DRAFT: founder/legal review required. This document describes Corvan's current practices in good faith, but legal counsel has not yet reviewed it and it is not the final binding agreement.
Corvan

Privacy Policy

Effective date: June 2, 2026

This Privacy Policy explains how Corvan handles your personal data. It is a working draft pending final legal review, but it reflects how the product operates today.

1. Who we are

Corvan provides an AI chief-of-staff assistant for founders and operators. This policy explains what personal data we process, why we process it, and the rights you have over it. Privacy questions can be sent to peter@corvanai.com.

2. Data we process

We process account data you provide, connected or imported content such as email, calendars, messenger threads, contacts, notes, documents and files, and operational metadata such as logins, device labels, usage and error telemetry. Corvan derives summaries, contact profiles and a private knowledge graph from this content. We do not sell personal data.

3. How we use your data

We use your data to operate the assistant, triage communications, prepare for meetings, draft replies, maintain profiles and the knowledge graph, authenticate you, bill subscriptions, provide support, and keep the service secure and reliable. AI features send only the content needed to generate a response.

4. Sub-processors

We use vetted providers only to deliver the service: OpenRouter for LLM routing; DeepSeek and Anthropic for model inference; Stripe for billing; MinIO on Netcup for files, exports and server infrastructure; and Sentry for error and performance telemetry. Providers receive only the data needed for their function and must protect it under contract. Model providers receive prompt content only when you make a request.

5. International data transfers

Some providers, including OpenRouter, Anthropic, Stripe and Sentry, process data in the United States. Transfers from the EEA or UK rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum where applicable, and appropriate technical and organisational safeguards.

6. Retention

We retain your account and content while your account is active. Deleted content is removed from active systems promptly and from backups during the normal rotation window. When you delete your account, we erase personal data and owned content, except information we must retain for legal, tax or fraud-prevention purposes. Anonymous aggregate data may be retained.

7. Your rights

You can access, correct, export and erase your personal data through the product. Depending on your location, you may also object to or restrict processing and complain to a data-protection authority. Use the in-app controls or contact peter@corvanai.com to exercise these rights.

8. Security

We protect data in transit with TLS, store passwords only as salted hashes, isolate tenant data and limit internal access to people who need it. No system is perfectly secure, but we continuously reduce risk and will notify affected users of a material breach when required by law.

9. Changes and contact

We may update this policy as the product and providers evolve. We will revise the effective date and notify you about material changes. Questions and requests can be sent to peter@corvanai.com. See also our Terms of Service.