Sign-in
Google, Microsoft, a magic link, and 2FA
Operators sign in with Google, Microsoft, a magic link emailed to their work address, or email plus a password. Authenticator 2FA is available at sign-in (Authy or Google Authenticator). That is the SSO we ship. Not SAML. A Google or Microsoft account does not join a workspace by itself — someone has to invite you, or you create your own. Owners can optionally list allowed email domains in Settings → Security. See pricing.
Four roles
| Role | What they can do |
|---|---|
| Owner | Billing, workspace, widget, team, articles, export, delete. |
| Admin | Widget, team, articles, inbox, workspace export. Not billing. |
| Agent | Inbox. Reply, assign, resolve, notes, contact export. |
| Viewer | Read-only if you see it in the picker. |
There are no custom roles and no team inboxes. Invite from Settings. Do not share one login — assignment and typing need a real seat.
GDPR export
- 1. Open Settings → Security. Privacy sits on that tab. Same path in the Cove Inbox app.
- 2. One contact. Enter an email or contact id. Any member who can export a contact gets JSON: profile, conversations, messages the desk can already open.
- 3. Whole workspace. Owners and admins only. Every person and thread in the tenant, capped if the desk is very large.
Help: GDPR export. Legal text: Privacy.
Account delete
Settings → Security → Delete account. Type DELETE. We remove the auth user (email, password, Google/Microsoft sign-in, 2FA) and take you off every workspace. If you are the only member, that workspace and its inbox, people, help, and widget data go with it. Paid subscriptions on those workspaces are cancelled when we can. Teammates’ accounts stay. Daily backups may lag by a day. The last owner of a workspace that still has teammates must promote another owner first.
Audit scope
The audit log records invite, export, ban, unban, and account delete. Owners and admins can read it. That is the list.
Login history is a placeholder. The plate says sign-in devices will show once we record them. Fake history was removed. We do not currently store a device list.
TLS, origin lock, backups
TLS in transit. The public widget key is locked to origins you list. Daily snapshots. Card data stays with Dodo Payments. Subprocessors are on Privacy: Supabase, Cloudflare, Dodo, Resend. We do not currently offer a customer-selectable EU-only region.
What we do not claim
- SAML — operators use Google, Microsoft, a magic link, and 2FA. Not SAML.
- HIPAA
- SOC 2 — ask help@coveinbox.co if you need a current report rather than assuming we have one
- Operator web push (VAPID is not live)
- A customer status product — /status is platform totals