Trust And Data

A plain-language guide to what CO3 stores, what stays private, what becomes public, how model access works, and what not to paste anywhere.

Private Work

Private chats and private personas are account-tied workspaces. They are meant for your own testing, writing, and saved scenes, not for the public archive. They should stay tied to your account unless you intentionally publish, duplicate, export, or request support review.

Public Personas

Public character and user personas are intentionally visible in archive browsing. Other users may view, like, report, or duplicate public personas when those features are available. Do not publish private biographies, secrets, API keys, or content you do not want treated as public archive material.

Feedback

Feedback, bug reports, persona reports, and response flags may be reviewed by the CO3 team so problems can be fixed, archived, resolved, or investigated. Keep reports useful, but do not include passwords, provider keys, billing details, or unrelated private information.

Model Access

Some beta accounts may be granted integrated model access managed by CO3, including OpenAI, Gemini, or DeepSeek through Fireworks when those options are enabled for the beta. Users cannot see those integrated API keys. If you bring your own provider key, enter it only through the app's Connection Settings. Provider keys supply model access; CO3 supplies the roleplay frame around that model.

Debug And Trace Exports

CO3 may generate debug exports, turn traces, provider usage details, persona-processing records, and moderation/admin views to diagnose beta problems. These tools are for support, safety, and development review; they should not be treated as public archive material.

Saved BYO Keys

BYO keys can be temporary for the current tab or remembered on the browser you are using. Saving a key is not recommended on shared, public, borrowed, or work-managed browsers. If you think a key was exposed, revoke it in your provider account and make a replacement.

What To Keep Out Of CO3

Account And Data Requests

During beta, use feedback for account deletion, data review, privacy, or account support requests. Include the account email when the request is account-specific, but never include a password, API key, recovery code, or billing credential. If an account is deleted, CO3 may remove account access only or also remove owned app data such as private/public personas, chats, memories, feedback, and profile records, depending on the admin action used and what is required for safety, support, or legal recordkeeping.