Cosmic

Privacy policy

This policy covers Cosmic, run by Synchromy. Synchromy decides how the data described here is handled.

What Cosmic is

Hosted by Synchromy. Each Cosmic is private and isolated by design, with its own database.

Cosmic reads your connected tools and organises what it learns. You and your AI agents can ask questions.

What Google data Cosmic reads

Cosmic reads Google data only after you connect a Google account and grant these permissions. Each scope is asked for one reason.

calendar.events.readonly
Your calendar events, including titles, times and attendees. Cosmic creates meeting pages and records who you meet.
gmail.readonly
Your email messages and their headers, read only. Cosmic creates pages about your email contacts, their companies and discussions. It never sends, changes or deletes mail.
drive.readonly
Your Google Drive files, including Docs, Sheets and Slides, read only. Cosmic finds documents and cites them in answers. It never writes to Drive.
tasks.readonly
Your Google Tasks lists and tasks, read only. Cosmic records your commitments.

Logging in with Google also gives Cosmic your name, email address and profile picture. They are used to create your account and to check who is logging in, and for nothing else.

How that data is used

What Cosmic reads from the tools you connect goes into your own Cosmic. It is used to build pages about people, companies and meetings, and to answer the questions you and your agents ask. It is used for nothing else.

Where it is stored

In your own Cosmic, hosted on Railway, in that deployment's own database. Backups are kept as encrypted archives in object storage. No other customer's Cosmic can read it.

What Cosmic does not do

Google user data is not sold. It is not used for advertising. It is not used to train any model, ours or anyone else's.

Who else sees it

No person at Synchromy reads your Google data. The AI agents you connect read it from your own Cosmic. The only exceptions: you ask the team to look at a specific message or file, a security problem, or the law requires it.

Google user data is not shared with third parties, except the two kinds of provider Cosmic runs on, each under contract. Railway hosts your Cosmic, its database and its backups. The model providers process text on your behalf to answer your own requests; they return an answer and are bound not to use your text to train models.

Cosmic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How to disconnect and delete

You can revoke Cosmic's access at your Google account permissions page at any time.

Inside Cosmic, disconnect a Google account under Connectors, or with Change account when Cosmic names the account you just connected. Either one deletes the stored tokens, stops any further reading and removes what Cosmic read from that account.

Disconnecting an account does not remove:

  • what Cosmic read before it began recording which account each page came from, in September 2026;
  • renewal, expiry and payment dates Cosmic noted on pages about services you use;
  • the lists of addresses and services Cosmic keeps to sort your mail, and the addresses your mail was sent from, which Cosmic asks you about.

You can delete those pages yourself, and all of it goes when you ask for your Cosmic to be deleted.

To take your data with you, export your Cosmic as files. To remove it, write to [email protected] and ask for your Cosmic to be deleted. The deployment and its database go with it.

How long it is kept

What Cosmic read from Google stays in your Cosmic until you delete it, disconnect that account with Change account, or ask for the Cosmic to be deleted. Access tokens are deleted as soon as you disconnect. Encrypted backup archives age out within 30 days of a deletion.

Contact

Synchromy, [email protected]. Ask us anything about this policy, or ask us to delete your data.

Last updated 26 September 2026.