cyos.io Privacy Policy
Plain language, on purpose. The short version: your questions and answers never leave your browser. We can't read what we never receive.
Effective date: 2026-08-27 · Policy version: 1.0
This is the published materialization of the v1 policy ratified by theCreator on 2026-08-26. Source of record: `theCreator/policies/CYOS-PRIVACY-POLICY-v1-DRAFT.md` at commit `38b6d7fd`, sha256 `954697abb159d0a2490351e366e86d47f1fb49e608cfa97fecfe6410f285dd85`. Only the documented substitution slots (effective date, legal entity, jurisdiction, contact mailboxes, log retention) were filled; no other byte of the ratified text was changed.
Who we are
cyos.io is operated by re2me Inc. ("we"). It is the delivery origin for reBe Intelligence, the sovereign website intelligence available at rebe.life.
This policy covers two very different groups of people, so it is split in two: visitors to websites that use reBe Intelligence, and owners who subscribe for their sites.
Part 1 — If you are a visitor to a site using reBe Intelligence
The core design commitment
reBe Intelligence runs the AI inside your own browser, on your own hardware. Your questions, the answers you receive, and your conversation history are processed and stored locally on your device. They are never transmitted to cyos.io and never transmitted to the website's server by reBe Intelligence. We cannot read, log, sell, or train on your conversations, because we never receive them.
What your browser does request from cyos.io
To work at all, your browser fetches static files from cyos.io, the same way it fetches any script or image on the web:
- the reBe Intelligence software (the SDK script),
- AI model weights (downloaded once, then cached on your device),
- the site's published context package (the public content the AI answers from).
Like every web server, ours receives the standard metadata of those requests: your IP address, browser user-agent, and the referring site's origin. We use ordinary short-retention server logs for security and capacity only (30 days). We do not use this metadata to build profiles of visitors, and we do not sell it or share it for advertising. No cookies are set on visitors by cyos.io. No advertising or third-party trackers, ever.
Where your conversation memory lives
In your browser's local storage (including origin-private file storage), under the website's origin. It belongs to you: clearing your browser data for that site removes it, and no copy exists anywhere else unless you create one.
Cross-site continuity (only if you say yes)
Some owners connect several of their sites so your assistant can remember you across them. This works through a consented shared browser storage area on the cyos.io origin. It happens only if you explicitly agree in the panel, it stays inside your browser, and declining changes nothing else. Taking your memory to another device is likewise your act (a key you hold — passkey/QR); we never hold a readable copy of your history on any server.
Analytics about visitors
None by default. On the highest owner tier, an owner may enable opt-in, privacy-preserving, aggregate-only statistics; these never include conversation content or anything identifying an individual visitor, and the feature is disclosed in the panel where it applies.
Part 2 — If you are an owner (account holder / subscriber)
If you claim a domain or subscribe, we process: your email address, your claimed domains, your tier and entitlement state, and your configuration (context overlays, Flow definitions). Payments are processed by Stripe; card details go to Stripe, not to us — see Stripe's privacy policy. We use owner data solely to provide the service, never for advertising, and we do not sell it.
You can export your configuration and overlays at any time, free and paid tiers alike, and you can delete your account; deletion removes our copies of your owner data (billing records are retained only as law requires).
The WordPress plugin (and other integration plugins)
The official reBe Intelligence plugin's server-side code makes zero network calls and sends no data to cyos.io or anyone else. Its only job is to place the standard embed line on your pages. Once embedded, each visitor's browser fetches the SDK from cyos.io as described in Part 1.
Changes and contact
Material changes to this policy are versioned, dated, and announced on this page before they take effect; the commitment that visitor conversations never leave the visitor's device is the product's foundation and is not subject to weakening by policy update. Questions: [email protected].