🔒 Privacy Policy
Your Privacy, By Design
KovelAI's retention controls limit session-content archives; your clients' data is never stored, never indexed, and never accessible — even to us.
1. Information We Collect
KovelAI collects the minimum information necessary to provide our services:
• **Account Information:** Firm name, administrator email, and billing details provided during registration.
• **Session Metadata:** Timestamp, duration, and token count for billing and compliance audit purposes. Session content is never stored.
• **Usage Analytics:** Aggregated, anonymized platform usage metrics via Google Analytics 4 with IP anonymization enabled.
**What We Do NOT Collect:**
• Client search queries or AI conversation content
• Browser history or browsing behavior
• Documents, files, or case materials
• Any personally identifiable information (PII) of your clients
2. Retention Controls
KovelAI applies retention controls intended to limit persistence of session content:
• AI inference is designed to run in short-lived compute contexts.
• Session content is not retained as a long-term product archive; operational exceptions and outages can still create residual records.
• Session metadata (timestamps, token counts) may be retained for up to 90 days for billing reconciliation, then deleted.
• Infrastructure logs may be retained for up to 30 days for security monitoring and are purged on schedule.
• Universal zero-retention or zero-metadata is not claimed.
3. Information Sharing
KovelAI does not sell, rent, or trade your information. We share data only in these limited circumstances:
• **Service Providers:** Google Cloud Platform (infrastructure), Stripe (payment processing). All providers are bound by data processing agreements.
• **Legal Compliance:** We may disclose information if required by law, subpoena, or court order. We can only produce records that actually exist under our retention controls.
• **Business Transfer:** In the event of a merger or acquisition, your data would be subject to the same privacy protections.
4. Security Measures
• AES-256 encryption at rest for all persistent data
• TLS 1.3 for all data in transit
• SOC 2 Type II assessment work in progress (not claimed as certified here)
• RBAC with MFA enforcement for all administrator accounts
• 15-minute session token rotation
• Cloud Armor WAF with 4 active security rules
• Immutable audit trails with tamper-evident checksums
• Penetration testing conducted annually by independent security firms
5. Your Rights
Depending on your jurisdiction, you may have the following rights:
• **Access:** Request a copy of the personal data we hold about you.
• **Correction:** Request correction of inaccurate personal data.
• **Deletion:** Request deletion of your personal data (subject to legal retention obligations).
• **Portability:** Request your data in a structured, machine-readable format.
• **Objection:** Object to processing of your personal data for specific purposes.
**GDPR (EU/EEA):** We process data under legitimate interest (Article 6(1)(f)) and contractual necessity (Article 6(1)(b)). DPA available upon request.
**CCPA (California):** We do not sell personal information. California residents may exercise their rights by contacting privacy@kovelai.com.
6. Contact & Updates
For privacy inquiries, data subject requests, or to report a concern:
• **Email:** privacy@kovelai.com
• **Mail:** ShadowTagAI, Inc. — Privacy Team
This policy is effective as of January 1, 2026 and was last updated on May 4, 2026. We will notify registered users of material changes via email at least 30 days before they take effect.