Privacy Policy
Last updated: August 7, 2026
This explains what Cobinar collects, why, and what control you have over it —
across your Cobinar account, Cobinar Mail, and any app or game you connect
using "Sign in with Cobinar."
1Information we collect
Cobinar is an identity provider first — the account you create here is the one you use to sign in across Cobinar's own products and any third-party app that supports "Sign in with Cobinar." Here's what we collect to make that work:
Account information
- Name, username, and the email address you sign up with
- Your Cobinar Mail address (
[email protected]), issued automatically with your account
- Your password, always stored as a salted hash — we never store or can see your actual password
- Date of birth (used for age verification and account recovery)
- Optional profile details you choose to add: phone number, gender, home/work/other addresses, and a profile photo
Security & sign-in data
- Two-factor authentication data: authenticator app secrets (encrypted at rest), passkey public keys, and a hashed record of your recovery email
- Device and session information: browser/device type, approximate sign-in time, and a partial (truncated) IP-derived region — kept only to show you your own active sessions and flag unfamiliar sign-ins, not to pinpoint your exact location
- When you set a new password, we check it (via a privacy-preserving lookup that never transmits your actual password) against known data-breach lists, so we can warn you if it's been compromised elsewhere
Cobinar Mail content
If you use Cobinar Mail, we store the emails you send and receive through it, the same way any email provider does, so your inbox works.
2How we use it
- To create and secure your account, and let you sign in — to Cobinar and to any app you've connected
- To operate Cobinar Mail if you use it
- To detect and prevent fraud, abuse, and unauthorized access
- To verify developers registering apps on the platform (see §10)
- To communicate with you about your account — security alerts, changes to these policies, and service updates. You control marketing/product communications separately from essential account and security notices
- To improve Cobinar's products, generally through aggregated or de-identified analysis rather than looking at individual accounts
3When we share it
We don't sell your personal information. We share it only in these circumstances:
- Apps you authorize — see §4, this is the core of how Cobinar sign-in works
- Service providers who process data on our behalf under contract, currently:
| Provider | Purpose |
| Google Cloud / Firebase | Account database (Firestore) and authentication infrastructure |
| Cloudflare | Application hosting, edge compute, storage, and bot/abuse protection (Turnstile) |
| Have I Been Pwned | Breach-password checking — receives only a partial hash prefix, never your password or email |
- Legal requirements — if required by valid legal process, or to protect the rights, safety, or property of Cobinar, our users, or the public
- Business transfers — if Cobinar is involved in a merger, acquisition, or asset sale, your information may transfer as part of that deal, under the same protections described here
4Third-party apps you connect
When you use "Sign in with Cobinar" for a third-party app or game, you're shown exactly
what that app is requesting — typically your name, email, or profile photo — before anything
is shared. Cobinar only sends the specific fields you approve; the app never receives your
password, and it doesn't get ongoing access to your Cobinar account beyond what was granted.
You can review and revoke any app's access at any time from
Accounts → Linked apps. Revoking access stops future sign-ins through that
app immediately; it doesn't retroactively delete data the app already has — that's governed
by that app's own privacy policy, not this one.
5Cookies & sessions
Cobinar uses a small number of cookies, all functional rather than advertising-related:
| Cookie | Purpose |
cobinar_session | Keeps you signed in across Cobinar's own apps. Essential — without it you'd need to sign in on every page. |
cobinar_chooser_v2 | Remembers which accounts you've used on this device so the account switcher can show them. Stores only your name, email, and photo — never a password. |
We don't use third-party advertising or tracking cookies.
6Security
- All traffic to and from Cobinar is encrypted in transit (HTTPS/TLS)
- Passwords are salted and hashed, never stored or logged in plain text
- Two-factor options — authenticator app codes, passkeys, and email verification — are available on every account
- Sensitive fields (like TOTP secrets) are encrypted at rest
- Sign-in attempts are rate-limited and checked against automated-abuse protection
No system is perfectly secure. If you believe you've found a security issue, please tell us
before disclosing it publicly — see
§13.
7Retention & deletion
We keep your account information for as long as your account is active. Specific items expire automatically on their own schedule regardless of account status — for example, session records and sign-in device history are kept only long enough to be useful for security review, then removed.
Deleting your account (Accounts → Privacy → Delete account) removes your profile, credentials, and Mail data. Some records may be retained briefly afterward where we're legally required to (e.g., fraud investigation, tax/financial records if applicable), then deleted.
8Your rights & controls
From your Cobinar account, you can at any time:
- Access & export your data (Accounts → Privacy → Export your data)
- Correct your profile information directly (Accounts → Personal info)
- Delete your account and associated data (Accounts → Privacy → Delete account)
- Revoke any third-party app's access (Accounts → Linked apps)
- Manage your two-factor methods (Accounts → Security & sign-in)
Depending on where you live, you may have additional rights under laws like the GDPR or CCPA — including the right to object to or restrict certain processing. Contact us (§13) to exercise any right not covered by the in-app controls above.
9Children's privacy
Cobinar is not directed at children under 13, and we don't knowingly
collect personal information from anyone under that age. If you believe a child has created
an account, contact us (§13) and we'll take appropriate action, including deletion.
Founder note — confirm this age threshold and whether any
additional regional rules apply (e.g., GDPR treats 13–16 differently by EU member state)
before this goes live; this is a placeholder default, not a compliance determination.
10Developers & KYD verification
If you register an app or game on Cobinar's developer platform, we additionally collect
information needed to verify you as a developer ("Know Your Developer," or KYD) — such as
business or identity details and proof of domain ownership — before your app can request
sensitive scopes or go live to other users. This information is used for verification and
platform-integrity purposes and is handled with the same protections described throughout
this policy.
11International transfers
Cobinar's infrastructure runs on global providers (Google Cloud, Cloudflare), which may
process data in countries other than your own. Where required, we rely on standard
contractual safeguards for these transfers.
12Changes to this policy
We'll update the date at the top of this page whenever this policy changes. For material
changes — ones that meaningfully affect how your information is handled — we'll also notify
you directly, such as by email or an in-app notice, before the change takes effect.