Cook

Privacy Policy

Last updated: August 30, 2026

Cook.ai is an AI-run marketing workspace operated by ClientAcquisition.io(“Cook”, “we”). This policy explains what personal data we handle, why, and the choices you have. Questions and requests: systems@clientacquisition.io.

The two roles we play

For your account and your use of Cook, we decide how data is handled — we are the data controller. For the business records your workspace holds (your clients, your leads, form submissions on your funnel pages), you are the controller and Cook processes that data on your instructions as a processor.

What we collect

  • Account data: name, email address, password (stored hashed), and sign-in identifiers from Slack or Discord if you use social sign-in.
  • Workspace content: chats with your AI departments, files you upload, documents, and generated media.
  • CRM records you or your integrations add: client and lead names, email addresses, phone numbers, notes, and pipeline status.
  • Funnel form submissions from your pages: the fields a visitor types, plus a consent record (what they agreed to, when, from which page).
  • Billing data: subscription and credit usage. Card details go directly to Stripe and never touch our servers.
  • Connected integration credentials, stored encrypted (AES-GCM).
  • Usage data: page analytics without cookies, and server logs for security and debugging.

Why we use it

  • To run the service you signed up for — your account, workspace, and AI agents (performance of a contract).
  • To bill you (performance of a contract, legal obligations).
  • To keep the service secure and debug problems (legitimate interest).
  • To measure product usage with cookieless analytics (legitimate interest).
  • To send marketing on behalf of our customers to their contacts — done on the customer's instructions; the customer is responsible for having a lawful basis.

AI processing

Cook does its work by sending workspace content to AI model providers (Anthropic, OpenAI, Google) and media generators. These providers process the content to produce the requested output. We do not use your content to train models of our own.

Who we share data with

We use the following service providers (subprocessors) to run Cook:

ProviderWhat it does
ConvexDatabase and application backend
VercelWeb and funnel-page hosting, cookieless page analytics
RailwayAI service hosting
CloudflareFile storage (R2) and course video streaming (Stream)
StripePayment processing
AutumnBilling and credit metering
ResendTransactional email delivery
OneSignalPush notifications
AnthropicAI text generation
OpenAIAI text generation
GoogleAI (Gemini) and Calendar sync
CohereSearch embeddings for course content
ElevenLabsAudio transcription
LiveKitReal-time voice sessions
MetaAd delivery and conversion measurement for customer campaigns
fal / KieAI image and video generation
Blaxel / E2BSandboxed compute for agent jobs
Freestyle / GitHubFunnel code repositories and previews
GoHighLevel / CloseCRM sync, when a customer connects one
FathomMeeting recording sync, when a customer connects it
Slack / Discord / Telegram / WhopMessaging bridges, when connected

We do not sell personal data. Beyond these providers, we disclose data only when the law requires it or to protect the service from abuse.

International transfers

Our providers process data primarily in the United States. Where data about people in the EU, EEA, or UK is transferred, we rely on the providers’ data processing agreements and standard contractual clauses.

How long we keep data

  • Account and workspace data: for as long as your account exists.
  • Backups: rolling snapshots kept for 14 days.
  • Billing records: as long as tax and accounting law requires.
  • Deleted data: removed from the live database at deletion time and from backups as they expire.

Your rights

You can access, correct, export, or delete your data. In the app: Settings lets you export your workspace’s data and delete your account or organization. By email: send requests to systems@clientacquisition.io and we will respond within 30 days. If you are in the EU, EEA, or UK, you also have the rights to restrict or object to processing and to complain to your supervisory authority. In Canada, you may complain to the Office of the Privacy Commissioner of Canada or, in Quebec, to the Commission d’accès à l’information du Québec. If your data is in a customer’s workspace (for example, you are their client or a lead), contact that business — they control it — and we will help them honor your request.

Cookies

The Cook app itself sets only cookies the service needs to work: your sign-in session, your theme, and your active workspace. Our page analytics does not use cookies. Funnel pages our customers publish are the customers’ own websites and may use advertising cookies with the visitor’s consent where consent is required — each funnel carries its own privacy policy.

Children

Cook is a business tool and is not directed at children under 16. We do not knowingly collect their data.

Contact us

Questions, requests, and data-deletion requests (subject line “Data Deletion Request”) go to systems@clientacquisition.io. Postal address: ClientAcquisition.io, 6740 Rue Briand, Montreal QC, H4E 3L5, Canada.

Changes

When this policy changes, we update this page and the date at the top. Material changes are announced in the app.

See also our Terms of Service.