lawful basis for the processing (including obtaining consents and releases where required, for example for a person's face, headshot, signature, name, image, likeness, or voice); honoring data-subject requests those individuals may make to you; and ensuring you are permitted to upload and use the data. We will assist you in responding to data-subject requests relating to data we process on your behalf, as described under "Your Privacy Rights." If we receive a request directly from one of your data subjects, we may refer that person to you or ask you to act on it.

1. Information We Collect

We collect the following categories of information. (Field-level detail reflects how the Service actually operates.) A. Account identity. Your email address (used as your login), display name, role, account status, workspace type, and Stripe customer identifier. B. Credentials and security data. A hashed (bcrypt) password, an "age 18+" confirmation flag, password-reset and email-verification tokens, and hashed session/refresh tokens with their expiry, and, where you connect a third-party integration or supply your own AI-provider API key, the encrypted connection tokens or key (encrypted at the application layer; for API keys we display only the key's last four characters). C. Device and session data. Your IP address and browser/device user-agent string, captured at login and tied to your sessions. D. Legal-consent records. When you accept our Terms, Privacy Policy, AI Art User Agreement, or age confirmation, we record the document accepted, its version, the date and time, your account identifier, your IP address, your user-agent, the source, and the method of acceptance (for example, "scroll to the bottom and click I agree"). These records are append-only and are retained to evidence your consent. (Your IP address and user-agent are also captured in our audit log; see item M.) E. Profile and business data. Information you enter in your account or vertical/agent profiles — which may include business name, brokerage or company, license number, phone, email, mailing address, headshot image URL, and brand details — depending on the workspace you use. F. Content you upload (User Content). Images, photographs, logos, brand assets, headshots, signatures, reference or "inspiration" images, prompts, briefs, listing and intake data, and other materials you submit. We store a snapshot of intake details (which may include business name and contact information) and a generation manifest (including content hashes of reference images and a prompt fingerprint) for each generated work. G. Generated content (Output). The images, text, and other materials the Service generates, edits, composes, or restores from your prompts and User Content, together with thumbnails and storage locations. Generated artwork saved through the Service may embed an invisible, machine-readable provenance watermark that encodes an opaque work identifier which Company can link to your account on its servers; the file itself does not encode your identity, your prompt, or other personal data. Where present, the watermark may persist in files you download or distribute. [CONFIRM: pixel watermarking is currently disabled by default in production (WATERMARK_EMBED_ENABLED=false) — confirm whether it is enabled at publication and keep this disclosure in lock-step with Exhibit A § 9.5.] H. Faces, signatures, and likenesses. Where you upload or generate them, images may contain or be derived from real people's faces (including headshots) and signatures, and may incorporate real brands, logos, and trademarks. Depending on the image and applicable law, this may include biometric or other sensitive information. We address how we handle this category, including the destruction schedule, under "Biometric and Facial Data" below. You are responsible for the rights and consents associated with this content; see "Roles: Controller and Processor" and our Terms of Service. I. CRM client and contact data (third-party personal information you upload or import). For businesses you track: name, business name, brand colors, vertical profile, tags, notes, billing address, office phone, and website (which the Service can attempt to auto-discover from the business name). For individual contacts: first/last/full name, title, email, phone, birthday, LinkedIn URL, and notes. We also store CRM files you upload (storage location, file type, size, and label). Where your organization connects an external CRM (see "Integrations You Connect"), we also import and store, on your instruction: the contact fields you choose to map (which can include every contact property in your CRM portal); the contact's deals (name, amount, stage, pipeline, close date); activity records — notes, calls, emails, meetings, and tasks — including their text content; and read-only lead-source and advertising-provenance fields (original source, campaign and ad names, an ad-click identifier, and the first conversion event). J. Sales-lead and prospecting data (third-party personal information, including data we help you obtain from external sources). For lead discovery and outreach: business name, address, phone, website, geolocation, decision-maker contact name/email/title, an AI "fit" score and reasoning, and draft outreach text. Some of this data is retrieved on your instruction from third-party data providers (see "Sub-Processors"); the individuals it concerns may have no prior relationship with the Service. You are the controller for this data and are responsible for your use of it under applicable law (including anti-spam and marketing laws). K. Deal, placement, contract, and financial data. Rates, contract values, payment terms, discounts, flight dates, and sign/location information you enter; and, where you use the contract and e-signature features: contract templates you upload (including documents the Service extracts a template from, and any separate terms-and-conditions document), insertion orders, the bill-to contact's name, email, and phone, e-signature envelope status, and the signed contract PDF and completion certificate returned by our e-signature provider. The signer is typically your client (third-party personal information you provide) — see "Roles: Controller and Processor." L. Payment and billing metadata. Payment provider, provider reference, amount, currency, and status; your Stripe customer link; credit-wallet balances and an append-only credit ledger; and an internal cost ledger of AI usage (model, operation, tokens, image size/quality, and cost). We do not store full payment-card numbers; card processing is handled by our payment processor (Stripe). M. Audit, moderation, and safety data. An append-only audit log (actor, event type, target, metadata, and IP address); content-moderation decisions, escalated cases, and safety scores; and takedown-request records (licensee, work, reason, and deadlines). N. Commission and organization data. For sales-rep commissions, rep name and email (which may belong to non-users), organization names, and amounts. O. Feedback and support data. If you use the in-app feedback tool, we collect your message, an optional screenshot, the page you were on, and a snapshot of your email and display name; we generate an AI triage summary and plan from it and may route it to our internal inbox, email, and CRM records. P. Community submissions. If you submit a Prompt Tip, we collect the tip title, body, category, an optional example image, and a snapshot of your display name for the byline; approved tips are displayed to all users of the Service. Q. Information submitted through no-login pages. Some pages can be used without an account — for example, a public "design your own billboard" page or a brand-intake wizard reached through a link one of our customers shares. If you submit information there (such as your name, business name, contact details, brand preferences, and images), it is collected on behalf of the customer whose link you used, becomes a lead or intake record in that customer's account, and is handled as customer data under "Roles: Controller and Processor." [ATTORNEY: confirm the processor characterization for data collected directly from non-users via customer-shared links, and whether these public pages must link to a short-form privacy notice at the point of collection.] R. Email-campaign audiences and delivery data. For Email Campaigns, we store the audience members you upload or select (name, email address), each message sent and its provider message identifier, and delivery and engagement status returned by our email provider (delivered, bounced, marked as spam/complained, unsubscribed), which we use to suppress future sends to that address. Sensitivity note. Some of the information above is sensitive or higher-risk — for example, third-party contacts' birthday, email, phone, and LinkedIn details; human faces, headshots, and signatures rendered into artwork; and cold-lead contact data obtained from external providers. We handle this information as described in this Policy and process customer-uploaded third-party data only on your behalf and instructions.

1A. Biometric and Facial Data

Some features let you upload or generate images that contain a person's face (including a headshot) or signature. Where images you provide contain a person's face or signature, any facial-geometry or biometric information derived in processing is used only to generate the artwork you requested and is not retained for any separate biometric purpose. We do not use this data for identification, surveillance, or to build any biometric template or profile. Retention and destruction. Face and signature source images, and the artwork derived from them, are deleted when the account that uploaded them is deleted. In no event do we retain facial or biometric identifiers longer than three (3) years after the depicted individual's last interaction with the Service — or, where the depicted individual has no direct relationship with the Service, three (3) years after the image was last uploaded to or processed by the Service — or after the purpose for which they were provided is satisfied, whichever occurs first; this outer limit applies even while the uploading account remains active. [ATTORNEY: confirm the controlling destruction trigger ("last interaction" vs. "purpose satisfied") consistently with the biometric row of the Records Retention & Legal Hold schedule (draft 04), and keep the two documents in lock-step — depicted third parties never themselves interact with the Service, and the previous sentence's account-lifetime retention can exceed this 3-year cap.] This destruction schedule is part of our Records Retention & Legal Hold schedule (see "Data Retention") and is intended to satisfy the written-retention-and-destruction-schedule requirements of biometric-privacy laws such as the Illinois Biometric Information Privacy Act (BIPA, 740 ILCS 14), the Texas Capture or Use of Biometric Identifier Act (CUBI, Tex. Bus. & Com. Code § 503.001), and the Washington biometric-privacy law. [CONFIRM: confirm the product enforces this destruction clock on biometric source inputs before publishing.] Consent and your responsibilities. As between you and us, you are the controller of any face or signature data you upload, and you are responsible for obtaining any consent that biometric-privacy or right-of-publicity laws require before you upload, edit, or render a real person's face, headshot, photograph, or signature. See "Roles: Controller and Processor" and our Terms of Service. If you are an individual whose face or signature appears in an image that one of our business customers uploaded, and you want it deleted, contact us at tony@thecognitivemuse.com; the customer is the controller of that data, and we will refer your request to them or assist them in responding, except where we are required to act by law.

1B. Organizations and Sharing Within Your Team

If your account belongs to an organization on the Service, certain records are shared with the other members of your organization. Depending on the features enabled for your organization, this can include: artwork, mockup, and brand assets shared to the organization library; contract templates; sign/location inventory ("Locations") you upload, which is shared with your organization by default; and [CONFIRM: in development — disclose only when enabled] your CRM clients, contacts, and related records. Shared records are visible to all organization members; the record owner and the organization head can edit or delete them; and if you leave the organization or delete your account, ownership of shared records may be transferred to the organization head so the organization can continue operating. Integrations connected organization-wide (for example an external CRM) are granted by an organization administrator and apply to the organization's shared data. Do not upload information to a shared organization workspace that other members are not permitted to see. [CONFIRM: Locations auto-sharing is currently gated behind the ORG_SHARED_INVENTORY flag — publish this section in the configuration actually enabled at launch.]

2. How We Use Information

We use information for the following purposes: (a) To provide the Service — authenticate you, generate, edit, store, and deliver artwork and other Output from your prompts and User Content, run CRM, lead-discovery, campaign, and reporting features, and operate the credit and billing system. (b) To process AI generation. Your prompts, uploaded reference images (including logos, faces, and brand materials), and business or lead context are sent to our AI sub-processors to produce Output. See "Sub-Processors and AI Processing." (c) To process payments and prevent fraud — through our payment processor — and to maintain credit, payment, and cost records. (d) To secure, monitor, debug, and improve the Service — including error monitoring, abuse and fraud prevention, content moderation, and rate-limit/quota enforcement. (e) To communicate with you — account, transactional, security, and support messages, and, where permitted, product and marketing messages you can opt out of. (f) To maintain legal, consent, audit, and accounting records and to comply with our legal obligations, enforce our agreements, and protect our rights and the rights and safety of others. We may use de-identified and aggregated data to operate, secure, and improve the Service. Prompts — what we store. We store your prompts. That includes both the text you write yourself (your brief, your refine and edit instructions, and similar input) and the engineered prompt our system builds from it and sends to the AI model, saved alongside the artwork they produced. We store them so that you can re-open, refine, re-run, and rebuild your own work, and so we have a record of what was generated and why. Prompts — how long we keep them. A prompt is kept for as long as your account exists. Deleting an artwork, including emptying it from Trash, does not by itself delete the prompt that produced it. Prompts are deleted when your account is deleted (see "Account Deletion and Effect"). Prompts — how we use them, and how we improve. We do not train artificial-intelligence models on your content. Company does not operate its own foundation model, and does not train, fine-tune, or otherwise adjust the weights of any AI model using your prompts, artwork, or uploads. What we do improve is our own written prompt-engineering instructions — the human-authored text our system combines with your brief before sending it to the model. To do that, our authorized staff may review prompts and the artwork they produced, so we can write better instructions for everyone. That review produces ordinary written text: it creates no model, no model weights, and no training dataset, and it can be changed or undone at any time. Apart from that, we do not use the content of your private User Content to train models except with your consent. Prompts — our AI providers are separate. To generate your Output we must send your prompts and uploads to the AI sub-processors listed under "Sub-Processors and AI Processing." What those providers do with that data is governed by their terms, not by this policy, and some providers may use content submitted to them to improve their own services, including review by their personnel. We do not currently rely on any provider-side setting that would exempt your prompts from that. If this matters to your work, review the provider list and their terms before submitting sensitive material. [CONFIRM with counsel and with each AI provider's then-current data-processing terms which providers train on submitted content, and on which plan or tier; the image-generation toggle can route prompts to a provider whose unpaid tier trains on submissions and permits human review, and no zero-retention or opt-out setting is implemented in code. Resolve the tier question and update this paragraph to state the confirmed position.]

3. Legal Bases for Processing (where GDPR/UK GDPR applies)

Where the EU/EEA or UK General Data Protection Regulation applies, we rely on the following legal bases: (a) Contract — to provide the Service you have requested and to administer your account and billing. (b) Legitimate interests — to secure, monitor, debug, and improve the Service, prevent fraud and abuse, and operate our business, balanced against your rights. (c) Legal obligation — to keep tax, accounting, consent, and audit records and to respond to lawful requests. (d) Consent — where required, for example for certain communications or where we ask for it; you may withdraw consent at any time without affecting prior processing. For personal information you upload about third parties, you (not we) are responsible for establishing and documenting the legal basis, and for any consents or notices required, as described under "Roles: Controller and Processor."

4. Sub-Processors and AI Processing

We use the following third-party service providers ("sub-processors") to operate the Service. They process information only as needed to provide their services to us and under contractual confidentiality and security obligations. This list may change; we will update it and, where required, provide notice. [CONFIRM this list against current production configuration before publishing; some providers (Replicate, HeyGen, Yelp, Google Places, Apollo, Microsoft OneDrive) are active only when their feature or API key is enabled; DocuSign is integration-verified and env-gated (the e-sign provider defaults to a fake/no-op provider unless ESIGN_PROVIDER_NAME=docusign with DOCUSIGN_* keys are set). Keep this list in lock-step with the sub-processor table in the Data Processing Agreement template — both must name the same vendors.] Core infrastructure and AI: - OpenAI (United States) — image generation, editing, and composition, and large-language-model/vision tasks. Receives your prompts and uploaded reference images, which may include logos, faces, and brand and business intake data. - Anthropic (United States) — text and analysis tasks such as lead scoring, CRM and ride-sheet text, design and spelling review, profile import, and logo classification. Receives business descriptions, lead/contact data, and website content. - Replicate (United States) — optional faster image generation ("Speed Mode"); receives prompts and reference images when enabled. - HeyGen (United States) — optional AI avatar/video generation when used. - Amazon Web Services (AWS S3) (United States; default region us-east-1) — private storage of uploaded and generated images (served via short-lived presigned links). [CONFIRM: object storage is an S3-compatible abstraction; the production storage target may be Cloudflare R2 / DigitalOcean Spaces rather than AWS S3 — name the actual provider here and in the DPA §5 table before publishing.] Payments, email, and monitoring: - Stripe (United States) — billing and payment processing; receives your Stripe customer identifier, payment amounts, and subscription state. - Resend (United States) — transactional and campaign email; receives recipient email addresses and message content. - Sentry (United States) — error and performance monitoring. Our configuration scrubs passwords, tokens, and image payloads and drops user email from error reports; it retains a Sentry user identifier, IP address, and error context. Contracts and documents: - DocuSign (United States) — electronic-signature envelopes for the contract features; receives the document to be signed and each signer's name and email address, and returns envelope status, the signed document, and the completion certificate. [CONFIRM: the DocuSign integration is env-gated — describe as available/scaffolded and config-gated, not unconditionally active, until activated for production.] - Intuit / QuickBooks Online (United States) — accounting integration for the contract-billing feature (Phase-1, Accounting-scope only); on your organization's connection, receives invoice and customer/accounting data to create and reconcile invoices in your QuickBooks Online company. Payment collection occurs on Intuit's hosted invoice page; no card or bank-account numbers are stored on our systems. - Microsoft (OneDrive / Microsoft Graph) (United States) — optional export of audit and reconciliation workbooks to a Company-controlled OneDrive when the POP Audit / Financial Audit features are enabled; receives advertiser and billing-reconciliation data. Lead discovery and enrichment (used only with the prospecting features): - Yelp Fusion (United States) — business lookup by location (business name, address, phone, rating). - Google Places (United States) — nearby-business search by location. - Apollo.io (United States) — decision-maker enrichment; returns third-party contact name, email, and title for leads. AI processing notice. Generative AI models are probabilistic. The Service sends your prompts and User Content to the AI sub-processors above to produce Output. We do not control, and cannot guarantee, how Output is generated or whether it is original, accurate, or non-infringing; see our Terms of Service and AI Art User Agreement. You must review Output before any use. We also disclose information where required by law or legal process, to enforce our agreements, to detect or prevent fraud or security issues, or in connection with a merger, acquisition, financing, or sale of assets (subject to this Policy).

4A. Integrations You Connect

Some features let you or your organization's administrator connect third-party accounts you control. These connections are made at your direction; the connected provider is not our sub-processor for your connected account, and its handling of data is governed by your agreement with it. When you connect an account, we store the OAuth or credential bundle needed to operate the connection, encrypted at the application layer (AES-256-GCM). - HubSpot (United States): if your organization connects HubSpot, we import the CRM records described in Section 1.I on your instruction (contacts, companies, deals, notes, and activities, including lead-source and advertising-provenance fields) and, where you use push features, transmit clients, contacts, companies, and deals from the Service to your HubSpot portal. - Meta Platforms (Facebook/Instagram Lead Ads) (United States): if enabled and connected, Meta sends us each new lead-ad submission (name, contact fields, form answers) together with the campaign, ad-set, and ad names, and we create a CRM contact from it. - DocuSign (bring-your-own): if your organization connects its own DocuSign account, we store the credential bundle encrypted and send your e-signature envelopes through your account. - Bring-your-own API keys: where offered, third-party API keys you provide are stored encrypted and used only to make calls on your behalf. [CONFIRM: BYO keys are currently inert — include only when enabled.] Disconnecting an integration stops future syncs; records already imported remain in your account until you delete them. Organization-wide connections are granted by an organization administrator on behalf of all members (see Section 1B). Data received through a connected integration is customer-uploaded third-party data under "Roles: Controller and Processor."

5. Do Not Sell or Share; No Targeted Advertising

We do not sell your personal information in exchange for money or other valuable consideration, and we do not "share" it for cross-context behavioral advertising, as those terms are defined under the California Consumer Privacy Act (as amended by the CPRA) and similar U.S. state laws. We do not use the personal information you or your authorized users provide, or the third-party personal information you upload, to serve you or others targeted advertising. We disclose personal information to our sub-processors solely to provide the Service, as described above. If our practices change, we will update this Policy and provide any opt-out mechanism the law requires.

6. Data Retention

We retain personal information for as long as needed to provide the Service and for the additional periods described below to meet legal, accounting, security, and consent-evidence requirements. We apply the following retention principles; the specific per-category retention windows are maintained in our internal Records Retention & Legal Hold schedule, which counsel uses to set the binding periods. [CONFIRM the specific retention windows (for example, the period after which IP/user-agent records, consent proofs, and financial records are deleted) with counsel before publishing.] Prompts are retained for the life of the account. Deleting an artwork does not delete the prompt that produced it; see "How We Use Information" and "Account Deletion and Effect". - Account, profile, CRM, lead, deal, content, and Output data: retained while your account is active. On account deletion, we permanently erase the personal data you own, as described under "Account Deletion." - Legal-consent records, audit-log entries, and AI cost-ledger entries: retained for our recordkeeping, security, and compliance needs. Our security audit log and legal-consent records are kept on an append-only basis (the audit log includes IP addresses); the AI cost-ledger is retained with your identifying link removed. These records are retained even after you delete your account. - Payment and billing records, including the Stripe customer link: retained as required for tax, accounting, and financial-record purposes. - Commission-ledger and sales-representative records: retained for financial-record purposes with your account link removed on account deletion; sales-representative records retain the representative's name and email address together with the commission history (see "Account Deletion and Effect"). - Backups and logs: retained for our standard backup and security-log cycles and then overwritten or deleted on a rolling basis (see "Erasure and backups" below). Where we retain data after account deletion, we limit its use to the purposes for which it was retained. Erasure and backups. When we permanently erase personal data — for example, on account deletion — the data is removed from our live systems immediately. Because we maintain encrypted, rolling backups for disaster-recovery and security purposes, residual copies of erased data may persist in those backups for up to thirty (30) days, after which they roll off and are overwritten in the ordinary backup cycle. During that window we do not restore erased data except as required to recover from a system failure, and erased data is removed again on any such restore. Records Retention & Legal Hold schedule. Our internal Records Retention & Legal Hold schedule sets, by record category, the retention period, the destruction trigger, and the legal basis (including the biometric destruction schedule described in "Biometric and Facial Data"). [ATTORNEY: confirm whether the in-Policy disclosure satisfies BIPA 740 ILCS 14/15(a)'s publicly-available written-policy requirement, or whether a standalone public schedule page is required.] Counsel maintains and updates this schedule. [CONFIRM: finalize and, where required by law, publish the per-category retention periods set in that schedule.]

7. Account Deletion and Effect

You can delete your account from your account settings. When you delete your account, we permanently erase the personal data you own. This includes your CRM clients, contacts, and files; your sales leads and lead records; your listings, polls, marketing assets, brands, and card decks; and your uploaded and generated images (including any faces, headshots, and signatures contained in them) together with their stored files. Your password is invalidated, all active sessions are revoked, and your credit-wallet balance is zeroed. Erasure of the data you own is immediate and cannot be undone. We remove your account link from certain financial and usage records we keep: commission-ledger entries and AI cost-ledger entries are retained without your identifying account link. Sales-representative records retain the representative's name and email address (which may identify you if you were the representative) together with the commission history, with the account link removed. [ATTORNEY: confirm retaining rep name/email post-deletion is defensible as a financial/commission record, or direct engineering to anonymize those fields in the purge.] We retain the following records, as required for tax, accounting, security-audit, and proof-of-consent purposes, even after your account is deleted: payment and billing records (including the Stripe customer link); our append-only security audit log (which includes IP addresses); and your legal-acceptance (consent) records. We also retain a minimized identity stub (your account marked deleted, your login email released for reuse and replaced with a placeholder, and your password scrambled) solely to anchor the retained financial and consent records described above. Where we retain data after deletion, we limit its use to the purposes for which it was retained, as described under "Data Retention." We also retain after account deletion: feedback you submitted through the in-app feedback tool (including the message, any screenshot, and the email and display-name snapshot captured at submission); approved community Prompt Tips you submitted (including the display-name byline and any example image), which remain displayed to users; and, where you used the contract and e-signature features, deal records and signed contract documents (including the bill-to contact information they contain). Third-party (CRM/lead) data you uploaded about your clients, contacts, and leads is erased as part of the permanent erasure described above. As the controller of that data, you remain responsible for fulfilling any separate deletion obligations you owe to those individuals while your account is active. Erasure may, in limited circumstances, be lawfully suspended or deferred — for example, where records are subject to a legal preservation hold. See "Limits on Deletion" under "Your Privacy Rights." If you want a copy of, or correction of, specific data, or to make any other privacy request, contact us at tony@thecognitivemuse.com and we will process your request as described under "Your Privacy Rights."

8. Security

We use technical and organizational measures designed to protect personal information, including encryption of passwords (hashing), hashed session tokens, private image storage served through short-lived presigned links, access controls, an append-only audit log, content moderation, and error monitoring with sensitive-field scrubbing. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for safeguarding your credentials and for the security of content you choose to upload.

9. International Data Transfers

We are based in the United States, and our sub-processors listed above process information in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States and other countries that may have data-protection laws different from those in your jurisdiction. Where we transfer personal information from the EU/EEA, the United Kingdom, or Switzerland to a country not deemed to provide adequate protection, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum), together with supplementary measures as needed. [CONFIRM that executed SCCs/DPAs are in place with each relevant sub-processor before relying on this statement.] You may contact us at tony@thecognitivemuse.com for more information about these safeguards.

10. Your Privacy Rights and How to Exercise Them

Depending on where you live and the law that applies, you may have some or all of the following rights regarding personal information we hold about you as a controller: to know/access the personal information we hold and how we use it; to receive a portable copy; to correct inaccurate information; to delete information; to opt out of any sale, sharing, or targeted advertising (we do not engage in these — see "Do Not Sell or Share"); to limit the use of sensitive information; to withdraw consent where processing is based on consent; and to be free from unlawful discrimination for exercising these rights. Where GDPR/UK GDPR applies, you may also object to or request restriction of certain processing and lodge a complaint with your supervisory authority. Residents of Texas, Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws may have similar rights of access, correction, deletion, and portability, rights to opt out of certain processing, and a right to appeal our refusal of a request. [ATTORNEY: Company is a Texas LLC — confirm Texas TDPSA applicability (including the small-business exemption analysis), whether to add a dedicated "Your U.S. State Privacy Rights" subsection with an appeal process, and whether the referral and commission Credit programs require a CCPA/CPRA notice of financial incentive.] How to exercise your rights. You can exercise several rights directly in your account settings, without contacting us: - Portability/export: you can download a portable copy of your personal data as a self-service export from your account. This export currently includes your account profile, CRM clients and contacts, and your artworks. Other categories you own — such as leads, listings, brands, card decks, and financial records — are erased when you delete your account but are not yet included in the self-service export file; for a copy of those categories, contact us at tony@thecognitivemuse.com and we will provide them as part of a manual access/portability request. - Deletion/erasure: you can permanently delete your account and the personal data you own from your account settings, as described under "Account Deletion." - You can also view your credit ledger in your account. For access, correction, restriction, objection, or any other request you cannot complete in-product, submit a request to tony@thecognitivemuse.com (subject line "Privacy Request") and we will handle it. Limits on deletion. We may decline, suspend, or defer a deletion or erasure request, and continue to preserve the relevant records, where we are required or permitted by law to retain them — for example, to comply with a legal obligation, or to establish, exercise, or defend legal claims (a litigation or regulatory hold). Where a preservation hold applies, a self-service deletion request will be refused until the hold is released, after which the request can be completed. In that case we limit use of the retained data to those purposes. If we cannot act on your request, we will tell you why, except where we are legally prohibited from doing so. Verification and timing. To protect your information, we will take reasonable steps to verify your identity before acting on a request, typically by confirming control of your account email. We will respond within the time required by applicable law (for example, generally 45 days under California law, extendable as permitted, and one month under GDPR/UK GDPR, extendable for complex requests). We do not charge a fee for most requests. Authorized agents. Where the law allows, you may use an authorized agent to submit a request; we may require proof of authorization and verification of your identity. Third-party (CRM/lead) data. If you are an individual whose information was uploaded to the Service by one of our business customers (for example, as a CRM contact or sales lead), that customer is the controller of your information. We process it only on their behalf. Please direct your request to that business; if you contact us, we will refer you to them or assist them in responding, and we will not independently grant access, correction, or deletion of data we process on their behalf except as required by law or their instructions. You may contact us at tony@thecognitivemuse.com for help identifying the relevant business where we are able. California "Shine the Light." California residents may request information about disclosures of personal information to third parties for their direct-marketing purposes. We do not make such disclosures. [ATTORNEY: confirm whether Company must designate an EU/UK representative under GDPR/UK GDPR Article 27 and/or appoint a Data Protection Officer given the Service's EU/UK exposure; if so, add the representative's/DPO's contact details to this section and to "Contact Us."]

11. Cookies, Analytics, and Tracking

The Service uses cookies and similar technologies that are strictly necessary to operate, including for authentication and session management, and to keep the Service secure. [CONFIRM the full cookie/SDK inventory, including any analytics, and add a cookie table or banner/consent mechanism if non-essential cookies are used, particularly for EU/UK visitors.] We use Sentry for error and performance monitoring, which may collect technical information such as IP address, a service-assigned identifier, and error context to help us detect and fix problems. Our configuration is set to scrub passwords, tokens, and image payloads and to drop user email from error reports. We do not use cookies or tracking technologies for cross-context behavioral advertising. If your browser sends a Global Privacy Control (GPC) or "Do Not Track" signal, we will honor it as required by applicable law for any opt-out it conveys.

12. Children’s Privacy

The Service is intended for business and professional use by adults and is not directed to children. You must be at least 18 years old to use the Service, and we ask you to confirm this at sign-up. We do not knowingly collect personal information directly from anyone under 16, and we do not knowingly collect personal information directly from children under 13. Content our business customers upload may depict minors; we process that content on the customer's behalf as a processor, and the customer is responsible for verified parental or guardian consent as required (see "Roles: Controller and Processor" and Terms of Service § 7.5). If you believe a child has provided us personal information, contact us at tony@thecognitivemuse.com and we will take appropriate steps to delete it.

13. Security Incidents and Breach Notification; Contact

We maintain the security measures described under "Security" and have a process for responding to security incidents. If we become aware of a personal-data breach affecting your personal information, we will investigate, take reasonable steps to contain and remediate it, and provide notice as required by applicable law and without undue delay. Where the EU/UK General Data Protection Regulation applies and we act as a controller, we will notify the competent supervisory authority of a personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, and will notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms (GDPR Articles 33 and 34). Where we act as a processor for data you upload, we will notify you without undue delay after becoming aware of a breach affecting that data so that you can meet your own notification obligations. For individuals in the United States, we will notify affected individuals and applicable regulators of a security breach in the manner and within the timeframes required by the data-breach-notification statutes of the applicable U.S. state(s) — generally, in the most expedient time possible and without unreasonable delay, subject to the needs of law enforcement and any measures necessary to determine the scope of the breach and restore the integrity of our systems. To report a suspected security vulnerability or privacy issue, contact us at tony@thecognitivemuse.com or support@thecognitivemuse.com and see our responsible-disclosure policy (SECURITY.md).

14. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice — for example, by posting the updated Policy with a new version and "Last updated" date, by in-product or email notice, and, where appropriate, by prompting you to re-accept through our acceptance gate. Changes are effective when posted unless stated otherwise. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy. If you do not agree, stop using the Service.

15. Contact Us

The Cognitive Muse, Inc., a Delaware corporation 2110 Ranch Rd 620 S, Box 341432, Austin, TX 78734 Privacy requests and questions: tony@thecognitivemuse.com By scrolling to the end and selecting "I have read and agree," you acknowledge that you have had the opportunity to review this Privacy Policy in full. DRAFT — REQUIRES REVIEW BY LICENSED COUNSEL BEFORE USE.

— End of Privacy Policy

© 2026 The Cognitive Muse, Inc. All rights reserved.