This document has not been translated yet and is shown in English.
Service: CoiOS hosted memory service (API at api.coios.amarbaro.tech, the CoiOS cockpit, and the @coios/mcp client)
Provider: AMARBARO — see the Impressum for the provider's identity and postal address
Effective date: 2026-09-08
Policy URL: https://amarbaro.com/privacy/coios
This policy covers the hosted CoiOS service only. The website amarbaro.com has its
own policy. CoiOS run on your own machine (the open-source kernel,
the cois CLI, the self-host option) sends nothing to us and is not covered here.
CoiOS stores notes you choose to put into a vault and lets AI tools you run recall them. To do that we hold your notes (encrypted at rest), the identity you sign in with, and a record of each API call (who called which tool, when, how much it cost — never the text of the note). We do not sell data, run advertising, or use tracking cookies. Your notes are read by our software only to answer your own requests.
The legal basis for all processing described here is the performance of our contract with you (Art. 6 (1) (b) GDPR) and, for logs kept to secure and bill the service, our legitimate interest in running it reliably (Art. 6 (1) (f) GDPR).
| Data | What exactly | Why | How long |
|---|---|---|---|
| Vault content | The notes, files and metadata you (or tools acting for you) write into a vault, plus the search index built from them | To store and recall your memory on request | Until you delete the note or the vault. A deleted vault stays recoverable for 30 days, then it is purged together with its backup copy |
| Account | A principal id, the API keys minted for it (we store only a hash of each key — the key itself is shown once and never kept), the tier you are on, grants that say which principal may use which vault | To authenticate you and enforce access | For the life of the account |
| Sign-in identity | If you sign in through an identity provider such as Google: the provider's name, the stable subject id it gives us, your verified e-mail address, and the time of your last sign-in | To map a sign-in to your existing account. Sign-in is link-only: we never create an account from a sign-in, and an unlinked address is refused | For the life of the account |
| Cockpit session | A random session id in an HttpOnly cookie, and a short-lived (10 minute) state cookie during sign-in |
To keep you signed in to the cockpit and to bind a sign-in to your browser | Session: until it expires or you sign out; state: 10 minutes |
| Usage record | Per API call: timestamp, region, vault id, principal id, tool name, cost units, latency, bytes in and out, error class, request id, number of hits returned, and the device label your client sends (if any) | Metering, quotas, the cockpit's analytics cards, billing, and abuse prevention | 12 months, then aggregated to daily totals without ids |
| Audit record | Administrative actions (keys created or revoked, grants changed, vault deleted) with actor, target and time | Security and accountability | 12 months |
| Connection data | The reverse proxy in front of the API records the same connection data described in the website policy (IP address, request line, status, timestamp). The API itself uses your IP address only in memory, to rate-limit sign-in attempts; it is not written to the usage record | Operating and defending the service | As stated in the website policy |
The content of your notes never appears in usage, audit or server logs.
Vaults are assigned to a region when they are created and never move. Today there is
one region, eu-central, on a server operated for us by Contabo GmbH in the European
Union. Each vault's content is encrypted at rest with its own key, held by the region's
router process. A write-through backup copy of every vault lives in the same region.
Nothing is replicated outside the region.
No other recipients. We do not use analytics, advertising or error-reporting services inside the hosted service.
Under the GDPR you may ask us for access to, rectification or erasure of your personal data, for restriction of processing, for a portable copy, and you may object to processing based on our legitimate interest. You may complain to a data protection supervisory authority. Write to support@amarbaro.com.
You can also act directly: every note and vault can be exported and deleted through the API and the cockpit; revoking an API key takes effect immediately; deleting a vault starts the 30-day retention window described above.
We will post changes here with a new effective date. If a change reduces your rights or adds a recipient, signed-in users are told in the cockpit before it takes effect.