Legal

Privacy Policy

Effective date: 1 April 2025  ·  Last updated: 8 July 2026

The short version

Cossi is local-first. Your calendar, contacts, email, vault contents, keys, and seed phrase live on your device — we cannot read them. AI runs on-device by default. Optional features you switch on (Google connect, a cloud AI provider with your own key, the Cossi Cloud relay) connect directly from your device and receive only what those features need — never raw personal data on our servers, and nothing is ever sold or used for advertising.

1. Who we are

Cossi is a personal productivity application developed and published by SI Analytics Ltd ("we", "us", "our"). We are registered in England and Wales. If you have questions about this policy, contact us at customer_services@sianalytics.tech.

2. Information we collect

We collect no personal information. Cossi is a local-first application. There are no user accounts on our servers and no analytics SDKs. The app transmits no data in the background unless you enable the optional Cossi Cloud relay (Section 6), which receives only redacted, pseudonymous job data.

What stays on your device

What we do not collect

3. Apple App Store and TestFlight

When you download Cossi from the Apple App Store or access it via TestFlight, Apple collects certain information as part of its standard platform operation (e.g. download records, crash logs if you have opted into sharing these with developers). This collection is governed by Apple's Privacy Policy, not ours.

Crash reporting: If you opt in to sharing crash data with developers in your iOS settings, Apple may forward crash reports to us. These reports contain technical stack trace information only — no personal data, no vault contents, no message content.

4. Third-party services

Cossi connects to services that you configure — your calendar server, your email provider, and optionally your cryptocurrency node. These connections are made directly from your device to those services. We are not party to those connections and do not intermediary, log, or inspect them.

The following optional integrations may involve third-party services:

5. Google user data

If you connect a Google account, Cossi requests only the scopes each feature needs, at the moment you use that feature:

How it is stored: OAuth tokens are stored in your device's secure enclave (iOS Keychain / Android Keystore). Message and document content is cached in the app's local SQLite database on your device. No Google user data is transmitted to, or stored on, any server operated by SI Analytics.

How it is shared: It is not. We do not sell Google user data, do not use it for advertising, and no human at SI Analytics can access it — it never reaches us. Google user data is never used to develop, improve, or train generalised AI or machine-learning models. If you have explicitly enabled a cloud AI provider (Section 6), redacted excerpts may be sent to that provider solely to provide user-facing features you request.

Limited Use disclosure: Cossi's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Optional cloud AI and the Cossi Cloud relay

Cossi's default AI runs entirely on your device. Two optional features involve a network:

7. Data deletion and revoking access

You are always one step from a clean slate:

8. Data security

Cossi's security architecture is designed so that a breach of our infrastructure — should one ever occur — would expose no user data, because we hold none. Nonetheless:

9. Your seed phrase

Your 24-word BIP-39 seed phrase is the master key to your account and encrypted vault. We do not store it, cannot recover it, and have no mechanism to reset it. If you lose your seed phrase, your vault contents cannot be recovered. Store it securely offline.

10. Children’s privacy

Cossi is not directed at children under 13. We do not knowingly collect any information from children. If you believe a child has provided information through our app, please contact us and we will take appropriate steps.

11. Changes to this policy

If we make material changes to this policy, we will update the effective date above and notify users via an in-app notice on the next app open. Continued use of Cossi after the effective date constitutes acceptance of the updated policy.

12. Your rights

Because we hold no personal data about you, most data subject rights (access, erasure, portability) are exercised directly on your device. If you have questions or concerns, or wish to exercise any rights under applicable data protection law, contact us at the address below.

13. Contact

For privacy questions or data subject requests:

SI Analytics Ltd
Email: customer_services@sianalytics.tech

Questions about privacy?

We're straightforward to reach. If something in this policy is unclear, email us and we'll respond within 2 business days.

customer_services@sianalytics.tech