KOSMOS INTEL

Política de Privacidade — Kosmos Safe Browsing

Atualizada em 24 de setembro de 2026

O Kosmos Safe Browsing é uma extensão de navegador da Kosmos Intelligence que avisa antes de abrir um site catalogado como ameaça (phishing, golpe, página falsa) na base da Kosmos Intel. Esta política explica quais dados a extensão trata, para quê e onde eles ficam.

Conta e credencial

Sem conta, a extensão funciona no plano Free e não trata nenhum dado de identificação. O plano Premium é para quem tem conta no painel Kosmos (tesseract.kosmosintel.ai). A extensão não pede senha: quando você está logado no painel neste navegador, ela envia ao nosso servidor o cookie de sessão do painel e recebe uma credencial própria, válida por 30 dias e renovada enquanto você usa. Ficam guardados no navegador essa credencial, o seu nome e o seu e-mail, que aparecem no popup.

Sites que você visita

A verificação acontece no seu navegador. A extensão guarda uma lista com os primeiros bytes do hash SHA-256 de cada domínio catalogado — não os domínios em si — e compara com o hash do domínio de cada página que você abre. Nenhum endereço sai do navegador nessa comparação.

Só quando o hash de um domínio coincide com um prefixo da lista, a extensão envia ao servidor o hash SHA-256 completo desse domínio para confirmar se é ameaça. Nunca enviamos o endereço completo, o caminho da página, parâmetros, conteúdo, formulários ou senhas. No Premium a consulta leva a sua credencial; no Free, nenhuma. O servidor responde se o hash está na base e não guarda os hashes consultados.

O que fica só no navegador

Comunicação com o servidor

A cada 5 minutos a extensão consulta o servidor da Kosmos (tesseract-api.kosmosintel.ai) para atualizar a lista. As chamadas levam o idioma do navegador e, no Premium, a sua credencial. Como em qualquer conexão, o servidor recebe o endereço IP; mantemos registros técnicos de acesso (IP, data e rota chamada) pelo tempo necessário à segurança e à operação do serviço.

O que não fazemos

Como apagar

Sair, no popup, apaga a credencial, a lista, as confirmações e o histórico de avisos. Desinstalar a extensão apaga todos os dados guardados por ela no navegador.

Seus direitos

Você pode pedir acesso, correção ou exclusão dos dados da sua conta, nos termos da Lei Geral de Proteção de Dados (Lei 13.709/2018), pelos canais de contato em kosmosintel.ai.

Alterações

Mudanças nesta política são publicadas nesta página, com a data de atualização acima.


Privacy Policy — Kosmos Safe Browsing

Last updated September 24, 2026

Kosmos Safe Browsing is a browser extension by Kosmos Intelligence that warns you before opening a site catalogued as a threat (phishing, scam, fake page) in the Kosmos Intel database. This policy explains which data the extension handles, why, and where it is kept.

Account and credential

Without an account, the extension runs on the Free tier and handles no identifying data. The Premium tier is for users with an account on the Kosmos panel (tesseract.kosmosintel.ai). The extension never asks for a password: when you are signed in to the panel in this browser, it sends the panel session cookie to our server and receives its own credential, valid for 30 days and renewed while you use it. The credential, your name and your email are stored in the browser and shown in the popup.

Sites you visit

Checks happen in your browser. The extension keeps a list with the first bytes of the SHA-256 hash of each catalogued domain — not the domains themselves — and compares it with the hash of the domain of each page you open. No address leaves the browser during this comparison.

Only when a domain hash matches a prefix in the list does the extension send the full SHA-256 hash of that domain to the server to confirm whether it is a threat. We never send the full URL, page path, parameters, content, forms or passwords. On Premium the request carries your credential; on Free, none. The server answers whether the hash is in the database and does not store the hashes it is asked about.

Data kept only in the browser

  • the prefix list and the confirmations received from the server;
  • the history of the last 50 warnings shown;
  • the domains you chose to allow;
  • your preferences and the light/dark theme chosen on the Kosmos panel, read from the panel page itself.

Communication with the server

Every 5 minutes the extension contacts the Kosmos server (tesseract-api.kosmosintel.ai) to update the list. Requests carry the browser language and, on Premium, your credential. As with any connection, the server receives your IP address; we keep technical access logs (IP, date and route) for as long as needed for the security and operation of the service.

What we do not do

  • we do not sell or share data with third parties;
  • we do not use data for advertising or credit assessment;
  • we do not collect your browsing history or page content;
  • we do not use analytics, tracking or remote code.

Deleting your data

Sign out, in the popup, deletes the credential, the list, the confirmations and the warning history. Uninstalling the extension deletes all data it stored in the browser.

Your rights

You may request access to, correction or deletion of your account data, under the Brazilian General Data Protection Law (Law 13,709/2018), through the contact channels at kosmosintel.ai.

Changes

Changes to this policy are published on this page, with the update date above.