Effective as of September 14, 2026
CoChat Inc (“the company,” “we”, “us” or “our”) provides a collaborative AI chat and research platform that enables users to interact with various large language models (LLMs), search and read scholarly literature, and collaborate in real time. This Privacy Policy describes how the company processes personal information that we collect through our digital or online properties or services that link to this Privacy Policy, including cochat.ai, app.cochat.ai, our desktop and mobile applications, and our connector for third-party AI assistants (collectively, the “Service”).
Our products and services are intended for business customers and personal use. This Privacy Policy does not apply to information that we process on behalf of our business customers while providing the Service, which is governed by our agreements with those business customers. If you have concerns regarding personal information that we process on behalf of a business, please direct your concerns to them.
Index
- Personal information we collect
- Tracking technologies
- How we use your personal information
- How we share your personal information
- Connected apps and AI assistants (ChatGPT, Claude and other MCP clients)
- How long we keep your personal information
- Your choices and rights
- Other sites and services
- Security
- International data transfer
- Children
- Changes to this Privacy Policy
- How to contact us
Personal information we collect
Information you provide to us
Personal information you may provide to us through the Service or otherwise includes:
- Contact data, such as your first and last name, email address, and username.
- Account credentials, such as passwords and other security information for authentication and account access.
- Communications data based on our exchanges with you, including when you contact us through the Service, social media, or otherwise.
- Chat content, including the messages, prompts, and conversations you create or participate in through the Service, whether in individual or collaborative chat sessions, and the responses generated for you.
- Files and media you upload, such as documents, PDFs, spreadsheets, images, and audio recordings you provide for transcription or analysis, and the text we extract from them.
- Research library data, such as the papers, citations, notes, research questions and collections you save, and the projects and folders you create.
- Plans, documents and other artifacts you create in CoChat or that a connected AI assistant creates in your account on your instruction (see “Connected apps and AI assistants” below).
- Transactional data, such as information relating to or needed to complete your credit or subscription purchases on or through the Service, including transaction history and token usage.
- Financial data, such as payment card information and billing address. Payment card details are collected directly by our payment processor (Stripe); we do not store full card numbers.
- Marketing data, such as your preferences for receiving our marketing communications and details about your engagement with them.
- Collaboration data, such as information about users you invite to chat sessions or projects, shared conversations, comments, and team interactions.
- Feedback and survey data, such as ratings of responses and answers to in-product surveys.
- Other data not specifically listed here, which we will use as described in this Privacy Policy or as otherwise disclosed at the time of collection.
Information we derive
- Memories. If you enable the memory feature, we derive short notes about your preferences, projects and recurring context from your chats and use them to personalize future responses. You can view, delete and disable memories at any time (see “Your choices and rights”).
- Aggregated and de-identified data, as described under “How we use your personal information”.
Third-party sources
We may combine personal information we receive from you with personal information falling within one of the categories identified above that we obtain from other sources, such as:
- Public sources, such as government agencies, public records, social media platforms, and other publicly available sources.
- Service providers that provide services on our behalf or help us operate the Service or our business.
- Third-party login services, such as Google or Microsoft, that you use to log into, or otherwise link to, your Service account. This data may include your name, email address, profile picture and other information associated with your account on that service that is made available to us based on your account settings there. Our use and disclosure of information received from Google’s APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
- LLM providers, from whom we may receive technical or operational data necessary to provide the Service.
- Connected AI assistants, such as ChatGPT or Claude, which send us the requests and content you instruct them to send when you have connected CoChat to them (see “Connected apps and AI assistants”).
- Scholarly databases and publishers, from which we retrieve publicly available bibliographic metadata and open-access full text in response to your searches.
Automatic data collection
We, our service providers, and our business partners may automatically log information about you, your computer or mobile device, and your interaction over time with the Service, our communications and other online services, such as:
- Device data, such as your computer or mobile device’s operating system type and version, manufacturer and model, browser type, screen resolution, device type (e.g., phone, tablet), IP address, unique identifiers, language settings, and general location information such as city, state or geographic area derived from your IP address.
- Online activity data, such as pages or screens you viewed, how long you spent on a page or screen, the website you visited before browsing to the Service, navigation paths between pages or screens, information about your activity on a page or screen, access times and duration of access, and whether you have opened our emails or clicked links within them.
- Usage data, such as the LLMs you interact with, the features and tools you use, the frequency and duration of your interactions, token usage, credit consumption, and error and performance information about the app on your device.
- Fraud-prevention and security signals, such as device and network characteristics and account behavior used to detect automated abuse and account takeover.
- Communication interaction data, such as your interactions with our email, text or other communications (e.g., whether you open and/or forward emails). We may do this through use of pixel tags (also known as clear GIFs), which may be embedded invisibly in our emails.
Tracking technologies
Cookies and other technologies
Some of the automatic collection described above is facilitated by the following technologies:
- Cookies, which are small text files that websites store on user devices and that allow web servers to record users’ web browsing activities and remember their submissions, preferences, and login status as they navigate a site. Cookies used on our sites include both “session cookies” that are deleted when a session ends, “persistent cookies” that remain longer, “first party” cookies that we place and “third party” cookies that our third-party business partners and service providers place.
- Local storage technologies, like HTML5 local storage, that provide cookie-equivalent functionality but can store larger amounts of data on your device outside of your browser in connection with specific applications.
- Web beacons, also known as pixel tags or clear GIFs, which are used to demonstrate that a webpage or email was accessed or opened, or that certain content was viewed or clicked.
We use the following third-party tracking and telemetry tools:
- PostHog (product analytics, in-product surveys and feature flags) on cochat.ai and app.cochat.ai.
- Google Analytics and Google Tag Manager on our marketing website, cochat.ai. You can learn more about Google Analytics and how to prevent its use at https://tools.google.com/dlpage/gaoptout.
- Grafana Faro (application performance and error monitoring) in app.cochat.ai, which records page load performance, JavaScript errors and failed requests. It does not record the content of your chats.
For information concerning your choices with respect to the use of tracking technologies, see “Your choices and rights” below.
How we use your personal information
We may use your personal information for the following purposes or as otherwise described at the time of collection:
Service delivery and operations
We may use your personal information to:
- provide the Service, including facilitating your interactions with various LLMs and research tools;
- search scholarly databases, retrieve open-access full text and verify citations on your behalf;
- enable collaborative features, such as real-time chat sharing, comments and user invitations;
- personalize responses using memories you have allowed us to keep;
- run automations and scheduled tasks you set up;
- process and manage your purchases, subscriptions, credits and token usage;
- enable security features of the Service, including authentication, fraud prevention and abuse detection;
- communicate with you about the Service, including by sending Service-related announcements, updates, security alerts, budget and billing notices, and support and administrative messages;
- provide support for the Service, and respond to your requests, questions and feedback.
Chat content processing
We process your chat content and uploaded files to:
- deliver LLM responses to your prompts, including by sending your prompts, relevant chat history, memories and file content to the LLM provider you select;
- transcribe audio you record and extract text from documents and images you upload;
- retrieve web pages and scholarly sources relevant to your request;
- enable collaborative chat features where you invite other users;
- respond to requests made by AI assistants you have connected to your account;
- comply with legal obligations or respond to legal requests.
Important: We do not train AI models on your chat content, and we do not permit LLM providers to train on it. We would only do so with your explicit, separate consent. Your private conversations remain private unless you choose to share them with other users, publish a share link, or connect an external AI assistant with access to your workspace.
Marketing
We, our service providers and our third-party partners may collect and use your personal information for marketing purposes, such as to send you direct marketing communications and to measure the effectiveness of our advertising. We may personalize these messages based on your needs and interests. You may opt out of our marketing communications as described in “Your choices and rights” below.
Compliance and protection
We may use your personal information to:
- comply with applicable laws, lawful requests, and legal process, such as to respond to subpoenas, investigations or requests from government authorities;
- protect our, your or others’ rights, privacy, safety or property (including by making and defending legal claims);
- audit our internal processes for compliance with legal and contractual requirements or our internal policies;
- enforce the terms and conditions that govern the Service; and
- prevent, identify, investigate and deter fraudulent, harmful, unauthorized, unethical or illegal activity, including cyberattacks, automated abuse and identity theft.
Service improvement and analytics
We may use your personal information to analyze your usage of the Service, improve the Service, improve the rest of our business, help us understand user activity on the Service (including which pages and features are most and least used and how visitors move around the Service), understand user interactions with our emails, monitor performance and errors, and develop new products and services.
Cookies and other technologies
In addition to the other uses included in this section, we may use the cookies and other technologies described above for the following purposes:
- Technical operation: to allow the technical operation of the Service, such as by remembering your selections and preferences as you navigate the site, and whether you are logged in when you visit password-protected areas of the Service.
- Functionality: to enhance the performance and functionality of our services, including maintaining your chat history and preferences.
- Analytics: to help us understand user activity on the Service and user interactions with our emails.
To create aggregated, de-identified and/or anonymized data
We may create aggregated, de-identified and/or anonymized data from your personal information and other individuals whose personal information we collect. We make personal information into de-identified and/or anonymized data by removing information that makes the data identifiable to you and we will not attempt to re-identify any such data. We may use this aggregated, de-identified and/or anonymized data and share it with third parties for our lawful business purposes, to the extent that such uses and sharing are in compliance with applicable laws, including to analyze and improve the Service and promote our business.
How we share your personal information
We may share your personal information with the following parties and as otherwise described in this Privacy Policy, in other applicable notices, or at the time of collection.
Affiliates
Our corporate parent, subsidiaries, and affiliates.
Service providers
Third parties that provide services on our behalf or help us operate the Service or our business. Our current categories of service providers, with the principal providers we use today, are:
- Hosting, storage and email delivery: Amazon Web Services (application hosting, databases, file storage and transactional email), Cloudflare (content delivery, security and bot protection).
- Product analytics and monitoring: PostHog (product analytics and surveys), Grafana Labs (application logs, metrics, performance and error monitoring), Google Analytics (marketing website).
- Fraud prevention: Castle (device and behavior signals used to detect automated signups and account abuse).
- Payments: Stripe (see “Payment processors” below).
- Customer support and business tools: providers of email, communication and support tooling.
LLM providers and AI service providers
When you use our Service to interact with LLMs, we share your prompts, relevant chat history, memories and uploaded content with the LLM provider needed to generate the response. Most models are accessed through OpenRouter, which routes your request to the provider of the model you selected (for example OpenAI, Anthropic, Google, Meta, Mistral, DeepSeek or xAI). We also use AI service providers for specific functions: OpenAI for speech-to-text transcription of audio you record, Mistral (via OpenRouter) for optical character recognition of scanned documents, and Cohere (via OpenRouter) for ranking search results. This sharing is limited to what is necessary to provide the Service to you. Each provider’s use of your data is governed by its own privacy policy and terms of service; we use these providers under terms that prohibit training on your content.
Web search and content retrieval providers
When you use web search or ask the assistant to read a web page, we send your search query or the page address to Exa (web search) and retrieve the page from its publisher.
Scholarly databases
When you search for papers, fetch full text, or verify a citation or claim, we send the search terms, identifiers (such as a DOI), citation details or claim text you provide to public scholarly databases and indexes, including CrossRef, Semantic Scholar, OpenAlex, arXiv, PubMed and other NCBI services, Europe PMC, ClinicalTrials.gov, ERIC, DataCite, DOAJ, Unpaywall, CORE, NIH RePORTER, NSF, PatentsView and Google Patents. These requests are not accompanied by your name or account identifiers. Each database’s handling of queries is governed by its own policies.
Connected AI assistants and other MCP clients
If you connect CoChat to a third-party AI assistant such as ChatGPT (OpenAI) or Claude (Anthropic), we transmit the results of the tools that assistant calls, which may include your chat content, plans and project information, to that assistant’s provider. See “Connected apps and AI assistants” below for details. The provider’s use of that data is governed by its own privacy policy.
Advertising measurement
When a purchase follows a click on one of our Google Ads advertisements, we send Google the click identifier from that ad, the time of purchase and the purchase amount so Google can measure the advertisement’s effectiveness. We do not send your name, email address or chat content to advertising partners.
Payment processors
Any payment card information you use to make a purchase on the Service is collected and processed directly by our payment processor, Stripe. Stripe may use your payment data in accordance with its privacy policy, https://stripe.com/privacy.
Collaborative chat participants
When you invite other users to join your chat sessions or projects, share conversations, or publish a share link, the content of those chats will be visible to all invited participants or to anyone with the link. You control who has access to your collaborative chats through the invitation and sharing features.
Linked third-party services
If you log into the Service with, or otherwise link your Service account to, a third-party service, we may share your personal information with that third-party service. The third party’s use of the shared information will be governed by its privacy policy and the settings associated with your account with the third-party service.
Professional advisors
Professional advisors, such as lawyers, auditors, bankers and insurers, where necessary in the course of the professional services that they render to us.
Authorities and others
Law enforcement, government authorities, and private parties, as we believe in good faith to be necessary or appropriate for the compliance and protection purposes described above.
Business transferees
We may disclose personal information in the context of actual or prospective business transactions (e.g., investments in the company, financing of the company, public stock offerings, or the sale, transfer or merger of all or part of our business, assets or shares), for example, we may need to share certain personal information with prospective counterparties and their advisers. We may also disclose your personal information to an acquirer, successor, or assignee of the company as part of any merger, acquisition, sale of assets, or similar transaction, and/or in the event of an insolvency, bankruptcy, or receivership in which personal information is transferred to one or more third parties as one of our business assets.
We do not sell your personal information.
Connected apps and AI assistants (ChatGPT, Claude and other MCP clients)
You can connect CoChat to third-party AI assistants and agents that support the Model Context Protocol (MCP), such as ChatGPT (OpenAI), Claude (Anthropic), and coding agents, using our connector at https://app.cochat.ai/mcp. This section describes what happens when you do.
Authorization
When you add the connector, the assistant redirects you to CoChat to sign in and approve access. The consent screen lists the permissions the assistant is requesting. You can decline. We issue the assistant an access token that is valid for 1 hour and a refresh token that is valid for 30 days, and we record the assistant’s registration (its name, the addresses it may be redirected to, and the permissions you granted). We do not share your CoChat password with the assistant.
Research permission
With the Research permission, the assistant can call the following tools. The inputs come from the assistant based on your conversation with it, and the outputs are returned to the assistant.
- search: receives a search query, optional year range, subject domain and a peer-reviewed-only flag; returns paper metadata (title, authors, year, venue, DOI, abstract summary, citation count, source database and open-access link) from the scholarly databases listed above.
- fetch: receives a paper identifier (DOI, arXiv id, ERIC id or URL); returns the paper’s title, its open-access full text or abstract, a link, and status information. Full text is retrieved from arXiv, Unpaywall, Semantic Scholar, CORE or ERIC.
- verify_citation: receives a title, DOI, authors, year and venue; returns whether the citation matches a real record in CrossRef and any differences found.
- verify_claim: receives a claim sentence and optionally the DOI it is attributed to; returns whether the claim appears in that paper’s text and which other papers contain matching passages. The claim text is sent to Semantic Scholar (with OpenAlex as a fallback).
Research queries are forwarded to the scholarly databases without your name or account identifiers and are not stored in your CoChat account. Fragments of a query may appear in our operational logs when a request fails; those logs are kept for 30 days. The open-access text of papers anyone fetches is cached for 180 days so it can be served faster to all users; this cache contains published papers, not personal information.
Workspace permission
With the Workspace permission, the assistant can read from and write to your CoChat account:
- chats_list: receives an optional title search and a limit; returns the ids, titles and last-updated times of your chats.
- chats_get: receives a chat id; returns up to 500 messages of that chat, including the messages of other participants in a collaborative chat you have access to.
- plans_list, plans_pull: return the plans (shared documents) in your account or project, their content and the review comments left on them.
- plans_share, plans_update: receive a title, document content and an optional project name; create or replace a plan document in your account and make it available to the people you collaborate with in that project.
- projects_list, projects_add: return your projects (folders) or create a new one from a name and description.
Everything returned by these tools is transmitted to the assistant’s provider and becomes subject to that provider’s privacy policy and your settings there (for example, OpenAI’s data controls for ChatGPT). We recommend granting the Workspace permission only to assistants you trust with your conversation history. We do not read your conversations with the assistant itself; we only receive the specific requests it sends to our tools.
What we log
For connector requests we log the permission used, the tool called and the outcome, without user identifiers or request content, for security and reliability monitoring. We do not use connector activity for advertising.
Your controls
- You can remove the connector at any time in the assistant’s settings; it will no longer be able to make requests to your account, and any token it still holds expires (access token within 1 hour, refresh token within 30 days).
- To have all tokens for a connected assistant revoked immediately, email hello@cochat.ai from your account email.
- Chats, plans and projects created through a connector appear in your CoChat account and can be deleted there like any other content.
- You can review what a connector can do before approving it, and grant Research without Workspace.
How long we keep your personal information
We keep personal information for as long as needed for the purposes described above, and then delete or anonymize it. Our current retention periods are:
| Data | Retention |
|---|---|
| Account and profile data | For the life of your account. Deleted or anonymized within 30 days after we process your deletion request. |
| Chat content, uploaded files, memories, plans, library data | Until you delete them or your account is deleted. Deleted items may remain in encrypted database backups for up to 7 days. |
| Memories | Until you delete them individually or use “Delete all memories”. Disabling memory stops new memories from being created. |
| Connected-app registrations and tokens | Access tokens 1 hour; refresh tokens 30 days; the assistant’s registration and your consent record for as long as the connection is in use. |
| Research search queries and claim text | Not stored in your account. Forwarded to scholarly databases for the request only. |
| Cached open-access paper text | 180 days from retrieval. |
| Operational logs (server logs, error reports, performance telemetry) | 30 days. |
| Product analytics events | Retained by our analytics provider (PostHog) under its retention schedule. We delete your analytics profile when you delete your account or on request. |
| Fraud-prevention signals | For as long as needed to detect and prevent abuse of the Service. |
| Billing and transaction records | 7 years, as required by tax and accounting law. |
| Marketing preferences and email engagement | Until you unsubscribe or your account is deleted. |
Where we are required to retain information for legal, regulatory or legitimate business purposes (such as resolving disputes or enforcing our agreements), we may keep it longer than stated above.
Your choices and rights
Opt out of communications
You may opt out of marketing-related emails by following the opt-out or unsubscribe instructions at the bottom of the email, or by contacting us. If you opt out of marketing emails, you may continue to receive service-related and other non-marketing emails.
Managing your chat content
You can delete individual chat conversations or your entire chat history in the app. You can also export all of your chats as a file from Settings. Deleted content may remain in backups for up to 7 days before permanent deletion.
Managing memories
You can turn the memory feature on or off in Settings, review the memories we hold, delete individual memories, or delete all of them.
Managing connected apps
You can disconnect any AI assistant you have connected in that assistant’s settings, and email us to revoke its tokens immediately, as described in “Connected apps and AI assistants”.
Sharing
You control who can see your chats and plans through the invitation and share-link features. You can revoke a share link or remove a participant at any time.
Cookies and other technologies
Most browsers let you remove or reject cookies, including cookies used for interest-based advertising. To do this, follow the instructions in your browser settings. Many browsers accept cookies by default until you change your settings. Please note that if you set your browser to disable cookies, the Service may not work properly, including the sign-in state of app.cochat.ai. For more information about cookies, including how to see what cookies have been set on your browser and how to manage and delete them, visit https://www.allaboutcookies.org.
Blocking images and clear GIFs
Most email clients allow you to disable the display of images by default, which prevents us from learning whether you opened our emails.
Do Not Track
Some internet browsers may be configured to send “Do Not Track” signals to the online services that you visit. We currently do not respond to “Do Not Track” or similar signals.
Declining to provide information
We need to collect certain personal information to provide the Service to you. If you do not provide the information we identify as required or mandatory, we may not be able to provide the Service.
Account deletion
You may request deletion of your account by contacting us at hello@cochat.ai from the email address on your account. Upon account deletion, we will delete or anonymize your personal information within 30 days, except where we are required to retain it for legal, regulatory, or legitimate business purposes.
Your privacy rights
Depending on where you live, you may have the right to request access to the personal information we hold about you, to receive a copy of it in a portable format, to correct inaccurate information, to have it deleted, to object to or restrict certain processing, to withdraw consent you have given, and to lodge a complaint with your local data protection authority. Residents of California and certain other U.S. states may also have the right to know the categories of personal information we collect, use and disclose, and to opt out of the “sale” or “sharing” of personal information. We do not sell personal information. To exercise any of these rights, email hello@cochat.ai. We will verify your identity by confirming control of the email address on your account and respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
Other sites and services
The Service may contain links to websites, mobile applications, and other online services operated by third parties, including LLM provider websites, scholarly databases, publishers’ websites and the AI assistants you can connect to CoChat. In addition, our content may be integrated into web pages or other online services that are not associated with us. These links and integrations are not an endorsement of, or representation that we are affiliated with, any third party. We do not control websites, mobile applications or online services operated by third parties, and we are not responsible for their actions. We encourage you to read the privacy policies of the other websites, mobile applications and online services you use.
Security
We employ technical, organizational and physical safeguards designed to protect the personal information we collect, including:
- Encryption of data in transit and at rest
- Regular security assessments and updates
- Access controls and authentication mechanisms, including scoped, short-lived tokens for connected apps
- Monitoring for suspicious activity
However, security risk is inherent in all internet and information technologies and we cannot guarantee the security of your personal information.
International data transfer
We are headquartered in the United States and use service providers that operate in the United States and other countries. Your personal information may be transferred to the United States or other locations where privacy laws may not be as protective as those in your state, province, or country. Where required, we rely on appropriate safeguards for such transfers, such as standard contractual clauses.
Children
The Service is not intended for use by anyone under 16 years of age. If you are a parent or guardian of a child from whom you believe we have collected personal information in a manner prohibited by law, please contact us. If we learn that we have collected personal information through the Service from a child without the consent of the child’s parent or guardian as required by law, we will comply with applicable legal requirements to delete the information.
Changes to this Privacy Policy
We reserve the right to modify this Privacy Policy at any time. If we make material changes to this Privacy Policy, we will notify you by updating the date of this Privacy Policy and posting it on the Service or by other appropriate means. Any modifications to this Privacy Policy will be effective upon our posting the modified version (or as otherwise indicated at the time of posting). In all cases, your use of the Service after the effective date of any modified Privacy Policy indicates your acknowledgment that the modified Privacy Policy applies to your interactions with the Service and our business.
How to contact us
Email: hello@cochat.ai
Mail: CoChat Inc 3175 Hanover Street Palo Alto, CA 94304-1130

