NOVA Privacy Policy
Last updated: 2026-09-19
NOVA (the "Service") is Cosmic Dot's AI companion device and its companion app. This document explains what information the Service handles.
1. Accounts and information access
- Basic setup does not require a separate Dot Station account. Optional Google features require Google authorization. When you connect Google, we receive and store your Google account identifier, email address, and granted permissions. We do not receive your Google password.
- We don't track your location in the background. Location features are optional, purpose-specific, and run only while you are using the companion app.
- We don't use advertising identifiers. There is no ad SDK.
- We don't access your contacts, photos, or health data.
2. What we collect and process
Device identifiers
| Item | Purpose | Where it is stored |
|---|---|---|
| Device serial (MAC address) | Identifies which device is yours | Backend |
| Claim token / session token | Proves device ownership, keeps the app↔︎device link | Secure storage on your phone (iOS Keychain / Android Keystore) |
The app keeps the session token and a random app-installation
identifier in your phone's secure storage
(FlutterSecureStorage). The session token is deleted when
you disconnect the device. The installation identifier is not an
advertising identifier.
Voice
After you say the wake word or press the button on the device, your speech is sent to the voice server and used for speech recognition and response generation. Conversation content is retained so that follow-up conversation has context.
- Nothing is transmitted before the wake word. Wake-word detection happens on the device and never leaves it.
- The app does not use your microphone. Audio goes from the device straight to the server.
Wi-Fi credentials
When you first set up the device, the app takes your Wi-Fi name and password and delivers them directly to the device over BLE.
- They are never sent to our servers. They are not stored in the app either.
- The transfer is encrypted (DH key exchange, then AES).
- The device keeps these values only in its own storage (NVS).
Camera
Used only to read the QR code shown on the device screen. Captured images are never stored or transmitted, and are discarded the moment the code is recognized.
Agenda and proactive notifications
NOVA stores agenda and reminder content, scheduled time, delivery state, and an opaque delivery identifier so an item can be delivered once through an available channel. When notifications are enabled for an opted-in installation:
- notifications contain generic guidance and opaque routing data unless you separately enable content-bearing notifications for that installation;
- sensitive integration approval notifications remain generic, and their details require authenticated access in the app;
- full agenda detail is fetched only after the app authenticates its current device session;
- the backend stores the active Firebase registration token and a one-way token digest, bound to the app session and current device owner;
- disabling notifications, provider invalidation, session revocation, reclaim, or factory reset disables the installation and clears its token and digest;
- notification permission is requested only from the notification settings screen. The user can disable receipt and control generic in-app foreground presentation there.
A notification already displayed by iOS or Android cannot be remotely removed. After reclaim or factory reset, tapping such a notification cannot reveal the prior owner's detail because authorization is checked again.
Optional Google integrations
When you connect Google and enable the relevant permissions, NOVA processes Google Calendar event information, Gmail senders, subjects, dates and message snippets, and text from Google Drive files you select. To prepare an available action for your approval, we also process its proposed contents, such as email recipients, subject and body or Calendar event title and times. Gmail reading requires its additional permission; available actions depend on your permissions and the enabled service capabilities.
Google connection records, permissions and selected-file records are associated with your NOVA device and its current owner authorization. OAuth credentials and stored approval payloads are encrypted on our backend, which can decrypt them to provide the service. This is not anonymous storage.
Private-account results and responses may be held in the active conversation and sent to the configured AI response-generation or speech-synthesis providers to answer your request. These turns are excluded from our ordinary persistent conversation and memory capture; this does not mean that they never leave the service or that third-party providers retain no data.
Optional location context
If you choose to enable a location feature, the companion app may read your phone's location for one of these purposes:
| Purpose | Location handled | Retention |
|---|---|---|
| Saved weather area | A coarse area confirmed by you | Until revoked or refreshed, with an initial maximum of 90 days |
| Live weather | A coarse grid from a foreground phone fix | One use or an initial maximum of 5 minutes |
| Route time from “here” | A precise foreground phone fix | One use or an initial maximum of 5 minutes |
Typing or saying a place name does not read your phone's location.
- Location is not stored in conversation memory or generic memory.
- The app does not collect location in the background.
- Saved and live uses have separate controls. OS permission alone does not enable them.
- Exact route origins are restricted to the location service and contracted place/route processors. They are not sent to speech recognition, the language model, speech synthesis, conversation history, general logs, or support exports.
- You can revoke a saved area or active live context in the app. Revocation invalidates the current consent generation and starts deletion, with an initial service target of 15 minutes.
3. Third-party processing
We use external AI service providers for speech recognition, response generation, and speech synthesis. Only the audio and text needed for that processing is passed to them.
For mobile notifications, the backend sends the notification payload and active registration token to Google Firebase Cloud Messaging. On iOS, Firebase uses Apple Push Notification service (APNs) to deliver it to the device. Apple and Google process this information under their respective service terms. Notifications are generic unless you separately enable content-bearing notifications for that installation. Sensitive integration approval notifications remain generic.
Google provides account authorization and the Calendar, Gmail and Drive APIs. Our Convex backend stores connection, permission and operation records and mediates authorized Google requests. Relevant content is also processed by the AI and speech providers described above. Google stores messages and Calendar changes made through its services under its own policies.
When you use an optional location feature, contracted weather, place, or route service providers receive only the fields needed for that request. A coarse area is used for weather. A precise origin may be used for a one-time route request. These providers are service processors and may not use the data for advertising or tracking.
4. Retention and deletion
Google integration approval requests have a five-minute authorization window. Stored request contents are removed when the request is completed, rejected, cancelled or processed as expired; expiration is not a guarantee that every related record is immediately deleted. Connection, selected-file, operation-status and security records can remain after disconnection.
Disconnecting Google invalidates service access and initiates provider-token revocation. It does not erase messages or events already stored in Google, or automatically erase every backend record. You can revoke a selected Drive file's grant in the app. For deletion of retained integration records, contact the address below.
- Conversation history is retained for as long as you use the Service.
- A pending proactive delivery expires 24 hours after its scheduled time. The current source does not define an approved maximum retention period for delivery history.
- Disconnecting the device in the app deletes the session token from your phone and disables its Push installation on the backend.
- Reclaim or factory reset cancels incomplete deliveries for the prior owner and prevents the new owner from reading prior agenda and notification detail.
- Revoking location consent, disconnecting, reclaiming, or resetting the device invalidates its saved and live location contexts and starts deletion.
- To have your data, conversation history, or retained delivery history deleted, contact us at the address below.
5. Children
The Service is not directed to children under the age of 14.
6. Contact
For access or deletion requests, or any other question, reach us at:
Contact: contact@cosmic-dot.com