Privacy Policy
InCosmos Brief collects only the account and app data needed to provide the research-reading experience. Effective date: 2026-08-09.
Account data
When you sign in with Google or Apple, the app stores an app-owned user record, provider subject, display name, email, email verification status, and session metadata.
Provider access tokens and refresh tokens are not stored.
Session cookies
After sign-in, the service uses a secure app-owned session cookie to keep you signed in.
The server stores only a hash of the session token, not the raw session token.
Personal state
Favorites and reading history are stored so they can sync across sessions while your account exists.
Public research content remains available to guests without account creation.
Outbound link and read events
When you explicitly open an outbound source link, the service records an outbound event: the destination URL, a title, the surface it was opened from, the related report and institution, a hashed IP address, and a hashed User-Agent.
If you are signed in, the event is linked to your account and session; if you delete your account, event rows linked to your account or session are removed.
Rate limiting
To protect the service from abuse, sign-in, write, and event requests are throttled per client. The throttle key is a hash of your IP address (or User-Agent when no IP is available), not the raw value.
Rate-limit counters are deleted automatically once their throttling window closes; they are not used to identify you outside of abuse prevention.
Security, search, and operational logs
We may keep limited audit records for sign-in, sign-out, authentication failures, account deletion, abuse prevention, troubleshooting, and service security. These records are used for operations and compliance, not for advertising.
Search and API requests are also processed transiently through the Cloudflare Workers platform for routing, performance, and abuse monitoring, subject to Cloudflare's own operational logging. InCosmos Brief does not maintain a separate, persistent store of your individual search queries.
Information we do not store
We do not offer password login and do not store your Google or Apple password.
We do not store provider profile pictures or raw Google or Apple profile payloads.
The current service does not include paid subscriptions, memberships, advertising, comments, user-generated content, trading signals, or investment-advice features.
How we use information
We use account data to create and maintain your app account, keep you signed in, sync saved reports, protect the service, and satisfy app-store, platform, operational, and legal requirements.
We do not sell personal information.
Third-party sign-in providers
Google and Apple are used only as identity providers. InCosmos Brief owns its own app accounts, sessions, and account-deletion behavior.
We do not automatically merge Google and Apple identities based only on a matching email address.
Deletion
You can delete your account from the Profile page. This is a hard deletion, applied immediately: the app-owned user record, sign-in identity link, active sessions, favorites, reading history, linked authentication audit rows, and user- or session-linked outbound event rows are removed as one atomic operation. We do not keep a recoverable, soft-deleted copy of this data.
If Apple is your only or an additional sign-in method, deletion requires a fresh Sign in with Apple authorization from the app immediately before the request; the service exchanges and revokes that Apple authorization with Apple as part of completing deletion.
The service keeps a new anonymous account_deleted event without user, session, IP, or User-Agent linkage for operational accounting.
Data retention
Account data is kept while your account remains active.
After account deletion, a later sign-in with the same Google or Apple identity creates a fresh app account with no restored personal state.
Children's privacy
InCosmos Brief is designed for users who can independently read and evaluate research material. It is not directed to children.
If you believe a child has provided personal information to us, contact us so we can review and address the issue.
Changes to this policy
We may update this Privacy Policy as the product, platform requirements, or legal requirements change.
The updated version will be posted on this page with a new effective date.
Contact
For privacy questions, account-data requests, or deletion support, contact hello@zaiu.jp.