Cosmo — Privacy Notice
Version 1.9 · Effective [to be completed: effective date]
Draft for legal review. This notice describes what the current version of Cosmo actually does. It has not been reviewed or certified by a lawyer. Items marked [OWNER REVIEW] must be completed by the owner.
Cosmo is developed by hackerlumu. Contact: [to be completed: contact e-mail or address].
The short version
- Cosmo works on your PC. Its companion features, such as media, coding activity, network, battery, focus, tasks and notes, are processed locally.
- Cosmo has no telemetry, analytics or tracking. It does not send us usage data. It has no account system. Once a day it may ask Cosmo's release server whether a newer version exists; you can turn that off, and updates install only when you click.
- Cosmo does not sell your data.
- The one time your content leaves your PC because of Cosmo: when you use AI Chat with a cloud provider you chose. Then your message and any file you attach go to that provider.
- Cosmo's built-in Buddy Core and the optional Cosmo Local model answer Chat on your PC; that chat is not sent anywhere.
- Optional voice: Cosmo listens when you press the mic — or, only if you turn on “Hey Cosmo”, a small detector on your PC listens for that phrase. Speech is turned into text on your PC; your voice is never recorded, kept or uploaded.
Local features (processed on your PC)
Each of these can be changed in Settings › Privacy (except battery, which is always local and has no setting).
Media awareness (on by default; switchable)
- What it reads: the playback status and the details Windows exposes for media sessions — title, artist, album, whether Windows reports music or video, artwork, and which app is playing.
- Finer switches: show media in Cosmo, music reactions, video reactions, artwork (off: never read), source app.
- What it does not read: browser history, web pages, cookies, passwords or URLs.
- When it is off: nothing is read, shown or kept.
Coding-agent integration (detection on by default; connecting is your choice)
- Detection: looks for supported tools (Claude Code, Codex) in their usual folders.
- Connecting happens only when you choose it. Cosmo then adds its own hook entries to that tool's settings, shows you the change first, and makes a dated backup.
- Once connected: the tool sends Cosmo events about its work (for example a step name, a file name or a command it runs, a permission request) through a local channel limited to your Windows user. Cosmo shows them; it never approves a permission without your click.
Network usage (on by default; switchable)
- What it reads: local byte counters of your network adapters, for speed and totals.
- What it does not read: traffic content, websites or addresses.
Active app awareness (off by default)
- What it reads: the name of the application in front, such as "VS Code". Never window contents, pages or URLs.
Notification access (off by default; Windows may also ask)
- What it reads: the app name and first line of your current Windows notifications, shown in Orbit only while you look.
- Storage: never stored.
Game detection (off by default)
- What it reads: the name of the app in front and whether it is fullscreen, and, every few seconds, the names of running programs, to notice a known game running in the background.
- Storage: the program names of games seen fullscreen are remembered on your PC, so Cosmo recognises them later. They are deleted with the rest of Cosmo's settings.
- What it does not do: read the screen or the game's memory, inject code or interact with anti-cheat software.
Battery and power (always local)
- What it reads: battery level, charging state and battery saver, to show Cosmo's battery reactions. On PCs without a battery, nothing is shown.
Focus, tasks and notes: stored only in your Windows profile (%APPDATA%\Cosmo).
Files you drop on Cosmo: copied into Cosmo's local inbox (%LOCALAPPDATA%\Cosmo\inbox). They go nowhere unless you ask about them in Chat.
Preferences and log
- Preferences: saved in %APPDATA%\Cosmo.
- Log: a small local log (%LOCALAPPDATA%\Cosmo\cosmo.log) records technical events, such as which kind of event happened and Cosmo's state. It never records media titles or chat content.
Buddy Core (always on): Cosmo's built-in companion replies to everyday Chat messages, such as hello, thanks, the time, battery, network, tasks, focus and what's playing. It runs on your PC from what Cosmo already shows; nothing is sent.
Cosmo Local (optional; off until you download a model)
- What it is: a small open language model that runs on your PC through the llama.cpp runtime installed with Cosmo. Your Chat messages are processed on your PC and are not sent to an AI provider.
- Download: only when you click Download. Cosmo then fetches the model file over HTTPS from Hugging Face (huggingface.co and its download servers). Hugging Face sees an ordinary download request (your IP address and the file asked for). Cosmo checks the file against its published fingerprint (SHA-256) before using it.
- Storage: model files are kept in %LOCALAPPDATA%\Cosmo\models until you remove them in Settings › AI.
- While running: the model listens only on this PC (127.0.0.1), protected by a random key, with no network access of its own, and stops when not in use.
- Graphics card: if your PC has a dedicated graphics card with enough free video memory, the model may run on it (through Vulkan) — still entirely on your PC. Cosmo reads how much video memory is free to decide; nothing is sent.
Cosmo Voice (optional; off until you turn it on)
- Listening: the microphone opens when you press the mic button, the Talk button or your push-to-talk shortcut, and closes when you stop talking, after 15 seconds, or when you press again. While it is open, Cosmo always shows "Listening…".
- “Hey Cosmo” (off unless you turn it on): when enabled, a lightweight wake detector on this PC listens for the phrase “Hey Cosmo” — only that phrase. It keeps a few seconds of audio in memory to check it and discards it continuously. To recognise different voices and accents, each short phrase spoken near the PC (up to about six seconds) is also turned into text by Cosmo's own speech recogniser on this PC and compared with “Hey / Hi / Hello Cosmo”; that text is dropped straight away unless it is the wake phrase (then anything said after it becomes your first question). Nothing is recorded, written to disk, sent to us, sent to an AI provider or uploaded anywhere; Cosmo's log keeps only whether a phrase matched, never the words. While it runs, Windows shows its own microphone-in-use icon. It pauses while a game is in front (unless you allow it), in battery saver, on battery if you choose, and while Cosmo itself is speaking. Only after the phrase is heard does Cosmo start a normal voice turn, shown with "Listening…". During setup Cosmo measures the room's noise level for a few seconds and keeps only that number. If you use “Teach Cosmo my voice”, Cosmo keeps only a sensitivity number worked out from how strongly the detector reacted — never the audio, the words or a voiceprint; “Reset” clears it. You can turn it off any time in Settings › AI › Voice.
- Permission: Cosmo asks for the microphone only after you turn voice on, and Windows' own microphone privacy setting always applies.
- Speech recognition: on your PC, with whisper.cpp installed with Cosmo, running on this PC only (127.0.0.1). The audio is kept in memory just long enough to be turned into text, then discarded. It is never saved to disk, never uploaded and never sent to an AI provider. The log records only how many characters were recognised, never the words.
- What happens to the text: it is placed in the Chat box (or sent, if you chose "Send automatically after speech") and is then treated like anything you type: answered on your PC by Buddy Core or Cosmo Local, or, if you use a cloud provider, sent to that provider as text.
- Download: a speech model is fetched over HTTPS from Hugging Face only when you choose one, checked against its published fingerprint (SHA-256), and kept in %LOCALAPPDATA%\Cosmo\voice until you remove it.
- Spoken replies: read aloud on your PC — by a voice installed in Windows (System Voice), or by Cosmo Natural Voice if you choose it — at Cosmo's own volume. Cosmo never changes the Windows volume.
- Cosmo Natural Voice (optional): a speech model that runs on this PC. When you click to set it up, Cosmo downloads the model and voice files from Hugging Face and two pronunciation dictionaries from GitHub (raw.githubusercontent.com), over HTTPS, from pinned versions checked by SHA-256. Those services see an ordinary download request (your IP address and the files asked for). The files are kept in %LOCALAPPDATA%\Cosmo\natural until you remove them; the text Cosmo speaks never leaves your PC.
- Interrupting Cosmo: while Cosmo speaks, if "Allow interruption" is on, the microphone is watched for loudness only (with echo cancellation), so that you can talk over Cosmo; nothing is recorded, and only when you start speaking does a normal voice turn begin.
Live security information (only when you ask)
- When you ask about current cybersecurity events ("latest cyber attacks…"), Cosmo fetches the public news and advisory feeds of the UK National Cyber Security Centre (ncsc.gov.uk), CISA (cisa.gov) and CERT-EU (cert.europa.eu) over HTTPS. Nothing about you or your question is sent — only an ordinary request for each public feed (those sites see your IP address).
- The latest results (up to 40 headlines with their links) are kept in %LOCALAPPDATA%\Cosmo\live-cyber.json, so that offline Cosmo can show "the latest I synced at …" — always labelled with its time, never as live.
- Content is shown with its source: NCSC under the Open Government Licence v3.0, CERT-EU under CC BY 4.0, CISA as published.
API keys: stored in Windows Credential Manager. Each key is only ever sent to its own provider. Cosmo shows only its last four characters.
Optional external feature: AI Chat with a cloud provider
Chat uses a cloud provider only after you choose one and add your own key or endpoint. Supported providers include OpenAI, Anthropic, Google Gemini, OpenRouter, and an OpenAI-compatible endpoint you configure.
What is sent
- When you send a Chat message: the text you typed, the earlier messages of that conversation, and any file you explicitly attached.
- These go directly from your PC to the provider you selected.
What is not sent automatically: your apps, media or show titles, network usage, battery, tasks, notes, coding activity or notifications.
Third-party processing: the provider processes your content under its own terms and privacy policy, which Cosmo does not control. Check those policies before you use a provider.
"Cosmo AI" (a hosted option run by us) is not available in this version.
Network connections
Connections Cosmo itself makes
- Your chosen AI provider, only when you use Chat with it or test the connection.
- Hugging Face, only when you click Download for a Cosmo Local model, a Cosmo Voice model or Cosmo Natural Voice; GitHub (raw.githubusercontent.com) for Natural Voice's pronunciation dictionaries, same click.
- ncsc.gov.uk, cisa.gov and cert.europa.eu, only when you ask a live cybersecurity question.
- Cosmo's release server (the website Cosmo is published on, hosted by Cloudflare): once a day to see whether a newer version exists, and when you click Install to download it. The request carries no ID or information about you; like any web request it reveals your IP address to the server and to Cloudflare, which processes it under its own privacy policy. Every update is checked against Cosmo's signing key before it runs. Turn the daily check off in Settings › Privacy › Check for updates.
- Nothing else. No analytics, tracking or remote-control servers.
Microsoft Edge WebView2
- Cosmo's windows are displayed by Microsoft Edge WebView2, part of Windows. WebView2 may contact Microsoft services, for example Microsoft Defender SmartScreen, under Microsoft's own privacy terms. Cosmo does not turn SmartScreen off.
- If WebView2 is missing, the installer downloads it from Microsoft.
Retention and deletion
Everything Cosmo keeps stays on your PC until you delete it.
- Uninstalling removes the app, its helper, its startup entry, its file inbox and its log.
- Your preferences, tasks, notes and downloaded Cosmo Local and Cosmo Voice models are kept unless you tick "Delete the application data" during uninstall.
- Backups you make (Settings › General › Backup) are saved in Documents › Cosmo Backups and stay there after uninstalling, until you delete them. They contain your preferences, notes and tasks — never API keys.
- Cosmo's coding-agent hooks are removed only if you agree. Your other settings in those tools stay unchanged.
- API keys you saved (Windows Credential Manager) are removed when you tick "Delete the application data" during uninstall. Only Cosmo's own entries are removed (names ending in ".app.cosmo.desktop"); no other application's credentials are touched. Without that box, they stay so a reinstall keeps working. You can remove a key at any time in Settings › AI › Remove.
Children
Cosmo is not directed at children. [to be completed: minimum age, if any.]
Your rights
Because Cosmo does not send us your data, we do not hold personal data about you from your use of Cosmo. Questions: [to be completed: contact]. [to be completed: jurisdiction-specific rights statements, if required.]
Changes
If this notice changes in a material way, Cosmo will show the new version and ask you to acknowledge it.
- 1.9: The daily update check with Cosmo's release server (can be turned off) and updates installed on your click after their signature is checked; backups you make are saved in Documents › Cosmo Backups. Nothing else changed.
- 1.8: Cosmo Local may use a dedicated graphics card. Nothing else changed.
- 1.7: “Hey Cosmo” now also checks short phrases spoken near the PC with Cosmo's local speech recogniser (text compared with the wake phrase and dropped; nothing recorded or sent), and “Teach Cosmo my voice” keeps one sensitivity number. Nothing else changed.
- 1.6: Two new, optional network uses: the Cosmo Natural Voice download (Hugging Face, GitHub — only on your click), and live security lookups from NCSC, CISA and CERT-EU (only when you ask; nothing about you is sent; a small dated cache for offline). Also: interrupting Cosmo by voice (loudness only, nothing recorded). Nothing else changed.
- 1.5: Cosmo Voice can now optionally listen for “Hey Cosmo” with a local wake detector (off unless you turn it on): what it listens for, that the audio stays in memory and is never recorded or sent, when it pauses, and the room-noise number kept from setup. The assistant is now always called Cosmo. Nothing else changed.
- 1.4: New section for the optional Cosmo Voice: push-to-talk listening with a visible indicator, on-device speech recognition with no recording or upload of your voice, the speech-model download from Hugging Face (only on your choice), spoken replies by Windows voices, and their removal with "Delete the application data". Nothing else changed.
- 1.3: New sections for Buddy Core and the optional Cosmo Local model: on-device Chat, the model download from Hugging Face (only on your click), where model files are kept, and their removal with "Delete the application data". Nothing else changed.
- 1.2: "Game detection" now says that it also checks the names of running programs, to notice a known game in the background, and remembers the program names of games seen fullscreen. Nothing else changed.
- 1.1: "Retention and deletion" now covers saved API keys. They are removed with "Delete the application data" during uninstall (Cosmo's own entries only) and are otherwise kept. Nothing else changed.