Privacy Policy
1. Who we are and how to reach us
Cofelt is a cosmic social network with an AI reflection feature called Ask. This Privacy Policy explains what personal data we collect, why, the legal bases we rely on, who we share it with, how long we keep it, and the rights you have. Cofelt is offered in English to people in most countries, so this policy is written to meet the EU and UK GDPR, the California CCPA and CPRA and other US state privacy laws, and India's Digital Personal Data Protection Act 2023.
The controller responsible for your personal data is Cofelt. You can reach us by email:
- Privacy and data requests: Cofelt privacy team
- General support: Cofelt support
- Billing: Cofelt billing team
Contacting us about your data
You can contact us about your data at any time at Cofelt privacy team.
Users in the EU, EEA, and UK
Users in the EU, EEA, or UK can reach us about their personal data at Cofelt privacy team.
India contact
For users in India, questions about how we process your personal data and any grievance can be raised with our contact at Cofelt privacy team. See section 13 for the grievance process and your right to escalate to the Data Protection Board of India.
2. What we collect
We collect the minimum we need to run the service. The list below is itemised so you can see exactly what we hold and why.
Account data
- Email address (login, billing notices, transactional mail)
- Password (stored as a bcrypt hash; we never see your plaintext password)
- Display name
- Phone number, if provided (reserved for planned verification; SMS recovery and user 2FA are not currently available)
- Language and country or locale
Birth data, the input to your cosmic pattern
- Date of birth (locks after onboarding; required to compute your chart)
- Time of birth (editable up to 3 times then locks)
- Place of birth as a city, which we geocode to a latitude and longitude
Your birth date, time, and place are used to compute your chart and the supporting calculation views. We treat your birth data, and the personality, emotional, relationship, and well-being patterns we infer from it, as sensitive data. See section 5.
Computed cosmic-pattern data
- Your chart and the underlying calculation outputs
- Supporting calculation views
- Compatibility or connection results
Profile and social data
- Display photo, if you upload one
- Optional bio (free text)
- Optional cultural community or religion. This is always private, is not shown to other members, and is never used as a public filter. We process it only if you choose to enter it, and you can edit or clear your value.
- Optional intent (the kind of connections you are looking for)
- Connections you make and the relationship type you label them
- Persistent long-form Echoes you choose to release
- Text-only direct messages between you and your connections
Ask and feedback content
- Your Ask conversation messages with Xarvos, stored so you can review your history and so the AI can follow the thread of your conversation.
- Memory facts the system extracts from your conversations so the AI can remember context you have shared.
- Reactions and resonance signals (for example a thumb-up or thumb-down on an AI response).
Verification data
- Your phone number, if you provide one. SMS delivery is not yet configured, so phone verification is not presently available and the number is not a working recovery or user-2FA method.
- A birth-date confirmation method and timestamp. If you self-attest, we store that method and when you confirmed it. If you choose document verification, an identity-verification provider checks a government-issued ID on our behalf. That provider processes the ID document; we receive and store only the result and verification date. We never receive or store the ID image, and we do not collect any biometric data (see section 5).
Billing and payment data
- Your subscription tier, status, and renewal date, and your Spark Pack purchase history and balance.
- Payment records from our payment provider. Your full card number and security code are handled by the payment provider, not by us; we do not store full card details.
Device, usage, and technical data
- IP address and browser user-agent (kept for security auditing)
- Device push tokens for notifications, delivered through our app-platform and push-notification providers
- Usage and diagnostic information needed to run and secure the app
- Error and crash reports through our error-monitoring provider
Safety data
- Crisis-detection event records created when our safety system detects a possible crisis signal in a conversation, so we can surface the right help and meet our safety and legal duties (see sections 4 and 9).
Data about other people that you enter
If you enter another person's birth details to run a compatibility or connection reading, we process the birth date, time, and place you provide about that person, and the chart we compute from it, on your instruction. The source of that data is you. By entering it you confirm you are allowed to do so (see section 16). If you are the person whose details were entered and you want them removed, contact Cofelt privacy team.
AI call metadata
Every AI call writes one row to our internal AI call log. The prompt and response content are not stored in that log. We record only metadata: a timestamp, your user ID, the model name, latency, token count, cost, a quality score, and any error type. This log is kept for 60 days.
3. How we use your data and our legal bases
We use your data only for the specific purposes below. For each one we name the GDPR legal basis we rely on. Where we rely on legitimate interests, we have assessed that our interest does not override your rights, and you can object (see section 7). Where a law requires opt-in consent for a specific optional use of sensitive data, that use must not begin until the required consent has been obtained.
| What we do | Why | Legal basis (GDPR) |
|---|---|---|
| Create and run your account and sign-in | To give you the service you asked for | Performance of a contract |
| Compute your chart and supporting calculation views from your birth data | The core cosmic-pattern feature | Performance of a contract; explicit consent first if a specific element requires Art. 9 consent |
| Power Ask and the personality, emotional, and well-being patterns it reflects back to you | The Ask feature | Performance of a contract; explicit consent first where special-category processing requires it |
| Compute compatibility and connections between you and people you connect with | The matching feature | Performance of a contract; explicit consent first where required |
| Store optional cultural community or religion | Only if you choose to add it | Your choice to provide it; explicit consent where required by law |
| Hold a phone number for planned verification once SMS is configured | Future anti-fake and account-security gate; not yet available | Legitimate interest in preventing fraud |
| Verify your birth date through an identity-verification provider, if you choose to | Optional anti-fake check for the Birth Verified badge | Consent for the optional verification; legitimate interest in preventing fraud |
| Take payment and manage your subscription and Spark Packs | To provide paid features | Performance of a contract; legal obligation for records |
| Provide support and respond to your requests | To help you | Contract; legitimate interest in supporting users |
| Run safety classifiers on messages and surface crisis resources | To keep users safe and meet safety duties | Legitimate interest in safety; legal obligation; vital interests in a crisis |
| Keep the service secure and prevent abuse | Security, fraud prevention, and integrity | Legitimate interest; legal obligation |
| Measure first-party product usage to run and improve the app | To understand what works | Legitimate interest; consent where required for non-essential analytics |
| Send you optional marketing email | Only if you opt in | Consent |
How we use Ask and direct-message content specifically
- Your Ask messages are loaded into the AI's context so it can follow your conversation. Xarvos runs on our own hardware.
- A thumb-up or thumb-down signal can feed our preference-tuning process. Only the signal itself is used, never your raw chat text.
- Direct messages between you and another user are never used to train AI.
- We do not sell your data or use Ask and direct-message content to build advertising profiles. See section 4.
We will not send you marketing email without your opt-in, and you can unsubscribe from non-essential email using the link in that message.
5. Sensitive data and your choices
Some of what we process is sensitive. Under the GDPR this is called special-category data, and under California law it is sensitive personal information. We treat the following as sensitive:
- The personality, emotional, relationship, and well-being patterns Xarvos infers from your birth data and conversations. Even though a birth date, time, and place are not health data on their own, the inferences we draw can reveal information about your state of mind, so we treat them as sensitive.
- Any optional religion or cultural community you choose to add.
- Your precise birth location, which is precise geolocation data.
- Your payment-account details, held by our payment provider.
The current product does not provide one separate, all-purpose consent switch for birth-derived calculations and Ask inferences. We process those core records to provide the feature you request. Any consent control shown in the app applies only to the purpose it names, such as training data, family comparison, or anonymised research.
Religion and cultural community are optional and are processed only if you choose to enter them. They remain private and can be edited or cleared. Where a specific optional use requires separate consent by law, we will ask before activating that use; if the required consent is not available, we will not perform that optional use. You can contact Cofelt privacy team about a consent or sensitive-data request. A change does not affect processing already carried out lawfully. California residents can also use the "Limit the use of my sensitive personal information" right in section 8.
Note for India: India's Digital Personal Data Protection Act does not have a separate sensitive-data category, so all of the above is personal data under that law and is handled under the lawful bases and choices described above. Data about children is specially protected (see section 10).
6. AI, automated processing, and what the readings are
Xarvos is an AI system, not a human. It is not a therapist, doctor, or any other licensed professional. We tell you this clearly inside the chat at the start of your first conversation, and you can ask at any time. AI-generated text in the app is produced by software.
Xarvos processes your conversation and, when relevant to the question, calculated pattern data to generate a response. It can explain an interpretive method and reflect patterns back to you. It does not predict the future and does not make guarantees. The quality of any reading depends on the accuracy of the birth date, time, and place you provide.
Our readings, matching, and safety prompts are designed to inform and support your own choices, not to make decisions for you. We do not use them to make a legal or similarly significant decision about you by purely automated means. Our crisis-detection feature flags a possible risk so we can surface help; it does not make a binding decision about you. If you believe an automated output has affected you and you want a person to look into it, contact Cofelt privacy team and we will arrange human review and let you share your point of view.
See section 9 for the important non-advice and safety disclaimers, and our Terms of Service for the full statement.
7. Your rights
If you are in the EEA, the UK, or Switzerland (GDPR)
- Access (Art. 15). Get a copy of the personal data we hold about you.
- Rectification (Art. 16). Correct inaccurate data. Birth-date and birth-time fields have edit limits to protect calculation integrity; if you need a correction beyond the in-app limits, contact us.
- Erasure (Art. 17). Ask us to delete your account and associated data.
- Restriction (Art. 18). Ask us to pause certain processing.
- Portability (Art. 20). Get your data in a machine-readable format.
- Object (Art. 21). Object to processing based on legitimate interests.
- Withdraw consent. Where we rely on consent, withdraw it at any time without affecting prior lawful processing.
- Complain. Lodge a complaint with a supervisory authority. UK users can contact the Information Commissioner's Office. EU users can contact their local data-protection authority.
If you are a California resident (CCPA and CPRA)
- Know the categories and specific pieces of personal information we collect, use, and disclose, looking back 12 months.
- Delete the personal information we hold, subject to legal exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information. At the effective date of this policy, we do not sell personal information or share it for cross-context behavioural advertising, so there is currently nothing to opt out of. We honour the Global Privacy Control signal as an opt-out preference.
- Limit the use of your sensitive personal information (see section 8).
- Non-discrimination. We will not deny you service, change your price, or lower quality because you exercised a right.
Other US states
If you live in another US state with a comprehensive privacy law, you have broadly similar rights, including opting out of targeted advertising and profiling. We do not currently use personal data for either purpose. In many states, you also have the right to appeal a decision on your request. To appeal, reply to our decision or email Cofelt privacy team. Where a state requires us to honour a universal opt-out signal such as the Global Privacy Control, we do.
Consumer health data (Washington, Nevada, and similar)
Because conversations with Xarvos can touch well-being topics, some data we hold may be treated as consumer health data in some US states. Cofelt is not a health service and does not sell this data. Where a specific use or disclosure requires opt-in consent, that use or disclosure must not begin until the required consent is obtained. Contact Cofelt privacy team to exercise the rights that apply where you live.
If you are in India (DPDP Act)
- Access and summary. Get a summary of the personal data we process and the processing activities, and the identities of any other parties we have shared it with.
- Correction and erasure. Correct, complete, update, or erase your personal data.
- Grievance redressal. Raise a grievance with us (see section 13).
- Nominate. Nominate another person to exercise your rights if you die or become incapacitated. Contact us to set this up.
Other regimes such as Brazil's LGPD, Canada's PIPEDA, and Australia's Privacy Act give broadly equivalent rights, and we honour them.
8. How to exercise your rights and privacy choices
You have more than one way to reach us, and self-serve tools in the app:
- Export your data: Settings, then Privacy, then Export. This produces a machine-readable copy of the main account, profile, birth, chart, reading, Ask, memory, connection, Echo, DM, Spark, subscription, refund, support, and bounded activity records associated with you. High-volume activity lists can be truncated and the file says when that occurs. Passwords, authentication secrets, embeddings, internal safety or crisis records, and internal moderation or report records are excluded. The app calls
GET /api/users/me/export. - Delete your account: Settings, then Delete account. The app calls
POST /api/users/me/request-deletion. This records a request and starts a 30-day processing window; it does not immediately hide the profile, stop account activity, or cancel a subscription. Cancel renewal separately through your billing provider. After the window, the deletion job removes data covered by the normal account process, subject to the legal and safety records described in sections 9 and 14. - Correct your data: Most fields are editable in Settings, then Profile. For birth-data corrections beyond the in-app limits, email Cofelt privacy team.
- Withdraw a named consent, object, restrict, limit sensitive data, or anything else: use a Settings control where it is shown for that specific purpose, or email Cofelt privacy team.
We respond within the time the law allows, which is generally one month in the EU and UK and 45 days in California, and we will tell you if we need a permitted extension. We verify your identity before we act on a request, to protect your account. Searches for your data are reasonable and proportionate. If an authorised agent makes a request for you, we may ask for proof of their authority.
If you are unhappy with how we handle a request, you can complain to a supervisory authority: your EU data-protection authority, the UK Information Commissioner's Office, the California Privacy Protection Agency, or the Data Protection Board of India, depending on where you live.
9. Safety, crisis support, and non-advice
Cofelt is for self-understanding and reflection. It is not medical, psychological, psychiatric, financial, legal, or other professional advice, and it is not a diagnosis or treatment. Xarvos is an AI system, not a human, therapist, or doctor. Always seek a qualified professional for advice, and do not delay or disregard professional advice because of something in the app.
Our safety system looks for signals of crisis, such as self-harm or suicidal thoughts, in conversations. If it detects such a signal, the app surfaces a crisis hotline appropriate to your country so you can reach real help. Cofelt is not an emergency service and cannot provide emergency help. If you or someone else is in danger, contact your local emergency number or a crisis hotline right away.
When the safety system flags a possible crisis, we create a crisis-detection event record. To meet our safety and legal duties, we keep these records for about 7 years, and they are excluded from the normal account-deletion process. This is one of the limited legal and safety retentions described in sections 8 and 14. We keep these records secure and use them only for safety, integrity, and legal purposes.
10. Children and age
Cofelt is only for people aged 18 and over. This is because the service involves payments and reflective AI content. The service is not offered to anyone under 18; if we learn that an account belongs to a younger person, we close it and handle the data as described below.
We require a birth date and use it to enforce the age requirement before an account can continue into the adults-only service. We do not run behavioural tracking, profiling, or targeted advertising aimed at children.
We design with the needs of younger users in mind, in line with the UK children's code and similar standards, in case a younger person reaches the service despite our age limit. If you believe someone under 18 has created an account, please email Cofelt privacy team and we will remove it. In India, the law sets the threshold at 18 and requires verifiable parental or guardian consent for anyone below it; our policy is to block under-18 accounts rather than process children's data.
12. International data transfers
Cofelt is a global service, and some of our providers are based in other countries, including the United States. This means your personal data may be transferred to and processed in countries outside your own.
- For transfers of EU and UK personal data to countries without an adequacy decision, we use approved safeguards, namely the European Commission's Standard Contractual Clauses and the UK International Data Transfer Agreement or Addendum.
- Where a provider is certified under the EU-US or UK-US Data Privacy Framework, we may rely on that adequacy framework.
- For users in India, your personal data may be processed outside India by the providers listed in section 4. Such transfers are permitted except to any country the Indian government restricts, and we will honour any such restriction.
You can ask for a copy of the relevant safeguards by emailing Cofelt privacy team. We transfer data only to operate the service, never to sell it.
13. Complaints and grievance redressal
If you have a concern or complaint about how we handle your personal data, please contact us first so we can put it right. Email Cofelt privacy team, or use the privacy contact in your settings. You can reach us electronically.
We will acknowledge your complaint within 30 days and respond without undue delay. For users in India, this is also our grievance-redressal channel under the Digital Personal Data Protection Act. Please use it before escalating.
If we cannot resolve your complaint, you can escalate:
- EU users: to your local data-protection authority.
- UK users: to the Information Commissioner's Office.
- California users: to the California Privacy Protection Agency or the Attorney General.
- India users: to the Data Protection Board of India.
14. Data retention
We keep your data only as long as we need it for the purpose we collected it, or as the law requires. The table below sets out the main periods.
| Data | Retention |
|---|---|
| Account and profile data | Until an account-deletion request is processed after the 30-day window |
| Birth data and computed charts | Until an account-deletion request is processed after the 30-day window |
| Ask history and memory facts | Until removed through an available feature or the account-deletion process |
| Echoes | Until you remove them or close your account, subject to safety and legal retention duties |
| Direct messages | While the account and conversation records remain active; the current interface has no self-service DM delete or unsend |
| AI call log (metadata only) | 60 days |
| Server access logs (IP and user-agent) | Kept short-term for security, then purged |
| Processing and security logs | About 1 year, for security and to meet legal duties |
| Billing and payment records | Up to 7 years, as tax and accounting law requires |
| Crisis-detection event records | About 7 years, for safety and legal reasons; excluded from the normal delete |
When you request account deletion:
- The request is recorded and a 30-day processing window begins.
- During that window the account may remain usable; the request does not itself hide the profile, stop AI calls, or cancel billing. Cancel renewal separately through your billing provider.
- After day 30 the deletion job removes data covered by the normal account process from primary systems.
- Backup copies expire on their normal rolling schedule after that.
Limited legal and safety records can survive account deletion. These include billing records required for accounting and crisis, security, or moderation records retained for the periods described above.
15. Security and data breaches
We use technical and organisational measures appropriate to the risk, including:
- Connections served over TLS in production
- Passwords stored as bcrypt hashes
- Encrypted-at-rest database storage; backup copies are encrypted before offsite transfer
- Access controls and a separated admin authentication realm, with admin two-factor authentication
- Rate limiting on login, signup, password reset, and Ask
- Audit logging for admin actions
- Restricted infrastructure access through protected channels
If you discover a vulnerability, please email Cofelt support so we can investigate.
If a personal-data breach is likely to affect you, we will notify you and the relevant authorities as the law requires. In the EU and UK we notify the supervisory authority within 72 hours where required, and in India we notify affected users and the Data Protection Board with a follow-up within about 72 hours.
16. Data you enter about other people
Cofelt lets you enter another person's birth details to run a compatibility or connection reading. If you do this, you confirm that you are allowed to enter that information and that you have any consent needed from that person. We process the data on your instruction to produce the reading you asked for.
We act as the controller of that information. If you are a person whose birth details were entered by someone else and you want them corrected or deleted, or you want to know what we hold, email Cofelt privacy team and we will help, subject to verifying who you are.
17. Changes to this policy
We may update this Privacy Policy as the product evolves or as the law changes. We review it at least once a year.
For material changes, meaning anything that affects your rights, what data we collect, who we share it with, or how we use it:
- We will tell you in advance, by email or an in-app notice.
- Where a change adds a new purpose for your data, we will ask for fresh consent if the law requires it.
For non-material changes, such as typos, clarifications, or formatting, we update the "Last updated" date below.
If you do not accept a change, you can delete your account at any time without penalty.
18. Contact
For privacy questions and to exercise your rights:
- General support: Cofelt support
- Billing: Cofelt billing team
The controller responsible for your personal data, and how to contact us about it, are set out in section 1.
