Privacy
What we collect, and where it goes.
Cosmic Council sends what you write to AI models operated by other companies. This page says exactly what is stored, who receives it, and what is still being settled.
This notice is not yet complete.
The following are still being confirmed and are deliberately not stated rather than guessed: the company's legal and register details, the lawful basis for each purpose, the transfer mechanism for model providers outside the EU, whether zero data retention is contractually in force, the address for exercising your rights. The sections below describe the system accurately as it stands today.
Who runs this service
Cosmic Council is built and operated by 1tm solutions GmbH. Full company details and the contact address for privacy requests are published in the imprint once finalised.
What is stored
- Your email address, used only to sign you in via a magic link. It is the sole contact identifier collected.
- Your display name and workspace name, as you supply them.
- The questions you ask a council, stored as plain text and linked to your profile — together with every member answer and the chair’s synthesis.
- Documents you upload as council knowledge, including their full text and the numeric embeddings derived from it.
- Images you upload as member avatars.
- Payment references if you buy something — the Stripe identifiers and the amount. We never see or store card details.
- Usage records — which model ran, how many tokens, what it cost, and when.
Questions you ask are sent to other companies
This is the part worth reading twice. When a council answers, your question — plus any passages retrieved from documents you uploaded — is sent through Vercel’s AI Gateway to the model provider that council uses: OpenAI, Anthropic, Google or xAI.
Cosmic Council invites reflective questions, and people bring real ones — about grief, work, relationships and health. Please treat anything you type as leaving our systems, because it does.
Who else receives data
- Vercel — hosting and the AI Gateway every model call passes through.
- Supabase — the database, sign-in, and file storage.
- OpenAI, Anthropic, Google, xAI — the model providers that generate council answers, and embeddings for document search.
- Stripe — payments, if you buy something.
- Firecrawl — only when you paste a link for a council to react to; it receives that URL and returns the page text.
Cookies
No analytics, tracking or advertising cookies are used, and no such SDK is present in the application. The cookies set are: your sign-in session, a cookie that stops a public thread double-counting your view, and two that remember interface preferences.
Publishing is always your choice
A council run stays private unless you publish it. Publishing is a deliberate action and cannot happen anonymously or automatically — once published, the question and the answers are readable by anyone.
How long we keep it
Council questions and the answers to them are deleted 24 months after the conversation they belong to was last used. An active conversation keeps its whole history for as long as you keep using it.
Documents you upload stay until you delete them — they are your working material, and expiring them would quietly break the councils that rely on them. Threads you chose to publish stay published until you unpublish them. Usage records that contain no text of yours (which model ran, how many tokens, what it cost) are kept for billing history.
Your rights
Under the GDPR you may request access to your data, correction, erasure, portability, restriction, and you may object to processing. Deleting your profile cascades to the records attached to it. A conversation export is available in the application.
The contact address for these requests is published in the imprint once finalised.
AI transparency
Council members and the chair are AI systems, disclosed wherever you meet them. Complying with the EU AI Act does not replace these data protection duties, and this notice is separate from that disclosure.