Resources / About This Website / Website Policies / Privacy Notice

Privacy Notice

Read the CISO Joe Privacy Notice to understand how personal information is collected, used, disclosed, retained and protected.

Last updated: September 15, 2026

Cocoon CS Inc. (“Cocoon CS,” “we,” “us,” or “our”) operates CISOJoe.com. This Privacy Notice explains how we collect, use, disclose, retain, and protect personal information when you visit CISOJoe.com or use CISO Joe’s sign-in and AI conversation features.

This notice applies specifically to CISOJoe.com. CocoonCS.com and the Cocoon CS platform have additional practices described in the Cocoon CS Privacy Policy.

Information we collect

We collect only the information needed to operate, secure, and improve CISO Joe.

Information you provide

  • Account information. If you sign in by email, we receive your email address. If you use Google, Apple, Facebook, or Microsoft, we may receive the name, email address, provider identifier, and basic profile information that you authorize the provider to share. CISOJoe.com does not create or store a password for you.
  • Conversation content. Text you submit, microphone audio you choose to transmit, and the resulting transcript or response are processed to provide the conversation. Do not submit passwords, personal records, regulated data, or confidential business information.
  • Requests and correspondence. If you contact us, we receive the information you include so we can respond.

Information collected automatically

  • Service and security data. Our systems receive ordinary request data such as IP address, browser and device information, timestamps, requested pages, and diagnostic events. Raw IP addresses are not persisted by CISO Joe’s usage-limit store. Instead, rotating hashed network identifiers are used to enforce abuse and usage limits.
  • Usage identifiers. We use a signed, HTTP-only visitor cookie for up to 30 days to apply service limits. It cannot be read by site JavaScript.
  • Authentication records. Short-lived sign-in transactions and email challenges expire after approximately 10 minutes. Signed-in sessions use a hashed session identifier and expire after approximately eight hours.

AI conversations and browser storage

CISO Joe uses OpenAI services to generate text and voice responses. Conversation content and audio are transmitted to OpenAI so the requested response can be produced. Text requests use OpenAI’s non-stored response mode, and Realtime tracing is disabled. OpenAI may still process or retain information according to the applicable account controls and its privacy policy.

CISOJoe.com does not store conversation text or audio in its application databases. Current conversations, recent conversations, and answers you choose to save are kept in your browser’s session storage and are cleared when that browser tab or session ends. Closing a voice session removes its server-side cleanup record after termination, although infrastructure queues and provider systems may take a short time to finish processing.

How we use information

We use information to:

  • provide text, voice, authentication, and account-session features;
  • deliver one-time sign-in codes and complete identity-provider sign-in;
  • enforce usage limits, prevent abuse, investigate failures, and protect the service;
  • maintain reliability, diagnose technical problems, and improve the service;
  • respond to access, correction, deletion, privacy, and support requests; and
  • comply with legal obligations and protect the rights, safety, and security of users, Cocoon CS, and others.

We do not sell personal information collected through CISOJoe.com.

Service providers and identity providers

We disclose information only as needed for the purposes above, including to:

  • Amazon Web Services, which hosts CISOJoe.com services and provides authentication, email delivery, databases, queues, logging, and related infrastructure;
  • OpenAI, which processes conversation inputs to generate CISO Joe responses;
  • Google, Apple, Meta, and Microsoft, when you choose one of those providers to authenticate; and
  • professional advisers, authorities, or a successor organization when disclosure is required by law, reasonably necessary to protect the service, or connected with a legitimate corporate transaction.

When you choose an external identity provider, that provider’s own privacy terms also apply. CISOJoe.com requests only the identity attributes needed to create and maintain your session.

Cookies and similar storage

CISOJoe.com uses essential storage only for service operation:

  • a signed visitor cookie lasting up to 30 days for usage and abuse controls;
  • short-lived authentication state and session cookies for secure sign-in; and
  • browser session storage for conversations and saved answers during the current browser session.

Blocking essential cookies may prevent conversations or sign-in from working. CISOJoe.com does not use these essential cookies for behavioural advertising.

Retention

We retain information only for as long as reasonably necessary for the purpose for which it was collected:

  • authentication challenges and transactions expire after approximately 10 minutes;
  • signed-in session records expire after approximately eight hours or are deleted when you sign out;
  • the visitor cookie expires after up to 30 days;
  • hashed quota counters expire shortly after the applicable usage window; and
  • account profile information remains in the authentication service until it is deleted or must be retained for security or legal reasons.

Operational backups, security records, and provider-held information may remain for limited additional periods under applicable retention schedules.

International processing

CISO Joe uses service providers that may process information outside your province, state, or country, including in the United States. Information processed in another jurisdiction may be subject to that jurisdiction’s laws. We use contractual, technical, and organizational safeguards appropriate to the service and the information involved.

Your choices and rights

Depending on where you live, you may have rights to request access to, correction of, or deletion of personal information, or to withdraw consent where consent is the applicable basis for processing.

To request deletion of CISO Joe account information, email info@cocooncs.com with the subject CISO Joe data deletion request and identify the email address used to sign in. We may need to verify your identity before completing the request. We will delete or de-identify information unless retention is required for legal, fraud-prevention, security, or legitimate recordkeeping purposes.

You can clear conversation content and saved answers immediately by closing the browser tab or clearing site data in your browser. You can also stop microphone access at any time through the conversation controls or your browser settings.

Security

We use administrative, technical, and physical safeguards designed to protect personal information. These include encrypted connections, HTTP-only cookies, hashed session and network identifiers, short expiration periods, access controls, and restricted production infrastructure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Children’s privacy

CISOJoe.com is intended for professionals and is not directed to children under 13. We do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided personal information so we can review and remove it where appropriate.

Changes to this notice

We may update this notice when CISO Joe’s features, providers, or legal obligations change. We will publish the revised notice here and update the date above. Material changes may also be announced through the website when appropriate.

Contact us

For privacy questions, requests, or complaints about CISOJoe.com, contact:

Cocoon CS Inc.
Email: info@cocooncs.com
Website: www.cocooncs.com

CISO Joe

Sign in or create an account

Choose how you want to continue. CISO Joe never asks you to create a password. Every sign-in method requires your email address; if your provider asks, allow it to share your email.

or

We’ll send a one-time code to your email address.

Use your company’s single sign-on (SSO).

A note before we talk

Joe is an AI guide. Audio and messages are processed by OpenAI so Joe can respond. Don’t share passwords, personal records, or confidential business information.

You choose how to join in. Voice requires your microphone permission; you can mute or end it at any time. Typing does not need microphone access.

We use a 30-day usage cookie and hashed network identifiers to enforce limits. The site does not save your conversation history; recent conversations stay only in this browser tab and clear when you close it.

If you sign in, AWS Cognito handles your account and we store a hashed, expiring session identifier in PostgreSQL. CISO Joe uses email codes or your chosen identity provider; no password is created or stored by this website.

Usage limits apply to this public service. Joe can help you explore ideas, but check important decisions with the right people for your organization.

Read OpenAI’s privacy policy