Back to HomeTerms & Conditions

Privacy Policy

At COSMOS-X, your privacy is a core priority. This Privacy Policy explains how COSMOS-X Technology OÜ, acting as the Data Controller, collects, uses, and protects your personal information when you use our AI productivity workspace — AI chat and voice assistants, tasks, notes, boards, documents, calendar, mindmaps, direct messages, flows — and related services.

Last Updated: July 19, 2026 · Effective: February 1, 2026

Table of Contents

1. Information We Collect2. Legal Basis for Processing (GDPR)3. Data Sharing & Sub-processors4. International Data Transfers5. AI Model Training6. Cookies7. Data Security8. Your GDPR Rights9. Data Retention10. Children11. Changes to This Policy12. Supervisory Authority

1. Information We Collect

Account Information

Name, email address, and credentials. For third-party logins (Google, GitHub), we collect your unique ID and profile picture URL.

Workspace & Conversation Content

Content you create in the Service: AI chat conversations (text inputs, file uploads, and AI-generated outputs), notes, tasks, boards, documents, calendar entries, mindmaps, flow configurations, and direct messages / channel messages you exchange with other users. This content is stored securely to provide you with history and continuity.

Voice Data

If you use voice features, your audio is processed by our AI providers to generate transcripts and responses. Transcripts are stored as part of your conversation history.

Usage & Diagnostics Data

IP address, browser type, device identifiers, and interaction logs (timestamps, features used). We also collect first-party product analytics (which features are used — event metadata only, never the content of your conversations or documents), aggregate performance metrics (web vitals), and error reports.

Payment & Payout Information

Handled exclusively by Stripe, Inc. We do not store credit card numbers. We only receive confirmation of payment and metadata (e.g., last 4 digits) for billing support. If you participate in our referral program, payout onboarding (identity and bank details) is handled by Stripe Connect; we do not store those details.

Optional Integrations

If you choose to connect an optional integration (e.g., Telegram or Zapier), we process the account identifiers and message/action content needed to operate that integration. Data you send through an integration is also subject to that provider's own privacy policy.

2. Legal Basis for Processing (GDPR)

Under the GDPR, we process your data based on the following:

Contractual Necessity (Art. 6(1)(b))

To provide the Service — your workspace, conversations, and wallet.

Legitimate Interests (Art. 6(1)(f))

To prevent fraud, ensure network security, and improve our platform's performance and features through the aggregate analytics described above.

Legal Obligation (Art. 6(1)(c))

To retain accounting and tax records as required by Estonian law.

Consent (Art. 6(1)(a))

For marketing communications and optional integrations you choose to connect. You can withdraw consent at any time.

3. Data Sharing & Sub-processors

We do not sell your data. We share data with the following categories of processors, only to the extent needed to provide the Service:

AI Model & Search Providers

Your prompts (and, for voice features, audio) are sent to the AI provider serving your request in order to generate a response: OpenAI, Anthropic, Google, Groq, xAI, Perplexity, OpenRouter, Cerebras, Fireworks AI, DeepInfra, Baseten, and SambaNova. Web-search features send your search queries to Tavily and Perplexity. We use API tiers whose terms exclude this data from being used to train the providers' public models.

Infrastructure & Storage

Vercel (hosting and cookie-free web analytics), Neon (database), Cloudflare R2 (file storage), Upstash (job queues and caching), Ably (real-time messaging delivery), and E2B (isolated sandboxes for code-execution features).

Authentication, Payments & Email

Clerk (authentication), Stripe (payments and referral payouts), and Resend (transactional email).

Optional Integrations

Telegram and Zapier, only if you connect them.

Compliance

We may disclose data to Estonian or EU authorities if legally mandated.

4. International Data Transfers

Some of the processors listed above are located in, or process data in, the United States and other countries outside the European Economic Area. Where data leaves the EEA, we rely on the safeguards required by Chapter V of the GDPR: an adequacy decision (including the EU–U.S. Data Privacy Framework for certified providers) or the European Commission's Standard Contractual Clauses, together with data processing agreements with each provider.

5. AI Model Training

Your conversations are NOT used to train our models or third-party models. We use API tiers whose terms exclude customer content from provider model training.

6. Cookies

We use only strictly necessary cookies: authentication/session cookies (set by Clerk) and payment security cookies (set by Stripe during checkout). We do not use advertising or cross-site tracking cookies. Our web analytics (Vercel Analytics) is cookie-free. If we ever introduce non-essential cookies, we will ask for your consent first.

7. Data Security

We employ "Security by Design" principles:

Encryption

TLS 1.3 for data in transit and AES-256 for data at rest.

Access Control

Strict internal "least-privilege" access for our developers and administrators.

8. Your GDPR Rights

Access, Rectification & Erasure

You can view, correct, or delete your personal data and account at any time.

Restriction of Processing

You can ask us to restrict processing of your data while a dispute about it is resolved.

Data Portability

You can request a machine-readable export of the personal data you have provided to us by contacting us; we will provide it within the GDPR's statutory deadline.

Right to Object

You can object to processing based on our legitimate interests.

Withdrawal of Consent

Where processing is based on consent (e.g., marketing), you can withdraw it at any time without affecting prior processing.

To exercise these rights, contact our Data Protection team at support@cosmosx.ai. We respond within one month.

9. Data Retention

Conversations & Workspace Content

Retained as long as your account is active.

Analytics & Diagnostics

Product analytics events and error reports are retained for 90 days; only aggregate statistics (which contain no personal content) are kept longer.

Wallet Records

Retained for 7 years to comply with Estonian accounting and tax laws.

Deleted Accounts

Data is purged from our active systems within 30 days of a deletion request. Residual copies in encrypted backups expire within our backup retention window (currently 7 days).

10. Children

The Service is not directed at, and may not be used by, anyone under 18 years of age. We do not knowingly collect personal data from minors; if we learn that we have, we will delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes we will notify you by email or in-app notice before the changes take effect. The "Last Updated" date above always reflects the current version.

12. Supervisory Authority

If you believe we have infringed upon your privacy rights, you have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon). Website: www.aki.ee

Questions about our privacy practices?

Contact us at support@cosmosx.ai

Join Our Newsletter

* Will send you weekly updates for your better business management.

Pages

  • Home
  • About Us
  • Features
  • Vision

Discover

  • Models
  • Blog
  • News
  • Support

Resources

  • Contact Us
  • Affiliates
  • Privacy Policy
  • Terms & Conditions

Social

  • Facebook
  • Instagram
  • Twitter
  • Linkedin

© Copyright 2026 COSMOS-X Technology OÜ. All rights reserved.

COSMOS-X