Security & Trust

Built to be transparent.
Not just to be trusted.

Cognlay is new, so trust has to be earned clearly. Here is what the app accesses, what it avoids, and how we reduce avoidable risk around your inbox, leads, and sender reputation.

No Google password collection

No selling lead or mailbox data to third parties

No Gmail API, Drive, Calendar, or Google OAuth scopes

No AI training on customer email content

Security controls
01

Encryption

Cognlay uses HTTPS/TLS for all data in transit. Stored workspace data and mailbox credentials are protected using encryption and provider-backed security controls.

02

Secure SMTP/IMAP access

Cognlay connects to mailboxes through provider-supported SMTP and IMAP settings only. We do not use the Gmail API, request Google OAuth scopes, or collect your Google password.

03

Minimal data access

SMTP sends configured emails. IMAP detects replies and maintains thread context. Cognlay is not designed for general inbox browsing outside your configured sequences.

04

Operational controls

We use role-based access controls, production access hygiene, dependency scanning, and logging around sensitive operations.

05

Isolated workspace data

Workspace data is logically separated per account. AI requests are built from the specific lead, sequence, draft, and thread context needed for that action only.

06

Transparent incident response

We monitor important system activity and notify affected users when required by applicable law following a confirmed security incident.

SMTP/IMAP access disclosure

What mailbox access Cognlay uses — and what it never requests.

SMTP sendSend configured outbound emails only
IMAP readReply detection and thread context for safety
Credential storageEncrypted — revocable by rotating your mailbox password

We do not request access to Drive, Calendar, or unrelated Google products. Cognlay does not use Gmail API scopes. Disconnecting the mailbox or rotating credentials stops all new access immediately.

Common questions

Who can access my data?

Authorized Cognlay personnel may access workspace data only when needed for support, security, abuse prevention, or service operation. Sensitive operations are designed to be logged and reviewed.

Where is my data stored?

Cognlay uses managed cloud infrastructure. We keep this honest: infrastructure providers may process data in their supported regions, and we avoid claiming a fixed residency guarantee until one is contractually available.

Can Cognlay read my emails?

The app processes message content and metadata for reply detection, thread context, and follow-up safety. Human access is limited to authorized support or security needs only.

What happens when I disconnect a mailbox?

Cognlay stops accessing new mailbox data immediately. Stored mailbox credentials are deleted within 30 days, and cached thread context is deleted or anonymized per the privacy policy.

Do you train AI models on my emails?

No. Cognlay does not use your mailbox content, lead data, replies, or sequence data to train general-purpose AI models.

Still have questions? Email hello@cognlay.com — Jay responds to every security question personally.