Cognitum One · ruOS
Privacy Policy
This policy explains what ruOS collects, why we use it, who receives it, how long we keep it, and the controls available to you.
Effective and last updated: September 28, 2026
1. Scope and controller
Cognitum One ("Cognitum", "we", "us") provides ruOS, including the website at ruos.cognitum.one, its dashboard and remote-desktop viewer, the ruOS MCP server and integrations for supported AI assistants such as Claude and ChatGPT, hosted desktops, connected-computer agents, and related support services.
Cognitum is the controller for account, service, security, and support data described here. For content you process on a computer through ruOS, you or your organization generally determines why that content is processed, and you are responsible for having the authority to use it.
This ruOS-specific policy supplements the Cognitum One Privacy Policy. If the policies differ for a ruOS operation, this policy controls for that operation.
2. Information we process
Account and authorization data
- Identity: email address, Cognitum account identifier, organization or workspace identifier, account role, and authentication status.
- OAuth permissions: granted scopes, client identifier, authorization and revocation events, and short-lived access/session tokens. We do not expose tokens to the language model.
- Support: contact details and the messages, diagnostics, or files you choose to send to support.
Desktop, device, and task data
- Machine records: a machine ID, display name, operating system, connection state, capabilities, assigned organization, firmware or agent version, and last-seen time.
- User-directed task content: the specific prompt, command, text, URL, file reference, or other input you ask ruOS to use. ruOS does not request or reconstruct your complete Claude or ChatGPT history, conversation summaries, memory, or unrelated uploaded files.
- Screen and interaction data: screenshots, live desktop frames, pointer positions, keystrokes, and clipboard or file content only when needed for a requested computer-use action. The control plane does not retain live screen frames, keystrokes, clipboard content, or command text by default.
- Recordings and artifacts: screenshots, recordings, documents, code, or other outputs when you explicitly create or save them.
- Connected-service metadata: for integrations you enable, such as GitHub, the connection status, public account name, and granted scopes. Credentials are stored server-side only when required for the connection and are not returned by ruOS tools.
Usage, reliability, and security data
- Metering: active session duration, managed-machine count, provisioned storage, network usage, model-cost units, quota decisions, plan limits, and reset times.
- Service logs: time, IP address, user agent, requested route, response status, error category, and coarse performance information.
- Privacy-minimized audit events: a pseudonymous actor identifier, organization, action class, target identifier, allow/deny decision, reason code, time, correlation identifier, and coarse cost units. These events do not contain prompts, command text, screenshots, clipboard content, bearer tokens, passwords, or VNC credentials.
- Necessary browser storage: Cognitum authentication/session state and local dashboard preferences. The public ruOS landing and legal pages do not use advertising cookies.
3. How we use information
- Authenticate you, enforce organization boundaries, and apply the permissions you approved.
- Provision, connect, display, and control the computer you selected.
- Execute the bounded task you requested and return the relevant result.
- Operate integrations you explicitly connect.
- Measure entitlements and usage, prevent unexpected spend, and administer existing plans.
- Detect abuse, credential attacks, cross-tenant access, unsafe automation loops, and service failures.
- Provide support, investigate incidents, comply with law, and enforce the ruOS Terms of Service.
Where applicable, our legal bases include performing our contract with you, our legitimate interests in operating and securing ruOS, consent for optional features, and compliance with legal obligations.
5. Retention timelines
| Data | Retention |
|---|---|
| Live desktop frames, transient screenshots, pointer/keyboard events, clipboard content, and command text | Processed in transit and not retained by the ruOS control plane by default. Explicitly saved recordings or artifacts follow the artifact rule below. |
| Connection tickets | Expire after approximately 2 minutes. Enrollment grants expire after approximately 15 minutes. |
| OAuth access tokens | Normally expire after approximately 15 minutes. Refresh tokens or browser sessions remain until expiry, sign-out, disconnection, or revocation. |
| Machine registration, preferences, and saved artifacts | While the account or machine is active, then deleted within 30 days after a verified deletion request, unless law or a security investigation requires longer. |
| Free hosted desktop storage | A free desktop may be deleted after 7 consecutive idle days. Once deleted, active storage is removed and backup copies expire within 35 days. |
| Raw web and service logs | Up to 90 days. |
| Privacy-minimized security and action audit records | Up to 12 months, or longer when required to investigate a documented incident. |
| Usage and entitlement records | Up to 24 months. Invoice and tax records, if any, may be retained for 7 years. |
| Support communications | 24 months after the last interaction. |
Deletion from active systems may occur sooner. Encrypted backups are isolated from ordinary use and expire on their normal rotation schedule.
6. Your controls and rights
- Choose the machine, tool, task content, and integration used for each request.
- Review requested OAuth scopes before authorizing them and revoke the ruOS connection from Cognitum, Claude, or ChatGPT.
- Take over an interactive desktop, stop a managed desktop, disconnect an integration, delete a machine registration, or remove saved artifacts.
- Request access, correction, export, deletion, restriction, or objection where applicable.
- Withdraw consent without affecting processing already completed lawfully.
- Complain to your provincial, state, national, or other applicable privacy regulator.
Email privacy@cognitum.one from the address associated with your account. We may verify your identity and will respond within 30 days unless applicable law permits more time.
7. AI assistants and model services
When you invoke ruOS in Claude or ChatGPT, the selected assistant sends the minimum tool arguments needed for that request and receives the relevant tool result. ruOS does not query, pull, or reconstruct the complete conversation, conversation summaries, assistant memory, or unrelated user-uploaded files. Tool results are designed to omit secrets, internal diagnostics, and unrelated personal data.
Computer-use and agent workflows may interact with websites, files, and external services. ruOS identifies write and potentially destructive actions so the client can request confirmation. You remain responsible for reviewing important actions and for complying with the rules of any third-party service you direct ruOS to use.
We do not use private desktop content, tool inputs, or tool results to train general-purpose AI models. A model provider may process task content under the settings and agreement applicable to your account when you direct a workflow to that provider.
8. Security
ruOS uses HTTPS, short-lived scoped authorization, tenant isolation, server-side secret storage, encrypted provider storage, rate limits, auditable action decisions, revocable desktop tickets, and emergency controls. Security telemetry deliberately excludes prompts, screen contents, clipboard contents, passwords, tokens, and command text.
No service can guarantee absolute security. Protect your Cognitum and connected-service accounts, review permission prompts, and report suspected unauthorized access to security@cognitum.one.
9. International transfers
ruOS desktop infrastructure is primarily operated in Canada, while Cognitum identity, fleet APIs, support, Anthropic, OpenAI, Fly.io, and services you connect may process data in the United States or other countries. Where required, we rely on contractual and organizational safeguards appropriate to the transfer.
10. Children
ruOS is intended only for adults aged 18 or older. We do not knowingly permit minors to create or use hosted ruOS accounts. If we learn that a minor has provided personal data, we will take reasonable steps to delete it. A parent or guardian may report a concern to privacy@cognitum.one.
11. Changes and contact
We may update this policy as ruOS changes. We will post the revised date and provide additional notice for material changes when required.
Privacy: privacy@cognitum.one
Security: security@cognitum.one
Support: Cognitum support