Privacy policy

Privacy policy

Last reviewed:

Who is responsible

Cohesive is operated by Alejandro Carbajo, a sole trader established in Spain, acting as the data controller under the EU General Data Protection Regulation. Requests to exercise your rights go to privacy@cohesivejournal.com; a postal address is supplied on request to that address. General questions go to hello@cohesivejournal.com.

This policy covers the website at cohesivejournal.com, the early-access waitlist, and the Cohesive application. Sections marked application describe processing that begins when you install and use the app; they do not apply if you have only joined the waitlist.

The waitlist

If you join the early-access list, the following is stored:

Nothing else is recorded. Your IP address is not stored with the signup. There is no tracking pixel, advertising tag, or third-party form embedded in the page — the address is posted to Cohesive’s own server and stored in Cohesive’s own database.

The lawful basis is consent (Article 6(1)(a)), given for one specific purpose: to be told once, by email, when Cohesive opens. The list is not used for a newsletter, a drip sequence, or any other message. If Cohesive never launches, the list is deleted and you hear nothing.

Submitting the same address twice does not create a second record and does not change your position; the page returns the same confirmation either way, so the form cannot be used to test whether a particular address is on the list.

The website

The site stores one first-party entry: your privacy choice, recorded with the version of the policy it was given under, so the choice can be honoured and requested again if the policy changes materially. This is strictly necessary to respect your decision and does not require consent.

Optional analytics stay switched off until you allow them. The default is essential-only, and choosing “Essential only” degrades nothing — no part of the site depends on analytics. Cohesive uses no third-party analytics service: there is no Google Analytics, no advertising network, no social pixel, and no session recorder anywhere on this site. If you do allow analytics, what is recorded is event names, timings, counts, and failure codes in Cohesive’s own database — never the content of anything you write.

The site is served as static files through a content delivery network, which processes the connection metadata inherent in serving any web page, including your IP address, in order to deliver the page and protect against abuse. That is the network’s own security processing and is not combined with anything else Cohesive holds about you.

The application

The event you catch, what led into it, your answers during an inquiry, and any context you have confirmed leave your device for Cohesive’s servers, and are sent to an external large-language-model provider under a data-processing agreement, because that is what makes the resulting question specific to your moment rather than a generic template. Nothing else is sent.

Cohesive does not inspect the contents of other applications on your device, does not read your screen, and does not collect a screen-time log. It infers nothing about you from your device; it works only from words you supplied or confirmed.

Your records are not sold, not used for advertising, not used to train public models, not used to optimise for engagement, and not read routinely. Access by a person is limited to the narrow cases described in the application’s “Who’s watching?” screen — principally a support request you have made, or a specific security or legal obligation — and each such access is recorded.

Processors

Cohesive uses a small number of service providers, each processing only what its function requires and under contract:

Where a provider operates outside the European Economic Area, the transfer is covered by the European Commission’s Standard Contractual Clauses together with that provider’s supplementary safeguards. The current list, naming the specific companies and their locations, is available on request at privacy@cohesivejournal.com and is kept accurate as providers change.

How long data is kept

Waitlist records are kept until Cohesive launches and the single announcement email has been sent, or until you ask for removal, whichever comes first. Once the announcement has gone out, the list is deleted within 90 days. If the product is abandoned, the list is deleted and you are told.

For application users, awareness records are kept until you delete them or delete your account. Deletion is real: it removes the record and propagates through anything derived from it, rather than hiding it from view. Billing records are kept for the period Spanish tax law requires, which is longer than your account. Security logs are kept for a short, bounded period. Backups roll off on their own schedule, so a deleted record can persist in a backup for a limited period before that backup expires.

Your rights

Under the GDPR you may request access to your data, correction of it, erasure, a portable copy, restriction of processing, and you may object to processing. Where processing rests on consent — the waitlist and optional analytics both do — you may withdraw it at any time, and withdrawal does not affect the lawfulness of processing that already happened.

For the waitlist, one email to privacy@cohesivejournal.com is enough, and every launch email also carries a one-click unsubscribe. For the application, export and real deletion are available inside the app and keep working whether or not you are a paying subscriber; they are never held back to discourage you from leaving.

Requests are answered within one month. If you are not satisfied, you may complain to the Spanish supervisory authority, the Agencia Española de Protección de Datos (aepd.es), or to the authority in your own EU country of residence.

Automated decisions and children

Cohesive makes no automated decision producing a legal or similarly significant effect about you. The question an inquiry asks is generated text, not a decision, assessment, score, or diagnosis, and you are free to disagree with it or ignore it.

Cohesive is not directed at children and is not intended for anyone under 16. If you believe a child has given us their data, write to privacy@cohesivejournal.com and it will be deleted.

Changes

If this policy changes in a way that affects you, the change is published here with a new review date, and where the change concerns consent, consent is requested again rather than assumed. The date at the top of this page is the date it was last reviewed.