cobrain
Create your brainGo to your brain
Privacy

Your data, said plainly.

This page says which data we process, why, where it lives and who touches it on our behalf. It is written to be read, not to cover us.

In short

Last updated: 4 September 2026.

  • To sign in we ask for an email address only. No card.
  • The notes are yours: you write them, or your AI does with your permissions. We read them only if you ask us to for support.
  • The data sits on servers in Ireland (European Union).
  • We do not sell data, we do not profile, and we do not use your notes to train models.
  • You can export everything whenever you want and ask us to delete your account.

The notice

Under Regulation (EU) 2016/679 (GDPR).

1. Who processes the data

The data controller is OverPress Media, Rome, via di Pietralata, VAT IT13366841008. For any request: privacy@cobrain.space.

2. Which data, and why

Account

Your email address and, if you enter it, your name. They are used to sign you in (with a link by email), to recognise you when a colleague shares a branch with you, and to send you service messages. Legal basis: performance of the contract.

Content

The notes, folders, tags, previous versions of every note and the shares you create. They are the service itself. They may contain personal data of third parties that you choose to write there: you are responsible for it, and we ask you to share it only with people entitled to read it. Legal basis: performance of the contract.

AI connections

When you authorise a program (Claude, ChatGPT, Claude Code or others) to connect to your brain, we record the program’s name, the date of the authorisation and the technical tokens that let it work with your permissions. Every note remembers who changed it, including when it was an AI. You can revoke any authorisation whenever you want. Legal basis: performance of the contract.

Technical data

Request logs (IP address, date and time, page or tool called, outcome, duration), kept for security and to understand failures. Legal basis: the legitimate interest in running and protecting the service.

Email

We write to you for the sign-in link, to tell you about a share you received, and for service messages (a change to this notice, for instance). No newsletter without consent.

3. What the AIs do with your data

Cobrain sends your notes to no model. It is the programs you connect (Claude, ChatGPT and the rest) that read and write them, with your permissions, when you ask them to in a conversation. What those programs do with what they read depends on their terms and on the settings you have with them: Cobrain does not control them and receives nothing from them beyond the operations they perform in your brain.

4. Who processes it for us

We use few suppliers, all with premises or servers in the European Union for the data that concerns us:

  • Supabase: database, authentication and AI authorisations. Servers in Ireland (eu-west-1 region).
  • Vercel: hosting for the application and the site. Functions executed in Dublin.
  • Resend: delivery of sign-in and service emails.

None of them uses your data for their own purposes. We do not pass data to anyone else and we do not sell it.

5. For how long

  • Account and content: for as long as your account exists. If you delete it, notes, versions and shares are removed within thirty days, except for backups, which expire within a further thirty.
  • Previous versions of notes: on the free plan the last ten, for seven days; on Pro until you delete them yourself.
  • Technical logs: ninety days at most.

6. Your rights

At any time you can ask us to access your data, correct it, delete it, restrict its processing, object, or receive it in a readable format. The full export you do yourself from the dashboard, without asking: they are Markdown files in folders. For everything else write to privacy@cobrain.space: we answer within thirty days. You may also complain to the Italian data protection authority (Garante per la protezione dei dati personali) or to your own supervisory authority.

7. Security

You sign in with a link by email, or with the code contained in the same email: they work once and they expire. The AIs connect with an OAuth authorisation that expires, renews and can be revoked. Permissions on the notes are applied by the database, on the same rule for the site and for the AIs: an unshared branch cannot be reached by anyone. Connections are encrypted.

8. Cookies

The site and the application use technical cookies only: the session cookie, to keep you signed in, the light/dark theme preference and the language preference. No tracking cookies, no advertising.

9. Minors

Cobrain is made for people at work. It is not aimed at children under fourteen and we do not knowingly collect their data.

10. Changes

If this notice changes in a way that affects you, we tell you by email before the change takes effect. The date at the top says when it was last updated.