Skip to content
Cornelius
How it works Memory Security Compare FAQ
Log in Get Cornelius
How it works Memory Security Compare FAQ Log in

Privacy Policy

Private beta. Last updated 18 August 2026.

The short version

  • Cornelius stores text: the memory files and event log your agent writes, plus your account details. That is essentially all.
  • We never run an AI model on your data. All interpretation happens inside your Claude, ChatGPT or Codex app.
  • We never hold your Gmail, Calendar or other connector credentials, and we never receive full email bodies or attachments.
  • You can export everything as a zip and delete everything from the dashboard. Your agent has no tool that can delete anything.
  • We do not sell your data and we do not use it for advertising. The beta is free, so we hold no payment details.

On this page

Who we are What we collect What we never collect How we use it Who else sees it Your controls How long we keep it Security International transfers Children Changes Contact

Who we are

Cornelius is operated by [Company legal name], [registered address] ("Cornelius", "we", "us"). We are the data controller for the personal data described in this policy. You can reach us at [privacy@yourdomain].

Cornelius is a remote connector (an MCP server) that holds the memory, persona, instructions and skills of a personal AI agent. The agent itself runs inside an app you already use: Claude Desktop, ChatGPT Desktop or Codex. This policy covers what we do. Your AI platform's own privacy policy covers what happens inside that app.

What we collect

Account data

Your email address, your name if you give one, and an identifier from the sign-in provider you use. If you sign in with a Google or other account, we receive only the basic profile fields needed to create and secure your account.

Memory data

The content your agent writes through our tools: Markdown memory files (people, projects, organisations, topics, journal entries), the immutable event log beneath them, your agent's persona and routine files, and every earlier version of those files. Each event carries a source tag (chat, daily cycle, email summary, calendar summary or your own note) and a trust tag (you, your platform, or external). This content is written by your agent on your behalf and can include personal data about you and about people you work with.

Connection and usage data

Timestamps and names of the tools your agent calls (never the AI's reasoning), the platform a call came from, connection status shown in your dashboard, the daily-cycle heartbeat used by the watchdog, and the thumbs-up or thumbs-down feedback your agent records about the morning brief.

Technical data

Standard server logs: IP address, browser or client identifiers, request times and error records. We keep these for security and reliability only.

Communications

Emails you send us, and our replies.

What we never collect

  • Connector credentials. Gmail, Google Calendar and any other connector are authorised inside your AI platform, not with us. We hold no tokens, keys or passwords for them.
  • Full emails or attachments. Your agent may write short summaries and structured facts into memory. Full message bodies and attachments are not stored by us.
  • Provider API keys. There is nothing to paste and nothing for us to hold.
  • Payment details. The private beta is free and there is no billing in the product.
  • Inference data. We never send your data to an AI model. We store and serve text; we do not interpret it.

How we use it

  • To run the service. Storing your memory and serving it back to your agent when it calls our tools; keeping versions so every change is reversible.
  • To keep your agent alive. If the daily cycle has not run for more than 36 hours, we send you a short nudge email with reconnect guidance. You can turn these off in the dashboard.
  • To protect the memory. Every write passes an injection-pattern scan; suspicious spans are stored but flagged, never silently absorbed. Trust and source tags are preserved end to end.
  • To confirm sensitive actions. Deleting your account triggers a confirmation email.
  • To support you and improve the product. Answering your messages, and looking at aggregate, de-identified usage (for example how many people complete setup) during the beta.
  • To meet legal obligations and to protect our rights and yours.

Where the GDPR or UK GDPR applies, our legal bases are: performance of our contract with you (running the service), our legitimate interests (security, reliability, product improvement) and your consent for optional emails, which you can withdraw at any time.

Who else sees it

  • Your AI platform. When your agent calls a Cornelius tool, the requested memory is returned to that app (Anthropic's Claude, OpenAI's ChatGPT or Codex). What the platform does with it is governed by its own terms and privacy policy.
  • Infrastructure providers. Cloud hosting and storage at [hosting provider and region], and a transactional email provider for the watchdog and confirmation emails. They process data only on our instructions.
  • Nobody else, unless the law requires it or you ask us to. We do not sell personal data and we do not share it with advertisers or data brokers.

Your controls

  • Export. The dashboard produces a zip of every memory file, every earlier version and the raw event log. It is yours to take anywhere.
  • Correct. Tell your agent in chat and it updates its files, keeping the old version visible; or edit an agent-writable file in the dashboard.
  • Delete. Only you can delete, from the dashboard. Deleting your account removes all data within [30 days] and we confirm by email. Your agent has no delete tool at all; if you say "forget this" in chat, it will point you to the dashboard.
  • Emails. Watchdog nudges can be switched off; account and security emails cannot.
  • Your rights. Depending on where you live you may also have rights to access, portability, restriction and objection, and the right to complain to your data protection authority. Write to us and we will help.

How long we keep it

Memory and account data stay as long as your account exists. After you delete your account, live data is removed within [30 days] and backups are purged within [a further 30 days]. Server logs are kept for [90 days]. Support emails are kept for as long as needed to resolve the matter and for our records.

Security

Data is encrypted in transit and at rest. Access inside the team is limited to what operating the service requires. The event log is append-only and every write is versioned, so nothing can be silently rewritten. Every write carries provenance and trust tags and passes an injection-pattern scan.

One honest note: because your agent can summarise external content into memory, memory poisoning is reduced, not eliminated. The immutable raw layer means you can always see what actually happened. If you find a security problem, please tell us at [security@yourdomain].

International transfers

Our infrastructure is located in [region]. Where personal data is transferred across borders we rely on appropriate safeguards such as standard contractual clauses.

Children

Cornelius is for adults. It is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

We will update this page when the product changes, and we will email account holders about any change that materially affects how we handle personal data. The date at the top always shows the current version.

Contact

[Company legal name], [registered address]. Email: [privacy@yourdomain].

Beta notice: this policy describes the private beta as designed. Items shown [in brackets] are placeholders to be completed by the company before launch.

Cornelius

The personal agent that runs on your platform. Bring your own platform.

Product

  • How it works
  • Memory
  • Security
  • Compare
  • FAQ

Company

  • Privacy
  • Terms
  • Contact
© 2026 Cornelius Claude is a trademark of Anthropic. ChatGPT and Codex are trademarks of OpenAI. Cornelius is not affiliated with either.