Back to cogshift last updated 24 August 2026

Privacy policy.

Cogshift is a local router: your prompts are handled on your own machine and go straight to the model providers you configure. This page describes the small amount of data everything else touches.

Applies to the cogshift.io website and to Cogshift accounts and config backup as those launch.

The short version

Most privacy policies are long because the product collects a lot. This one is short for the opposite reason.

  • Your prompts and AI requests never reach Cogshift’s servers.
  • This site runs no analytics, no trackers, no advertising and no third-party scripts.
  • The contact form emails your message to us. It is not stored in a database.
  • When accounts launch, the account record holds who you are — not what you did with the router.
  • Config backup is encrypted on your device with a key we never receive. We hold ciphertext we cannot read.

The router runs on your machine

Cogshift’s core product is a local router. It reads each request, decides which model should handle it, and sends it directly from your machine to the model provider you configured. The request goes to that provider, not through us.

So in the local product there is nothing for us to collect: prompts, completions, file contents, code, route names and provider names never transit Cogshift’s servers. What those providers then do with a request you send them is covered by their own privacy policies, not this one.

This website

cogshift.io is a static site. There is no analytics package, no tag manager, no advertising network, no social widget and no third-party script of any kind. Nobody is measuring how you read this page.

The web server that serves the site keeps standard access logs — the kind every web server writes: the requested address, a timestamp, the IP address the request came from, and the browser’s user-agent string. They exist to run and secure the server, and they are not used to build a profile of you or joined to anything else.

The contact form

The contact form on the home page takes your name, email address and message. Those three things are relayed to us by email. They are not written to a database, not added to a mailing list, and not passed to anyone else.

What is left afterwards is an email in our inbox, kept for as long as it is useful to have the conversation on record. If you would like a message you sent us deleted, ask and we will delete it.

Accounts, when sign-in launches

Accounts are not open yet. When sign-in launches, an account will be created by signing in with Google or GitHub, and the account record will hold:

  • which provider you signed in with, and that provider’s user identifier for you
  • the email address the provider shows for you, so we can tell one account from another and reach you about the account
  • when the account was created
  • the devices you have registered, by the name you gave them
  • your entitlements — which tier the account is on

That is the whole record. We do not store prompts, usage patterns, request counts, route names or provider names. Nothing in the account is derived from how you use the router, because the router does not report back to us.

Config backup, when the vault launches

Config backup — the vault — is not open yet. When it launches it will be optional, and it will work like this: your configuration is encrypted on your own device, with a key derived from a passphrase we never receive, and only the encrypted blob is uploaded.

What we hold is ciphertext. We can see how many bytes it is and when it was written; we cannot see what is inside it. A small number of previous versions is kept so you can recover from a bad edit, and those are ciphertext too.

The other side of that: because the key never leaves your device, we cannot recover a backup for you if you lose your passphrase. That is covered again in the terms.

Signing in with Google or GitHub

When sign-in launches, it will use Google and GitHub as identity providers. From them we receive two things: your user identifier with that provider, and your email address. Nothing else — no contact list, no repositories, no documents, no profile beyond that.

We never receive and never store your Google or GitHub password. The token the provider issues during sign-in is used once, server-side, to confirm who you are, and is not retained afterwards.

Cookies

The site as it stands sets no cookies at all. When sign-in launches there will be exactly two, and neither of them tracks you:

  • A session cookie, set after you sign in, so you stay signed in. It is HttpOnly and secure, and it does nothing except identify your session.
  • A short-lived cookie during the sign-in redirect, to carry you safely back from the provider. It expires as soon as sign-in finishes.

There are no advertising cookies, no analytics cookies and no cross-site tracking cookies, and there is no plan to add any.

Where the data lives

Our servers are hosted on Amazon Web Services in a United States region. Email — including the contact-form relay and anything you write to us — goes through Microsoft 365.

Those two providers are the only places account data or messages sit. We do not sell data, and we do not share it with anyone for advertising or profiling.

Deleting your data

When accounts launch, deleting your account will be one action, and it will take everything with it: the account record, every encrypted backup and its previous versions, every session, and every device registration. It is immediate and permanent — there is no restore.

Whatever is on your own machine is untouched by this. Your local configuration stays where it is; deleting the account only removes what we hold.

Your rights

You can ask us what we hold about you, ask for a copy of it, ask us to correct it, or ask us to delete it. In practice the answer to the first question is short, and deletion is a button you press yourself once accounts launch.

If you would rather we did it, get in touch through the contact form and we will.

Changes to this policy

This policy will change as parts of Cogshift launch — accounts and config backup are described here before they exist, and the wording will be tightened to match once they do. The date at the top of the page is the date of the current version.

If a change ever means we handle your data in a materially different way, we will say so rather than quietly reissue the page.

Getting in touch

Questions about any of this, or a request about your data, go through the contact form. We read them and we reply.

Get in touch