Privacy Policy
Effective: July 8, 2026
Medici & Company ("Medici," "we," "us," or "our") is a Delaware C-Corporation. This Privacy Policy describes how we collect, use, and protect information when you use our website at cosimo.work and our Cosimo platform (collectively, the "Services").
1. Information We Collect
Information You Provide
- Contact information (name, email address, phone number) when you request a discovery call or contact us
- Company and fund information provided during onboarding
- Documents and data you upload to the Cosimo platform
Information Collected Automatically
- Device and browser information (browser type, operating system)
- IP address and approximate location
- Pages visited and interactions with the Services
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Services
- Process and deliver fund operations deliverables
- Respond to your inquiries and schedule discovery calls
- Improve and develop the Services
- Send administrative communications related to your account
- Comply with legal obligations
3. Data Segregation and Security
Every client runs on a fully segregated instance. Your documents, fund structures, and LPA terms never leave your environment. Client data is never used to train shared models or made accessible to other clients.
We implement industry-standard technical and organizational security measures, including encryption in transit and at rest, access controls, and regular security assessments.
4. Data Retention
We retain your information for as long as your account is active or as needed to provide you with the Services. When you terminate your engagement, we delete your data from our systems within 90 days, except where retention is required by law.
5. Connected Accounts and Google User Data
Cosimo lets you connect third-party accounts, such as Google Calendar, to provide features within the platform. Cosimo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- What we access. With your explicit consent via Google's OAuth consent screen, Cosimo requests read-only access to your Google Calendar (the "calendar.readonly" scope): event titles, times, and availability. We never edit, create, or delete calendar data, and we do not request access to any other Google data.
- How we use it. Calendar data is used solely to provide user-facing features you invoke — answering your questions about your schedule and working around your reporting deadlines. It is never used for advertising, never sold, never used to train shared models, and never shared across clients.
- Storage and retention. We store only the credential needed to maintain your connection, encrypted at rest. Calendar data is retrieved at the time of your request; responses may be retained in your workspace's history within your segregated instance.
- Disconnecting. You can disconnect Google Calendar at any time from your account settings, or via your Google Account permissions. On disconnect we immediately revoke our access with Google and delete the stored credential.
- Sharing. We do not transfer Google user data to third parties except as necessary to provide these features, to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- Human access. Humans do not read your Google user data except with your explicit permission (for example, a support request), where required for security or legal compliance, or in aggregated, anonymized form.
6. Third-Party Services
We may use third-party service providers to assist in operating the Services (e.g., hosting, analytics). These providers are contractually obligated to protect your information and may only use it to perform services on our behalf.
We do not sell, rent, or share your personal information with third parties for their marketing purposes.
7. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal information we hold about you
- Request correction of inaccurate information
- Request deletion of your information
- Object to or restrict processing of your information
- Request portability of your data
To exercise any of these rights, contact us at info@medici.ai.
8. Children's Privacy
The Services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised effective date.
10. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
Medici & Company
Email: info@medici.ai