✶✶✶

Privacy Policy.

Effective Date: August 21, 2026 · COTID Inc.
This Privacy Policy describes how COTID Inc. ("COTID," "we," "us") handles information in connection with the COTID™ desktop application and the cotid.ai website (collectively, the "Service").

Summary.

The Service is architected to process Your Content (as defined below) entirely on Your device. We do not collect, transmit, host, or otherwise process Your Content on our servers or the servers of any third party. The limited categories of information we do receive — account and billing information, and any metrics You affirmatively elect to share — are described in Sections 5 through 8 below.

Definitions.

"You" / "Your"

The natural person or entity that downloads, installs, or uses the Service.

"Your Content"

All documents, notes, tables, diagrams, charts, projects, prompts, queries, conversations with the AI, files, uploads, browsing activity, and other materials created, imported, or processed by You through the Service.

"On-Device AI"

The machine-learning models that execute locally on Your hardware as part of the Service.

Local Processing; No Cloud Processing.

All AI inference, document processing, data analysis, and content generation performed by the Service occurs on Your device. There is no cloud processing of Your Content. Your Content is stored only in local storage on Your device and is never uploaded, synchronized, backed up, or otherwise transmitted to us. We have no technical ability to access, view, retrieve, or recover Your Content.

Because Your Content never leaves Your device except at Your express direction (for example, when You export or send a document), Your Content is not "collected" within the meaning of applicable privacy laws.

Categories of Information We Do Not Collect.

We do not collect or receive: the content of Your documents, notes, projects, or conversations; Your prompts or AI queries; Your files or uploads; Your browsing or search history within the application; usage analytics or product telemetry (except as expressly described in Section 7); device identifiers linked to Your identity; or the substance of any request made to On-Device AI.

Information We Collect.

5.1 Account information

When You create an account, we collect Your email address and authentication credentials. Account creation and authentication are handled through Supabase, which acts as a processor on our behalf. Authentication data is used solely to administer Your subscription and access to the Service.

5.2 Billing information

If You purchase a subscription, payments are processed by Stripe, Inc. Your full payment-card details are submitted directly to Stripe and are not stored on our systems. We receive billing status, transaction identifiers, and billing metadata (for example, plan type and invoice history).

5.3 Communications

If You contact us for support or otherwise correspond with us, we receive the information You choose to provide, such as Your email address and the contents of Your message.

Service Providers and Subprocessors.

We rely on a limited set of third-party providers to operate the Service. Each processes only the information necessary to perform its function, under contractual obligations to process it solely on our instructions:

DigitalOcean

Website hosting and application infrastructure. DigitalOcean Privacy Policy

Supabase

Account authentication and associated database services. Supabase Privacy Policy

Stripe

Payment processing and subscription billing. Stripe Privacy Policy

None of these providers receives Your Content. Their privacy policies govern their own handling of the information described above; this Privacy Policy does not.

Network Communications.

After installation, the Service operates offline except for the following, each of which is limited to the minimum data necessary:

7.1 Initial download

The application and On-Device AI model (approximately 4 GB) are downloaded at first launch.

7.2 Software updates

Optional background update checks. Update checks may be disabled in whole in Settings, and the Service remains fully functional when they are disabled.

7.3 License verification

A subscription verification performed once per billing period. The verification transmits authentication tokens only and contains no user content.

No analytics SDKs, advertising networks, tracking pixels, or third-party telemetry frameworks are integrated into the application.

Optional Metrics (DiffusionScope™).

You may optionally enable sharing of anonymized performance and quality metrics through DiffusionScope™. This sharing is disabled by default, requires Your affirmative opt-in, and each metric category is an independent toggle that may be withdrawn at any time with immediate effect.

Where enabled, shared data is limited to operational measurements (for example, model generation speed, TID™ confidence scores, quality ratings, hardware tier, and crash diagnostics). Shared data contains no document content, prompts, or personal identifiers. Safeguards include: batched transmission (weekly batches of no fewer than fifty data points to prevent individual session fingerprinting), calibrated differential privacy noise applied to all shared metrics, and rotation of anonymous session identifiers on a weekly basis such that shared metrics cannot be associated with any person or account.

Web Research and Private Browsing.

Where You direct the Service to retrieve web content, requests are issued through a stateless HTTP engine that does not store cookies, retain browsing history, persist fingerprints, or keep persistent records of any kind. Account management performed within the embedded browser uses an ephemeral profile that is discarded when the window closes.

Retention and Security.

Your Content persists on Your device until You delete it; deleting the application deletes Your Content. Account and billing records are retained for as long as Your subscription is active and as required by applicable tax, accounting, and fraud-prevention obligations, after which they are deleted or irreversibly anonymized. We apply industry-standard administrative, technical, and physical safeguards to the limited information we hold.

Cookies on the Website.

The public website does not set advertising or cross-site tracking cookies. Any cookies or equivalent storage used by the website are strictly necessary (for example, to maintain Your signed-in session) and are not used to profile You across other sites.

Children's Privacy.

The Service is not directed to children under the age of 13 (or the equivalent minimum age in Your jurisdiction), and we do not knowingly collect personal information from children. If You believe a child has provided us with personal information, contact us and we will delete it.

Your Rights.

Depending on Your jurisdiction, You may have rights of access, correction, deletion, portability, and objection regarding personal information we hold about You. Because the vast majority of information processed by the Service never reaches us, most rights concerning Your Content can be exercised directly on Your device by editing or deleting the relevant material. For personal information we do hold (account and billing records), contact privacy@cotid.ai and we will respond within the timeframe required by applicable law.

Users in the European Economic Area and the United Kingdom: our lawful bases for processing are performance of contract (account and license administration), legitimate interests (service security and improvement), and consent (any optional metric sharing, withdrawable at any time). Users in California: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not process personal information for cross-context behavioral advertising.

International Transfers.

Your Content is not transferred internationally because it is not transmitted anywhere. Account and billing information may be processed in the United States and other countries where our providers (DigitalOcean, Supabase, and Stripe) maintain infrastructure; where required, such transfers are protected by appropriate contractual safeguards.

Changes to This Policy.

We may update this Privacy Policy from time to time. Material changes will be announced in the application or by email to the address associated with Your account before taking effect. The Effective Date above reflects the date of the current version.

Contact.

Questions about this Privacy Policy may be directed to COTID Inc. at privacy@cotid.ai, or by mail to our registered address listed on our corporate filings.

Privacy you can verify.

Download COTID™ and see for yourself. Free for 14 days.

Download Free Trial