Privacy Notice

Effective 2026-08-18

cozysocials Privacy Notice Version draft-2026-08-18. Effective 2026-08-18. Contact: legal@metalabworks.co. DRAFT FOR REVIEW. This is a working draft, not final and not legal advice. A lawyer will review it before launch. This Notice explains what personal data cozysocials collects, why, how long it is kept, and your rights. It is written to be read alongside the Terms of Service. 1. Who is responsible The controller of your personal data is Metalabworks, the operator of cozysocials, identified in the Terms of Service. You can reach the operator at legal@metalabworks.co. 2. What we collect Account data: your name, email address, an optional profile photo, and the content you create or upload. Usage data: information needed to run the app, such as project membership and activity. Acceptance evidence and abuse-prevention signals: when you accept the Terms of Service, and when needed to keep the service secure, we record the exact agreement and its hash, your account identifier, your verified email at the time, the date and time, your IP address, your browser's user agent, and a device signal we derive from your browser (for example screen size, time zone, language, and platform, combined into a single value). We do not use a third-party tracking or fingerprinting service, we do not use these signals for advertising or to track you across other websites, and this collection runs without any third-party script. 3. Why we collect it, and our lawful bases To provide the service you asked for. To keep the service secure and to prevent abuse and fraud. The AI features cost real money to run, so we use signals such as your IP address and the device signal to detect and prevent abuse, including one person creating multiple or automated accounts to get around usage limits. This rests on our legitimate interest in protecting the service, and we use these signals only for security and abuse prevention, never for advertising. To establish, exercise, or defend legal claims. The acceptance evidence in particular is collected so that, if a dispute arises, we can show that you agreed to the Terms. Where the law requires consent, we ask for it. 4. IP address and attribution, stated plainly An IP address identifies a network connection, not a specific person, and under shared-address networks it may be common to several users. We record it as supporting evidence together with the time, not as proof of identity. The stronger proof that you accepted is your signed-in, verified account and your typed name at the time of acceptance. 5. How long we keep it Account and content data are kept while your account is active and for a reasonable period afterward, unless you ask us to delete them sooner. Images you attach in AI chat are stored as files for up to 3 months, then deleted automatically. Images the AI generates for you are kept for up to 6 months. When an image is attached, the AI writes a short text description of it, and that description stays with the chat as its record, including after the image file expires, and is what the AI reads on later turns. During AI processing, a hidden planning note about your request may also be produced by a second AI model and stored with the reply. Deleting a chat deletes its image files together with its messages. When you delete a chat, we remove it from your account and you cannot restore it. We do not keep a copy of every deleted chat. We keep a copy only where there is a specific reason to, for example an abuse or infringement report about that content, a security investigation, or a legal preservation duty or request from an authority. Where we do keep a copy, it stays out of your account, it is not used to run the service, and it is deleted once the reason for keeping it ends, normally within 30 days. A legal hold can require us to keep it for longer, and in that case we keep it until the matter is resolved. Acceptance evidence is kept for up to ten (10) years after your most recent acceptance, or longer while a related dispute or legal hold is active, so that we can establish, exercise, or defend legal claims. This means we may keep your proof of acceptance even after you delete your account or other data. The final retention figure is confirmed with legal review. 6. Who we share it with We use trusted service providers to run the app, including cloud hosting and storage (for example Google Firebase and Google Drive) and our AI providers. We do not sell your personal data. Some providers may process data outside the Philippines. Data we obtain from connected Google services, including Google Calendar, is never shared with our AI providers or any other third party; see section 7. 7. Connected Google services If you connect a Google account, we act only within what you approve on Google's consent screen, and you can withdraw it at any time in your Google account or by disconnecting in the app. How we access it: through Google's official APIs, using a token you grant us. We never ask for or store your Google password. What we access, and why: for Google Calendar, we read the calendars and events you choose so your planner can show your existing commitments behind your time blocks, and we create and manage one calendar named "Cozy Planner" that holds a copy of the blocks you make in the app. We ask only for permission to read your calendars and to manage calendars this app created. We do not ask for, and cannot obtain, permission to change your other calendars or the meetings in them. How we store it: to keep the planner usable offline and quick to open, we cache the events from the calendars you selected, including their titles, dates and times, in your own private area of our database, readable only by your signed-in account. Your access tokens are held encrypted on our servers and are never sent to your browser. How long we keep it: the cached events stay until you disconnect. Disconnecting Google Calendar deletes that cache from our database. It deliberately does not delete the "Cozy Planner" calendar from your Google account: that calendar and its events remain yours, and you can remove them in Google if you want to. How we share it: we do not. Google Calendar data is not sold, not shared with any third party, not used for advertising, and not used to train any AI model. It is used only to provide the planner feature to you. 8. Security We restrict access to personal data, store acceptance evidence in server-only records that the app's own users cannot read or change, and take reasonable measures to protect it. No system is perfectly secure. If a data breach affects your personal data, we will act on it and give any notices the law requires. 9. Your rights Subject to law, you may ask to access, correct, or delete your personal data, object to or restrict certain processing, and withdraw consent where processing is based on consent. To make a request, email legal@metalabworks.co. Some data, such as acceptance evidence, may be retained where the law allows us to keep it to defend legal claims, and we will tell you when that applies. 10. Deletion requests We do not offer automated account deletion. A deletion request is handled manually by the operator, who removes your operational data from our systems and from the Drive archive, except for the limited legal evidence described above. Because deletion depends in part on provider systems, it may take time to complete. To request deletion, email legal@metalabworks.co. 11. Changes to this Notice We may update this Notice. Material changes will be made visible in the app. 12. Contact For privacy questions or requests, email legal@metalabworks.co.