Covey
Version 1.1.0
This Privacy Policy describes how Covey ("we", "us") collects, uses, and protects information when you use the Covey mobile application (the "Service").
Covey is end-to-end encrypted. We are technically unable to read the content of your messages, calls, photos, calendar events, mood logs, prompt answers, vault files, or any other personal content you store in the Service. This document explains exactly what we can see, what we cannot see, and what we do with the operational metadata that makes the Service work.
All of the following is end-to-end encrypted. Encryption keys are generated on your device and never transmitted to our servers. We hold only ciphertext for these categories:
This is a technical reality, not a policy promise. Even if we wanted to read your content, we could not. We do not hold the keys.
When you create an account, we collect:
To deliver the Service, we process:
With your consent, we collect anonymous crash reports through Firebase Crashlytics. Reports include the stack trace, device model, OS version, app version, and locale. They never include message content, photo content, names, contact information, or any encryption key material. You can disable crash diagnostics at any time in Settings → Privacy & Security → Crash Diagnostics.
Our cloud infrastructure generates operational logs that may include your account UID, request timestamps, and HTTP status codes. These logs are retained approximately 30 days by Google Cloud Logging and used only to diagnose service issues.
We do not use your information to build advertising profiles. We do not sell, rent, or trade your information to anyone.
The Service relies on a small number of infrastructure providers who process data on our behalf:
These providers see only ciphertext for any personal content, plus the operational metadata listed in Section 2.2. They are contractually bound to use the data only to provide the services we have engaged them for.
When either partner taps Disconnect (Settings → Disconnect), an automated cleanup process runs within minutes and deletes all shared server-side data: Vault files, calendar events, chat envelopes, prompt answers, mood logs, encrypted backups associated with the Pair. Content already downloaded to either device's local database remains on that device.
When you tap Delete Account (Settings → Delete Account), the deletion is immediate and irreversible:
Cloud Function operational logs containing your UID may remain in Google Cloud Logging for approximately 30 days before automatic rotation deletes them.
Depending on your jurisdiction, you have rights regarding your personal data. To exercise any of the following, contact us at [email protected]:
We aim to respond to requests within 30 days. We will not charge you for a request unless it is manifestly unfounded or excessive.
If you are in the European Union, European Economic Area, or United Kingdom, the General Data Protection Regulation applies.
California residents have rights under the California Consumer Privacy Act (CCPA), as amended by the CPRA:
The Service is intended for users 17 years of age or older. We do not knowingly collect personal information from anyone under 17. If we become aware that we have collected information from a person under 17, we will immediately terminate the account and delete all associated data.
We use industry-standard cryptographic primitives:
No security system is perfect. If you discover a vulnerability, please disclose it responsibly to [email protected].
We respond to valid legal requests in accordance with applicable law. Because the Service is end-to-end encrypted, the content of your communications and stored files is not available to us and therefore cannot be provided in response to any request, court order, or warrant.
We can provide only the information we hold, which is limited to: account identifiers (UID, sign-in method, registration timestamp), pairing relationship (which UID is paired with which), subscription tier, operational metadata about message routing (counts, timestamps, sizes - never content), and push-notification delivery flags.
We may update this Policy from time to time. If we make material changes, we will notify you by in-app notification and/or email at least 30 days before the changes take effect. The updated Policy will be available in the app and on our website. Continued use of the Service after the effective date of the revised Policy constitutes acceptance.
For all privacy and data-rights inquiries - access, deletion, portability, GDPR, CCPA, complaints, or general questions - please reach us at: