Cosmovex Tools

Privacy Policy

Last updated 8 October 2026

Short version: we have no accounts. Most work happens in your browser. Some tools keep data on our servers because that is how they work (a webhook inbox, a hosted mock API, a shared room). This page says exactly what each one stores, for how long, and how to delete it.

Content you work on

Where a tool can do its job inside your browser, it does, and that content is not sent to our servers. Some tools need a server to work: they receive requests while your tab is closed, serve an API to your app, or let several people work on the same thing. Those tools, and exactly what they store, are listed under What each tool stores on our servers. All of it is kept in Google Firebase Realtime Database, hosted in the United States.

Anonymous sign-in

Tools that store anything on our servers sign your browser in anonymously with Firebase Authentication. This creates a random identifier, not an account. It is not linked to your name or email, and it lets the database rules make sure only you (or the people you share a link with) can change what you created. Clearing your browser's site data removes the identifier; anything tied only to it can then no longer be managed from that browser.

What each tool stores on our servers

Hookwatch Webhook Tester

The Webhook Tester gives your browser an inbox URL. Anything that sends a request to that URL has the request stored: the method, path, query string, headers, body (up to 256 KB), time, size, the first part of the sender's IP address (a /24 for IPv4 or a /48 for IPv6, never the full address) and the sender's country. Only the browser that created the inbox can read it, plus anyone the owner gives a Pro invite link to. Free inboxes keep the newest 50 requests for 7 days and Pro inboxes the newest 1,000 for 30 days; an inbox that receives nothing for 30 days is deleted with everything in it. You can delete single requests, all requests or the whole inbox at any time in the tool's Settings. Signing secrets you paste for signature checks stay in your browser's local storage and are never sent to us. Webhooks can contain personal data about your own customers; you are responsible for what you send to the inbox, so delete it when you are done.

Mock API Studio

A mock API has to answer while your tab is closed, so Mock API Studio stores the project definition (resource names, fields, settings), the generated and edited records, a daily request counter, and a log of the last 100 requests (method, path, status, duration, time and the host name of the calling site; never request bodies or headers). Anyone with a project's URL can read and change its records through the API, which is what a mock API is for, so do not put real personal data in one. A free project's data is cleared after 14 days without requests and the project is deleted after 60 days without requests. For Pro projects the licence key is also kept on the server, never readable by anyone, so the API can serve Pro limits. You can delete a project at any time from "Your projects" in the tool.

Sprint Poker

A poker room is shared live, so it stores the room name, the display names people type when they join, each person's role and online state, the stories (keys and titles you add or import), votes and the agreed estimates. Votes are hidden from other people until the round is revealed. Everyone with the room link can see the room. A room idle for 90 days is deleted, and the facilitator can delete a room for everyone at any time from the room menu. Pro team spaces additionally keep session summaries (story titles, final estimates and vote statistics) and any cycle times you import, until the team owner deletes the team space (History, Team). Your display name, recent rooms and imported data are also kept in your browser's local storage.

PairPad

A PairPad room stores the room's files and shared run output so everyone with the link sees and edits the same code; code itself runs in your browser, not on our servers. While you are in a room, a small presence record (a random client id, the name on your cursor and your cursor position) is visible to the others and removed when you leave. Free rooms are deleted 30 days after the last edit. Pro rooms you own are kept, with their full edit history for replay, until you ask us to delete them; Pro also keeps your saved templates and the list of your rooms. Interviewer notes and scorecards (Pro) are readable only by the person who wrote them. Anyone with a room link can read and edit the room unless its owner locks it, so do not share secrets in one. To have a room deleted sooner, email us the room link.

Schema Diff Studio

Comparing, verifying, diagrams and exports run in your browser. Projects (schema text and diagram positions) are kept in this browser's IndexedDB, and the in-browser Postgres engine files are cached in your browser. Nothing is uploaded unless you create a read-only share link (Pro): that uploads the schema text of the project's versions and its diagram layout, never table data. Anyone with the link can read it until you turn the link off in the tool, which deletes it. A share link is tied to a one-way hash of your licence key, not to a person.

Pro licences and payments

Payments are handled by Dodo Payments, the merchant of record. Your name, email, billing address and card details go to Dodo Payments, not to us; their privacy policy applies to that data. When you activate Pro, the licence key you paste and a short label for your browser (for example "Chrome on macOS") are sent through our server to Dodo Payments to activate, check and release the licence. The key and activation id are also stored in your browser's local storage so Pro stays on; clearing site data removes them.

Analytics

We use Google Analytics 4 to count page views and which tool features are used (for example "export started" or "checkout opened"), so we can see what works and fix what does not. These events do not include the content you work on or your licence key. Google Analytics uses cookies and processes your IP address to estimate a rough location; you can block it with a browser extension or your browser's tracking protection and every tool still works.

What we do not do

  • No accounts, no passwords, no profiles.
  • No advertising and no selling or sharing of data with advertisers.
  • No reading of the content you process in your browser, and no use of stored tool data for anything other than running that tool.

Service providers

  • Google Firebase (hosting, anonymous authentication, Realtime Database for the tool data described above, Cloud Functions) — United States.
  • Google Analytics 4 — anonymous usage measurement.
  • Dodo Payments — checkout, receipts, tax and licence keys.
  • Google Fonts — the typefaces on this site are loaded from Google's servers.

Your rights

Depending on where you live (for example under the GDPR or CCPA) you can ask what we hold about you, ask us to delete it, or object to processing. Because we have no accounts, the only data we can find for you is something you point us to: a room, inbox, project or share link, or a licence key. Most of it you can delete yourself in the tool, as described above. For anything else, email contact@cosmovex.com.

Children

The tools are developer utilities and are not directed at children under 13.

Changes

We will update the date above when this policy changes.

Contact

Cosmovex · contact@cosmovex.com