Privacy Policy
Effective: 21 August 2026 · Last updated: 21 August 2026
This policy explains what Cosmoose collects, what we do with it, who else touches it, and how you get it back or get it deleted. Cosmoose is a social media publishing tool: you connect your social accounts, schedule posts, and when a post fails we read the error the platform returned, fix what caused it, and publish again.
J1 Media Productions LLC (“J1 Media,” “Cosmoose,” “we,” “us”)
8390 E Via De Ventura, Ste F-110, PMB 1034, Scottsdale, AZ 85258, USA
support@cosmoose.io
Using Cosmoose means you accept what is described here. If you do not, do not use it.
1. The short version
- We collect your account details, the posts and media you give us, the connections you authorize, and how you use the app.
- We connect to social platforms only with your permission, only to do what you asked, and only for as long as you leave the connection in place.
- We do not sell your personal information and we do not share it for advertising.
- We do not use your content to train anyone’s AI models.
- You can disconnect an account, export your data, or delete everything at any time. Section 10 says exactly how.
The sections below control. This summary is for convenience.
2. What we collect
2.1 Account information
- Name and email address.
- A password, stored hashed. We never hold a plain-text password.
- Your plan, your settings, and your preferences.
2.2 Content you give us
- Post text, captions, links, hashtags, and scheduling times.
- Images, video, and other media you upload, including the metadata embedded in those files such as EXIF, IPTC, and XMP.
- Anything the app generates from what you gave it, such as a repaired caption or a re-encoded video.
2.3 Social platform connections
This is the part that matters most, so it gets its own section. See section 3.
2.4 Usage and diagnostic data
- IP address, browser, device, and operating system.
- What you did in the app and when: features used, posts queued, publishes attempted, errors hit.
- Performance and crash data.
2.5 Payment information
When paid plans are live, card payments will be processed by Stripe. Stripe collects card details directly and we never see or store a full card number. We keep limited billing records such as the last four digits, card brand, billing name and address, plan status, and transaction history. Stripe handles that data under its own privacy policy.
3. Social platform connections and platform data
Cosmoose only reaches a social platform because you connected it. You authorize the connection through that platform’s own login and permission screen, and the platform, not us, decides what we are allowed to see and do.
3.1 What we receive from a connected platform
- An access token that lets us act on your behalf, and its expiry.
- The account, page, or channel identifier, the username or handle, and the display name and profile image so you can tell your accounts apart in the app.
- The result of anything we publish for you: the platform’s post ID, its timestamp, and whether it succeeded.
- The error the platform returns when a publish fails, including its code and message. This is what the repair engine reads.
- Where you have granted it and where the platform allows it, basic performance figures for posts we published, and comments or messages on those posts when you have turned on a feature that needs them.
3.2 What we do with it
We use platform data to publish what you scheduled, to tell you when something failed, to diagnose why it failed and repair it, to show your own results back to you, and to keep your connection alive. Nothing else.
3.3 What we never do with it
- We do not sell it, rent it, or trade it.
- We do not use it for advertising or ad targeting, ours or anyone else’s.
- We do not use it to train AI models, and we do not permit our providers to.
- We do not build profiles of you, your audience, or anyone who interacts with your posts.
- We do not access accounts, pages, or data you did not connect.
3.4 Tokens
Access tokens are stored encrypted and used only to carry out actions you set up. You can revoke a token at any time, either by disconnecting the account inside Cosmoose or from the platform’s own app settings. When a token is revoked or expires we stop using it, and we delete the stored token. Anything already published stays published, because it lives on the platform and not with us.
3.5 Platform rules
Your use of each connected platform stays governed by that platform’s own terms and privacy policy. We handle platform data in line with each platform’s developer terms, and we delete it when you disconnect, when you delete your account, or when the platform requires it.
4. Why we process it
To run the service and do what you asked, to authenticate you and secure your account, to take payment and manage your plan, to contact you about your account and about failures, to debug and improve the product, to detect fraud and abuse, and to meet legal obligations. Where a legal basis is required, we rely on performing our contract with you, your consent, our legitimate interests, and compliance with law.
5. Who else touches your data
We use a small number of providers who process data on our behalf, under contract, only for the purposes we set.
| Provider | What it does | What it sees |
|---|---|---|
| Supabase | Database and file storage | Account data, your posts and media, connection records, usage data |
| Anthropic | AI features, including diagnosing a failure and drafting a repair | The post content and the platform error involved in that request |
| Google (Gemini) | AI features | The content you submit to a feature that uses it |
| Stripe | Payments, once paid plans are live | Billing and card data, which it collects directly |
| Connected social platforms | Publishing and results, at your instruction | Whatever you send them, plus the account you connected |
Our AI providers are used under terms where customer content is not used to train their models. We keep this list current. If we add a provider that processes your personal data, this page changes with it.
Do not upload confidential third-party data, government identifiers, health information, or anything you are not authorized to process. This is a publishing tool. Everything in it is headed for a public platform.
6. When we share outside that list
- Legal and safety. When the law, a subpoena, or a legal process requires it, or to protect the rights, property, or safety of J1 Media, our users, or the public.
- Business transfer. If the business is merged, acquired, or sold, your information may transfer. We will tell you before it changes hands.
- With your instruction. When you tell us to.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
7. Cookies
We use cookies to keep you signed in, remember settings, keep the service secure, and understand how the app is used. You can control cookies in your browser, though turning some off will break the app. Where the law requires consent for non-essential cookies, we ask for it.
8. How long we keep things
- Account data and content stay while your account is open.
- Connection records and tokens are deleted when you disconnect the account or close your account.
- Publishing history and failure records are kept while your account is open, because they are the record of what we did for you.
- Some records survive account closure where law, tax, accounting, fraud prevention, or a dispute requires it. Payment records are the usual example.
- Backups are overwritten on a rolling schedule, so deleted data can sit in a backup for a limited period after it leaves the live system.
9. Security
We use encryption in transit, encryption of stored access tokens, access controls, and reputable infrastructure providers. No system is perfectly secure and we do not claim otherwise. If a breach affects your data, we will notify you as the law requires.
10. Your data, your call
10.1 Disconnect a social account
Open Settings, find the account, and disconnect it. The token is revoked and deleted. You can also remove Cosmoose from the platform’s own connected-apps settings, which does the same thing from the other side.
10.2 Export everything
Request an export from inside the app and you get an archive of your content, your schedule, and your publishing and failure history. Leaving should not cost you your archive.
10.3 Delete your data
Two ways, and both work:
- In the app. Settings, then delete your account. This removes your account, your content, your connections, and your stored tokens.
- By email. Write to support@cosmoose.io from the address on your account with the subject line
Data Deletion Request. We verify it is you, then delete, and we confirm when it is done.
We act within the time the applicable law allows, and sooner where we can. Section 8 covers the narrow categories we are required to keep.
10.4 Rights under GDPR, UK GDPR, and Swiss law
If you are in the EEA, the UK, or Switzerland you can ask for access, correction, erasure, restriction, portability, and you can object to processing or withdraw consent. Withdrawing consent does not undo processing that was lawful before it. You can complain to your data protection authority. J1 Media Productions LLC is the controller.
10.5 Rights under CCPA and CPRA
If you are a California resident you can ask what we collect and disclose, get a copy, delete it, correct it, opt out of sale or sharing, limit the use of sensitive information, and you will not be treated worse for asking. We do not sell or share personal information as those terms are defined. We verify requests before acting on them, and you may use an authorized agent.
10.6 Everywhere else
Other states and countries grant similar rights. Ask and we will honor them.
11. International transfers
We are based in the United States and our providers process data in the United States and elsewhere. If you use Cosmoose from outside the US, your information is transferred to and processed in the US, where data protection law differs from your own. Where required, we rely on Standard Contractual Clauses for transfers out of the EEA, the UK, and Switzerland.
12. AI-generated output
Some features use AI, including the part that reads a platform error and proposes a repair. AI output can be wrong. Review anything the app drafts or changes before it goes out, and remember that you are responsible for what publishes under your name and for holding the rights to whatever you upload.
13. Children
Cosmoose is not for children. You must be at least 13, or older where your country requires it. We do not knowingly collect information from children under 13, and we delete it if we find it. Tell us at support@cosmoose.io if you believe a child has given us data.
14. Changes
We will update this policy as the product changes. Material changes get a new date at the top and, where it matters, an email or an in-app notice. Continuing to use Cosmoose after a change means you accept it.
15. Contact
Email support@cosmoose.io, or write to J1 Media Productions LLC, 8390 E Via De Ventura, Ste F-110, PMB 1034, Scottsdale, AZ 85258, USA.