Our Philosophy
We’re not in the surveillance business. We’re in the business of building beautiful software that respects your privacy and dignity.
Privacy isn’t a feature we tack on—it’s a fundamental principle woven into everything we build. We believe your data belongs to you, not us. We don’t harvest, sell, or exploit your personal information. We don’t play games with dark patterns or buried consent forms.
This policy tells you exactly what we collect, why we collect it, and who else might see it. No corporate doublespeak. No legal sleight of hand.
Who We Are
CosmoLabs FZCO
Dubai, United Arab Emirates
Contact: legal@cosmolabs.org
What We Collect (and Why)
Email Addresses
- When: You create an account, subscribe to our newsletter, or contact us
- Why: To create your account, send you updates you requested, or respond to your questions
- How long: Until you delete your account or unsubscribe
- Shared with: Our email service provider (see Third Parties section)
Account Credentials
- When: You create an account on any CosmoLabs product
- What: Encrypted password, authentication tokens
- Why: To verify it’s actually you when you log in
- How long: Until you delete your account
- Security: Encrypted in transit and at rest, we can’t see your actual password
- Shared with: Supabase (authentication provider)
User-Generated Content
- When: You create, save, or share content in our products
- What: Whatever you choose to create (documents, data, files, etc.)
- Why: To provide the service you’re using
- How long: Until you delete it or close your account
- Shared with: Stored on Supabase infrastructure, encrypted where possible
Usage Data (Minimal)
What we collect:
- Error logs and crash reports (to fix bugs)
- Privacy-preserving analytics (no tracking, no fingerprinting)
- Essential performance metrics
What we DON’T collect:
- Your browsing history
- Your location beyond country-level (for legal compliance)
- Detailed behavioral profiles
- Cross-site tracking data
- Advertising identifiers
What We Don’t Collect
Let’s be crystal clear about what we deliberately avoid:
- No behavioral surveillance - We don’t track your every click and scroll
- No social graphs - We don’t map your relationships or connections
- No device fingerprinting - We don’t create sneaky unique identifiers
- No selling your data - Not now, not ever, to anyone
- No advertising profiles - We’re not building dossiers on you
- No dark patterns - We don’t trick you into giving us more data
Many of our products are designed to work with zero personal data. Where we can build something without collecting information, we do.
Cookies: We Don’t Deal With That Tracking Nonsense
Here’s our cookie policy in plain English:
We use cookies only for essential functionality:
- Keeping you logged in between sessions
- Remembering your preferences (theme, language, settings)
- Basic security protection
We do NOT use cookies for:
- Tracking you across the internet
- Building advertising profiles
- Third-party analytics
- Behavioral targeting
- Social media tracking pixels
No consent banner spam. No cookie walls. No sneaky tracking. If you’re logged in, we use a cookie to remember that. That’s it.
Technical note: We use session cookies (deleted when you close your browser) and limited persistent cookies (for “remember me” functionality). You can disable cookies entirely, but some features won’t work.
Mobile App Permissions
When you use our mobile apps (iOS/Android), we may request permissions to access device features. You control these permissions in your device settings.
Permissions we may request:
- Camera: For profile photos, document scanning, QR codes
- Photo Library: To save/upload images
- Notifications: For important updates and reminders
- Location (optional): For location-based features (you control precision)
- Contacts (optional): For inviting friends (never uploaded without consent)
We only request permissions necessary for features you use. You can revoke permissions anytime in device settings.
Browser Extension Privacy
Our browser extensions follow strict data minimization principles:
What we access:
- Only data necessary for the extension’s primary function
- No browsing history collection
- No cross-site tracking
Permissions explained:
- Storage: To save your preferences locally
- Tabs (if applicable): To integrate with active tab only
- Network: To communicate with our secure API
Chrome/Firefox compliance:
All data transmitted over HTTPS. No sensitive data stored unencrypted.
Third-Party Services (Our Limitations)
We wish we could build everything from scratch in a privacy-preserving way. Reality check: we use some third-party services, and each has its own privacy implications.
Third-Party SDKs (Mobile Apps)
Our mobile apps may include third-party software development kits (SDKs):
- Mobile Analytics: Crash reporting and performance monitoring (privacy-preserving)
- Authentication SDKs: Supabase Auth for secure login
- Payment SDKs: Stripe SDK for in-app purchases (when applicable)
- Push Notifications: Firebase Cloud Messaging (FCM) for Android, APNs for iOS
All SDKs are vetted for privacy compliance and data minimization.
Services We Use
Supabase (Database & Authentication)
- What they see: Your encrypted account data, user-generated content
- Why we use them: Reliable, secure database and authentication infrastructure
- Their policy: supabase.com/privacy
- Location: Data stored in their SOC 2 compliant data centers
Cloudflare (CDN & Security)
- What they see: Your IP address, basic request metadata (for DDoS protection)
- Why we use them: Fast content delivery, security, DDoS protection
- Their policy: cloudflare.com/privacypolicy
DigitalOcean (Infrastructure)
- What they see: Server-level access logs (not application data)
- Why we use them: Hosting infrastructure
- Their policy: digitalocean.com/legal/privacy-policy
Stripe (Payment Processing)
- What they see: Payment information, billing details (when you purchase paid products)
- Why we use them: Secure payment processing, we never see your full card details
- Their policy: stripe.com/privacy
- PCI Compliance: Stripe is PCI DSS Level 1 certified
Privacy-Preserving Analytics
- What: Aggregate usage statistics (no individual tracking)
- Why: To understand what’s working and what’s broken
- How: Privacy-first analytics tools (Plausible or similar)
- No: Personal identifiers, cross-site tracking, or data selling
Our Commitment
We choose vendors carefully. We contractually require GDPR compliance. We minimize data sharing. We encrypt wherever possible. But understand: once data reaches a third party, we’re bound by their practices.
Your Rights (And How to Exercise Them)
You have real, enforceable rights over your data. Here’s how to use them:
Right to Access
- What: Get a copy of all data we have about you
- How: Email privacy@cosmolabs.org with subject “Data Access Request”
- Timeline: We’ll respond within 30 days
Right to Correction
- What: Fix inaccurate data
- How: Log into your account and edit it directly, or contact us
- Timeline: Immediate (for self-service), or 30 days (if you contact us)
Right to Deletion
- What: Delete your account and associated data
- How: Account settings → Delete Account, or email us
- Timeline: Immediate deletion from active systems, complete purge within 90 days
- Exceptions: We may retain some data for legal compliance (invoices, tax records)
Right to Portability
- What: Export your data in a machine-readable format
- How: Use built-in export features, or email privacy@cosmolabs.org
- Timeline: Immediate (for self-service), or 30 days
Right to Object
- What: Object to certain processing (like marketing emails)
- How: Click unsubscribe, or email us
- Timeline: Immediate
Right to Complain
- What: File a complaint with a data protection authority
- Where: Your local data protection authority, or UAE’s relevant authority
- Our preference: Contact us first—we’ll work with you to resolve it
GDPR Compliance
We comply with the EU General Data Protection Regulation (GDPR), even though we’re based in the UAE. Why? Because we believe privacy is a universal human right, not a regional checkbox.
Legal bases for processing:
- Consent: When you explicitly agree (e.g., newsletter signup)
- Contract: When necessary to provide services you requested
- Legitimate interest: For essential operations (fraud prevention, security)
International transfers: When data leaves the UAE (e.g., to Supabase servers), we ensure adequate safeguards (standard contractual clauses, adequacy decisions).
Security
We take security seriously:
- Encryption in transit: TLS 1.3 for all connections
- Encryption at rest: Database encryption, encrypted backups
- Access controls: Principle of least privilege, role-based access
- Regular security audits: Penetration testing, vulnerability scanning
- Incident response: 72-hour breach notification (GDPR standard)
But let’s be real: perfect security doesn’t exist. We do our best, we stay vigilant, and we’ll be transparent if something goes wrong.
Children’s Privacy
Our services are not directed at children under 16. We don’t knowingly collect data from children. If we discover we’ve collected data from a child, we’ll delete it immediately.
Changes to This Policy
We’ll update this policy when our practices change. When we do:
- We’ll update the “Last Updated” date at the top
- For material changes, we’ll email active users
- Continued use after changes means acceptance (or you can close your account)
Version history: We track all changes in our public repository for transparency.
Data Retention
We keep your data only as long as necessary:
- Active accounts: While your account exists
- Deleted accounts: 90-day grace period, then permanent deletion
- Backups: Deleted from backups within 90 days
- Legal requirements: Tax records, invoices (7 years per UAE law)
- Anonymous analytics: Retained indefinitely (no personal data)
Governing Law
This policy is governed by the laws of the United Arab Emirates. For EU residents, GDPR rights supersede where applicable.
Contact Us
Questions? Concerns? Complaints? We’re here:
- Email: privacy@cosmolabs.org
- Legal inquiries: legal@cosmolabs.org
- General: hello@cosmolabs.org
We aim to respond within 3 business days for privacy requests, 30 days maximum for formal GDPR requests.
The Bottom Line
Your privacy matters. We build with privacy by default, we collect only what we need, we’re transparent about limitations, and we give you real control over your data.
We’re building technology that respects human dignity. That starts with respecting your privacy.
CosmoLabs FZCO
Elevating Human Potential