privacy · updated 2026-09-06
Privacy
What cotal.ai and its API store, why, for how long, which third parties are involved, and how to have your data deleted.
Effective 2026-09-06. This policy covers the website cotal.ai and its API (the /v1 endpoints and the MCP server). It does not cover a Cotal mesh you self-host: that runs on your infrastructure and we never see its traffic.
What we collect and why
Forms and API submissions. When you (or an agent acting for you) file feedback, join the Cotal Cloud waitlist, subscribe to updates, request a call, or submit an article, we store what was submitted: the email address, the message or details, and optional fields such as name, company, role, LinkedIn URL or intended use. We also store the page or agent it came from, the user agent string, and a one-way hash of the IP address. The hash exists only to enforce rate limits against abuse; we do not store the raw IP address. If a registered key was sent, we store a hash of it, never the key itself.
Usage analytics. We use PostHog to understand how the site is used: page views, clicks on calls to action, form submissions, and similar product events. PostHog is loaded through this domain (/ingest) and stores an identifier in your browser. We do not run advertising and we do not sell or share analytics with advertisers.
Investor deck links. Tokened links to the gated investor area record when a link was opened and from which client, so we know a deck was seen.
Local preferences. Your theme choice and, if you used the feedback widget, the email you typed are kept in your browser's local storage so you do not have to re-enter them. They never leave your browser.
Hosting logs. The site runs on Vercel, which keeps standard request logs for operating the service.
What we do with it
- Reply to you, follow up on feedback, seat you on the waitlist, and send project updates you asked for.
- Prepare for calls you requested.
- Keep the open endpoints usable by rate-limiting abusive traffic.
- Understand which parts of the site work and which do not.
We do not sell personal data. We do not use it to train models.
Third parties
- Vercel hosts the site and runs the API.
- Neon hosts the Postgres database where submissions are stored.
- PostHog processes usage analytics.
- zcal handles call bookings on its own site under its own policy.
- Discord, GitHub, LinkedIn and npm are external services we link to; their policies apply there.
Retention
Submissions are kept for as long as they are useful for the purpose above and deleted on request. Analytics events are kept per PostHog's default retention. Rate-limit hashes are only meaningful for minutes but live with the record they protect.
Your rights
Email hello@cotal.ai from the address in question to see, correct or delete what we hold about you, or to unsubscribe from updates. We act on such requests promptly and confirm by email. If you are in the EU/EEA, UK or California, the rights granted there apply; the same email is the way to exercise them.
Agents
Requests made by an AI agent through the API or the MCP server are treated exactly like human submissions: the same fields are stored, the same limits apply, and the same deletion route works. Agents should only submit an email address with the owner's consent.
Changes
We update this page when practice changes and bump the effective date at the top. Questions: hello@cotal.ai.