Cosmic OS

Privacy Policy

Last updated: August 23, 2026

Cosmic OS is a local-first personal workspace. This policy explains what the application stores, what is sent to connected services, and the choices available to you.

Information Cosmic handles

You may provide an email address, display name, and password to create an account. Cosmic stores authentication and session records to sign you in and protect account-owned data. Modules can contain information you enter, including Mail, Calendar, School, Garage, Finance, Notes, Projects, and AI requests. Browser-local records are stored in scoped local storage; provider credentials are handled separately and are not included in browser exports.

Connected providers and financial data

If you connect a supported service, Cosmic sends the minimum request needed to authenticate or provide that integration. Providers may process data under their own policies.

Cosmic Finance may connect to financial institutions through Plaid, MX, Mastercard Open Finance/Finicity, or another supported aggregation provider depending on institution availability. Users authorize the selected provider directly; Cosmic does not receive or store online-banking usernames or passwords from aggregator authentication. Cosmic stores normalized account, balance, transaction, sync-status, category, and connection metadata needed to provide Finance. Imported history is preserved after disconnect unless you separately delete it through an available control or account deletion workflow. Finance data is not used for advertising targeting.

Advertising and consent

Cosmic Free may eventually show clearly labeled advertisements only on approved, non-sensitive surfaces. Cosmic+ is designed to be ad-free. Live advertising is not enabled by this application phase. Cosmic does not intentionally send Finance balances or transactions, Mail bodies, Notes, Garage VINs or plates, AI prompts, Calendar event content, or private School content to advertising placement systems for targeting.

Cookies, security, and deletion

Authentication uses session mechanisms appropriate to the deployment. The browser may also contain local storage for preferences and scoped module data. Cosmic uses account scoping, origin checks on sensitive mutations, protected server routes, and encrypted provider credential storage where configured. No internet service can guarantee absolute security. You may clear browser-local data and delete your account from the Account page; clearing local storage does not necessarily disconnect external providers.

Changes and contact

Cosmic may update this policy as the service changes. For privacy questions or deletion help, use the public Support route.

COSMIC OS

Preparing your workspace

Getting the essentials ready…

1 of 5 essentials ready