Privacy Policy
Last updated: August 3, 2026
The short version: COS is local-first by architecture. The software runs on your own machine, through your own AI accounts, and we operate no backend that stores your working data. What we do collect is small and listed plainly below: standard website analytics, an email address if you subscribe to updates, and your basic Google profile if you sign in to a COS service with Google.
Who we are
GotCOS ("COS," "we") is the home of the open-source COS starter kit, the COS Glasses application for Even Realities G2, the @gotcos/glasses-server software, and related COS services. The site and software are operated by Miles Ukaoma. This policy covers the gotcos.com website and COS software and services that link to it.
What we collect on this website
- Analytics. gotcos.com uses Google Analytics to understand aggregate site usage (pages viewed, approximate location, device type). Analytics data is not tied to a COS account and is governed by Google's privacy policy. You can block analytics with standard browser tools and the site works fine.
- Email subscriptions. If you submit your email in a form on this site (for example, glasses feature updates), we store that address in our CRM (HubSpot) and use it to send the updates you asked for. Nothing else. Every email includes a way to unsubscribe, and you can request deletion at the contact below.
The website has no user accounts, and browsing it requires no personal information.
What the COS software collects
Nothing that reaches us. The COS starter kit, glasses server, and COS Glasses app run entirely on hardware you control:
- Queries and answers route from your devices to a server on your own computer, then to the AI provider through your own signed-in account (Claude Code or Codex) or your own API keys. We never see them.
- Voice audio is transcribed locally on your machine when local transcription is installed, or through your own OpenAI key if you configure it. Audio is not stored by default.
- Conversation history, context files, photos, and media are stored in files on your own machine. They are not transmitted to us.
- No telemetry. The software contains no analytics, crash reporting, or usage tracking that reports to us.
Third-party services you connect through your own accounts (Anthropic, OpenAI, Even Realities' Even Hub platform) are governed by their own policies: Anthropic, OpenAI. Your API keys live in local configuration files on your machine; we have no access to them.
Google user data
Some COS services offer Sign in with Google. If you choose it, we receive your basic Google profile: your name, email address, and profile picture. We use that information only to create and secure your session and to identify you inside the service. We do not sell it, share it for advertising, or use it to train AI models.
Where you connect Google data through connectors you explicitly authorize, that data is read to answer your requests. How it is stored depends on how you run COS:
- Self-hosted COS. Connected data is read on demand and stays within your own COS instance, on infrastructure you or your organization control.
- Our hosted service. We store what is needed to keep the connection working and to answer your requests, such as OAuth tokens and an indexed knowledge graph built from the content you connect. This is held in access-controlled storage, encrypted at rest, and described under How we protect your data below.
In both cases we do not sell your Google data, share it for advertising, or use it to train AI models.
COS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Revoking access: you can revoke COS's access to your Google account at any time at myaccount.google.com/permissions. Sign-in data we hold for a service session is deleted when the account or deployment is removed, or on request at the contact below.
How we protect your data
We protect your data, including sensitive Google user data (Gmail and Drive content) accessed through connectors you authorize, with the following measures:
- Encryption in transit. All data is transmitted over secure, encrypted connections using HTTPS/TLS (version 1.2 or higher). Google user data is never transmitted over unencrypted channels.
- Encryption at rest. Where data is stored, for example an indexed knowledge graph, OAuth tokens, or a graph file saved to your own Google Drive, it is held in access-controlled storage that is encrypted at rest by our infrastructure providers.
- Access controls and isolation. Access to your Google user data is restricted to your own authenticated account. Each user's data is logically isolated, and internal access is limited to the minimum necessary to operate and support the service.
- Least-privilege, read-only scopes. We request read-only access to your Gmail and Drive content, and the per-file
drive.filescope only to save your knowledge graph to your Drive. We never modify or delete your existing emails or Drive files. - Secure credential handling. OAuth access and refresh tokens are stored securely and are never shared with third parties. You can revoke access at any time at myaccount.google.com/permissions.
- Data minimization and deletion. We store only what is needed to provide the service. You can disconnect a connected source or delete your account at any time, which removes the associated stored data.
Retention and deletion
- Software data: stored on your machine, deleted whenever you delete it. Uninstalling removes the software; your context files are yours to keep or remove.
- Subscription emails: kept until you unsubscribe or ask us to delete them.
- Google sign-in data: deleted with the account/deployment or on request.
- Connected Google content (hosted service): OAuth tokens and any indexed knowledge graph built from content you connect are deleted when you disconnect that source or delete your account, and on request at the contact below. Revoking access at myaccount.google.com/permissions immediately stops further access.
Children's privacy
COS is not directed at children under 13, and we do not knowingly collect information from children.
Changes to this policy
Updates are posted on this page with a new date. Material changes to how a COS service handles Google data will be reflected here before they take effect.
Contact
Questions about this policy: dev@gotcos.com