Privacy Policy

Last updated: May 31, 2026

This Privacy Policy explains how Cothon AI, Inc. (“Cothon AI,” “Cothon”, “we,” “us,” “our”) collects, uses, and shares information through the Cothon AI Chrome extension and the connected Cothon web application and website at cothon.ai (collectively, the “Services”).

1. What Cothon Is and What This Policy Covers

Cothon helps you verify statements in writing, AI outputs, and web content against your own trusted sources. The Chrome extension lets you highlight text on a page, save webpages and documents to your evidence base, and check what your sources say about a given statement without leaving the page you are working on. The connected web application stores your projects and sources and lets you review entire documents.

This policy describes the data we collect through the extension and the connected web application, how we use that data, and who we share it with.

2. What We Collect

The categories below reflect the data-collection categories we disclose on our Chrome Web Store listing.

Personal Data

When you create an account, we collect your name and email address through our authentication provider, Clerk. We use this information to identify you within the Services and to communicate with you about your account. We do not store account passwords; authentication is delegated to Clerk.

Authentication information

We use short-lived authentication tokens issued by Clerk to keep you signed in. The extension holds these tokens in memory and does not persist them to disk. The extension stores your authentication state and email locally in your browser so you remain signed in across sessions. If you are already signed in to the Cothon web application in the same browser, the extension may read the existing Cothon session cookie to sign you in automatically, without a separate login.

Website content

When you take an explicit action in the extension or web application, we collect website or document content related to that action:

  • Text you select for verification. The extension sends the selected text only, not the surrounding page content.
  • The content of a webpage you save to your evidence base using the bookmark widget. The page content is fetched server-side once you save it.
  • Screenshots you capture for text recognition and claim extraction.
  • Documents you upload through the web application.

The extension displays its interface (the “orb”) on the pages you visit so the Services are available in context, but it does not read or transmit page content unless you take an explicit action. It does not run a background scraper and does not capture content you have not asked it to capture.

Web browsing activity

While the extension’s verification interface is open, the extension reads the URL and title of your current browser tab so it can associate your verification work with the page you are on. The extension also records the URL and title of any page you save as a source. This is the only web-browsing-activity data the extension collects, and it is collected solely to support the verification feature. The extension does not log or transmit web browsing activity in the background.

User activity

We collect information about how you use the Services: claims you extract, sources you save, verifications you run, projects you create, and similar interactions. We also collect technical request metadata (request identifier, timestamp, endpoint, response status, latency) and, in security and audit logs, your IP address and user agent.

Data we do not collect

The Services do not collect health information, personal communications, location data, or payment information.

3. How We Use What We Collect

We use the data we collect to:

  • Provide the Services, including claim extraction, source management, verification, and document analysis.
  • Authenticate you and manage your access to workspaces and projects.
  • Improve the quality and accuracy of the Services. We build internal evaluation datasets from prompts, model responses, document fragments, and associated metadata generated through your use of the Services. Authorized Cothon engineering personnel use these datasets to measure and improve claim extraction, verification, and retrieval quality.
  • Monitor and debug our AI workflows. To do this, we transmit the prompts we send to AI providers, the AI responses we receive, and related document fragments to an AI observability service for monitoring and quality assurance. This data includes metadata that can be associated with your account. Authorized Cothon engineering personnel may review this data for debugging, quality assurance, and product improvement.
  • Improve the web application using session analytics, configured to mask all text, digits, and form inputs.
  • Detect, prevent, and respond to fraud, abuse, security incidents, and to enforce our terms.
  • Communicate with you about your account and the Services, and comply with legal obligations.

4. Who We Share Data With

We share data with service providers who process data on our behalf to operate the Services. We have contracts with each of them that require them to protect your data and to process it under standards at least as strict as this policy.

We use service providers in the following categories:

  • Cloud infrastructure (hosting, storage, database, monitoring).
  • Authentication and identity management.
  • AI model and embedding providers used for claim extraction, verification, and document indexing.
  • Document parsing services used to convert uploaded documents into structured text.
  • Web content extraction services used when you save a webpage to your evidence base.
  • AI observability for monitoring and debugging our AI workflows.
  • Web analytics for monitoring product use and stability.

A current list of the specific service providers we use is available at Cothon Sub-Processors Privacy Policy. We may update that list from time to time as our providers change.

We may also share your data:

  • With successors (or potential successors) to all or part of our business.
  • With government entities, including judicial, regulatory, or law enforcement authorities, pursuant to lawful requests.
  • With any third party with your consent or if you direct us to do so.

We do not sell our users’ data. We do not share our users’ data with advertising networks or data brokers.

5. Chrome Web Store User Data Policy Compliance

Cothon’s collection, use, and transfer of user data through the Chrome extension complies with the Chrome Web Store User Data Policy. In particular:

  • We use the data we collect only to provide and improve the Services’ verification features.
  • We disclose your data to third parties only as necessary to operate, provide, and improve the Services, to comply with applicable laws, to protect against fraud or abuse, or in connection with a merger or acquisition (with notice and consent where required).
  • We do not sell our users’ data.
  • We do not use or share our users’ data for personalized, retargeted, or interest-based advertising.
  • We do not use or share our users’ data to determine credit-worthiness or for lending purposes.
  • Human access to user data is restricted to the narrow purposes permitted by policy: with your consent for specific data, in connection with security investigations, to comply with law, or for internal operations. Access is limited to those who need to know, and is role-based, logged, and limited to what is necessary.

We apply least-privileged and data minimization principles: the extension does not collect page content or browsing data except as described in Section 2 (for example, selected text you choose to verify, and the URL / title while the verification interface is open).

6. How We Secure Your Data

  • All data is encrypted in transit using TLS.
  • Documents are stored in Amazon S3 with server-side encryption via AWS Key Management Service (KMS) using a Cothon AI-controlled customer master key.
  • Our application database is encrypted at rest with a KMS customer master key.
  • The application runs in a private virtual private cloud; the database is not publicly accessible.
  • Project content is logically isolated at the application, service, and vector-store layers, including per-project tenant isolation in the vector database.
  • We use AWS GuardDuty, CloudTrail, and VPC Flow Logs for monitoring.
  • Multi-factor authentication is available through our authentication provider but is not required.
  • Evaluation datasets are stored in access-controlled, private repositories. Access is limited to authorized Cothon personnel.

No system can be made perfectly secure. If we become aware of a security incident affecting your information, we will notify you and applicable authorities as required by law.

7. Your Choices and Data Retention

Your choices

  • Access and update your account information through the Services.
  • Delete individual documents and projects directly within the Services.
  • Uninstall the Cothon extension at any time through your browser. Extension-local data (such as authentication state, cached project and document metadata, orb position, and settings) is stored in your browser and is removed when you uninstall the extension. You can also clear this local data at any time through your browser settings.
  • Deactivate your account by contacting info@cothonai.com. Deactivation suspends access to your account and is typically performed manually on request.
  • Request deletion of your account and associated data by contacting info@cothonai.com. We will process these requests within a reasonable time. Self-service full account deletion is planned but not yet available.
  • Evaluation datasets derived from AI observability traces (prompts, model responses, document fragments, and associated metadata) are retained separately from the 30-day observability window and kept for as long as they remain useful for evaluating and improving the Services. On account deletion request, we will use reasonable efforts to remove your data from active evaluation datasets; aggregated or anonymized derivatives may be retained.

Data retention

  • Project content and sources you add are retained until you delete them or your account is deleted. In collaborative workspaces, some content you contributed may remain as part of workspace records.
  • URLs and titles associated with your verification activity are retained as part of your project history until you delete the related item or project.
  • Security log records (including IP address and user agent) are retained for up to 90 days. Certain audit records are retained as historical records and may be anonymized.
  • AI observability traces (prompts, responses, related document fragments, and associated metadata) are retained for up to 30 days for debugging and quality assurance. Web session analytics data is retained for up to 30 days.
  • System backups are retained for up to 35 days on a rolling basis and then deleted.
  • Documents processed by our document parsing service are handled under a zero-retention configuration and are not stored at rest by the provider or its sub-processors.
  • We may keep your data for a longer period if we need it for legal compliance purposes, or if we need it to enforce or defend our legal rights.

Please note: when an account is deleted, some content associated with the projects and workspaces you participated in (including documents, AI-generated claims and evidence, and audit records) may be retained as part of those records. We do not currently offer automated export of all data associated with an account.

If you have questions about your data or want to exercise rights you may have under applicable law, contact info@cothonai.com.

8. Children

The Services are intended for business and professional use and are not directed to children under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact info@cothonai.com and we will delete it.

9. Changes and Contact

We may update this Privacy Policy from time to time without notice to you. Changes are effective upon posting and we will update the “Last updated” date above. For certain material changes, we may provide additional notice through the Services or by email.

For any privacy-related question, contact info@cothonai.com.

10. Chrome Web Store Specific Notices

Permissions and justifications

  • Host permission for all URLs (<all_urls>) — the extension displays its interface (the “orb”) on the pages you visit so your Cothon evidence library is available in context on any site. The extension does not read page content unless you take an explicit action, as described in Section 2.
  • storage — used to persist your authentication state, cached project and document data, orb position, and settings across browser sessions, and tracks which tab triggered a sign-in so the extension can refocus it afterward.
  • cookies — enables Clerk’s session-sync feature: when you are already signed in to the Cothon web app, the extension reads the existing session cookie to authenticate without a separate login.
  • alarms — schedules a periodic background authentication refresh so your short-lived session token does not silently expire.
  • declarativeNetRequest — rewrites the Origin header on the extension’s requests to the Cothon backend so it can use the same API as the web app.

Remote code: The extension does not execute remotely hosted code. All executable code runs from the extension package. The extension uses the Clerk Chrome Extension SDK for authentication, which communicates with Clerk’s Frontend API (clerk.cothon.ai) and may load non-executable authentication resources from Clerk’s infrastructure as part of standard session synchronization. No user data is transmitted beyond what authentication requires.

Google APIs: The Services do not use Google sign-in, other single sign-on, or other Google APIs that are covered by the Google API Services User Data Policy. If we add single sign-on or other such features in the future, we will include the required disclosures in the same release.