Cosmentum

Privacy policy

Last updated September 18, 2026

Cosmentum is operated by Imperium Marketing Solutions LLC, of 3501 SW 2nd Ave Ste 2100, Gainesville, FL 32607. This explains what we hold, who else can see it, and for how long.

There are two kinds of people in here

The agency’s staff. People with a seat. They chose to use Cosmentum and we hold their name, work email, job title, profile, and a record of when they signed in. For them we are the data controller.

The agency’s clients. Businesses and the people who work at them, whose details the agency records in order to do their job. They never chose us and have mostly never heard of us. That data belongs to the agency — we only hold it and act on their instructions. For it we are the processor and the agency is the controller.

Nothing below waters that second part down: the agency decides what goes in, how long it stays, and when it is removed.

What we store

  • Clients and their contacts — names, emails, phone numbers, addresses.
  • What each client pays: fees, retainers, ad spend, price changes over time.
  • Campaigns, care plans, projects and their checklists.
  • Deals in the pipeline, their stage and value.
  • Tasks, notes and the timeline of what happened when.
  • Any custom fields the agency invents, and every change ever made to them.
  • Seats, profiles and permissions.
  • Sign-in records, and a record of every support visit we make.

What we deliberately do not store

  • Card numbers. No payment details of any kind are held in Cosmentum.
  • Your files. If you connect Google Drive, documents stay in your own Drive. We ask only for access to a folder the app creates, not to the rest of it, and we never copy the contents onto our servers.
  • Passwords. What is stored is a scrypt hash, which cannot be turned back into the password. We could not tell you yours if you asked.
  • Tracking. There is no advertising pixel, no analytics tag and no third-party script following anybody around.

Who else can see any of it

These are the only companies involved, and each gets the least we can manage:

  • DigitalOcean — runs the application and the database, in New York. They hold everything above, as our hosting provider. The database is closed to the public internet.
  • Sentry — receives error reports when code breaks. It is configured to strip customer data before anything leaves: no names, no email addresses, no search terms, no connection strings, no tokens. What it gets is the error, the page, and the workspace as a meaningless identifier. Session recording is switched off.
  • Resend — sends invitations and password resets. They see the recipient’s email address and the message.
  • Google — only if an agency connects Drive, and only then. The connection is theirs and can be revoked from their own Google account.
  • UptimeRobot — checks from outside that the site is answering. It sees no customer data at all, only whether a page responds.

We do not sell data, share it for advertising, or use it to train machine-learning models.

Where it lives

On servers in the United States (New York). If you are in the UK or the EU and need a data processing agreement or transfer terms, email [email protected] and we will put one in place.

How long

Your data stays while your workspace is open, because a CRM whose history evaporates is not a CRM. Nothing is deleted on a timer.

When a workspace closes, it stays readable for 30 days so you can export it, then it is deleted. We also keep encrypted backups of the whole database, held outside our hosting provider so that losing one account cannot lose both, and swept automatically after 30 days. So a deleted workspace can survive in a backup for up to 30 days more, and then it is gone and cannot be recovered by anyone, including us.

Cookies

One cookie. It holds a random session token, it is marked httpOnly so no script can read it, and it is scoped to app.cosmentum.com alone. It exists to keep you signed in.

There are no advertising or analytics cookies, which is why Cosmentum has no cookie banner — there is nothing to ask permission for.

When we open your workspace

Only to support you, and every visit is written down before it starts, with a reason. You can read the full list in your own Settings, we cannot delete it, everything we touch is recorded under our name rather than one of yours, and the visit expires by itself after an hour.

Keeping it safe

  • Everything travels over TLS.
  • Passwords are hashed with scrypt; invitation and reset links are stored hashed and work once.
  • The database is not reachable from the public internet.
  • One live session per seat, so a borrowed login is visible rather than silent.
  • Every screen checks who is asking before it reads anything.

No system is perfect. If there is a breach affecting your data we will tell you without delay, and in any case within 72 hours of knowing, with what happened and what we are doing about it.

Your rights

If you hold a seat, you can ask us for a copy of what we hold about you, ask us to correct it, or ask us to delete it.

If you are a client of an agency that uses Cosmentum, your request goes to the agency, not to us — it is their record and they decide. Tell us anyway if you cannot reach them and we will help you get to the right people.

Either way, start at [email protected]. A person reads it.

Terms of servicePrivacy policySecuritySign in