Cosmos Watch
Privacy Policy
Last Updated: 29 July 2026 Effective Date: 29 July 2026
1. Introduction
Cosmos Watch ("we", "our", or "the App"), operated by Cosmos One, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, share, protect, retain, and delete information when you use Cosmos Watch.
Cosmos Watch is an offline, local-first Android phone companion for a Wear OS watch face. It provides a watch-face preview, installation guidance, customisation instructions, a home-screen digital clock widget, legal information, and local diagnostics. It does not require an account or connect to a Cosmos One backend.
By using Cosmos Watch, you agree to the practices described in this Privacy Policy.
2. Overview
- No account or sign-in is required.
- The App does not request Android runtime permissions.
- The App does not include a backend, advertising, analytics, billing, artificial intelligence, cloud storage, push notifications, or a remote crash-reporting service.
- Consent choices, diagnostic preferences, and bounded diagnostic logs are stored in the App's private device storage.
- Diagnostic logs are not uploaded automatically. Copying or sharing them requires an explicit user action.
- The Wear OS watch face renders step count, heart rate, battery, and user-selected complication values supplied locally by the watch and its providers. The phone companion and Cosmos One do not receive those values.
- The App does not sell personal information.
- Local App data can be removed through the in-app clear action, Android's clear-data control, or uninstalling the App.
- The App is intended for users aged 13 or older.
3. Information We Collect
3.1 Information You Provide
The App does not ask for an account, name, email address, phone number, payment details, health data, location, contacts, calendar data, photos, microphone recordings, or files.
If you choose Report an Issue or Request a Feature, you enter a message that is passed to Android's share sheet. The App does not transmit or retain that message itself. The external app you select may process it under that app's terms and privacy policy.
3.2 Information Created Through App Use
The App stores the following locally:
- acceptance of the Terms of Use and Privacy Policy, their effective-date versions, and the acceptance timestamp;
- whether detailed debug logging is enabled and when it expires;
- an acknowledgement identifier for a previously shown abnormal-process-exit event;
- local diagnostic entries, including app lifecycle milestones, user-visible action outcomes, errors, and bounded crash information.
3.3 Device and App Information in Diagnostics
Local diagnostic records or user-created diagnostic archives may include:
- device manufacturer and model;
- Android version and API level;
- App version, version code, and build type;
- timestamps, log level, category, thread name while detailed logging is enabled, and sanitised error information;
- Android's description of a previous crash, ANR, low-memory exit, signal, or excessive-resource exit where available.
The diagnostic system redacts common credentials, tokens, cookies, email addresses, phone numbers, and secret-shaped values before writing logs. It is not intended to record health data shown by the Wear OS watch face.
3.4 Watch Face Values We Do Not Receive
The Wear OS watch face can render step count, heart rate, battery, and user-selected complication content supplied locally by Wear OS, the watch, its sensors, and complication providers. Availability depends on the watch, supported sensors, installed providers, and permissions granted on the watch.
These watch-side values are not received by the phone companion, written to its diagnostic logs, sent to Cosmos One, or stored in a Cosmos One backend. The App does not collect advertising identifiers, precise location, payment-card data, account credentials, or Google user data.
4. Permissions, Storage, and Device Access
| Permission or Access | Purpose | Required or Optional |
|---|---|---|
| Android runtime permissions | None are declared or requested | Not applicable |
| Wear OS watch-face data fields | Render step count, heart rate, battery, and selected complication content locally on the watch | Controlled by Wear OS, the watch, providers, and watch-side permissions |
| Home-screen widget | Display the device time and open the watch-face guide when tapped | Optional, added through Android's widget picker |
| App-private files | Store bounded diagnostic logs and a crash marker | Used locally |
| App-private preferences | Store legal consent, debug expiry, and recovery acknowledgement | Used locally |
| Cache storage | Create a diagnostic ZIP only after a share action | Optional, user initiated |
| Clipboard | Copy currently visible diagnostic text after the user taps Copy | Optional, user initiated |
| Android share sheet | Send an issue, feature request, or diagnostic archive to an app chosen by the user | Optional, user initiated |
| Google Play intent | Open the watch-face listing in the installed Play Store or a browser | Optional, user initiated |
The App has no foreground or background service, notification permission, overlay, accessibility service, device administrator, exact alarm, broad storage access, camera, microphone, location, Bluetooth, contacts, calendar, or network permission.
5. How We Use Information
We use local information only to:
- read the device clock locally to update the home-screen clock widget;
- remember legal consent;
- maintain and expire the optional 24-hour debug-logging state;
- diagnose local failures and present crash-recovery information on the next launch;
- create text or ZIP content after the user asks to copy or share it;
- operate and improve the App, meet legal obligations, and respond to support requests the user chooses to send.
We do not use information for advertising, profiling, sale, automated decision-making, unrelated analytics, or training artificial-intelligence models.
6. Data Storage and Security
| Data or Component | Location | Protection |
|---|---|---|
| Legal consent and diagnostics preferences | Android app-private settings files | Android application sandbox and device file-based encryption where supported |
| Diagnostic logs | Android app-private files directory | Android application sandbox; sanitisation; five-file and seven-day limits |
| Crash marker | Android app-private files directory | Android application sandbox; bounded content |
| Diagnostic ZIP | App cache diagnostics directory |
Created only on user request; shared using a restricted FileProvider URI |
Log files rotate at approximately 512 KiB each, with no more than five retained files and a maximum local age of seven days. The in-app viewer and clipboard output are bounded to 4,000 lines. No security measure is absolute; users should maintain device-level security and install operating-system updates.
7. Data Sharing and Disclosure
| Recipient | Purpose | Data Shared |
|---|---|---|
| App selected through Android's share sheet | User-requested issue report, feature request, or diagnostic export | Only the message or archive the user elects to share |
| Google Play or browser selected by Android | Open the watch-face store listing | The external app handles the request under its own policy |
| Authorities or regulators | Compliance with a valid legal obligation | Only information lawfully required and available to us |
We do not sell personal information. Diagnostic information remains local unless the user deliberately copies or shares it. Once information is sent to another app, that recipient controls its subsequent handling.
8. Third-Party Services
| Service | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|
| Google Play | Display and install the phone or Wear OS artifact when the user opens the listing | Google independently processes store and device-account information | Google Privacy Policy |
| Wear OS | Render the watch face and supply watch-side system, sensor, and complication values | Google, the watch manufacturer, and complication providers process data under their own arrangements | Google Privacy Policy |
| User-selected share app | Deliver content chosen by the user | The selected message or archive | The selected app's privacy policy |
AndroidX Core is a local runtime library used to share cache files securely. It is not a remote service and does not receive App data.
9. Data Retention and Deletion
| Data | Retention | Deletion Method |
|---|---|---|
| Legal consent and diagnostics preferences | Until replaced, app data is cleared, or the App is uninstalled | Android Settings > Apps > Cosmos Watch > Storage > Clear data, or uninstall |
| Diagnostic log files | Up to seven days, five files, approximately 512 KiB each | Logging & Debugging > Clear, clear App data, or uninstall |
| Crash marker | Until acknowledged, cleared, or expired by local cleanup | Tap Continue in recovery, clear logs, clear App data, or uninstall |
| Diagnostic ZIP files | Temporary App cache until Android or the App clears them | Clear App cache/data or uninstall; delete any received copy separately |
| Shared or copied content | Controlled by the receiving app or clipboard after the user shares or copies | Delete it from the receiving app or replace/clear clipboard content |
There is no Cosmos One account or server-side App database to delete. Device backups, screenshots, exported files, and copies sent to other apps must be managed separately by the user.
10. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, object to, restrict, or withdraw consent to processing of personal information. Because the App is local-first and has no account, most rights can be exercised directly by viewing or clearing logs, clearing App data, or uninstalling the App.
For questions or complaints that cannot be resolved on-device, contact us using section 14.
11. Children's Privacy
The App is intended for users aged 13 or older. Users under the age of majority should use it with the involvement of a parent or guardian where applicable. The App is not designed to collect children's personal information and does not provide accounts, advertising, social features, or remote data collection.
12. International Data Transfers
App-created consent and diagnostic data stays on the device unless the user deliberately shares it. Google Play and an app selected through the Android share sheet may process information in countries outside Australia under their own privacy arrangements.
13. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the App, law, or our practices. The Last Updated date will change. Significant changes may be communicated in the App, and a changed effective date will require renewed acceptance. Continued use after acceptance of an updated policy means agreement where legally appropriate.
14. Contact Information
For privacy questions or requests, contact:
Email: [email protected]
Subject Line: [Cosmos Watch Privacy]
Website: https://cosmosone.cloud
Response Time: Within 5 business days
15. Summary
| Area | Summary |
|---|---|
| Account | No account or sign-in |
| Storage | Legal consent and bounded diagnostics in app-private local storage |
| Backend | None |
| AI | None |
| Ads | None |
| Billing | None detected; paid-app status is not established by the source |
| Sharing | Only after explicit copy, Play-open, or share actions |
| Deletion | Clear logs, clear App data/cache, or uninstall |
| Contact | [email protected] |
