Cortex is operated by ArcSoft Pty Ltd ("Arc"), an Australian entity. This notice is given under the Australian Privacy Act 1988 / Australian Privacy Principles; other applicable privacy law (e.g. the GDPR for users in the EU) applies where it applies. This notice states no privacy posture stronger than the code enforces.
This notice explains what data Cortex handles, where it goes, and what Arc does and does not receive. The short version: Cortex is local-first. Your conversation content and compiled state stay on your machine; Arc does not receive them. Two things do leave your machine — (a) what you choose to compile goes to your model provider, and (b) only if you sign in or refresh an account key, a minimal, content-free license signal goes to Arc. By default Arc receives nothing.
1. What Cortex processes locally (stays on your machine)
- Your transcripts — read read-only; Cortex never modifies them.
- The compiled store (
.cortex/) — evidence, states, patches, orientation, the manifest, the audit log. Written only under.cortex/. This is your data on your disk. - Arc does not receive, upload, or store your conversation content, workspace files, or compiled state.
2. What leaves your machine to a third-party model (BYOK)
- When you compile/ingest, the relevant transcript turns are sent to a language model provider of your choice, under your own subscription/API key (default: Anthropic Claude via the Claude Agent SDK; or any OpenAI-compatible endpoint you configure — one you run locally keeps data on-device).
- This is your data going to your provider, under that provider's privacy terms — not to Arc. You decide what to compile; nothing is sent without your authorization (the cost gate).
- You are responsible for what you choose to compile. Transcripts may contain personal information, client/student/patient material, source code, secrets, or keys. Review before compiling regulated or confidential material.
3. What goes to Arc (license/account only — no content)
By default, nothing. The preview entitlement ships inside each release and is verified on your machine (offline); it is never refreshed over the network. Cortex contacts Arc's License Authority only when you run one of two commands, and then sends a minimal, content-free signal:
cortex license login(device sign-in):{ product, device fingerprint, device label, product version }, then a poll carrying the one-time device code.cortex license refresh(renewing an account-held entitlement):{ account_id, product, device fingerprint, product version }.- Like any server, Arc's server sees the IP address a request comes from. No conversation, file, or compiled-state content is ever sent.
- Account data: the email/identity you register for your Arc Account, and your entitlement/billing status (billing via the payment processor, not stored as card data by Arc).
- Product-level telemetry: there is none in the current release. If it is ever added, it will carry event-level signals only — e.g. login success, license refresh, a command name, an error code, a coarse workspace-size bucket. Never conversation content, file names, paths, compiled state, or the orientation output.
Arc uses this to operate licensing, detect license abuse (e.g. one license used as a service across many devices), and understand product usage at an aggregate level.
4. What Arc does not do
- Arc does not read or store your conversations, your workspace, or your compiled state.
- Arc does not sell personal information.
- Cortex is described as filesystem-constrained with gated, capped, user-authorized model calls — not as "your data never leaves your machine" (compiling sends data to your model provider). We will not claim more than the code enforces.
5. Your choices and rights
- You control what you compile (and can avoid compiling sensitive material).
- You can run without a license on the continuity floor; you can
cortex license logoutto remove the local token. - You may have rights to access, correct, or delete the account/license data Arc holds, and to complain to a regulator, under the Australian Privacy Act and other applicable law. To make a request, write to contact@arcintelligence.ai.
6. Children, changes, contact
- Cortex is not directed to children under 18.
- This notice may change as Cortex moves toward productisation; material changes will be notified consistent with Research Preview Terms §2.
- Operator: ArcSoft Pty Ltd (trading as Arc Intelligence), Sydney, Australia. Privacy contact: contact@arcintelligence.ai.
Cortex Privacy Notice, version 1.0.