Cognitum One · ruOS

Privacy Policy

This policy explains what ruOS collects, why we use it, who receives it, how long we keep it, and the controls available to you.

Effective and last updated: September 28, 2026

Plain-language summary. ruOS lets you operate hosted or connected computers through supported AI assistants, including Claude and ChatGPT, and through the ruOS dashboard. We process only the account, machine, usage, and task data needed to provide that service. We do not sell personal data, use desktop content for advertising, or give ruOS access to your complete AI-assistant conversation history or memory.

1. Scope and controller

Cognitum One ("Cognitum", "we", "us") provides ruOS, including the website at ruos.cognitum.one, its dashboard and remote-desktop viewer, the ruOS MCP server and integrations for supported AI assistants such as Claude and ChatGPT, hosted desktops, connected-computer agents, and related support services.

Cognitum is the controller for account, service, security, and support data described here. For content you process on a computer through ruOS, you or your organization generally determines why that content is processed, and you are responsible for having the authority to use it.

This ruOS-specific policy supplements the Cognitum One Privacy Policy. If the policies differ for a ruOS operation, this policy controls for that operation.

2. Information we process

Account and authorization data

Desktop, device, and task data

Usage, reliability, and security data

Do not provide restricted data. Do not enter passwords, API keys, MFA or one-time codes, payment-card data, government identifiers, or protected health information into AI-assistant prompts or ruOS tool fields. Use a service's dedicated credential flow when one is provided.

3. How we use information

Where applicable, our legal bases include performing our contract with you, our legitimate interests in operating and securing ruOS, consent for optional features, and compliance with legal obligations.

4. Recipients and subprocessors

We disclose only the data needed for each service. We do not sell personal data or share desktop content for third-party advertising.

Recipient categoryPurpose and data involved
Cognitum OneIdentity, OAuth, organization membership, support, and service administration.
Google Cloud PlatformCanadian-hosted ruOS desktop infrastructure, networking, encrypted storage, secrets, and operational logs.
Fly.ioTenant-scoped fleet API and eligible hosted desktop workloads, including service metadata and encrypted workload storage.
Anthropic / ClaudeThe minimum tool arguments and relevant tool results needed for a ruOS request when you use the Claude connector or plugin. Anthropic's handling is governed by your Anthropic agreement and privacy settings.
OpenAI / ChatGPTThe minimum tool arguments and relevant tool results needed for a ruOS request when you use the ChatGPT app. OpenAI's handling is governed by your OpenAI agreement and privacy settings.
Services you connectFor example, GitHub receives API requests when you enable and use its integration. Each connected service processes data under its own terms.
Model providers you selectTask content sent to an AI model only when the requested workflow requires that provider and your account or organization enables it.
Professional advisers and authoritiesLimited disclosure when reasonably necessary for security, legal claims, audits, or a binding legal request.

We require service providers to protect data and process it only for the contracted purpose. An up-to-date subprocessor list is available from privacy@cognitum.one.

5. Retention timelines

DataRetention
Live desktop frames, transient screenshots, pointer/keyboard events, clipboard content, and command textProcessed in transit and not retained by the ruOS control plane by default. Explicitly saved recordings or artifacts follow the artifact rule below.
Connection ticketsExpire after approximately 2 minutes. Enrollment grants expire after approximately 15 minutes.
OAuth access tokensNormally expire after approximately 15 minutes. Refresh tokens or browser sessions remain until expiry, sign-out, disconnection, or revocation.
Machine registration, preferences, and saved artifactsWhile the account or machine is active, then deleted within 30 days after a verified deletion request, unless law or a security investigation requires longer.
Free hosted desktop storageA free desktop may be deleted after 7 consecutive idle days. Once deleted, active storage is removed and backup copies expire within 35 days.
Raw web and service logsUp to 90 days.
Privacy-minimized security and action audit recordsUp to 12 months, or longer when required to investigate a documented incident.
Usage and entitlement recordsUp to 24 months. Invoice and tax records, if any, may be retained for 7 years.
Support communications24 months after the last interaction.

Deletion from active systems may occur sooner. Encrypted backups are isolated from ordinary use and expire on their normal rotation schedule.

6. Your controls and rights

Email privacy@cognitum.one from the address associated with your account. We may verify your identity and will respond within 30 days unless applicable law permits more time.

7. AI assistants and model services

When you invoke ruOS in Claude or ChatGPT, the selected assistant sends the minimum tool arguments needed for that request and receives the relevant tool result. ruOS does not query, pull, or reconstruct the complete conversation, conversation summaries, assistant memory, or unrelated user-uploaded files. Tool results are designed to omit secrets, internal diagnostics, and unrelated personal data.

Computer-use and agent workflows may interact with websites, files, and external services. ruOS identifies write and potentially destructive actions so the client can request confirmation. You remain responsible for reviewing important actions and for complying with the rules of any third-party service you direct ruOS to use.

We do not use private desktop content, tool inputs, or tool results to train general-purpose AI models. A model provider may process task content under the settings and agreement applicable to your account when you direct a workflow to that provider.

8. Security

ruOS uses HTTPS, short-lived scoped authorization, tenant isolation, server-side secret storage, encrypted provider storage, rate limits, auditable action decisions, revocable desktop tickets, and emergency controls. Security telemetry deliberately excludes prompts, screen contents, clipboard contents, passwords, tokens, and command text.

No service can guarantee absolute security. Protect your Cognitum and connected-service accounts, review permission prompts, and report suspected unauthorized access to security@cognitum.one.

9. International transfers

ruOS desktop infrastructure is primarily operated in Canada, while Cognitum identity, fleet APIs, support, Anthropic, OpenAI, Fly.io, and services you connect may process data in the United States or other countries. Where required, we rely on contractual and organizational safeguards appropriate to the transfer.

10. Children

ruOS is intended only for adults aged 18 or older. We do not knowingly permit minors to create or use hosted ruOS accounts. If we learn that a minor has provided personal data, we will take reasonable steps to delete it. A parent or guardian may report a concern to privacy@cognitum.one.

11. Changes and contact

We may update this policy as ruOS changes. We will post the revised date and provide additional notice for material changes when required.

Privacy: privacy@cognitum.one
Security: security@cognitum.one
Support: Cognitum support