Cohese Cohese

Privacy Policy

Effective September 13, 2026. If we make a material change, we'll update this date — this page won't grow a separate changelog.

Cohese is a product of Brwnd Labs LLC ("we," "us," "our").

1. Who this covers

This Privacy Policy describes how Cohese collects, uses, and protects information for everyone who uses Cohese, including dependent profiles managed by a parent or guardian.

2. Information we collect

Cohese does not collect continuous background location. The only location-like information Cohese has is the addresses or areas someone enters for a specific Event or Ride.

3. How we use information

To provide Cohese's coordination features (showing you what's happening in your Groups, letting you register, request, commit, and see what's covered), to send you the notifications your Group activity and settings call for, to keep the service secure, to respond when you contact us, and to meet legal obligations.

4. What we don't do

Cohese does not sell personal information. Cohese does not build an advertising profile from your activity, and does not use youth Group-activity data for marketing. Cohese does not send names, emails, phone numbers, exact locations, or private message content to analytics or crash-reporting tools.

5. Who we share information with

The people your own Group memberships and Cohese's built-in privacy rules already authorize to see it — for example, your Group's other members can see what your Group's settings show them, and a Ride's exact details go only to the assigned driver. Beyond that, Cohese shares information only with the service providers that help us run Cohese:

Each provider is bound to use information only to provide that service to us. We may also disclose information if required by law or to protect someone's safety.

6. Children's privacy

Cohese's interactive accounts require you to be 13 or older. A person under 13 can be represented in Cohese only as a dependent profile that a parent or guardian creates and controls; the guardian decides what information is entered for that dependent, and Cohese limits what a dependent profile collects to what the product actually needs.

Pending qualified legal review before any future feature collects personal information directly from a child rather than through a parent/guardian: Cohese's practices are being prepared with the Children's Online Privacy Protection Act (COPPA) in mind, and a formal verifiable-parental-consent mechanism will be put in place and reviewed by qualified counsel before any such feature ships. No such feature exists in Cohese today — every under-13 dependent profile is entered and controlled by an adult guardian's own account.

7. How long we keep information, and deletion

See our separate Data & Deletion Policy for the full retention schedule. In short: when you delete your Cohese account, we disable it immediately and complete deletion or anonymization of your profile information within about 30 days; a Ride's exact pickup/drop-off details are deleted within about 7 days after the ride ends; and a dependent profile with no remaining active Group membership or guardian relationship is reviewed for deletion within about 90 days. Some narrow, minimal records (for example, that a security-relevant action happened) may be kept longer where noted in the Data & Deletion Policy, for security, fraud-prevention, or legal purposes.

8. Data storage and security

Account, Group, and activity data is stored securely on Amazon Web Services, encrypted in transit and at rest. Access to personal information is limited to what a given feature or support need actually requires, and we regularly review our security practices. Cohese never asks for or stores your Apple or Google password. Some information — for example, your current session — is also cached briefly on your device to make the app responsive; logging out clears it.

9. Data breach notification

If a security incident compromises your personal information, we will investigate and contain it, notify affected users without unreasonable delay and consistent with applicable law, and report to relevant authorities where required. Cohese's engineering team follows a documented incident-response process covering evidence preservation, credential rotation, and root-cause remediation for every suspected incident, not only ones that reach the reporting threshold above.

10. Your rights and choices

11. Regional privacy rights

California residents. Under the California Consumer Privacy Act, you have the right to know what personal information we collect, request its deletion, opt out of its sale, and not be discriminated against for exercising these rights. Cohese does not sell personal information, so there is nothing to opt out of today.

Pending qualified legal review: Cohese is currently intended for use within the United States (see "Where we operate" below). If Cohese is ever offered to residents of the European Economic Area or United Kingdom, this section will be expanded with the specific rights the General Data Protection Regulation provides (access, rectification, erasure, restriction, portability, and objection) and reviewed by qualified counsel before that expansion.

12. Where we operate

Cohese is currently intended for use within the United States. If that changes, this policy will be updated to describe how information may be handled across borders.

13. Changes to this policy

Cohese may update this Privacy Policy. The "Effective" date at the top of this page will change when it does.

14. Contact

Questions about this Privacy Policy, or a request about your information, can be sent to privacy@cohese.app.