Privacy policy
Last updated: April 20, 2026
This is the legal privacy policy. For the plain language explanation of the consent architecture, see the privacy architecture page.
Introduction
Cognifica ("we," "our," or "us") is committed to protecting your privacy. This policy explains how we collect, use, disclose, and safeguard information when you use the Cognifica screening and risk stratification products, including CogAI Workforce and CogAI Medical.
The posture is HIPAA aligned. A Business Associate Agreement is available on request.
Information we collect
From members and employees
- Responses to validated instruments: PHQ-9, GAD-7, PCL-5, DAST-10, AUDIT, PSQI, Work Wellness
- Usage data and engagement metrics
- Optional messages to the clinical team through LiveChat
From tenants (employers, clinics, insurers)
- Tenant contact information
- Roster for platform access only, never for score linkage
- Billing information
How we use information
- Provide validated screening, R-Score stratification, and routed clinical support
- Generate aggregate, deidentified tenant insights where consent supports it
- Facilitate crisis intervention through the Cognifica clinical team
- Improve the platform and services
- Comply with legal obligations
The employer never sees
The employer tenant will never receive:
- Any individual score
- Any identity linked to any data
- Any therapy notes or messages
- Any signal that a specific employee used the platform
Employers receive only aggregate, deidentified data subject to a minimum cohort floor. No individual level data leaves the clinical boundary.
Data security
Security measures include:
- AES 256 encryption at rest and in transit
- HIPAA aligned infrastructure, BAA on request
- Access controls and audit logging at the clinical boundary
- Scoped identity resolution limited to the Medical Provider role
Crisis situations
If a check in response indicates immediate risk of harm to self or to others, anonymity may be paused solely to connect urgent clinical or crisis support. This is the only circumstance under which identity is disclosed, and the escalation runs through the Cognifica clinical team.
Your rights
- Access personal data held about you
- Request correction of inaccurate data
- Request deletion of personal data
- Revoke consent at any time; the change is timestamped in the record
- Receive a copy of personal data in a portable format
Contact
For privacy inquiries, contact privacy@cognifica.app or call (914) 705 6830.