cosd
Sign in

Privacy

What cosd stores, why, and what it never does.

Cookies and browser storage

When you sign in with Discord, a strictly necessary session cookie keeps you signed in. When you vote without an account, a separate necessary cookie lets that browser update or withdraw its ballot for one year. The cookie's random value stays in your browser; cosd stores only a round-specific cryptographic digest. Product analytics does not set an analytics cookie, but it does store an anonymous identifier in local storage so separate page visits can be counted together.

Product analytics

cosd uses PostHog's EU service to record page views and a small set of explicit actions, such as opening a cosplay or submitting a vote. Analytics is active by default and sent through cosd.app. Broad click or form autocapture and session replay are disabled. Query strings, fragments, IP addresses, location enrichment, raw user agents, form contents, emails, and Discord account IDs are not retained in analytics.

After sign-in, the analytics identity uses cosd's internal user ID, your display name, and your public creator handle when you have one. Browser and device categories may be retained for aggregate compatibility analysis. Analytics is never sold or used for advertising.

Discord sign-in and voting

Signing in uses your Discord account. cosd stores your Discord identity (username, avatar, email) to create your account, and checks your membership in a creator's Discord server for members-only votes and suggestions. Public votes do not require membership or sign-in. Following always requires an account. cosd never posts to Discord on your behalf.

Browsing without an account

Public profiles, cosplays, and visible vote results can be viewed without an account. Creators may also allow account-free voting. Anonymous page views and explicit product interactions may still be counted, but no PostHog person profile is created until you sign in.

Your votes

Vote tallies shown to creators and visitors are aggregated per option. Individual ballots are only used to compute totals and to let you review or withdraw your own submission. On public rounds, creators see aggregate authenticated and anonymous counts, never voter names or Discord IDs. If you sign in after voting in the same browser, cosd reconciles the two records to avoid counting both.

Discord social previews

When a server owner enables X previews, cosd asks X for the public post needed to build the requested Discord preview. If X's official API cannot return a public post, cosd may retry through X's web interface. A dedicated cosd-operated X session may be used for public age-gated posts; cosd never uses a Discord member's X account or cookies, and protected posts are not reconstructed.

Normalized public X post data may be cached for five minutes while a post is editable and for up to 24 hours afterward. Definitively unavailable results may be cached for 15 minutes. Raw X responses, private content, location data, Discord sender identities, and X session credentials are not stored in that post cache.

When a server owner enables Instagram previews, cosd reads only public, embeddable Instagram posts and Reels needed to build the requested Discord preview. cosd does not use Instagram accounts, cookies, or session credentials. Private, removed, restricted, or embed-disabled posts are not reconstructed.

Instagram media may be stored in cosd's private cache for no longer than 14 days and is rechecked at least every six hours when accessed. A definitive removal or privacy response purges it immediately. This cache contains media bytes and technical manifests only—not captions, usernames, Discord sender or server IDs, raw Instagram pages, or an analytics dataset. Discord may independently retain its own proxied copy under Discord's policies.

Retention and deletion

Product analytics is retained for no longer than 12 months. You can contact cosd support to request access to or deletion of your account and linked analytics. Analytics deletion includes the PostHog person and associated events; provider-side event purging may complete asynchronously after the request is accepted.

Public-vote idempotency records expire after 24 hours. Pseudonymous abuse-limit buckets expire after 48 hours and never contain raw IP addresses. Ballots remain until they are withdrawn, their round or account is deleted, or cosd applies its product retention policy.