InCosmos Brief

Privacy Policy

InCosmos Brief collects only the account and app data needed to provide the research-reading experience. Effective date: 2026-09-06.

Account data

When you sign in with email, Google, or Apple, the app stores an app-owned user record, the verified sign-in identities you connect, display name, email, email verification status, and session metadata.

Provider access tokens and refresh tokens are not stored.

An unfinished verification is held in app memory. The app may keep a yes-or-no marker so it can explain that verification needs to restart after the app closes. This marker contains no email address, verification code, identity token, or linking secret. Adding a sign-in method does not upload previously local reading data.

Email verification and linked sign-in methods

When you request a verification code, we use your email address to send it through Cloudflare Email Sending. Cloudflare processes the recipient address and verification message for delivery.

Codes expire after 10 minutes, allow at most five attempts, and can be used once. We store a protected hash of each code. Verification records also include the email address, request status, expiry, and any account or session needed to complete the request. Address and IP rate-limit records use protected hashes.

Verification records and rate-limit counters become eligible for removal 24 hours after their expiry and are removed on a subsequent maintenance pass. Linking proofs and their protected completion receipts expire after 10 minutes. Browser continuation records also expire after 10 minutes. These records are removed on a subsequent maintenance pass after expiry. Maintenance is triggered by authentication traffic and normally checks for eligible records at most once every six hours; it is not a guaranteed deletion deadline. Account deletion removes the corresponding verification and linking records.

Linking records contain the verified identity, its source and proof time, the intended account when known, and hashes of the continuation and recovery secrets. Browser continuation also records the return page and language. We do not store raw provider tokens or verification codes in these records. Connected sign-in identities remain until account deletion.

Adding a sign-in method requires verification of the existing account and the new method. A matching email address alone does not link accounts or merge two existing accounts.

Session cookies

After sign-in, the service uses a secure app-owned session cookie to keep you signed in.

The server stores only a hash of the session token, not the raw session token.

Personal state

Favorites and reading history are stored so they can sync across sessions while your account exists.

Public research content remains available to guests without account creation.

Outbound link and read events

When you explicitly open an outbound source link, the service records an outbound event: the destination URL, a title, the surface it was opened from, the related report and institution, a hashed IP address, and a hashed User-Agent.

If you are signed in, the event is linked to your account and session; if you delete your account, event rows linked to your account or session are removed.

Rate limiting

To protect the service from abuse, sign-in, write, and event requests are throttled per client. The throttle key is a hash of your IP address (or User-Agent when no IP is available), not the raw value.

Rate-limit counters are deleted automatically once their throttling window closes; they are not used to identify you outside of abuse prevention.

Security, search, and operational logs

We may keep limited audit records for sign-in, sign-out, authentication failures, account deletion, abuse prevention, troubleshooting, and service security. These records are used for operations and compliance, not for advertising.

Search and API requests are also processed transiently through the Cloudflare Workers platform for routing, performance, and abuse monitoring, subject to Cloudflare's own operational logging. InCosmos Brief does not maintain a separate, persistent store of your individual search queries.

Information we do not store

We do not offer password login and do not store your Google or Apple password.

We do not store provider profile pictures or raw Google or Apple profile payloads.

The current service does not include paid subscriptions, memberships, advertising, comments, user-generated content, trading signals, or investment-advice features.

How we use information

We use account data to create and maintain your app account, keep you signed in, sync saved reports, protect the service, and satisfy app-store, platform, operational, and legal requirements.

We do not sell personal information.

Third-party sign-in providers

Google and Apple are used only as identity providers. InCosmos Brief owns its own app accounts, sessions, and account-deletion behavior.

Email, Google, and Apple can be connected to the same account after verification. We do not automatically merge accounts based only on a matching email address.

Deletion

You can delete your account from the Profile page. This is a hard deletion, applied immediately: the app-owned user record, sign-in identity link, active sessions, favorites, reading history, linked authentication audit rows, and user- or session-linked outbound event rows are removed as one atomic operation. We do not keep a recoverable, soft-deleted copy of this data.

If Apple is your only or an additional sign-in method, deletion requires a fresh Sign in with Apple authorization from the app immediately before the request; the service exchanges and revokes that Apple authorization with Apple as part of completing deletion.

The service keeps a new anonymous account_deleted event without user, session, IP, or User-Agent linkage for operational accounting.

Data retention

Account data is kept while your account remains active.

After account deletion, a later sign-in with the same email, Google, or Apple identity can start a new account setup. Creating a new account does not restore the deleted personal state.

Children's privacy

InCosmos Brief is designed for users who can independently read and evaluate research material. It is not directed to children.

If you believe a child has provided personal information to us, contact us so we can review and address the issue.

Changes to this policy

We may update this Privacy Policy as the product, platform requirements, or legal requirements change.

The updated version will be posted on this page with a new effective date.

Contact

For privacy questions, account-data requests, or deletion support, contact hello@zaiu.jp.