Privacy Policy
Last updated: July 24, 2026 · Applies to VITNA and all COS TRINITY products
- ✓Cloud storage is the default. Your agents send events and checks to our API and we store them.
- ✓We store less than you send: raw action text and raw payloads from checks are not stored.
- ✓Rate limits are enforced server-side, so we do hold per-agent request counts.
- ✓We never sell your data or share it with third parties for their own purposes.
- ✓Want zero cloud storage of events? Local and desktop mode keeps them on your device, with the tradeoff that we cannot sign an evidence package for data we never receive.
1. Who We Are
VITNA is a product of COS TRINITY ("COSTRINITY"). We build developer tools for AI agent operators. Our registered contact is hello@costrinity.xyz.
2. What Data We Collect
3. Exactly What Is Sent and Stored
This mirrors the "What VITNA sends and stores" section of our docs, and the two are kept in sync deliberately.
4. How We Use Your Data
We use account data to authenticate you, bill the plan you signed up for, reach you about security or material policy updates, and answer support requests you start. We use agent event and decision data to operate the product for you: running the checks you call, enforcing plan and rate limits, producing your evidence exports, and debugging faults you report. We do not use it to train models, we do not sell it, and we do not share it for advertising.
5. Storage, Retention, and Security
Account credentials (email + bcrypt hash) and agent data live in a PostgreSQL database (Supabase), encrypted at rest and in transit. Retention depends on your tier: Free keeps event payloads 7 days and incident records 30 days; Pro and Team keep event payloads 90 days and incident records 1 year; Enterprise is custom per Master Services Agreement. Stating this plainly: no tier below Enterprise retains event payloads for six months, so if you have a six-month logging obligation, do not rely on our hosted retention alone. The way any tier satisfies it is to export the Ed25519-signed evidence package and keep it yourself. Once exported it is a self-contained artifact that does not depend on our retention or on our servers continuing to exist.
6. Local and Desktop Mode
Local mode is the alternative to cloud storage, and it is opt-in, not the default. With storage_mode set to local, events are written to your device rather than to our database: browser-mode events to your browser's IndexedDB, VITNA Desktop events to a local SQLite file in your OS user data directory. In that mode those events do not reach our servers and there is no server-side copy of them to read, share, or delete. Two honest limits. First, this scoping applies only to the event payloads held locally; account authentication, billing, and any check you explicitly call still involve our servers. Second, we cannot produce a server-signed evidence package for data we never receive, because signing happens where the signing key is, so local mode trades the signed evidence artifact for zero cloud storage of events.
7. Data Sharing
We do not sell, rent, lease, or share your data with any third party for their own purposes, ever. We use a small set of sub-processors to run the service, currently our database and hosting providers and our transactional email provider, each of which processes data only to deliver the service to you. Our payment processor receives your email when you upgrade, subject to its own privacy policy. The current sub-processor register is published at /api/compliance/sub-processors.
8. Your Rights
9. COS TRINITY, All Products
This policy applies to all current and future COS TRINITY products including VITNA (compliance and safety evidence for AI agents), GRiiD (Solana trading primitives, archived), CRYpT (desktop file encryption, archived), and any products we release in the future. The core principle is the same across all of them: your data is yours, we do not sell it, and we do not share it with third parties for their own purposes.
10. Changes to This Policy
If we make material changes to this policy, we will notify you by email (at the address on your account) at least 14 days before the change takes effect. The updated date at the top of this page always reflects the last change.
11. Contact
Questions, data requests, or concerns: hello@costrinity.xyz. We respond within 48 hours.