Privacy Notice
Read the CISO Joe Privacy Notice to understand how personal information is collected, used, disclosed, retained and protected.
Last updated: September 15, 2026
Cocoon CS Inc. (“Cocoon CS,” “we,” “us,” or “our”) operates CISOJoe.com. This Privacy Notice explains how we collect, use, disclose, retain, and protect personal information when you visit CISOJoe.com or use CISO Joe’s sign-in and AI conversation features.
This notice applies specifically to CISOJoe.com. CocoonCS.com and the Cocoon CS platform have additional practices described in the Cocoon CS Privacy Policy.
Information we collect
We collect only the information needed to operate, secure, and improve CISO Joe.
Information you provide
- Account information. If you sign in by email, we receive your email address. If you use Google, Apple, Facebook, or Microsoft, we may receive the name, email address, provider identifier, and basic profile information that you authorize the provider to share. CISOJoe.com does not create or store a password for you.
- Conversation content. Text you submit, microphone audio you choose to transmit, and the resulting transcript or response are processed to provide the conversation. Do not submit passwords, personal records, regulated data, or confidential business information.
- Requests and correspondence. If you contact us, we receive the information you include so we can respond.
Information collected automatically
- Service and security data. Our systems receive ordinary request data such as IP address, browser and device information, timestamps, requested pages, and diagnostic events. Raw IP addresses are not persisted by CISO Joe’s usage-limit store. Instead, rotating hashed network identifiers are used to enforce abuse and usage limits.
- Usage identifiers. We use a signed, HTTP-only visitor cookie for up to 30 days to apply service limits. It cannot be read by site JavaScript.
- Authentication records. Short-lived sign-in transactions and email challenges expire after approximately 10 minutes. Signed-in sessions use a hashed session identifier and expire after approximately eight hours.
AI conversations and browser storage
CISO Joe uses OpenAI services to generate text and voice responses. Conversation content and audio are transmitted to OpenAI so the requested response can be produced. Text requests use OpenAI’s non-stored response mode, and Realtime tracing is disabled. OpenAI may still process or retain information according to the applicable account controls and its privacy policy.
CISOJoe.com does not store conversation text or audio in its application databases. Current conversations, recent conversations, and answers you choose to save are kept in your browser’s session storage and are cleared when that browser tab or session ends. Closing a voice session removes its server-side cleanup record after termination, although infrastructure queues and provider systems may take a short time to finish processing.
How we use information
We use information to:
- provide text, voice, authentication, and account-session features;
- deliver one-time sign-in codes and complete identity-provider sign-in;
- enforce usage limits, prevent abuse, investigate failures, and protect the service;
- maintain reliability, diagnose technical problems, and improve the service;
- respond to access, correction, deletion, privacy, and support requests; and
- comply with legal obligations and protect the rights, safety, and security of users, Cocoon CS, and others.
We do not sell personal information collected through CISOJoe.com.
Service providers and identity providers
We disclose information only as needed for the purposes above, including to:
- Amazon Web Services, which hosts CISOJoe.com services and provides authentication, email delivery, databases, queues, logging, and related infrastructure;
- OpenAI, which processes conversation inputs to generate CISO Joe responses;
- Google, Apple, Meta, and Microsoft, when you choose one of those providers to authenticate; and
- professional advisers, authorities, or a successor organization when disclosure is required by law, reasonably necessary to protect the service, or connected with a legitimate corporate transaction.
When you choose an external identity provider, that provider’s own privacy terms also apply. CISOJoe.com requests only the identity attributes needed to create and maintain your session.
Cookies and similar storage
CISOJoe.com uses essential storage only for service operation:
- a signed visitor cookie lasting up to 30 days for usage and abuse controls;
- short-lived authentication state and session cookies for secure sign-in; and
- browser session storage for conversations and saved answers during the current browser session.
Blocking essential cookies may prevent conversations or sign-in from working. CISOJoe.com does not use these essential cookies for behavioural advertising.
Retention
We retain information only for as long as reasonably necessary for the purpose for which it was collected:
- authentication challenges and transactions expire after approximately 10 minutes;
- signed-in session records expire after approximately eight hours or are deleted when you sign out;
- the visitor cookie expires after up to 30 days;
- hashed quota counters expire shortly after the applicable usage window; and
- account profile information remains in the authentication service until it is deleted or must be retained for security or legal reasons.
Operational backups, security records, and provider-held information may remain for limited additional periods under applicable retention schedules.
International processing
CISO Joe uses service providers that may process information outside your province, state, or country, including in the United States. Information processed in another jurisdiction may be subject to that jurisdiction’s laws. We use contractual, technical, and organizational safeguards appropriate to the service and the information involved.
Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, or deletion of personal information, or to withdraw consent where consent is the applicable basis for processing.
To request deletion of CISO Joe account information, email info@cocooncs.com with the subject CISO Joe data deletion request and identify the email address used to sign in. We may need to verify your identity before completing the request. We will delete or de-identify information unless retention is required for legal, fraud-prevention, security, or legitimate recordkeeping purposes.
You can clear conversation content and saved answers immediately by closing the browser tab or clearing site data in your browser. You can also stop microphone access at any time through the conversation controls or your browser settings.
Security
We use administrative, technical, and physical safeguards designed to protect personal information. These include encrypted connections, HTTP-only cookies, hashed session and network identifiers, short expiration periods, access controls, and restricted production infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
Children’s privacy
CISOJoe.com is intended for professionals and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information so we can review and remove it where appropriate.
Changes to this notice
We may update this notice when CISO Joe’s features, providers, or legal obligations change. We will publish the revised notice here and update the date above. Material changes may also be announced through the website when appropriate.
Contact us
For privacy questions, requests, or complaints about CISOJoe.com, contact:
Cocoon CS Inc.
Email: info@cocooncs.com
Website: www.cocooncs.com