Privacy Policy
This Privacy Policy describes how Zapusk Partners LLC ("Zapusk," "we," "us," or "our") collects, uses, stores, and protects information in connection with the financial management application made available at kosmoscap.com and its subdomains (the "Service").
The Service is operated for a single authorized user (the principal of Zapusk Partners LLC) and is used to aggregate and analyze the principal's personal financial accounts. The Service does not onboard third-party end users, does not provide investment advice to others, and does not sell or share personal data with any party other than the providers required to operate the Service.
1. Information We Collect
We collect only the information necessary to operate the Service.
1.1 Account Credentials
A username and a password (stored as a salted hash; we never store passwords in plaintext) and a multi-factor authentication secret (TOTP) used to sign in to the Service.
1.2 Financial Account Data via Plaid
When you connect a financial account through Plaid Inc. ("Plaid"), Plaid acts as the data provider and we receive from Plaid:
- Account identifiers, names, types, and subtypes (e.g., checking, credit card, brokerage)
- Account balances (current and available)
- Transaction history (date, amount, merchant, category)
- Holdings and investment positions where applicable
- Identity fields associated with the account where applicable (name, address, email, phone as reported by the financial institution)
- Access tokens issued by Plaid that allow us to retrieve the data above on an ongoing basis
We do not receive your online banking credentials. Your financial institution credentials are entered directly into Plaid and are never visible to us.
1.3 Operational Telemetry
Standard server logs (timestamps, request paths, response codes, error traces) used to operate and secure the Service. Logs are sanitized to exclude financial values and identifiers.
We do not use third-party advertising or analytics trackers and we do not deploy cookies for any purpose other than authentication.
2. How We Use Information
We use the information we collect to:
- Authenticate the user and maintain session integrity
- Display account balances, transactions, holdings, and net-worth calculations
- Maintain a local historical record of balances and transactions for trend analysis
- Detect and investigate security or operational anomalies
We do not use the information for advertising, marketing, profiling for third parties, or any purpose unrelated to operating the Service.
3. How We Share Information
We do not sell, rent, or share personal or financial information for marketing or commercial purposes.
We share information only with the following parties, and only to the extent necessary to operate the Service:
- Plaid Inc., which provides the financial account connectivity layer. Plaid's processing of personal information is governed by Plaid's own End User Privacy Policy, available at https://plaid.com/legal/.
- DigitalOcean LLC, which provides the cloud infrastructure on which the Service runs.
- Regulators or law enforcement, where required by valid legal process or where we believe in good faith that disclosure is necessary to protect rights, safety, or property.
We do not transfer personal information to any other third party.
4. Data Retention
We retain account, transaction, and balance data for as long as the connected financial account remains linked plus a reasonable historical window to support analysis. Operational logs are retained for a limited period sufficient to support security investigations and are then deleted.
You may at any time:
- Disconnect a linked financial account, which causes us to revoke the corresponding Plaid access token and stop receiving new data from that account
- Request deletion of stored data associated with a linked account
- Request deletion of all user account data
Requests are honored within thirty (30) days. Some records may be retained beyond that period only to the extent required by law (for example, to comply with tax, audit, or anti-fraud obligations) and are stored under restricted access.
5. How We Protect Information
We apply administrative, technical, and physical safeguards designed to protect information against unauthorized access, alteration, disclosure, or destruction. These safeguards are described in our Information Security Policy and include:
- Encryption of data in transit using TLS 1.2 or higher
- Encryption of data at rest on the underlying cloud infrastructure
- Multi-factor authentication on the Service for the authorized user
- Multi-factor authentication on all administrative accounts (cloud provider, source control, password manager, financial institutions)
- Least-privilege access controls, key-based administrative access, host-based firewalling, and non-default administrative network exposure
- Secret management via a reputable password manager protected by a strong master credential and MFA
- Endpoint controls on administrative devices including full-disk encryption and current operating-system security updates
- Logging and periodic review of authentication and access events
No system is impenetrable. Despite reasonable safeguards, we cannot guarantee absolute security and we do not warrant against unauthorized access in the event of a sophisticated or unforeseen attack.
6. Your Rights
Because the Service has a single authorized user (the principal of Zapusk Partners LLC) and does not onboard third parties, individual data-subject rights under U.S. state privacy laws are exercised by the principal. The principal may at any time:
- Access the data the Service holds
- Correct inaccuracies
- Request deletion of all or part of the data
- Revoke a Plaid connection
To exercise any of these rights, contact us using the information in Section 9.
7. Children's Privacy
The Service is not directed to, and we do not knowingly collect information from, anyone under the age of eighteen. If we learn that information from a person under eighteen has been collected, we will delete it.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be reflected by updating the "Last updated" date at the top of this document and, where appropriate, by posting a notice within the Service. Continued use of the Service after a material update constitutes acceptance of the updated policy.
9. Contact
Questions, requests, or concerns regarding this Privacy Policy or our handling of your information may be directed to:
Zapusk Partners LLCAttn: Privacy
235 Second Street
Sutherland, IA 51058
Email: privacy@kosmoscap.com
This Privacy Policy is intended to comply with applicable U.S. federal and state privacy laws, including the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and with Plaid's data-handling requirements as published at https://plaid.com/legal/.