Privacy Policy

Last updated: 6 July 2026

This policy explains how GLB Group Ltd (company no. [COMPANY NUMBER], registered office [REGISTERED ADDRESS]) ("we", "us") handles your personal data when you use Cohort. We are the data controller. Contact us about privacy at hello@glbgroup.org.

What we collect

  • Account & purchase: your email address and payment metadata (Stripe processes your payment — we never see or store your full card details).
  • Your Anthropic API key: stored encrypted at rest (AES-256-GCM), never logged, decrypted only in memory when your team runs.
  • Content you create: the prompts, chats, and outputs generated in your workspace.
  • Basic technical & attribution data: e.g. a referral tag from the link you arrived through, and standard server logs.

How we use it

To deliver and support the Service: issue and deliver your licence, run your agents, provide customer support, prevent abuse, and meet legal obligations. Our legal bases under UK GDPR are performance of our contract with you and our legitimate interests in running and securing the Service.

Who processes data for us

We use a small set of sub-processors, each only for the purpose stated:

  • Stripe — payment processing.
  • Supabase — database, authentication, and storage.
  • Resend — transactional email (your licence delivery).
  • Anthropic — the Claude models that process your prompts when your team runs.
  • Vercel — application hosting.

Some of these process data outside the UK/EEA (e.g. in the US); where they do, appropriate safeguards (such as Standard Contractual Clauses) apply.

Retention

We keep your data for as long as your account is active and as needed to provide the Service and meet legal/accounting obligations, then delete or anonymise it.

Your rights

Under UK GDPR you can request access to, correction of, or erasure of your personal data, and object to or restrict certain processing. To exercise any of these — including deleting your workspace and purging your stored encrypted key — email hello@glbgroup.org and we'll action it within 30 days. You can also complain to the UK Information Commissioner's Office (ico.org.uk).

Cookies

We use only essential cookies needed to keep you signed in and secure. We don't currently use advertising or third-party analytics cookies; if that changes, we'll ask for consent first.

Security

We encrypt sensitive data at rest, never log your API key, and restrict access to production systems. No system is perfectly secure, but we take reasonable measures to protect your data.

Changes

We may update this policy; the "last updated" date above reflects the latest version.