Privacy Policy
Last updated: August 2026
This policy explains what consent (“we”, “us”) collects, why, and for how long — both from people who create a consent account (“you”, “site owners”) and, on your behalf, from visitors to the websites you add to consent.
1. Information we collect from you
- Account information — the email address and password you sign up with (your password is hashed by Firebase Authentication; we never see or store it in plain text).
- Site information — the domains you add and the banner configuration you create for them (message text, colors, category labels, and similar settings).
2. Information we collect from your visitors
When a visitor to one of your sites interacts with the consent banner, our embed script records:
- An anonymous, randomly generated visitor ID (stored in their browser’s local storage, not tied to a real identity).
- Which cookie categories they accepted, rejected, or customized, and when.
We deliberately do not collect visitors’ IP addresses, names, or other directly identifying information through the banner.
3. How we use this information
To operate the service: authenticating you, rendering and serving your consent banner, recording consent decisions on your behalf, and showing you aggregate statistics about how visitors respond.
4. Data retention
- Individual consent decision records (the audit log behind your Consent Log tab) are kept for the period included in the plan of the account that owns the site (30 days on Starter, 12 months on Growth, 3 years on Enterprise) and then automatically and permanently deleted.
- Aggregated, anonymous statistics (daily totals and rates shown on your Stats tab) contain no visitor identifiers and are retained indefinitely so you can see long-term trends.
- Banner configuration history is retained for as long as your account exists, so you can see how your banner has changed over time.
- Your account and site data are retained until you delete the site or your workspace. When a workspace is deleted, everything held for it is erased once Connect's grace period ends — see “Your rights”.
5. Where data is stored
Data is stored with Google Firebase / Google Cloud Platform (Cloud Firestore and Firebase Authentication), in the asia-south1 (Mumbai) region. Google acts as our sub-processor and is bound by its own data protection commitments.
6. Cookies this site uses
consent.app itself sets exactly one cookie: a strictly-necessary, httpOnly session cookie used to keep you signed in. We don’t use analytics or advertising cookies on our own marketing pages.
7. If you’re a visitor to one of our customers’ websites
consent provides the consent-banner technology; the website you’re visiting — not consent — is the data controller responsible for that site’s own privacy practices. Please contact that website directly with requests about your data; we act as their processor.
8. Your rights
If you’re a site-owner account holder, you can delete your workspace from your CosmoOps Connect account. Connect first holds the deletion for a grace period, during which you can cancel it; when the period ends we erase everything held for the workspace — its websites and their settings, the consent records and statistics collected through them, scan results, and your team’s account records. Nothing is kept afterwards. You can also ask for a copy of your account data by contacting us below; we don’t yet offer a self-service export.
9. Security
We rely on Firebase Authentication for credential storage and enforce access to every site’s data at the application layer: only members of the workspace that owns a site can reach it, and what each can do depends on the role they have been given. No method of transmission or storage is 100% secure, but we take reasonable steps to protect your information.
10. Changes to this policy
We’ll update the date at the top of this page when this policy changes and, for material changes, try to notify account holders directly.
11. Contact
Questions about this policy? Email us at hello@cosmoops.com.