🔒privacy policy · coios

This document has not been translated yet and is shown in English.

Privacy Policy — CoiOS

Service: CoiOS hosted memory service (API at api.coios.amarbaro.tech, the CoiOS cockpit, and the @coios/mcp client) Provider: AMARBARO — see the Impressum for the provider's identity and postal address Effective date: 2026-09-08 Policy URL: https://amarbaro.com/privacy/coios

This policy covers the hosted CoiOS service only. The website amarbaro.com has its own policy. CoiOS run on your own machine (the open-source kernel, the cois CLI, the self-host option) sends nothing to us and is not covered here.

Summary

CoiOS stores notes you choose to put into a vault and lets AI tools you run recall them. To do that we hold your notes (encrypted at rest), the identity you sign in with, and a record of each API call (who called which tool, when, how much it cost — never the text of the note). We do not sell data, run advertising, or use tracking cookies. Your notes are read by our software only to answer your own requests.

The legal basis for all processing described here is the performance of our contract with you (Art. 6 (1) (b) GDPR) and, for logs kept to secure and bill the service, our legitimate interest in running it reliably (Art. 6 (1) (f) GDPR).

Data we hold

Data What exactly Why How long
Vault content The notes, files and metadata you (or tools acting for you) write into a vault, plus the search index built from them To store and recall your memory on request Until you delete the note or the vault. A deleted vault stays recoverable for 30 days, then it is purged together with its backup copy
Account A principal id, the API keys minted for it (we store only a hash of each key — the key itself is shown once and never kept), the tier you are on, grants that say which principal may use which vault To authenticate you and enforce access For the life of the account
Sign-in identity If you sign in through an identity provider such as Google: the provider's name, the stable subject id it gives us, your verified e-mail address, and the time of your last sign-in To map a sign-in to your existing account. Sign-in is link-only: we never create an account from a sign-in, and an unlinked address is refused For the life of the account
Cockpit session A random session id in an HttpOnly cookie, and a short-lived (10 minute) state cookie during sign-in To keep you signed in to the cockpit and to bind a sign-in to your browser Session: until it expires or you sign out; state: 10 minutes
Usage record Per API call: timestamp, region, vault id, principal id, tool name, cost units, latency, bytes in and out, error class, request id, number of hits returned, and the device label your client sends (if any) Metering, quotas, the cockpit's analytics cards, billing, and abuse prevention 12 months, then aggregated to daily totals without ids
Audit record Administrative actions (keys created or revoked, grants changed, vault deleted) with actor, target and time Security and accountability 12 months
Connection data The reverse proxy in front of the API records the same connection data described in the website policy (IP address, request line, status, timestamp). The API itself uses your IP address only in memory, to rate-limit sign-in attempts; it is not written to the usage record Operating and defending the service As stated in the website policy

The content of your notes never appears in usage, audit or server logs.

Where the data is

Vaults are assigned to a region when they are created and never move. Today there is one region, eu-central, on a server operated for us by Contabo GmbH in the European Union. Each vault's content is encrypted at rest with its own key, held by the region's router process. A write-through backup copy of every vault lives in the same region. Nothing is replicated outside the region.

Who else receives data

  • Your identity provider (for example Google) — only if you choose "Sign in with …". The provider learns that you signed in to CoiOS; we receive the identity data listed above. Google's handling of that sign-in is governed by Google's privacy policy.
  • Stripe — if you subscribe to a paid tier. Stripe receives your payment details and a count of your metered usage per billing period; we never see your card number. See Stripe's privacy policy.
  • Contabo GmbH — hosting provider, acting as our processor under a data processing agreement. Contabo has no key to your vault content.

No other recipients. We do not use analytics, advertising or error-reporting services inside the hosted service.

Your rights

Under the GDPR you may ask us for access to, rectification or erasure of your personal data, for restriction of processing, for a portable copy, and you may object to processing based on our legitimate interest. You may complain to a data protection supervisory authority. Write to support@amarbaro.com.

You can also act directly: every note and vault can be exported and deleted through the API and the cockpit; revoking an API key takes effect immediately; deleting a vault starts the 30-day retention window described above.

Changes

We will post changes here with a new effective date. If a change reduces your rights or adds a recipient, signed-in users are told in the cockpit before it takes effect.