Privacy
Short enough to actually read.
Cozy exists because your messages are sensitive. The design keeps them on your Mac; this page says exactly what leaves, when, and what happens to it. Last updated August 11, 2026.
What stays on your Mac
- Your messages. Cozy reads the Messages database that is already on your Mac. Your database is never uploaded, mirrored, or backed up. If you separately opt in to trajectory sharing, a contributed record may contain the limited excerpts and query results used for that answer (section 03).
- The search index. Cozy builds its own local copy to answer questions quickly. It lives in your user library, on the Mac, and only you can delete it (how: section 05).
- Contact names. If you allow Contacts access, the name-to-number mapping is used locally so you can ask about "Sarah" instead of a phone number. It stays on the Mac.
What leaves for AI processing
- Questions. Your question and the few message excerpts Cozy's local search selects as relevant are sent to the model that answers it. The rest of your message history stays on your Mac.
- Awaiting Reply. This feature is on by default. During initial message sync and as new messages arrive, Cozy may send a conversation identifier, the contact name, and up to 280 characters of the latest incoming message to a model to decide whether it needs a reply. It does not send the full conversation for this classification.
- Drafts in your voice. Only when you click to draft a reply, Cozy may send the latest incoming message, up to six recent messages from that conversation, and locally selected examples of messages you have sent: up to 12 to that person and five short examples sent to other people. These examples are capped at 200 and 120 characters respectively. The generated draft opens in Messages and is not stored by Cozy.
- How it is handled. AI traffic goes over TLS through ModelRelay (the billing and routing platform Cozy is built on) to the model provider. Ordinary AI requests are not stored as content by Cozy or ModelRelay. Model providers process requests under API terms that exclude using them to train their models. Explicit trajectory contributions are a separate Cozy feature described next.
Optional data sharing
- Off by default. Anonymous diagnostics and trajectory sharing are separate choices during setup and in Settings. Neither is enabled until you choose it.
- Anonymous diagnostics. These are content-free facts such as token and request totals, timing, model routes, reasoning-step counts, app/runtime versions, terminal status, and typed errors. Raw diagnostic events expire within 90 days.
- Trajectory contributions. If you opt in, future records may include conversation excerpts, generated queries and code, query results, errors, and Cozy's answers. Cozy encrypts these records in Cozy-owned storage and may use them for debugging, evaluation, and training to improve Cozy.
- Control and deletion. Turning sharing off stops new capture and upload. Settings shows submitted trajectory records and lets you request their deletion. Authorization is checked again before a trajectory can enter a training or evaluation corpus, and contributed trajectories expire within 180 days. Deletion removes the active encrypted replay immediately; encrypted database backups age out under the backup retention schedule and cannot be exported through the contribution service.
Your account and billing
- Sign-in. You sign in with Google; Cozy keeps your email address to identify your account. No password is ever seen or stored by Cozy.
- Payments. Subscriptions are processed by ModelRelay through Stripe. Your card number never touches Cozy's or ModelRelay's servers — it goes straight to Stripe. Your card statement will read MODELRELAY.
- Usage records. ModelRelay keeps the billing ledger (tokens used, amounts charged) needed to run your balance and subscription — numbers, not message content.
What we never do
- No ads, and no selling or sharing your data with anyone.
- No retaining or training on ordinary Cozy traffic. Content-bearing debugging, evaluation, or training requires the separate trajectory-sharing opt-in.
- No content analytics inside conversations unless you explicitly contribute the corresponding trajectory.
Leaving
Signing out removes Cozy's saved credentials but keeps your local data so it is available when you sign back in. To permanently remove Cozy's local message index, chat history, saved memory, retained evaluation records, and saved credentials, choose Cozy → Settings → Erase Local Data. Cozy does not delete your original Messages or your account. Submitted trajectories are managed separately in Settings → Data Sharing, where you can stop future sharing and request deletion of records already accepted by Cozy Cloud. Cancel a subscription any time from your account page — it takes two clicks. Billing records are retained by Stripe as payment regulations require.
Questions about any of this: ask directly. If this page and the product ever disagree, that's a bug — tell us and we'll fix whichever one is wrong.