Privacy Policy
Last updated: August 11, 2026
Cook.ai (“Cook”, “we”) is an AI-run marketing workspace. This policy explains what personal data we handle, why, and the choices you have. Questions and requests: austin@clientacquisition.io.
The two roles we play
For your account and your use of Cook, we decide how data is handled — we are the data controller. For the business records your workspace holds (your clients, your leads, form submissions on your funnel pages), you are the controller and Cook processes that data on your instructions as a processor.
What we collect
- Account data: name, email address, password (stored hashed), and sign-in identifiers from Slack or Discord if you use social sign-in.
- Workspace content: chats with your AI departments, files you upload, documents, and generated media.
- CRM records you or your integrations add: client and lead names, email addresses, phone numbers, notes, and pipeline status.
- Funnel form submissions from your pages: the fields a visitor types, plus a consent record (what they agreed to, when, from which page).
- Billing data: subscription and credit usage. Card details go directly to Stripe and never touch our servers.
- Connected integration credentials, stored encrypted (AES-GCM).
- Usage data: page analytics without cookies, and server logs for security and debugging.
Why we use it
- To run the service you signed up for — your account, workspace, and AI agents (performance of a contract).
- To bill you (performance of a contract, legal obligations).
- To keep the service secure and debug problems (legitimate interest).
- To measure product usage with cookieless analytics (legitimate interest).
- To send marketing on behalf of our customers to their contacts — done on the customer's instructions; the customer is responsible for having a lawful basis.
AI processing
Cook does its work by sending workspace content to AI model providers (Anthropic, OpenAI, Google) and media generators. These providers process the content to produce the requested output. We do not use your content to train models of our own.
Who we share data with
We use the following service providers (subprocessors) to run Cook:
| Provider | What it does |
|---|---|
| Convex | Database and application backend |
| Vercel | Web and funnel-page hosting, cookieless page analytics |
| Railway | AI service hosting |
| Cloudflare | File storage (R2) and course video streaming (Stream) |
| Stripe | Payment processing |
| Autumn | Billing and credit metering |
| Resend | Transactional email delivery |
| OneSignal | Push notifications |
| Anthropic | AI text generation |
| OpenAI | AI text generation |
| AI (Gemini) and Calendar sync | |
| Cohere | Search embeddings for course content |
| ElevenLabs | Audio transcription |
| LiveKit | Real-time voice sessions |
| Meta | Ad delivery and conversion measurement for customer campaigns |
| fal / Kie | AI image and video generation |
| Blaxel / E2B | Sandboxed compute for agent jobs |
| Freestyle / GitHub | Funnel code repositories and previews |
| GoHighLevel / Close | CRM sync, when a customer connects one |
| Fathom | Meeting recording sync, when a customer connects it |
| Slack / Discord / Telegram / Whop | Messaging bridges, when connected |
We do not sell personal data. Beyond these providers, we disclose data only when the law requires it or to protect the service from abuse.
International transfers
Our providers process data primarily in the United States. Where data about people in the EU, EEA, or UK is transferred, we rely on the providers’ data processing agreements and standard contractual clauses.
How long we keep data
- Account and workspace data: for as long as your account exists.
- Backups: rolling snapshots kept for 14 days.
- Billing records: as long as tax and accounting law requires.
- Deleted data: removed from the live database at deletion time and from backups as they expire.
Your rights
You can access, correct, export, or delete your data. In the app: Settings lets you export your workspace’s data and delete your account or organization. By email: send requests to austin@clientacquisition.io and we will respond within 30 days. If you are in the EU, EEA, or UK, you also have the rights to restrict or object to processing and to complain to your supervisory authority. If your data is in a customer’s workspace (for example, you are their client or a lead), contact that business — they control it — and we will help them honor your request.
Cookies
The Cook app itself sets only cookies the service needs to work: your sign-in session, your theme, and your active workspace. Our page analytics does not use cookies. Funnel pages our customers publish are the customers’ own websites and may use advertising cookies with the visitor’s consent where consent is required — each funnel carries its own privacy policy.
Children
Cook is a business tool and is not directed at children under 16. We do not knowingly collect their data.
Changes
When this policy changes, we update this page and the date at the top. Material changes are announced in the app.
See also our Terms of Service.