Privacy Policy
COSBRIK
Last updated: August 6, 2026
Package: com.cosbrik.app
This page explains what information COSBRIK collects through the website, web app,
and mobile app, how that information is used, and what choices are available to users.
This is the canonical privacy policy for the COSBRIK website, frontend experience,
and mobile application.
1. Introduction
COSBRIK is a construction and business operations platform provided by COSBRIK
("we," "us," or "our"). This Privacy Policy explains what information COSBRIK
collects through the website, web app, and mobile app, how that information is used,
and the choices available to users.
This policy is intended to describe the current behavior of the services as
implemented at the time of this update. If you do not agree with this policy,
do not use the services.
2. Scope
This policy applies to the COSBRIK website, web application, mobile application,
and information processed through those services. It does not govern the privacy
practices of third-party websites, app stores, device manufacturers, or
operating-system providers that may also interact with your device or app distribution.
3.1 Information you provide when signing in or using the app
Depending on your role and how your organization uses COSBRIK, the app may process:
- Email address used to sign in
- Password entered at sign-in
- Your name and profile details returned by the COSBRIK backend
- Company, role, and site assignment information associated with your account
- Business records you create, view, update, or approve in the app, such as site, material, ledger, payment, customer, supplier, or other operational data
- Images or attachments that you choose to capture or upload through app features
3.2 Authentication and device-related data
To support secure sign-in and session management, the app processes:
- Access tokens used for authenticated API requests
- Refresh tokens used to renew sessions
- A generated device identifier used by the backend login flow
- A biometric-login preference stored on the device
- Optional saved credentials on the device when the user enables convenience features tied to biometric sign-in
3.3 Biometric authentication
If you enable biometric sign-in, the app uses the biometric capabilities exposed
by your device operating system, such as fingerprint or face authentication.
- We do not receive or store your raw fingerprint, face scan, or other biometric template on our servers.
- Biometric matching is handled by your device and operating system.
- The app only receives the result of whether local authentication succeeded.
3.4 Images, camera, and photo selection
Some features allow you to attach images for operational records.
- If you choose to take a photo, the app may request camera access.
- If you choose to upload an existing image, the app may request access to photos or media made available by the operating system.
- The app accesses images only when you initiate those actions.
3.5 Automatically processed technical data
When the app communicates with the backend, standard technical information may be
processed by our systems or infrastructure, such as:
- IP address
- Request metadata
- Device-generated identifiers used for session handling
- Error and diagnostic information needed to operate and secure the service
4. How We Use Information
We use information processed through the app for the following purposes:
- To authenticate users and maintain active sessions
- To provide role-based access to business features and data
- To store and retrieve records needed for construction, finance, sales, material, and site workflows
- To support optional biometric sign-in on the user's device
- To upload, display, and manage user-selected images and related records
- To protect the service, investigate misuse, and maintain operational security
- To comply with applicable law, lawful requests, and internal recordkeeping needs
5. What the App Stores on the Device
The mobile app and browser session may store limited data locally on the device, including:
- Access token in app memory during an active session
- Refresh token in secure device storage
- Generated device identifier in secure device storage
- Optional saved email and password in secure device storage when the user enables biometric convenience flows
- Biometric-enabled preference in secure device storage
Locally stored data is used to keep users signed in, support session refresh,
and allow optional biometric login behavior in the mobile experience. Browser-based
sessions may use cookies or similar storage mechanisms as needed for the web experience.
6. Data Sharing and Disclosure
We do not sell personal information.
We may disclose or make information available only in limited situations such as:
- To service providers or infrastructure providers that host or support the backend service
- Within your organization, to authorized users based on role and permissions
- When required by law, regulation, court order, or valid governmental request
- As part of a merger, acquisition, financing, reorganization, or asset transfer
- To protect the rights, security, and operation of COSBRIK, our users, or others
7. Third-Party and Platform Dependencies
The app relies on platform and software components that may process limited
technical information as part of providing their function, including:
- Google Play and Android platform services used to distribute and run the app
- Device biometric frameworks used for local authentication
- Secure local storage mechanisms provided by the device platform
These third parties operate under their own terms and privacy practices.
8. Data Retention
We keep data for as long as reasonably necessary for operational, contractual,
legal, security, and recordkeeping purposes.
- Data stored locally on the device may remain until the user signs out, disables a feature, clears app data, or uninstalls the app, subject to device behavior.
- Backend records may be retained for legitimate business and compliance purposes even if a user stops using the app.
9. Security
We use reasonable administrative, technical, and organizational measures intended
to protect information processed through the app. No method of storage,
transmission, or electronic processing is completely secure, and we cannot
guarantee absolute security.
For production use, the app is intended to communicate with the configured
production backend over HTTPS. Security also depends on the configuration and
operation of the backend environment and the user's device.
10. Your Choices
Depending on your device and organizational use of COSBRIK, you may be able to:
- Choose whether to enable biometric sign-in
- Decline camera or photo access permissions
- Remove the app from your device
- Request account, profile, or data assistance through your organization or by contacting us
- Request deletion of your account and associated data by visiting our Delete Account page
If you want locally stored credentials removed from the device, you should sign
out, disable biometric login if enabled, and clear app data or uninstall the app
if needed.
11. Children
COSBRIK is a business application and is not intended for children.
12. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update
the "Last Updated" date above. Continued use of the app after an update means the
updated policy will apply going forward.
14. Android Permissions Summary
At the time of this update, the Android app manifest explicitly declares:
- INTERNET for backend communication
- USE_FINGERPRINT and USE_BIOMETRIC for optional biometric authentication
In addition, app features may trigger operating-system-managed camera or
photo-selection access when the user chooses to capture or upload images.