Who this policy covers
Two groups. Customers are people who create a Cove workspace (operators, billing contacts). Visitors are people who load a customer’s website with the Cove snippet and may send a message. Marketing visitors to coveinbox.co are a third, smaller set (this website).
We are not a law firm and this is not legal advice. If you embed the widget, you are responsible for telling your visitors that a third-party messenger is on the page, including cookies, in line with the laws that apply to you.
Controller and processor
For customer account data (email, workspace settings, billing identifiers), Cove is the controller. For visitor messages, contacts, and widget events stored in a workspace, the customer is typically the controller and Cove is the processor — we process that data to provide the inbox and messenger they asked for.
Account and billing data
When you sign up we store name, email, authentication data (via Supabase Auth), workspace name, seat invites, roles, and settings you save (widget appearance, articles, quick replies, routing rules). Card numbers are not stored by Cove. Checkout and payment methods are handled by Dodo Payments over HTTPS. We store plan, status, and identifiers needed to keep the subscription in sync.
Visitor and conversation data
If a visitor sends a message we store the transcript, timestamps, optional name and email they give, last page URL the widget reports, attachments they upload (widget-uploads), CSAT if they rate after resolve, and operator notes on that thread. We do not run a live visitor map of everyone on the site. We do not sell visitor lists. We do not train public machine-learning models on your workspace threads.
Draft-from-articles on Plus reads published help articles in that workspace only — not PDFs, not a site crawl, not the open web.
How we use data
- To operate the messenger, inbox, help articles, and APIs you asked for
- To send transactional mail (invites, password reset, outbound replies via Resend when a contact has a real address)
- To bill and prevent abuse (spam through the widget, scraped public keys)
- To debug incidents when you write help@coveinbox.co
Legal bases
Where GDPR or similar law applies: contract (providing the service you signed up for), legitimate interests (security, product improvement that does not include training public models on your tickets), and consent where you rely on it for cookies on your own site. Customers must have a lawful basis for putting the widget on their properties.
Subprocessors
We use these processors to run Cove. We do not list a fake law firm.
| Processor | Role |
|---|---|
| Supabase | Database, authentication, file storage for widget uploads |
| Cloudflare | CDN / edge delivery of the widget and realtime conversation rooms |
| Dodo Payments | Checkout, invoices, payment methods. Card data stays with Dodo. |
| Resend | Transactional email and outbound public replies when an address exists |
If we add a processor that handles customer or visitor personal data, we will update this table. Connect-screen integrations you enable (Slack, Shopify, and others) send data to those providers under your instruction — they are not Cove subprocessors for other customers.
International transfers
Cove is operated with infrastructure that may process data in the United States and other regions where those processors run (Supabase, Cloudflare, Dodo, Resend). We do not currently offer a customer-selectable EU-only region. If you need that constraint, do not put EU-only visitor traffic on Cove until we say otherwise.
Retention, export, deletion
Conversation history is kept for the life of the workspace unless you delete threads or the workspace. Operators download a JSON export of a contact or the workspace from Settings → Security / Privacy (same path in the Cove Inbox app). That file is the profile, conversations, and messages the desk can already open. Delete the workspace to remove operator accounts’ workspace data we store for that tenant. Backups may lag deletion by the backup window (daily snapshots). Visitor cookies live on the visitor’s device until they expire or are cleared.
Your rights
Depending on where you live you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Customers should handle visitor requests for transcripts stored in their workspace from Settings → Security / Privacy, and we will assist via help@coveinbox.co. Account holders close an operator account in Settings → Security / Privacy → Delete account (same path in the Cove Inbox app). The last owner of a workspace that still has teammates must promote another owner first. Closing a solo-owned workspace deletes that tenant’s inbox data. We may refuse requests that are unlawful or that would break security for other customers.
Children
Cove is not directed at children under 16. Do not install the widget on a service you know is used primarily by children without appropriate consent mechanisms. We do not knowingly collect account sign-ups from children.
Security
TLS in transit. Origin lock on the public key so a copied snippet does not run on an origin you did not list. Desk operators can sign in with Google, Microsoft, a magic link, a password, and authenticator 2FA. Daily backups. This is not a SOC 2 marketing page — ask help@coveinbox.co if you need a current report rather than assuming we have one. More on security.
Changes and contact
We will update the date at the top when this policy changes. Material changes to subprocessors or cookie behavior will be reflected here. Contact help@coveinbox.co. Related: Terms, Contact.