Privacy policy
This policy covers Cosmic, run by Synchromy. Synchromy decides how the data described here is handled.
What Cosmic is
Hosted by Synchromy. Each Cosmic is private and isolated by design, with its own database.
Cosmic reads your connected tools and organises what it learns. You and your AI agents can ask questions.
What Google data Cosmic reads
Cosmic reads Google data only after you connect a Google account and grant these permissions. Each scope is asked for one reason.
- calendar.events.readonly
- Your calendar events, including titles, times and attendees. Cosmic creates meeting pages and records who you meet.
- gmail.readonly
- Your email messages and their headers, read only. Cosmic creates pages about your email contacts, their companies and discussions. It never sends, changes or deletes mail.
- drive.readonly
- Your Google Drive files, including Docs, Sheets and Slides, read only. Cosmic finds documents and cites them in answers. It never writes to Drive.
- tasks.readonly
- Your Google Tasks lists and tasks, read only. Cosmic records your commitments.
Logging in with Google also gives Cosmic your name, email address and profile picture. They are used to create your account and to check who is logging in, and for nothing else.
How that data is used
What Cosmic reads from the tools you connect goes into your own Cosmic. It is used to build pages about people, companies and meetings, and to answer the questions you and your agents ask. It is used for nothing else.
Where it is stored
In your own Cosmic, hosted on Railway, in that deployment's own database. Backups are kept as encrypted archives in object storage. No other customer's Cosmic can read it.
What Cosmic does not do
Google user data is not sold. It is not used for advertising. It is not used to train any model, ours or anyone else's.
Who else sees it
No person at Synchromy reads your Google data. The AI agents you connect read it from your own Cosmic. The only exceptions: you ask the team to look at a specific message or file, a security problem, or the law requires it.
Google user data is not shared with third parties, except the two kinds of provider Cosmic runs on, each under contract. Railway hosts your Cosmic, its database and its backups. The model providers process text on your behalf to answer your own requests; they return an answer and are bound not to use your text to train models.
Cosmic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Answering by voice
When you answer Cosmic's first-session questions by voice, Cosmic sends your audio to Soniox to transcribe it into text. Cosmic keeps the transcribed words in your own Cosmic. Cosmic does not store your audio.
How to disconnect and delete
You can revoke Cosmic's access at your Google account permissions page at any time.
Inside Cosmic, disconnect a Google account under Connectors, or with Change account when Cosmic names the account you just connected. Either one deletes the stored tokens, stops any further reading and removes what Cosmic read from that account.
Disconnecting an account does not remove:
- what Cosmic read before it began recording which account each page came from, in September 2026;
- renewal, expiry and payment dates Cosmic noted on pages about services you use;
- the lists of addresses and services Cosmic keeps to sort your mail, and the addresses your mail was sent from, which Cosmic asks you about.
You can delete those pages yourself, and all of it goes when you ask for your Cosmic to be deleted.
To take your data with you, export your Cosmic as files. To remove it, write to [email protected] and ask for your Cosmic to be deleted. The deployment and its database go with it.
How long it is kept
What Cosmic read from Google stays in your Cosmic until you delete it, disconnect that account with Change account, or ask for the Cosmic to be deleted. Access tokens are deleted as soon as you disconnect. Encrypted backup archives age out within 30 days of a deletion.
Contact
Synchromy, [email protected]. Ask us anything about this policy, or ask us to delete your data.
Last updated 30 September 2026.
