Cortana

Privacy Policy

Effective Date: January 28, 2026
Last Updated: October 8, 2026

Visionary Creations Inc. ("Cortana," "we," "us," or "our") operates the Cortana platform at usecortana.ai and app.usecortana.ai. This policy explains what personal information we collect, why, who we share it with, how long we keep it, and the rights you have over it.

1. Who We Are and Our Two Roles

Cortana is a platform businesses use to track where their leads and sales come from, talk with their contacts through AI agents, and run their sales and support. We hold personal information in two different roles:

  • About our customers (the businesses and agencies that use Cortana, and their team members), we decide why and how the information is used. For this information we are the organization responsible for it (a "controller" or "business").
  • About our customers' website visitors, leads, contacts and buyers, we process information on our customer's behalf and on their instructions. For this information our customer is responsible, and we act as their service provider (a "processor"). Our Data Processing Agreement sets out those terms. If you are a visitor to, or a contact of, a business that uses Cortana, that business's own privacy policy also applies to you, and you may contact them directly.

Written to: PIPEDA Sch. 1, Principle 4.1 (Accountability) and 4.1.3 (third-party processing); Quebec Act respecting the protection of personal information in the private sector ("Quebec Private Sector Act") ss. 3.1, 18.3; GDPR Arts. 4(7)–(8), 13, 28; CCPA Cal. Civ. Code § 1798.140(ag).

2. Information We Collect About Our Customers

  • Account information: name, email address, phone number, company name and login credentials of account owners and team members.
  • Billing information: your plan, invoices and payment status. Payments are processed by Stripe; we do not store full card numbers. If your default payment method fails, we may charge another payment method saved on your account as described in our Refund Policy.
  • Checkout consent records: when you buy through our checkout, the terms you accepted, the time, your IP address and browser, kept as proof of the agreement.
  • Connected services: when you connect a service (for example GoHighLevel, Meta, Google, HubSpot, Stripe or Fathom), the access credentials and the data that service shares with us on your instruction.
  • Support and communications: the messages you send us in the app, by email or in Slack, screenshots and screen recordings you send (including their audio), and our calls with you (see Section 7).
  • Product usage: how you use the app (pages, features, device and browser) and session replays, collected with our product analytics provider.
  • Visitors to our website: on usecortana.ai, our own Cortana pixel collects the information described in Section 3.1; the Meta Pixel and the Google Ads tag tell Meta and Google about your visit so we can measure and target our advertising; from our servers we also send Meta the pages you view and the conversions our own pixel records here (such as booking a call), and Google Ads those conversions; our hosting provider's analytics measure visits and page performance; if you book a call with us or apply on one of our hiring pages, the form runs on our CRM provider, which receives what you enter (such as your name, email and phone); and one landing page embeds a presentation from a third-party provider, which receives your IP address and browser details and may set its own cookies.

Written to: PIPEDA Principles 4.2 (Identifying Purposes), 4.4 (Limiting Collection), 4.8 (Openness); Quebec Private Sector Act s. 8; CCPA § 1798.100(a), § 1798.110; GDPR Art. 13(1).

3. Information Our Customers Collect Through Cortana

We process this information for our customers, as their service provider. What is collected depends on what each customer turns on.

3.1 The Cortana tracking pixel

When a business installs the Cortana pixel on its website, the pixel collects, for each visit:

  • A visitor identifier stored in a first-party cookie on the business's domain (see Section 8), and the identifiers of advertising cookies already on the site (Meta, TikTok, LinkedIn, HubSpot, CallRail).
  • The page address (including its query string), the referring page, the page title, the time on the page, how far the page was scrolled and how many clicks it received.
  • Ad campaign parameters and ad click identifiers (for example UTM parameters, fbclid, gclid, ttclid, msclkid).
  • Your IP address and browser user agent, and from them your device type, browser, operating system and an approximate location (country, region, city), looked up through an IP geolocation provider.
  • Device signals: screen and window size, time zone, language, pixel ratio, number of processor cores and platform.
  • What you enter in a form's name, email and phone fields, including an email or phone number typed before you submit it. The pixel does not read password fields, hidden fields, payment card fields, address fields or company fields. A page address that carries your name, email or phone is recorded the same way.
  • On Shopify stores, checkout details: email, phone, name, shipping and billing address, and the order.

We link visits from the same browser, and visits from different sessions when the same identity, ad click or device and network signals match, so the business can see which ad or channel led to a lead or a sale. The pixel does not use canvas, audio or font fingerprinting and does not record sessions. Bot traffic is flagged rather than discarded.

3.2 Contacts, conversations and sales data

  • Contacts: name, email, phone, address fields, company and custom fields, from forms, bookings, checkouts, the business's CRM or imports.
  • Conversations: SMS, WhatsApp, iMessage, Facebook and Instagram messages, email and voice calls between the business (or its AI agents) and its contacts.
  • Sales and payments: bookings, deals and payments from the services the business connects (for example Stripe, Shopify, Whop or Calendly).
  • Calls and meetings: see Section 7.

A business that installs the pixel or uses our agents is responsible for telling its visitors and contacts about it and for obtaining any consent the law requires.

Written to: PIPEDA Principles 4.3 (Consent), 4.4, 4.8; Quebec Private Sector Act ss. 8, 8.1 (technology that can identify, locate or profile a person); CCPA § 1798.100(a)–(b); GDPR Arts. 13–14, 28(3).

4. How We Use Information

  • To provide Cortana: attribute leads and sales to their source, run our customers' AI agents, sync their CRMs and send their conversions to the ad platforms they connect.
  • To bill our customers, recover failed payments and keep proof of the terms they accepted.
  • To support our customers, investigate problems they report and improve our own help content.
  • To keep the service secure, prevent fraud and abuse, and keep records the law requires.
  • To tell our customers about changes to the service.

We use information our customers collect through Cortana only to provide the service to that customer, on their instructions, and as the law requires. We do not use it for our own advertising.

Written to: PIPEDA Principles 4.2, 4.5 (Limiting Use, Disclosure and Retention); Quebec Private Sector Act ss. 4, 12; CCPA § 1798.100(c), § 1798.140(e); GDPR Arts. 5(1)(b), 6(1).

5. How Information Is Shared

5.1 With the services our customers connect

On a customer's instruction, we send information to the platforms they connect, using their own accounts:

  • Ad platforms (Meta, Google Ads, TikTok, LinkedIn, Whop): when a conversion happens, the event and its value with identifiers the platform uses to match it — email, phone and name (hashed, except where a platform requires them in plain text, such as LinkedIn names and Whop), and for some platforms the contact's city, state and country, company and job title, the IP address, user agent, ad click identifiers and the contact's ID in Cortana. Page addresses are stripped of contact details first. A business may also choose to send Meta the page views on its website, with the visitor's IP address, user agent, Meta cookie identifiers and, when known, hashed email and phone.
  • CRMs and calendars (GoHighLevel, HubSpot, Close, Salesforce, iClosed, Google Calendar, Outlook, Zoom): contacts, custom fields, tags, appointments and conversation history.
  • Automation tools and the Cortana API (Zapier, Make, n8n or the customer's own systems): contact details, conversions and their attribution, including visit details such as IP address and user agent.
  • Messaging channels (SMS, iMessage, Meta and email): the messages the business's agents send and the recipient's number or address.

5.2 With our service providers (subprocessors)

We use service providers for hosting, databases, file storage, email, telephony, AI models, analytics and support. They process information only to provide their service to us, under their own data processing terms. We provide the list to a customer that asks: [email protected].

5.3 For legal reasons and business transfers

We may disclose information when the law requires it, to protect our rights or the safety of others, and to a buyer or successor if Cortana is sold or merged, under the same protections as this policy.

5.4 Google API Services User Data Policy (Limited Use)

Cortana's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Limited Use Commitment

The use of raw or derived user data received from Google Workspace APIs (including Google Calendar) will adhere to the Google User Data Policy, including the Limited Use requirements. We do not transfer or sell Google user data to third parties for advertising or any other unrelated purpose. We do not use, transfer, or sell Google Workspace user data to develop, improve, or train any generalized or foundational artificial intelligence or machine learning models. Google Calendar data is used solely to provide user-facing features you request, such as checking availability and creating, updating, or cancelling appointment events on your connected calendar.

We Do Not Sell Personal Information

We do not sell personal information. Our own website uses the Meta Pixel and the Google Ads tag, and our servers send Meta the visits, and Meta and Google Ads the conversions, our own pixel records there, to measure and target our advertising, which California and several other states treat as "sharing" for cross-context behavioral (targeted) advertising. To opt out, email us with the subject "Do Not Sell or Share" (Section 11).

When our customers send their conversion data to their own ad accounts through Cortana, we do so on their instructions, as their service provider.

Written to: PIPEDA Principles 4.1.3, 4.5; Quebec Private Sector Act ss. 17, 18.3; CCPA §§ 1798.115, 1798.120, 1798.140(ad)–(ah); GDPR Arts. 13(1)(e), 28(2).

6. Artificial Intelligence

  • Our customers' AI agents answer and send messages and calls for them. To do that, the conversation and the contact's details are sent to AI model providers (including a voice AI provider for calls), and the agent keeps a memory of past conversations with the contact. A customer may connect its own AI provider account instead of ours.
  • Summaries and analysis: we use AI models to summarize contacts and calls, to analyze ad creatives, and to read the support requests, screenshots and screen recordings our customers send us.
  • No training of generalized models: we do not use our customers' data, or the data they collect through Cortana, to train generalized or foundation AI models. We use support conversations to improve our own help content.

Written to: PIPEDA Principles 4.2, 4.8; Quebec Private Sector Act ss. 8, 12.1 (decisions based exclusively on automated processing); CCPA § 1798.100; GDPR Arts. 13(1)(c), 13(2)(f), 22.

7. Call and Meeting Recordings

  • Our calls with customers: our team records and transcribes calls with our customers; we keep the summary and transcript to support the customer and to check the conditions of our Refund Policy.
  • Our customers' meetings: when a customer connects their own Fathom account, we store the summaries and transcripts of their meetings (not the audio) and match them to the contact.
  • AI voice calls: calls made or answered by a customer's AI voice agent are recorded and transcribed, and stored with the contact. The telephony provider that carries a call may also record it.

A business that records calls through Cortana is responsible for giving the notice and obtaining the consent its laws require (some jurisdictions require every participant's consent).

Written to: PIPEDA Principles 4.2, 4.3; Quebec Private Sector Act s. 8; Cal. Penal Code § 632; GDPR Arts. 6, 13.

8. Cookies and Similar Technologies

  • On our customers' websites: the Cortana pixel sets a first-party cookie, ak_tid, that identifies the browser for 365 days, and keeps a copy in the browser's local and session storage in case cookies are blocked. It also stores the visit's campaign parameters for the rest of the session. It reads the advertising cookies already on the site to match conversions.
  • On usecortana.ai: our own Cortana pixel (Section 3.1), the Meta Pixel and the Google Ads tag (advertising), our hosting provider's analytics, our CRM provider's booking and application forms when you use them, and a presentation embedded on one landing page (its provider may set its own cookies).
  • In the app: cookies that keep you signed in and secure, and product analytics.

You can delete or block cookies in your browser settings. Blocking them on a site that uses the Cortana pixel limits how visits are linked, but visits may still be recorded from the information your browser sends with each request.

Written to: PIPEDA Principle 4.3; Quebec Private Sector Act s. 8.1; CCPA § 1798.100; GDPR Art. 13; ePrivacy Directive 2002/58/EC Art. 5(3).

9. How Long We Keep Information

  • While an account is active, we keep its information — contacts, conversations, call recordings and transcripts, tracking data, payments and support records — for as long as the customer uses Cortana, unless the customer or the person deletes it sooner.
  • Tracking data (visits, page views, conversions and form captures) is deleted 60 days after a business's Ad Tracking subscription ends, when it has no other active plan.
  • When a business is deleted, it is removed from the app and can be restored for 45 days; its information is permanently deleted when the customer asks us to (Section 11).
  • Technical logs: pixel diagnostics are kept for 120 days, webhook delivery logs for 30 days, and our AI provider's copy of a support session for 30 days after it ends.
  • Records the law requires (such as invoices and proof of accepted terms) are kept as long as that law requires.

Written to: PIPEDA Principle 4.5 (Limiting Retention); Quebec Private Sector Act ss. 23, 28; CCPA § 1798.100(a)(3); GDPR Arts. 5(1)(e), 13(2)(a).

10. Security

  • Information is encrypted in transit (TLS).
  • Access to the credentials of the services our customers connect is restricted, and we are moving them to encrypted storage.
  • Access to a business's data is limited to that business's authorized users and to Cortana staff who need it to provide support.
  • We log access to sensitive operations and review our security practices against SOC 2 and ISO 27001 controls.

No system is perfectly secure. If a confidentiality incident creates a risk of serious harm, we will notify the people affected and the authorities as the law requires, and we will inform our customers without undue delay about incidents affecting the data we process for them.

Written to: PIPEDA Principle 4.7 (Safeguards), s. 10.1 (breach reporting); Quebec Private Sector Act ss. 3.5–3.8, 10; CCPA § 1798.100(e), § 1798.150; GDPR Arts. 32–34.

11. Your Rights and How to Use Them

Depending on where you live, you may have the right to:

  • Know what personal information we hold about you and get a copy, including in a structured, commonly used format.
  • Correct information that is wrong or incomplete.
  • Have your information deleted.
  • Withdraw your consent, object to or restrict a use, and opt out of the sale or sharing of your information or its use for targeted advertising.
  • Be told when a decision about you is based exclusively on automated processing, and ask about it.
  • Appeal our answer, and complain to a privacy authority.
  • Use these rights without being treated differently.

How: email our Privacy Officer at [email protected] with the subject "Privacy Request" (or "Do Not Sell or Share" to opt out of the sharing described in Section 5). We will verify your identity before acting, except for an opt-out, which needs no verification. If you are a visitor or contact of one of our customers, we will pass your request to that business, which is responsible for answering it, and help them do so.

When: we answer within 30 days (Canada and Quebec), within one month (EEA, United Kingdom and Switzerland) and within 45 days (United States), and tell you if we need the extension the law allows. If we refuse a request, we will tell you why and how to appeal.

Written to: PIPEDA Principles 4.9 (Individual Access), 4.10 (Challenging Compliance), s. 8(3); Quebec Private Sector Act ss. 27, 28, 28.1, 30, 32; CCPA §§ 1798.105, 1798.106, 1798.110, 1798.120, 1798.125, 1798.130(a)(2); Va. Code § 59.1-577; Colo. Rev. Stat. § 6-1-1306; GDPR Arts. 12(3), 15–22, 77.

12. Canada and Quebec

  • Person in charge of the protection of personal information: Matei Parvu, reachable at [email protected].
  • Information outside Quebec and Canada: our service providers process information in the United States (see Section 15), under their contractual commitments to protect it.
  • Technology that identifies, locates or profiles: the Cortana pixel links visits and estimates location (Section 3.1). A business that uses it must tell its visitors and offer the means to turn such functions off.
  • Complaints: you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d'accès à l'information.

Written to: PIPEDA Sch. 1; Quebec Private Sector Act ss. 3.1, 8, 8.1, 17, 27–28.1, 81; Law 25 (S.Q. 2021, c. 25).

13. United States

California and other state privacy laws. In the last 12 months we collected, about our customers and on our customers' behalf: identifiers (name, email, phone, IP address, device and cookie identifiers); commercial information (purchases and payments); internet activity (visits, pages, ad clicks); approximate geolocation; audio and electronic information (call recordings, messages); and professional information (company, job title). We collect it from the people themselves, their browsers and the services our customers connect, for the purposes in Section 4, and disclose it to the recipients in Section 5 for those business purposes. We do not sell personal information. Our website shares visitors' identifiers and browsing activity with Meta and Google for our own advertising, which California law calls "sharing"; to opt out, email us with the subject "Do Not Sell or Share". We do not knowingly collect sensitive personal information for inferring characteristics.

Residents of states with consumer privacy laws (including California, Virginia, Colorado, Connecticut, Utah, Texas and Oregon) have the rights in Section 11, including the right to appeal a refusal by replying to our answer.

Written to: CCPA/CPRA Cal. Civ. Code §§ 1798.100–1798.199.100, 11 CCR § 7011; Va. Code § 59.1-575 et seq.; Colo. Rev. Stat. § 6-1-1301 et seq.; Conn. Gen. Stat. § 42-515 et seq.; Utah Code § 13-61-101 et seq.; Tex. Bus. & Com. Code § 541.001 et seq.; Or. Rev. Stat. § 646A.570 et seq.

14. European Economic Area, United Kingdom and Switzerland

For our customers' information we rely on these legal bases: performing our contract with you; our legitimate interests in securing, supporting and improving the service; your consent, where we ask for it; and our legal obligations. For information we process on our customers' behalf, the customer determines the legal basis. You may complain to your local data protection authority.

Written to: GDPR Arts. 6(1), 13(1)(c)–(d), 77; UK GDPR; Swiss Federal Act on Data Protection (FADP) Art. 19.

15. Where Information Is Processed

Cortana is based in the United States, and our main service providers process information in the United States. Information from Canada, the EEA, the United Kingdom and Switzerland is transferred there. Where the law requires a transfer mechanism, we use the safeguards available for it, such as standard contractual clauses.

Written to: PIPEDA Principle 4.1.3; Quebec Private Sector Act s. 17; GDPR Arts. 13(1)(f), 44–46; UK GDPR Art. 46; FADP Art. 16.

16. Children

Cortana is a business service and is not directed to children. We do not knowingly collect personal information from children under 16. If you believe a child has given us information, contact us and we will delete it.

Written to: COPPA 15 U.S.C. § 6501 et seq.; CCPA § 1798.120(c); Quebec Private Sector Act s. 4.1; GDPR Art. 8.

17. Changes to This Policy

We will update this policy when our practices change, and change the "Last Updated" date above. For a material change we will notify our customers by email or in the app before it takes effect.

Written to: PIPEDA Principle 4.8; Quebec Private Sector Act s. 8; CCPA § 1798.130(a)(5); GDPR Art. 13(3).

18. Contact Us and Our Privacy Officer

Visionary Creations Inc. (Cortana)

1111B South Governors Ave, STE 39741

Dover, DE 19904

United States

Privacy Officer: Matei Parvu

Email: [email protected]

Website: https://usecortana.ai

This Privacy Policy is effective as of January 28, 2026, and was last updated on October 8, 2026.