Open CocoCrocoCocoCroco

Privacy Policy

How CocoCroco handles information when your work stays local—and when you choose to send it elsewhere.

Last updated August 27, 2026
Privacy PolicyTerms of Service

At a glance

CocoCroco is a BYOK (bring your own key) AI chat application for branching conversations on a visual canvas. The boards, conversations, attachments, provider keys, and settings you create in the app are stored locally on your device. CocoCroco does not operate a cloud database for your chat content and does not proxy your AI conversations.

When you choose to send a message, the relevant prompt, context, and attachments leave your device and go directly to the AI provider you selected. That provider’s own privacy policy and terms govern its processing.

Information stored on your device

Depending on how you use CocoCroco, the app stores the following locally:

  • boards, nodes, edges, messages, text, code, branch relationships, and local search indexes;
  • attachments and information needed to display them;
  • AI provider configuration and provider API keys;
  • personas, prompts, blueprints, skills, plugins, usage information, and app settings;
  • export files you choose to create, wherever you save them; and
  • local identifiers used for license activation, checkout handoff, and app preferences.

On the web, this information is stored in this browser’s private SQLite/OPFS storage. In the desktop app, it is stored in a local SQLite database file. CocoCroco does not automatically sync this information between devices. Use the app’s export and import tools when you choose to move or back up your data.

Information sent to other services

AI providers

When you send a request, CocoCroco sends the content needed for that request to the provider, model, endpoint, or local CLI you selected. This can include your prompt, inherited conversation context, selected text, attachments, tool inputs, and the provider key needed to authenticate the request. CocoCroco does not control how that provider stores or uses the request. Review the provider’s terms and privacy policy before sending sensitive information.

Checkout and licensing

When you start a Pro purchase, CocoCroco creates a random local device identifier and sends it to its licensing service to connect the checkout with the device that started it. Payment, purchase email, and card information are handled by Polar, our payment and license provider. CocoCroco does not receive your payment card number through the app.

For license activation and verification, the licensing service may process the device identifier, license key information, activation status, and technical request information. Pending activation information is held temporarily in memory so a completed purchase can be delivered to the app, then expires or is removed when it is no longer needed.

Website analytics

The web version uses Umami analytics to understand whether the public site is being used. Umami is configured without cookies. The app sends limited events such as page views and pricing-button interactions. These events are not sent with your boards, messages, attachments, or provider keys. The analytics provider may receive ordinary technical information associated with an analytics request.

Rate limiting and operations

Requests to CocoCroco’s licensing and download services may be associated with an IP address temporarily for rate limiting and abuse prevention. Operational systems may also process request, activation, and error information needed to keep those services working and secure.

Third-party services

CocoCroco can connect to services that you select or enable, including AI model providers, local command-line tools, web-search providers, content-extraction providers, Polar checkout and licensing, and Umami analytics on the web. Each third party operates under its own terms and privacy policy. A custom provider or plugin may send information to its configured endpoint; check that service before using it with sensitive content.

Your provider keys are used to make requests to the provider you choose. They are not intended to be sent to CocoCroco’s chat service. On desktop, CocoCroco uses operating-system-backed encryption for stored keys when the operating system makes that facility available; on the web, browser storage is protected by the browser and device security model.

Retention and deletion

Your local app data remains on your device until you delete it, clear the relevant browser or desktop app data, or replace it through import. Clearing browser data can permanently remove the web copy, so export important boards before doing so. Exported files are under your control and are not uploaded to CocoCroco by the export feature.

CocoCroco retains service-side information only for as long as reasonably needed to provide checkout and licensing, operate the website, prevent abuse, resolve support requests, comply with legal obligations, and maintain security. Retention can differ for Polar payment records, provider records, and analytics records because those services maintain their own systems and policies.

Your choices and rights

You control the content stored in the app. You can export it, delete it, or clear the local storage that contains it. You can choose which AI provider receives a request and whether to configure a provider at all.

Depending on where you live, you may have rights to request access to, correction of, deletion of, or information about personal data processed by CocoCroco. To ask a question or make a request about service-side information, email [email protected]. We may need enough information to verify and locate the relevant request or purchase.

Security

CocoCroco is designed to keep ordinary app data local and to send content to an AI provider only when you initiate a request. No storage or transmission method is completely secure. Protect your device, browser profile, provider keys, exported files, and license email. Do not use a shared or compromised device for sensitive work.

Children’s privacy

CocoCroco is not directed to children. Do not use the service if you are not legally able to agree to its terms in your location. If you believe a child has provided personal information to CocoCroco’s service-side systems, contact [email protected].

Changes to this policy

We may update this Privacy Policy when CocoCroco’s features, providers, or data practices change. The “Last updated” date at the top will change with a new version. Continued use after an update means the revised policy applies to future use, subject to any rights that cannot be waived.

Contact

Questions about this Privacy Policy or CocoCroco’s data practices can be sent to [email protected].

CocoCroco
Questions? [email protected]Read the docs