cobrain is a workspace where a team keeps its files, tables and chats, and works with an AI agent that can read and act on them. It is operated by Mithril, Zurich, Switzerland (“Mithril”, “we”, “us”). This policy explains what personal data we handle when you visit cobrain.ch or use cobrain, why, who else processes it, and what you can ask of us. Questions go to hello@mithril.digital.
Who is responsible
For your account, billing and the website, Mithril is the controller. For the content a customer puts into its workspace — files, tables, chats, and anything read through an connector — the customer organisation is the controller and we process it on their behalf and on their instructions. If you use cobrain through your employer, questions about that content are best sent to them first; we will help them answer.
What we collect
- Account data — your name, email address and profile picture, and which sign-in method you use (email, Google or Microsoft).
- Workspace content — the files, tables, chats, prompts and automations you and your colleagues create, and the messages you send to the agent, including by email, Slack, Microsoft Teams or WhatsApp if your workspace connects them.
- Connector data— when you connect an outside account such as Gmail, Google Drive, Outlook or SharePoint, the access token that account issues, and whatever the agent reads through it when you ask it to. See “Google user data” below.
- Usage and billing data — which models were used and what they cost, seat and plan information, and payment details, which are collected and held by Stripe; we never see a full card number.
- Technical data — IP address, browser and device information, and logs of requests, kept to operate and secure the service. A session cookie keeps you signed in. Our website analytics (Vercel Web Analytics) count page views without cookies and without identifying you.
How we use it
- To provide cobrain: store your workspace, run the agent when you ask it to, and show you the result.
- To bill for seats and model usage.
- To keep the service secure, prevent abuse, and fix problems.
- To tell you about changes to the service or to your account.
We do not sell personal data, we do not use it for advertising, and we do not use your workspace content or connector data to train or improve AI models — ours or anyone else’s.
The AI models
When you ask the agent something, the relevant part of your workspace — the conversation, the files it opens, and what it reads through your connectors — is sent to the language model your workspace has chosen, to produce the answer. Gemini and Claude models run on Google Cloud’s Vertex AI in the EU. OpenAI, Mistral and DeepSeek models run on Microsoft Azure AI Foundry: OpenAI models in Microsoft’s EU data zone, Mistral and DeepSeek wherever Microsoft serves them. The model picker shows where each model runs. Requests are used to answer that request only.
Dictating into the message box uses your browser’s own speech recognition, which is run by your browser’s provider rather than by us.
Google user data
cobrain lets you connect Google Calendar, Google Drive and Gmail, and sign in with Google. Each is a separate connection that you start yourself, on Google’s own consent screen, and each asks only for the permissions it lists there.
- Sign in with Google — your name, email address and profile picture, to create and identify your account.
- Google Calendar — to read your events and free/busy times, and to create or change events when you ask the agent to.
- Google Drive — to search the files you can reach and read their contents when you ask the agent about them. cobrain does not change or delete files in your Drive.
- Gmail — to search and read your messages and attachments when you ask the agent to, and, only if you granted those permissions, to write drafts and to send email as you when you ask it to.
How we use it. Only to provide the features you use in cobrain: the agent reads Google data when you, or an automation you set up, asks it to do something that needs it, and shows you the result. Nothing is read in the background for any other purpose.
How we store it. The access and refresh tokens Google issues are encrypted before they are stored. We do not copy your mailbox, calendar or Drive. Content the agent reads to answer a request becomes part of the chat in which you asked — and of a file or table, if you ask it to save something there — and is visible to the people in that chat. It is kept until that chat, file or table is deleted.
Who we share it with. The AI model provider that answers the request, as described above, and our infrastructure providers listed below, only to provide the service. We do not sell Google user data, use it for advertising, or transfer it to data brokers or information resellers. We do not use it to develop, improve or train generalised AI or machine-learning models.
Who can read it. Our staff do not read your Google data unless you ask us to (for example in a support request), it is necessary for security purposes such as investigating abuse, or the law requires it.
Removing access.Disconnecting a connector in cobrain deletes its stored tokens and revokes them at Google. You can also remove cobrain’s access at any time at myaccount.google.com/permissions. To have content deleted, delete the chats or files that hold it, or write to us.
cobrain’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft 365 data
Outlook, SharePoint and Microsoft Teams connections work the same way: you connect them on Microsoft’s consent screen, the tokens are encrypted, the agent reads your mail, calendar or documents only when a request needs them, and nothing read is used for any other purpose or to train models. You can remove access in your Microsoft account settings or by disconnecting in cobrain, which deletes the stored tokens.
Who processes data for us
- Convex — database and backend, in the European Union (Ireland).
- Vercel — website and application hosting, the agent’s runtime, the AI Gateway and web analytics.
- AI model providers — as listed under “The AI models”.
- Microsoft Azure — the database behind workspace tables, in Switzerland (Zurich).
- Stripe — payments and invoicing.
- Resend — sending and receiving email.
Some of these providers, and some AI models, process data outside Switzerland and the European Economic Area, including in the United States. Where they do, we rely on adequacy decisions or the European Commission’s standard contractual clauses.
How long we keep it
Workspace content is kept until the workspace deletes it or closes its account, after which it is deleted from our systems, apart from backups that expire on their own schedule. Billing records are kept for as long as Swiss accounting law requires. Logs are kept for a limited period for security and troubleshooting.
Security
Data is encrypted in transit and at rest, connector credentials are encrypted separately and are never shown to the AI model, and access within a workspace follows the roles and folder rules its administrators set.
Your rights
Under the Swiss Federal Act on Data Protection and, where it applies, the GDPR, you can ask for a copy of your personal data, have it corrected or deleted, restrict or object to its processing, and take it elsewhere. Write to hello@mithril.digital. You can also complain to the Swiss Federal Data Protection and Information Commissioner or to the data protection authority where you live.
Changes
If we change this policy we will update the date at the top, and tell account holders by email about a significant change.