Privacy Policy
Last updated July 24, 2026
Cortex is a browser extension that lets you share the page you are on to the network you choose. It is built to keep your data in your own browser. The only information that leaves your device is the content you deliberately choose to share (sent to the network you pick), an anonymous identifier used for Pro licensing, and anonymous usage counts. Cortex does not sell your data, does not use it for advertising, and does not track your browsing.
This policy explains what Cortex collects, how that information is used, where it is stored, and how it is shared. It applies to the Cortex browser extension and the cortexapp.com website, both operated by Superfuture (Super, Inc.).
Data collection
Cortex collects only the data listed in the disclosure table below: the page content you deliberately share, OAuth tokens for services you choose to connect, your Google account email/name and contacts (read only, only if you connect Gmail), the message you compose, an anonymous identifier for Pro licensing, and anonymous usage counts. Each row of the table states exactly what is collected and when.
Passwords and credentials. Cortex never asks for, collects, transmits, or stores your passwords, PINs, or security questions for any service. When you connect a service such as Google, X, or Reddit, you sign in on that service's own official page; your password is entered there and is visible only to that service. The only authentication data Cortex handles is the OAuth access token the service issues after you sign in, and that token is stored locally in your browser as described below.
Data handling and use
Every category of data is used solely to deliver the share you initiate or to operate Pro licensing and anonymous usage statistics. Cortex does not sell user data, does not use it for advertising or credit purposes, and does not track browsing. Use of Google user data adheres to the Limited Use requirements described below.
Data storage and retention
All personal data (tokens, account details, contacts) is stored locally in your browser's extension storage and never on Cortex servers. Message and page content is not stored at all; it exists only while the share is composed and delivered. Retention details for the anonymous identifiers appear in the retention section below.
Data sharing
Data is shared only with the destination service you explicitly choose for a share (for example Gmail, X, or Reddit) at the moment you invoke it. No data is shared with any other third party. The table below lists every recipient per category.
Data disclosures at a glance
Cortex collects or handles the following categories of user data. For each category, here is how it is collected, how it is used, where it is stored, and every party it is shared with:
| Category | What and when | Where stored | Shared with |
|---|---|---|---|
| Personally identifiable information | Your Google account email address and name, and your Google Contacts (read only), accessed only if you choose to connect Gmail. Used to show which account you send from and to let you pick a recipient. | Locally in your browser's extension storage. Never stored on our servers. | Google (Gmail and Google Contacts APIs), only to provide the sending feature you invoke. No one else. |
| Authentication information (passwords, credentials, security questions, PINs, OAuth tokens) | Passwords, security questions, and PINs: never collected. You sign in on each service's own official page, so your password goes only to that service and is never seen, collected, or stored by Cortex. The only authentication information Cortex handles is the OAuth access token issued by the services you choose to connect (for example Google, X, Reddit), received only after you sign in, and used solely to post the shares you create. | Locally in your browser's extension storage. Never transmitted to or stored on Cortex servers. | Only the issuing service itself, when making the API request you initiate. No one else. |
| Personal communications | The message or email you compose when sharing (for example an email sent via Gmail, or a message posted to a network). Collected at the moment you write it, used solely to deliver that share. | Not stored by Cortex. It exists in your browser only while you compose it. | Only the destination you choose (see the full list of destinations below). |
| Website content | The link, title, selected text, or image of the page you are on, read only at the moment you invoke Cortex to share it. Cortex does not log or transmit your browsing history. | Not stored by Cortex beyond your local share history in your browser. | Only the destination you choose (see below). |
All parties user data may be shared with, in full: the destination services you explicitly share to, which are Google (Gmail), X (Twitter), Facebook, Threads, Bluesky, Mastodon, LinkedIn, Reddit, Pinterest, Tumblr, Slack, Telegram, WhatsApp, Pocket, and Instapaper (each only when you choose it, via its official API, governed by its own privacy policy); Cloudflare (hosts our website and licensing backend); and Stripe (processes Pro payments made on our website). Cortex shares data with no other parties. We do not sell user data, we do not share it with advertisers or data brokers, and we do not transfer it for purposes unrelated to Cortex's single purpose of sharing the content you choose.
1. Information Cortex collects and accesses
- Content you choose to share. When you open the Cortex menu and pick a network, Cortex reads the link, title, and any image or text you selected on the current page so it can hand that content to the network you chose. Cortex only accesses page content at the moment you invoke it to share; it does not log or transmit your general browsing history.
- Google account information (only if you connect Gmail). If you choose to connect Gmail, Cortex uses Google Sign-In and, with your permission, accesses: your Google account email address (to show which account you are sending from), your Google Contacts, read only (so you can pick a recipient), and permission to send email through Gmail on your behalf (to deliver a share as an email that you compose). Cortex requests no other Google data. If you never connect Gmail, none of this is accessed.
- Authentication information. Cortex does not collect passwords, security questions, or PINs for any service. Sign-in always happens on the service's own page. After you sign in, the service issues an OAuth access token; that token is the only credential Cortex holds, it is stored locally in your browser's extension storage, and it is sent only back to the issuing service to perform the shares you request. Disconnecting a service or uninstalling Cortex deletes its token.
- Settings and connection state. Your enabled networks, preferences, and which services you have connected, saved locally in your browser.
- Licensing information. A randomly generated install identifier and, if you upgrade to Pro, your Pro license status. If you paste a license key to move Pro to another browser, that key is included. This contains no name or email.
- Anonymous usage events. Cortex sends a small number of anonymous events (that the extension was installed or opened) tied only to a random identifier, to understand aggregate usage and keep the extension reliable. These events contain no personal information and no page or share content.
2. How Cortex uses information
- To deliver the share you initiate to the network you selected.
- If you connect Gmail: to show which account you are sending from, to let you choose a contact as a recipient, and to send the email you compose. Your Google data is used only to provide these share features that you asked for.
- To remember your settings and connected services between sessions.
- To verify whether your install is licensed for Pro.
- To measure anonymous, aggregate usage and reliability.
Cortex does not use your information for advertising, does not build a profile of you, and does not sell your information.
3. Google user data and Limited Use
Cortex's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- We only use Google user data (your email address, Contacts, and Gmail sending permission) to provide and improve the user-facing sharing features you request inside Cortex.
- We do not transfer this data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice.
- We do not use Google user data for advertising, and we do not sell it.
- We do not allow humans to read your Google data unless we have your explicit consent for a specific issue, it is necessary for security or to comply with the law, or the data is aggregated and anonymized.
- Your Contacts and account email are used within your browser to compose and send a share, and are not stored on our servers.
4. How and where information is stored
- On your device. Your settings, connected services, Google sign-in token, loaded contacts, and share history are stored locally in your browser's extension storage. This data stays on your device and is removed when you disconnect a service or uninstall Cortex.
- On our licensing backend. Your anonymous install identifier and Pro license status are stored on Cortex's backend at cortexapp.com so your purchase can unlock Pro. This is hosted on Cloudflare.
- On our analytics backend. Anonymous usage events tied to a random identifier are stored on our internal metrics service (superfuture-metrics.pages.dev), used only in aggregate.
We retain licensing and anonymous analytics data only for as long as needed to operate Pro and understand usage, and you can request deletion (see below).
5. How information is shared
- With the networks you choose. When you share, your selected content is sent to that network through its official interface and is then governed by that network's own privacy policy. We encourage you to review the policies of the networks you use.
- With Google. If you use the Gmail feature, the email you compose is sent through Google's Gmail service at your direction.
- With service providers. We use Cloudflare to host our website and backends, and Stripe to process Pro payments made on our website. These providers process data only to provide their service to us.
- We do not sell your personal data, share it with advertising networks or data brokers, or use it to track you across other sites.
- We may disclose information if required by law or to protect the rights, safety, and security of our users and service.
6. Data retention and deletion
Because most data is stored locally, you can clear it at any time by disconnecting a network in settings or by removing the extension, which deletes its local storage. You can revoke Cortex's access to your Google account at any time at myaccount.google.com/permissions. To request deletion of the anonymous install and licensing data associated with your install, contact us through the contact page and we will delete it within 30 days.
7. Your choices and controls
You decide which networks to enable and whether to connect Gmail. You can disconnect any service, revoke Google access, disable or uninstall the extension, and request deletion of server-side licensing and analytics data at any time.
8. Children
Cortex is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we will delete it.
9. Security
We use industry-standard measures to protect information in transit and at rest, and we keep the data Cortex handles to the minimum needed. No method of transmission or storage is completely secure, but we work to safeguard your information.
10. Changes
If this policy changes, we will update the date above. Material changes will be reflected on this page.
11. Contact
Questions about privacy, or a data deletion request? Reach us on the contact page.