CosHub
CosHub Privacy Policy
Effective and last updated: August 10, 2026
The CosHub operator ("we") processes information only as needed to provide cosplay planning, recruitment, messaging, photo and file sharing, and delivery features.
1. Information we collect
We collect the identifier used for Sign in with Apple or Google, email address when provided, display name, handle, profile information, and support requests.
We store projects, recruitment posts, posts, reviews, messages, photos, files, links, schedules and meeting places (coarse location), approvals, expenses, and split-bill information that you choose to create or send. For purchases, we or our payment providers process name, email, billing address, product and transaction identifiers, and subscription and refund status. We record content actions, downloads, and deliveries to provide app features. We access Photos or Calendar only after your action and permission.
To understand service usage, we record a randomly generated app installation identifier, first app open, account creation, the selected purpose, completion or skipping of the purpose-based tutorial, sign-in screen views and button taps, cancellations, failures and successful sign-ins, first use of a core feature, and action types selected from a predefined list. Account creation is recorded by our server. Onboarding completion is recorded separately only when the user actually finishes the tutorial, not when the account is created. We also record the app version, build number, and supported app language. For purchases, we calculate counts and other aggregates from our verified purchase ledger. These analytics events do not contain post or message text, URLs, file names, search terms, other user content, or free-form values.
The Google Sign-In SDK may process name, email address, phone number, account and device identifiers, coarse location, usage data, and other technical information under Google's policies for authentication and SDK functionality and analytics. Our server receives from the Google ID token only the Google account identifier, email address when provided, and display name. During network requests, hosting and delivery providers may process technical information such as IP address and User-Agent for security, load control, and failure investigation.
2. How we use information
We use information to authenticate accounts, store and share content, support recruitment and messaging, deliver files, verify paid access, answer requests, prevent abuse, investigate failures, improve reliability, and aggregate feature usage. We do not use analytics information for advertising or track you across other companies' apps or websites.
3. Sharing and service providers
Content is shown to the project members or public-post viewers you select. We use providers as necessary, including Apple for authentication and in-app purchases; Google for authentication and Google Sign-In SDK functionality and analytics; Stripe and its affiliate Sold through Link, LLC for web payments and Managed Payments merchant-of-record services (tax calculation and collection, fraud and dispute handling, order management, and transaction support); Render for API hosting and technical logs; Neon for database hosting; and Cloudflare for delivery, file storage, and technical logs. We share with each provider the information needed for those functions. We do not sell personal information and disclose it when required by law.
4. Retention and account deletion
We retain information while needed to provide CosHub. Pending analytics events are stored on the device up to 200 events and no longer than 29 days, and are removed after the server acknowledges receipt. The server stores an HMAC-derived pseudonymous key instead of the app installation identifier itself. Raw analytics events are deleted no later than 180 days after server receipt; aggregate results that do not directly identify a person or installation may be kept longer. Deleting your account in Settings immediately disables it and deletes or de-identifies authentication data, profile data, public posts, message bodies, and shared files, and deletes analytics events linked to your account. First-open and certain sign-in interaction events that are not directly linked to an account remain associated only with the pseudonymous installation key for up to 180 days. Minimal payment, fraud-prevention, legal, and backup records may remain for the required period and are then deleted. Deleting a CosHub account alone does not cancel an App Store subscription, a legacy Stripe web subscription, or a Sold through Link subscription. Cancel first through Apple, CosHub Billing, or Link order management as applicable. A request to delete payment information held by Stripe or Link is a separate request governed by their privacy process.
5. Security and your choices
We use encrypted transport, access controls, and short-lived signed file URLs. In the app you can edit your profile, delete posts, block or report users, and delete your account. Contact us for other access, correction, or deletion requests.
6. Children, changes, and contact
CosHub is not for children under 13. Material changes will be announced here or in the app. Privacy contact: kimuhi1224@gmail.com.