Legal

Privacy policy

This policy describes how Cove (“we”) handles personal data for the service at coveinbox.co. It is written for Cove, not copied from another helpdesk. Last updated September 3, 2026. Questions: help@coveinbox.co.

Who this policy covers

Two groups. Customers are people who create a Cove workspace (operators, billing contacts). Visitors are people who load a customer’s website with the Cove snippet and may send a message. Marketing visitors to coveinbox.co are a third, smaller set (this website).

We are not a law firm and this is not legal advice. If you embed the widget, you are responsible for telling your visitors that a third-party messenger is on the page, including cookies, in line with the laws that apply to you.

Controller and processor

For customer account data (email, workspace settings, billing identifiers), Cove is the controller. For visitor messages, contacts, and widget events stored in a workspace, the customer is typically the controller and Cove is the processor — we process that data to provide the inbox and messenger they asked for.

Account and billing data

When you sign up we store name, email, authentication data (via Supabase Auth), workspace name, seat invites, roles, and settings you save (widget appearance, articles, quick replies, routing rules). Card numbers are not stored by Cove. Checkout and payment methods are handled by Dodo Payments over HTTPS. We store plan, status, and identifiers needed to keep the subscription in sync.

Visitor and conversation data

If a visitor sends a message we store the transcript, timestamps, optional name and email they give, last page URL the widget reports, attachments they upload (widget-uploads), CSAT if they rate after resolve, and operator notes on that thread. We do not run a live visitor map of everyone on the site. We do not sell visitor lists. We do not train public machine-learning models on your workspace threads.

Draft-from-articles on Plus reads published help articles in that workspace only — not PDFs, not a site crawl, not the open web.

Cookies and local storage

The snippet sets first-party cookies on the customer’s site, scoped to that site, so a returning browser can resume a visitor id and a short session:

  • cove_vid_* — visitor identifier, Max-Age one year, SameSite=Lax. Also mirrored in localStorage as cove:vid:… when storage is available.
  • cove_st_* — short-lived session token, Max-Age twelve hours, so a thread can resume. Also cove:st:… in localStorage.

These are functional, not advertising pixels. If a visitor clears cookies they look like a new visitor. coveinbox.co itself may set cookies needed to sign in to the app (Supabase session). We do not run a third-party ad network on the marketing site.

If you arrive from a link that includes standard utm_* query fields (source, medium, campaign, term, content), we store the first set we see in a first-party cove_utm cookie, Path=/, Max-Age ninety days, SameSite=Lax. That cookie is so we can remember how you found Cove if you sign up later. It is not sold, not sent to an ad network, and we do not store click ids such as gclid or fbclid.

How we use data

  • To operate the messenger, inbox, help articles, and APIs you asked for
  • To send transactional mail (invites, password reset, outbound replies via Resend when a contact has a real address)
  • To bill and prevent abuse (spam through the widget, scraped public keys)
  • To debug incidents when you write help@coveinbox.co

Subprocessors

We use these processors to run Cove. We do not list a fake law firm.

ProcessorRole
SupabaseDatabase, authentication, file storage for widget uploads
CloudflareCDN / edge delivery of the widget and realtime conversation rooms
Dodo PaymentsCheckout, invoices, payment methods. Card data stays with Dodo.
ResendTransactional email and outbound public replies when an address exists

If we add a processor that handles customer or visitor personal data, we will update this table. Connect-screen integrations you enable (Slack, Shopify, and others) send data to those providers under your instruction — they are not Cove subprocessors for other customers.

International transfers

Cove is operated with infrastructure that may process data in the United States and other regions where those processors run (Supabase, Cloudflare, Dodo, Resend). We do not currently offer a customer-selectable EU-only region. If you need that constraint, do not put EU-only visitor traffic on Cove until we say otherwise.

Retention, export, deletion

Conversation history is kept for the life of the workspace unless you delete threads or the workspace. Operators download a JSON export of a contact or the workspace from Settings → Security / Privacy (same path in the Cove Inbox app). That file is the profile, conversations, and messages the desk can already open. Delete the workspace to remove operator accounts’ workspace data we store for that tenant. Backups may lag deletion by the backup window (daily snapshots). Visitor cookies live on the visitor’s device until they expire or are cleared.

Your rights

Depending on where you live you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Customers should handle visitor requests for transcripts stored in their workspace from Settings → Security / Privacy, and we will assist via help@coveinbox.co. Account holders close an operator account in Settings → Security / Privacy → Delete account (same path in the Cove Inbox app). The last owner of a workspace that still has teammates must promote another owner first. Closing a solo-owned workspace deletes that tenant’s inbox data. We may refuse requests that are unlawful or that would break security for other customers.

Children

Cove is not directed at children under 16. Do not install the widget on a service you know is used primarily by children without appropriate consent mechanisms. We do not knowingly collect account sign-ups from children.

Security

TLS in transit. Origin lock on the public key so a copied snippet does not run on an origin you did not list. Desk operators can sign in with Google, Microsoft, a magic link, a password, and authenticator 2FA. Daily backups. This is not a SOC 2 marketing page — ask help@coveinbox.co if you need a current report rather than assuming we have one. More on security.

Changes and contact

We will update the date at the top when this policy changes. Material changes to subprocessors or cookie behavior will be reflected here. Contact help@coveinbox.co. Related: Terms, Contact.