Coventra
PlatformMCPResourcesHelp
Sign inStart free
Privacy · independent beta

Data Policy

Effective: June 20, 2026

Coventra is not a repository for sensitive personal data. Use only public literature and aggregate research data that does not identify and cannot reasonably be used to identify an individual. Do not upload PHI, patient records, individual participant data, or confidential corporate data.

Contents
  1. Scope and operator
  2. Data we collect
  3. Prohibited data
  4. How we use data
  5. Infrastructure and service providers
  6. Security and access
  7. Retention and deletion
  8. Browser storage and telemetry
  9. Optional automated processing
  10. Your choices and rights
  11. International users
  12. Incidents and legal requests
  13. Children
  14. Changes and contact

1. Scope and operator

This policy explains how the independent operator of Coventra.app collects and handles information. Coventra is an independent experimental beta, not a registered company. Contact: support@coventra.app.

2. Data we collect

Account and profile data

  • Email address, account identifier, authentication records, optional profile fields
  • Project roles, invitations, access settings, and preferences

Research and collaboration data

  • Project metadata, imported citations, uploaded PDFs, extraction rows, analyses, plots, and exports
  • Screening, risk-of-bias, quality, GRADE, comments, tasks, audit history, and provenance
  • Community profile fields, opportunities, reports, and participant-only messages when Community is enabled

Operational data

  • Request and correlation identifiers, route, status, duration, account and project identifiers, and query/cache timing
  • Job type, status, duration, technical errors, browser performance, IP-derived network information, and security events

We do not intentionally place document contents, abstracts, PDFs, extracted values, passwords, tokens, or request bodies in observability events.

3. Prohibited data

You must not submit: PHI, identifiable health information, medical records, individual participant data, patient-level records, credentials, government identifiers, financial data, confidential/proprietary/embargoed corporate material, or content you are not allowed to process.

You are responsible for determining that uploaded content can be lawfully processed. If prohibited data is uploaded by mistake, stop using the affected project and contact support promptly.

4. How we use data

  • Authenticate accounts and provide screening, extraction, analysis, collaboration, and export workflows
  • Store project content and run requested R analyses and background jobs
  • Provide support, prevent abuse, enforce permissions, and investigate incidents
  • Measure reliability and performance, debug errors, and improve the Service
  • Comply with law and protect users, the public, and the Service

We do not sell research data, use it for our own publications, share it with advertisers, or train Coventra models on private project content without separate explicit agreement.

5. Infrastructure and service providers

  • Application database and authentication: self-hosted Supabase software on Coventra-controlled application infrastructure
  • Documents and analysis artifacts: Cloudflare R2 object storage
  • Public delivery and protection: Cloudflare ingress and related network services
  • Statistical processing: a separate R analysis service using open-source R packages
  • Operational observability: Axiom receives sampled technical metadata, errors, and job/request performance events
  • Email delivery: an external transactional email provider receives recipient addresses and delivery metadata

Optional model-assisted table processing may use a configured external provider, such as Google Gemini, or a locally hosted model. Only invoke such features with content you are permitted to send to that provider.

6. Security and access

We use role-based project permissions, database access controls, authenticated sessions, encrypted transport, operational monitoring, and other reasonable safeguards. Collaborators access project data according to their role. Community opportunities and selected profile fields may be public; private messages are limited to participants and may be accessed by authorized support personnel when reasonably required for safety, support, abuse investigation, or legal compliance.

No internet service is perfectly secure. The beta is not offered for PHI or other highly sensitive data.

7. Retention and deletion

We retain account and project data while needed to provide the Service, maintain security and audit integrity, resolve disputes, or meet legal obligations. Deletion from active systems may not be immediate, and limited copies may remain temporarily in backups, logs, fraud-prevention records, or legally required records until normal retention cycles expire. Keep your own exports; Coventra is not a permanent archive.

8. Browser storage and telemetry

The Service uses browser storage and, where applicable, strictly necessary cookies to maintain sessions, protect authentication, and remember interface preferences. We do not currently use advertising pixels or sell behavioral profiles. Operational telemetry is used to diagnose reliability and performance, not targeted advertising.

9. Optional automated processing

Some workflows use deterministic extraction, entity recognition, embeddings, or a configured language model to suggest structure from user-selected content. Suggestions can be wrong and require human review. Coventra does not use these features to make legal, clinical, employment, or similarly significant decisions about individuals.

10. Your choices and rights

  • View, correct, export, or delete supported project data through the Service
  • Request account deletion or applicable access, correction, deletion, restriction, or portability rights by contacting support
  • Decline optional model-assisted workflows by not invoking them

We may need to verify your identity and may retain data where law or legitimate security needs require it.

11. International users

Coventra may process data in countries other than yours. Do not assume EU, UK, or any other specific data residency unless confirmed in writing. Local privacy law may provide mandatory rights that this policy does not limit.

12. Incidents and legal requests

If we become aware of a security incident affecting personal data, we will investigate, mitigate, and notify affected users or regulators when and within the time required by applicable law. We may preserve or disclose information to comply with valid legal process, enforce Terms, investigate abuse, or protect rights and safety.

13. Children

The Service is not intended for anyone under 18, and we do not knowingly permit children to create accounts.

14. Changes and contact

We may update this policy as the beta and providers change. Privacy questions, rights requests, and prohibited-data reports may be sent to support@coventra.app.

© 2026 Coventra · Independent beta project
Terms of UseThird-Party NoticesHome