Privacy Policy
Free readiness assessments
We use your name, company and verified email to give you private access to your report. When you submit a book, Cosmolabe’s founder receives your contact details, the context you provide and a summary of the files and results. The email does not include raw book rows. This does not enroll you in marketing email.
Assessment files and reports are kept for 30 days from your first saved import. You can delete them from the assessment page sooner. An unused assessment expires after seven days. Access links expire after 20 minutes; browser access lasts up to seven days. Deleted or expired assessments cannot be opened. Routine database backups follow the backup retention policy; an email already sent cannot be recalled.
1. Scope
This policy explains what Cosmolabe collects, how we use it, and your choices. It covers the Cosmolabe website and application, and the customer-facing pages contractors present under their own name — online enrollment, coverage lookup, and claim forms. Cosmolabe is a business-to-business service: contractors are our customers, and where a homeowner's information reaches us — typed by the contractor's staff, or by the homeowner on one of those pages — we process it on the contractor's behalf, to run their warranty program.
2. What we collect
- Account data — your email, password (stored only as a one-way hash), your role, and the company you act for. If you enable two-factor authentication, the authenticator secret needed to verify your codes.
- Customer Data you upload — units (installed systems) and claims/jobs, and pricing inputs. This may include equipment, dates, costs, and ZIP codes. Do not upload data you lack the right to use.
- Warranty records — when a contractor sells and services warranties through Cosmolabe: the contract holder's name, service address, phone and email; covered-equipment details; and the claims filed against each contract, including notes describing the failure.
- Consent records — where a homeowner agrees to be contacted, we keep the record that proves it: the channel, the wording shown, when, the IP address it was captured from, and who captured it. This record exists to protect the homeowner — it is the evidence a contact-consent dispute turns on.
- Complaint records — a complaint's channel, the consumer's name and state, and its resolution, kept because regulators may ask.
- Business profile — the contractor's trading name, contact details, and business postal address (required by law on any commercial email sent in their name).
- Usage & technical data — logs, IP address, and basic request metadata used to operate and secure the service, including a per-tenant audit trail recording who performed each significant action, from where.
We maintain an inventory of every database column that holds personal data, checked mechanically against the application's schema on every release — a new personal-data field cannot ship unclassified.
3. How we use it
- To provide the service — price warranties, run analytics, and produce rate sheets for you.
- To secure the service and prevent abuse.
- To improve pooled pricing (credibility weighting) — only for tenants that have explicitly consented, and only in aggregated, de-identified form.
- To send service messages — claim status updates, contract documents, workspace invitations. These are transactional. We send no marketing messages today; any future marketing email would carry sender identification, a postal address, and a working opt-out, as federal law requires, and would never override a homeowner's recorded contact preferences.
4. Pooling and sharing
We do not sell your data. Your Customer Data is isolated per tenant. Cross-company pooling is opt-in: if you consent, your experience contributes to shared, credibility-weighted aggregates — never in a form that identifies your company to another. We share data with service providers only as needed to run the service (see Sub-processors), and when required by law.
5. Sub-processors
We use Amazon Web Services (hosting, database, and email delivery) and, for payments when enabled, Stripe. We never send your card details to our servers — payment entry is handled by the payment provider.
When the optional AI assistant is enabled for your workspace, Anthropic processes what is needed to answer: the questions your staff type and summaries of your own tenant's records that the answer requires. Two narrower uses exist during imports and claims: unresolved spreadsheet column headers and unrecognised equipment-type labels (never customer rows) may be sent to suggest mappings, and a claim's failure description may be sent to suggest which repair line it matches — never the claim's dollar amount, and never the customer's identity. All of this is optional: without it configured, every feature falls back to its non-AI path. These providers process data on our behalf under their own security and privacy commitments.
6. Security
Traffic is encrypted in transit (HTTPS). Passwords are stored as salted, memory-hard hashes; session and reset tokens are stored only as hashes. Access is tenant-scoped, authenticated, and permissioned by role, with an audit trail of significant actions. Two-factor authentication is available to every account and required for platform-administrator access. Application pages run under a Content-Security-Policy that blocks injected script. No method is perfectly secure, but we apply reasonable, layered controls.
7. Retention
We keep Customer Data while your account is active and as needed to provide the service. On termination you may request an export within a reasonable window before deletion. We retain limited records as required for legal, security, and accounting purposes.
8. Your choices
You control what you upload and whether you consent to pooling (and can revoke it). You may request access to, correction of, or deletion of your data, subject to legal limits, by contacting us.
If you are a homeowner: your warranty is with your contractor, and they control the records of it. Direct requests about your information to them first — we assist them in fulfilling those requests. A consent you gave to be contacted can be withdrawn at any time, and withdrawing it never affects your coverage or your claims.
9. Changes
We may update this policy; material changes will be posted here with a new "last updated" date.
10. Contact
Privacy questions or requests: tanner@cosmolabe.ai.