Privacy Policy
What we collect when you use this website, why we hold it, and how to have it removed
Last updated 23 August 2026.
This policy covers the Cofibrant website at cofibrant.ai. It does not cover the Cofibrant compiler toolchain, which runs inside your own build pipeline and sends us nothing. That is described on our security page.
Who we are
Cofibrant, Inc. is the controller of the personal data described here. We are a Delaware corporation. You can reach us at contact@cofibrant.ai or by post at 131 Continental Dr, Suite 305, Newark, DE 19713, United States.
What we collect
We collect only what you type into a form on this site. There is no account to create and no profile to build.
- Early access form
- Your name and email address, which are required, and your company, industry and team size, which are optional.
- Vulnerability report form
- Your name and email address, and whatever you choose to include in the report itself.
- Email you send us
- Your address and the contents of your message, held for as long as we need to deal with it.
- Server logs
- Vercel, which hosts this site, records standard request logs, which include IP addresses, for security and reliability. We do not use these to identify or profile visitors.
What we do not collect
This site sets no cookies. It runs no analytics, no advertising pixels and no third-party tracking of any kind. Nothing you do here is measured or shared with anyone for marketing purposes.
The one thing we store in your browser is your choice of light or dark theme, kept in local storage on your own device. It never reaches us and it identifies nobody.
We also never receive your source code. The compiler runs on your machines, and no source, binaries, build artefacts or telemetry are transmitted to us.
Why we hold it, and on what basis
We use your details for one purpose: to reply to you and to keep you informed about early access to the product you asked about.
Our lawful basis is legitimate interest, specifically responding to an enquiry you chose to send us about a business product. Where we send you a product update that goes beyond answering your enquiry, our basis is your consent, and you can withdraw it at any time by replying to any message or writing to contact@cofibrant.ai. For vulnerability reports, our basis is our legitimate interest in investigating and fixing security issues in our own products.
We do not sell your data, rent it, or share it with anyone for their own marketing.
Who else sees it
We use a small number of service providers who process data on our instructions and for no purpose of their own.
- Formspree
- Receives and forwards submissions from both forms on this site. Based in the United States.
- Vercel
- Hosts and serves the site, and keeps the request logs described above. Based in the United States.
- Google Workspace
- Receives the forwarded submissions and carries and stores the correspondence that follows, under Google's data processing terms.
Beyond these, we disclose personal data only where the law requires it, or where it is necessary to establish or defend a legal claim.
Transfers outside the UK and EEA
We are a United States company and our service providers operate in the United States, so anything you send us is transferred and stored there. If you are writing to us from the UK or the EEA, please send only what you are comfortable having processed in the United States. A name, a work email address and a company name are all we ask for.
Where a provider offers a data processing agreement and an approved transfer safeguard, such as the standard contractual clauses or certification under the EU-US Data Privacy Framework, we put it in place. Write to contact@cofibrant.ai and we will tell you what is in place for any provider named above.
How long we keep it
We keep early access enquiries for 24 months from your last contact with us, after which they are deleted. Vulnerability reports are kept for as long as the issue is open and for 24 months afterwards, so that we have a record of what was fixed and when. You can ask us to delete your data sooner.
Your rights
If you are in the UK or the EEA, data protection law gives you the following rights. We do not charge for exercising them and we will respond within one month.
- Access
- Ask for a copy of the personal data we hold about you.
- Rectification
- Have anything inaccurate corrected.
- Erasure
- Ask us to delete your data. For a waitlist entry this is immediate and unconditional.
- Objection
- Object to processing we carry out on the basis of legitimate interest.
- Restriction
- Ask us to hold your data without using it while a question about it is resolved.
- Portability
- Receive the data you gave us in a machine-readable form.
- Complaint
- Complain to your data protection regulator. In the UK that is the Information Commissioner's Office at ico.org.uk.
To exercise any of these, write to contact@cofibrant.ai.
Children
This site is aimed at people working in software and security, and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
Security
We hold very little, which is the main protection. What we do hold is encrypted in transit, restricted to the people who need it, and kept in accounts protected by multi-factor authentication. No transmission or storage is ever completely secure, and we make no claim otherwise.
Changes to this policy
If we change how we handle personal data, we will update this page and move the date at the top. Where a change is significant and we hold your address, we will tell you directly.
Contact
Questions about this policy, or about anything we hold, go to contact@cofibrant.ai.