Privacy Policy
This policy explains the information Cohuno processes when you visit the site or use the private AI workflow studio.
Effective and last updated: August 29, 20261. Scope and contact
This policy applies to the Cohuno website, Google sign-in flow, private workflow studio, and related support. Cohuno is the name used for this service. Questions, access requests, or deletion requests can be sent to [email protected].
2. Information we process
- Google account information: your Google account identifier, verified email address, display name, and profile image when supplied by Google. Cohuno requests only the
openid,email, andprofilescopes for sign-in. Cohuno does not receive your Google password, verifies the returned identity token, and does not retain a Google access or refresh token. - Workspace content: workflows, agent and task configurations, run inputs and outputs, schedules, evaluations, knowledge sources, and other content you choose to store or process.
- Connection information: provider, tool, and MCP connection settings. Secret values saved in Cohuno are encrypted at rest.
- Technical information: request, error, security, and diagnostic data generated when the service operates. This may include IP address, browser information, timestamps, and requested routes.
- Communications: information included when you request support or a demonstration.
3. How information is used
Cohuno uses information to authenticate authorized users; provide, secure, troubleshoot, and improve the service; run the workflows and integrations you request; communicate about support and service changes; and prevent misuse. Cohuno does not sell personal information or use workspace content for third-party advertising.
4. Service providers and integrations
Google processes sign-in information under its own terms. Hosting and infrastructure providers may process technical data to operate Cohuno. When you connect an AI model, MCP server, knowledge source, or other tool, Cohuno sends the information required to perform your requested action to that provider. Those providers apply their own privacy terms, and workspace administrators are responsible for selecting and configuring them.
5. Cookies and session security
Cohuno uses strictly necessary cookies to protect the Google OAuth exchange and maintain an authenticated session. Session cookies are signed and configured with HttpOnly, SameSite, and HTTPS protections in production, and the signed session expires after 12 hours. Cohuno does not currently use advertising cookies on these pages.
6. Retention, security, and deletion
Information is retained while needed to provide the workspace, comply with applicable obligations, resolve disputes, and protect the service. Retention can also depend on the connected provider and the workspace administrator's configuration. Cohuno uses access controls, encrypted secret storage, private network boundaries, and transport security, but no system can guarantee absolute security. Contact support to request account or workspace deletion; limited copies may remain temporarily in protected backups or where retention is legally required.
7. Your choices and rights
You can choose which workflows, knowledge, and third-party connections to provide. You may also ask to access, correct, export, object to, restrict, or delete personal information where applicable. Cohuno may need to verify your identity before completing a request. You may also have a right to contact your local data-protection authority.
8. International use, children, and updates
Cohuno and connected providers may process information in countries other than yours. The service is designed for organizations and is not directed to children under 18. This policy may change as the service or legal requirements evolve. Material changes will be reflected here with a new effective date.