✧ KOSMOKAI

Privacy & data

Updated 4 October 2026. Kosmokai is a private, single-operator research workspace. It is not a public service or a product sold to other users. This notice describes the currently implemented system; it is not a statement that YouTube has approved the research use case.

Google sign-in

Google Identity Services provides identity verification. The server verifies the signed identity token and permits only the configured owner account. It stores the owner's Google account identifier, email, hashed session credentials, workspace selections and selection audit events. Raw Google ID tokens and Google passwords are not stored. No Gmail, Drive, YouTube account management or channel analytics permission is requested.

Session cookies are Secure and HttpOnly. Sessions expire after eight hours, are revoked on logout, and expired session records are removed when a new authentication challenge is created. The challenge expires after five minutes. There are no advertising or third-party analytics cookies. Explicit acceptance of this notice and the private use terms is required before private access; the accepted policy version is stored with the session. Earlier sessions without the current policy version do not unlock private features.

YouTube research data

The Hunter uses YouTube Data API public metadata and statistics for editorial research. The research collector is currently paused. The private portal displays collector status, historical record counts, research hypotheses and, only when permitted by its freshness checks, observed channel and gate evidence. It does not download YouTube video, audio or transcripts.

Research scores and classifications are Kosmokai's own analysis, not metrics supplied or approved by YouTube or Google. Channel RPM, earnings, copyright safety and monetization eligibility are not presented as verified facts.

Storage and current limitations

Application records are stored on the operator's DigitalOcean server. The portal accesses a read-only telemetry snapshot, separately from the research database and API key. Google identity verification uses Google's services. DNS is managed through Vercel. Operational server logs may contain IP addresses, request paths and timestamps. Personal account details and tokens are not intentionally logged.

The portal excludes expired channel metadata and statistics from display. The legacy research database and its backups still require a reviewed refresh/deletion migration. Display filtering is not deletion. Collection remains paused until this lifecycle issue and the applicable YouTube analytics permission are resolved. This notice does not claim an implemented 30-day deletion guarantee for the legacy archive.

Control, deletion and revocation

The owner can remove workspace selections and log out through the portal. Account-bound identity records and historical audit data require an operator-managed deletion procedure; no self-service account deletion is currently implemented. Revoking the Google connection does not by itself erase locally stored records or immediately invalidate an already issued local session: use Logout to revoke that session. Requests about local data are handled by the private operator through the support contact configured for the Google application.

Google connections can be reviewed or revoked in Google Account connections. Google's handling of data is described in the Google Privacy Policy. Use of YouTube API Services is subject to the YouTube Terms of Service and YouTube API Services Developer Policies.

← Back to Mission Control