Kosu
TermsPrivacy

Privacy Policy

Last updated: May 4, 2026

What we collect

  • Account info (name, email via Clerk)
  • URLs you save and their fetched metadata
  • Browser extension data, including the current tab URL and title when you choose to save a page
  • Billing info (processed by Stripe – we don't store card details)
  • Basic usage and technical data

What we don't do

  • Sell your data to third parties
  • Use tracking cookies on the marketing site
  • Read or store full page content (just metadata like titles and thumbnails)
  • Use the browser extension to track every page you visit or sell browsing data

Anonymised usage data

  • We collect anonymised usage patterns (content types, engagement, queue activity) to improve the Service and develop features like recommendations
  • This data cannot identify you personally
  • Enabled by default – you can opt out in your account settings

Your control

  • Access, export, and delete your data at any time
  • Opt out of anonymised usage data collection
  • Cancel subscription and request account deletion

Questions? Contact matt@mattspear.co


1. Information We Collect

Account information. Name, email address, and authentication credentials (managed by Clerk).

Billing information. Payment method details (processed by Stripe – we do not store card numbers), transaction history, and subscription status.

Queue data. URLs you save, metadata fetched from those URLs (titles, descriptions, thumbnails, favicons, content type), queue state (position, status, timestamps, lifecycle events), and API keys you create (managed by Unkey).

Browser extension data. If you use the Kosu browser extension, the extension sends us the current tab URL and title when you choose to save a page to Kosu. The extension may also store local extension settings in your browser, including its Kosu API key, cached queue state for saved URLs, setup state, and domains you pin so the Kosu button stays visible. Those local extension settings are stored in your browser extension storage, not in our application database, unless they are separately sent to Kosu as part of saving or updating an item.

Usage data. Items added, opened, archived, and deleted. Queue reordering activity. Feature usage patterns. API usage metrics.

Technical data. IP address, browser type, device information, pages visited, and time spent.

2. How We Use Your Information

Provide the Service. Account management, subscription billing, metadata fetching, queue management (ordering, lifecycle, decay), API access, and customer support.

Improve the Service. Analyse usage patterns, identify bugs, develop new features.

Browser extension. Connect the extension to your account, save pages you choose to save, update queue item state from the extension UI, keep the on-page Kosu button visible on domains you pin, and maintain local extension state so the extension can show whether a page is already in your queue.

Anonymised data and recommendations. We collect anonymised usage data – content types saved, engagement patterns, queue behaviour – to improve the Service and develop features like content recommendations. This data is aggregated and stripped of personally identifiable information. Enabled by default. You can opt out at any time in your account settings. Opting out does not affect core functionality.

Communications. Service notifications (billing, security, updates), support responses, and promotional emails (you can opt out). You cannot opt out of service-related communications.

Security and compliance. Fraud prevention, terms enforcement, and legal obligations.

3. How We Share Your Information

We do not sell your personal information.

We share data only with these service providers:

  • Clerk – authentication
  • Stripe – payment processing
  • Autumn – billing orchestration
  • Unkey – API key verification and rate limiting
  • Vercel – application hosting
  • PlanetScale – database (US-East)
  • Fathom Analytics – cookieless website analytics

All providers are contractually required to protect your data. We may also disclose information if required by law, court order, or to protect our rights. In the event of a merger or acquisition, your data may be transferred with prior notice.

The browser extension injects a small Kosu interface into web pages so you can save and update pages from the browser. We do not sell data collected through the extension, and the extension does not send us the contents of pages you visit.

4. Data Storage and Security

Data is stored in the United States (US-East, PlanetScale) with global CDN via Vercel. Security measures include encryption in transit (TLS/SSL), encryption at rest, access controls, and API key hashing.

No method of transmission is 100% secure. We strive to protect your information but cannot guarantee absolute security.

The browser extension stores its Kosu API key in local browser extension storage. Treat that browser profile and device as you would any signed-in account. You can revoke API keys from your Kosu settings if a key or device is lost or compromised.

5. Data Retention

Active accounts. Data retained while your account exists (including free plan).

Cancelled subscriptions. Account reverts to Starter plan. All data remains intact, subject to Starter limits.

Soft-deleted items. Recoverable for 30 days, then permanently removed.

Extension data. Local extension settings remain in your browser until you clear them, reset the extension, or uninstall the extension. API keys can be revoked from Kosu settings.

Account deletion. When you request deletion (via settings or matt@mattspear.co): account and queue data deleted within 30 days, billing records retained 7 years for compliance, anonymised aggregated data may be retained indefinitely, backups may retain data up to 90 days.

6. Your Rights

Access and export. View account info in settings, export queue data, or request a copy of your personal data via email.

Correction. Update account info in settings or by contacting us.

Deletion. Delete individual items, cancel your subscription (no data deleted), or request full account deletion.

Opt out of anonymised data. Disable anonymised usage data collection in your account settings at any time. Core functionality is unaffected.

Marketing. Unsubscribe from promotional emails via link or settings.

7. Third-Party Links

When you open a URL from your queue, you leave Kosu and visit a third-party website. We are not responsible for the privacy practices of those sites. We encourage you to review their privacy policies.

8. Cookies

Marketing site (usekosu.com): Fathom Analytics, cookieless, no personal data collected.

Application: Essential cookies only (Clerk authentication, session management). No advertising or third-party tracking cookies.

9. GDPR (European Users)

We process data based on contract performance, legitimate interests (including anonymised data for recommendations), legal obligations, and consent (marketing). You have the right to access, rectify, erase, restrict, port, and object to processing of your data. You may withdraw consent at any time or lodge a complaint with your local data protection authority. Contact matt@mattspear.co to exercise these rights. For EEA/UK transfers to the US, we rely on Standard Contractual Clauses.

10. CCPA (California Residents)

You have the right to know what personal information we collect, request deletion, opt out of data "sale" (we do not sell your data), and non-discrimination for exercising rights. Contact matt@mattspear.co.

11. Children

The Service is not intended for anyone under 18. We do not knowingly collect information from children.

12. Changes

We may update this policy. Material changes will be communicated via email or notice in the Service. Continued use after changes constitutes acceptance.

13. Contact

Email: matt@mattspear.co
Web: usekosu.com

For GDPR inquiries, use the subject line "Privacy Rights Request".

© 2026 Kosu