Privacy Policy
Last updated: 11 August 2026
CogniScope helps game studios and publishers understand what their players are saying. Our platform takes player feedback — store reviews, forum posts, Discord messages, support tickets, survey responses — and turns it into structured insight.
This policy explains what personal data we handle, why, and what control you have over it. If anything here is unclear, write to us at info@cogniscope.co and we’ll explain it properly.
1. Who we are
CogniScope operates through three companies: one in Türkiye, one in the United Kingdom, and one in Delaware, United States. Which one is responsible for your data depends on where you are and which contract your organisation signed with us. In practice, you can contact any of us at the same address:
Our registered office is:
CogniScope 14 East Bay Lane, Queen Elizabeth Olympic Park The Press Centre, Here East Plexal, London, England, E20 3BS
2. The two kinds of data we handle
This distinction matters, because it decides who you should talk to about your data.
Data about people who use CogniScope. If you work at a studio that uses our platform, visit our website, or talk to our sales or support team, we decide how your data is used. We are the controller, and this policy governs that data.
Data inside player feedback. When a studio connects a feedback source, we analyse it on their instructions. They decide what gets sent, why, and how long it’s kept. They are the controller; we are the processor. Our contract with them, not this policy, governs that data.
So: if you’re a player who wants your feedback removed from a studio’s analysis, the studio is the right place to start. Section 9 explains what to do if that isn’t possible.
3. What we collect
From people who use our platform
- Account details — name, work email, job title, employer, role and permissions in your workspace, and any preferences you set.
- Login information — passwords, single sign-on identifiers if your company uses SSO, multi-factor settings, and session records.
- Billing information — billing contact, company address, tax number, subscription and invoice history. Card payments go through our payment provider; we never see or store full card numbers.
- Support conversations — emails, chat transcripts, tickets, and anything you attach to them.
- Usage data — which features and dashboards you use, queries you run, reports you export, and when.
- Technical data — IP address, browser, operating system, device type, and error logs.
From website visitors
Pages viewed, how you arrived, and cookie data as described in Section 6. If you fill in a demo request or newsletter form, we keep what you submitted and your marketing preferences.
Player feedback sent by our customers
When a studio connects a source, we may receive:
- The text of a review, post, comment, or ticket, written by a player
- Usernames, handles, avatars, and profile links as published on the source platform
- Context: timestamp, platform, language, region, rating, game title, build version
- Pseudonymous player IDs, where a studio attaches them
- Attachments such as screenshots or crash logs, where the integration includes them
Our contracts require studios not to send us special category data (health, religion, political views, sexual orientation, and similar), government identifiers, financial account details, or precise location. We know free-text feedback is unpredictable and this can slip through, so we also run automated redaction — see Section 5.
4. Why we use it
| What we do | Why we’re allowed to |
|---|---|
| Create and run your account | It’s necessary to provide the service you signed up for |
| Bill you and keep tax records | Contract, and legal obligation for accounting records |
| Answer support requests | Contract, and our legitimate interest in running a working service |
| Keep the platform secure and prevent abuse | Our legitimate interest in protecting the service and our customers |
| Fix bugs and improve the product | Our legitimate interest in maintaining a service that works |
| Analytics on how the product is used | Your consent where cookies require it |
| Send marketing to business contacts | Your consent, or our legitimate interest where you’re already a customer |
| Defend or bring legal claims | Our legitimate interest, and legal obligation |
Where we rely on legitimate interests, we’ve weighed our interest against your rights and concluded the processing is proportionate. You can ask us to explain that reasoning, and you can object — see Section 9.
We do not sell personal data. We do not share it for advertising. We do not build profiles of individual players.
5. How we use AI
We’re an AI product, so this deserves a clear answer rather than a vague one.
What our models do. They detect language, translate, sort feedback into topics, score sentiment and urgency, group similar feedback together, extract mentions of features and characters, summarise clusters, and flag spam and review-bombing.
Who runs them. Some models we host ourselves; others run through third-party APIs. We keep the current list of these providers on our subprocessors page, and each is under contract with us covering confidentiality and data handling.
Training. We do not use customer data or player feedback to train foundation models. Our agreements with model providers prohibit them from doing so with data we send them. We only fine-tune on a customer’s data if that customer explicitly asks us to, and any resulting model stays inside their own account.
Redaction. Before feedback reaches a model, we automatically detect and mask common identifiers — email addresses, phone numbers, card-number patterns. This is pattern matching, not magic, and it won’t catch everything across every language players write in. Studios can add their own redaction rules or strip author identifiers entirely at ingestion, and we recommend doing so if they don’t need author-level attribution.
Human review. Our staff can access customer data to investigate a support ticket, fix a bug, or respond to a security incident. That access is limited to staff who need it for those purposes and is covered by confidentiality obligations.
No automated decisions about you. Our outputs are analytical — they describe what players are saying so a person can act on it. We don’t make decisions with legal or similarly significant effects about anyone. If a studio uses our analysis to make decisions about individual players, that’s their responsibility under their own policies.
Accuracy. Model outputs are probabilistic and sometimes wrong, especially with sarcasm, gaming slang, and languages with less training data. Every insight in our product links back to the source text so a human can check it.
6. Cookies
We use four kinds:
- Essential — logging you in, keeping your session secure, remembering your cookie choices. These can’t be turned off without breaking the product.
- Functional — language, theme, saved dashboard layouts.
- Analytics — understanding which features get used and where the product is slow.
- Marketing — measuring whether our campaigns work.
In the UK, EEA, and Türkiye we ask for consent before setting anything beyond the essential ones, with accept and reject given equal weight. You can change your mind any time through the Cookie Settings link in our footer, or block cookies in your browser.
We honour the Global Privacy Control signal as an opt-out. We don’t respond to Do Not Track headers, because there’s no agreed standard for what they mean.
7. Who we share it with
- Our own companies — between our Turkish, UK, and US entities, to run the platform and support you.
- Service providers — cloud hosting, AI model providers, error monitoring, support tooling, analytics, email delivery, payments, and CRM. Each is under contract to process data only on our instructions and to keep it secure. The current list is on our subprocessors page.
- Your employer — if you use CogniScope through a company workspace, your administrators can see your account and your activity in it.
- Advisers — lawyers, auditors, and accountants, all bound by confidentiality.
- In a sale or merger — subject to confidentiality protections. If your data would become subject to a materially different policy, we’ll tell you.
- Authorities — where legally required. We check every request for validity, insist on formal legal process rather than informal asks, and tell the affected customer before disclosing their data unless the law forbids it. Where the data belongs to a customer, we redirect the request to them wherever we’re allowed to.
8. Where your data goes, and how long we keep it
International transfers. Our teams and infrastructure span Türkiye, the UK, the EEA, and the US, so data moves between them. For transfers out of the EEA we use the European Commission’s Standard Contractual Clauses; out of the UK, the UK Addendum or International Data Transfer Agreement; out of Türkiye, the standard contract mechanism under Article 9 of the KVKK. Enterprise customers can ask for their data to be stored in a specific region.
How long we keep things.
| Data | Kept for |
|---|---|
| Account details | While your account is open, plus 90 days |
| Login and session logs | 12 months |
| Security and audit logs | 24 months |
| Support conversations | 3 years after the ticket closes |
| Billing and tax records | 10 years in Türkiye, 7 in the UK and US, as tax law requires |
| Marketing contacts | 24 months of inactivity, or until you opt out |
| Website analytics | 14 months |
| Backups | 35 days, rolling |
Player feedback is kept for as long as the studio sets, defaulting to 24 months from ingestion. When a customer’s contract ends, they have 30 days to export their data, after which we delete it from live systems within 60 days. Backup copies age out on the schedule above.
Data that has been properly anonymised is no longer personal data and may be kept for statistics and benchmarking.
9. Your rights
Depending on where you live, you can ask us to:
- Show you what data we hold about you and give you a copy
- Correct anything inaccurate or incomplete
- Delete your data, where there’s no remaining reason for us to hold it
- Restrict what we do with it, in certain situations
- Send it elsewhere, in a machine-readable format
- Stop processing based on legitimate interests, and stop marketing entirely — no reason needed
- Withdraw consent, where consent is what we relied on
- Complain to a regulator, without going through us first
In Türkiye, Article 11 of the KVKK also gives you the right to learn whether your data has been processed, what for, who it was shared with in Türkiye and abroad, to have corrections passed on to those recipients, to object to results produced solely by automated analysis, and to claim compensation for unlawful processing.
In the US, residents of states with comprehensive privacy laws have equivalent rights to know, correct, delete, and opt out. We don’t sell personal information or share it for cross-context behavioural advertising, and we won’t treat you differently for exercising your rights.
How to ask. Email info@cogniscope.co, or use the privacy request form in your account settings. Tell us what you want and enough detail for us to find your records. We’ll verify who you are — usually just by confirming you control the account email — and we’ll use whatever you send for verification only, then delete it.
We reply within 30 days, and can extend that for genuinely complex requests. There’s no charge unless a request is repetitive or excessive.
If you’re a player. Contact the studio behind the game first — they decide what happens to your feedback. If you tell us which game or platform it came from, we’ll pass your request to them and help them answer it. If you can’t work out who the studio is, or they don’t respond, write to us anyway and we’ll do what we can.
If you want to complain, you can go to the Kişisel Verileri Koruma Kurumu in Türkiye, the Information Commissioner’s Office in the UK, your national data protection authority in the EEA, or your state Attorney General in the US. We’d rather you came to us first, but you don’t have to.
10. Children
CogniScope is a business tool. We don’t knowingly collect data from children through our website or platform accounts.
Player communities are different — feedback from games with young audiences can come from minors. So our contracts require studios to have a lawful basis for everything they send us, to apply age gating before sending it, and to comply with COPPA, GDPR age-of-consent rules, the KVKK, and the UK Children’s Code. We give them tools to exclude sources, strip author identifiers, and set shorter retention for datasets that might include children.
We don’t profile individual players, track them across services, or use their feedback for advertising.
If you think a child’s data has reached us, tell us at info@cogniscope.co. We’ll investigate, tell the relevant studio, and delete it unless the law requires us to keep it.
11. Security
We take measures appropriate to the risk to protect personal data against loss, misuse, and unauthorised access. If you need details of our current security practices — for a vendor assessment, for example — write to us at info@cogniscope.co and we’ll share what’s relevant.
If a breach happens, we’ll notify the relevant regulator within 72 hours where the law requires it, tell affected customers without delay so they can meet their own obligations, and contact individuals directly where there’s a high risk to them.
Your side of this: use a strong unique password, turn on multi-factor authentication, keep API keys secret and rotate them, and check your workspace’s user list from time to time. Anything suspicious, tell us at info@cogniscope.co.
12. Other things worth knowing
Turkish version. A Turkish translation of this policy is available on our website and serves as our aydınlatma metni under Article 10 of the KVKK. If the two versions disagree, the Turkish version applies for people in Türkiye. Commercial emails to Turkish recipients are registered through İYS, and you can manage consent there or through the unsubscribe link.
Links to other sites. We link to documentation, community platforms, and the sources our customers connect. We don’t control those, and this policy doesn’t cover them.
Changes. If we update this policy, we’ll change the date at the top and keep older versions available. For material changes — a new purpose, a new category of recipient, a change to your rights — we’ll email account holders at least 30 days beforehand and show a notice in the app. Where a change needs your consent, we’ll ask first.
13. Contact
For questions, requests, complaints, and security issues:
CogniScope 14 East Bay Lane, Queen Elizabeth Olympic Park The Press Centre, Here East Plexal, London, England, E20 3BS
We aim to acknowledge every privacy enquiry within five working days.
© 2026 CogniScope
← Back to site