Privacy Policy
Last updated: June 20, 2026.
This Privacy Policy explains what information Coveton (“Coveton”, “we”, “us”) collects when you use our communication platform and related websites, how we use it, the legal bases for processing it, and the rights you have. The short version: your conversations are end-to-end encrypted, the keys live on your devices, and we cannot read them.
1. Our zero-knowledge commitment
Coveton is built on a zero-knowledge architecture. Message content, voice notes and files are encrypted on your device before they ever reach our infrastructure. The encryption keys are generated and stored on your authorized devices and are never transmitted to us in a form we can use. We store only ciphertext, and we do not possess the keys required to decrypt it.
This is a technical guarantee, not just a policy promise. We cannot read, scan, index, sell or hand over the plaintext of your conversations, because at no point do we have access to it. Where we are legally compelled to produce data, we can only provide the limited account and metadata described below and the ciphertext we hold, which is useless without your keys.
2. Categories of data we process
To operate the service, we process a deliberately limited set of data:
- Account and identity data: name, email address, organization name, role and authentication credentials, used to create and secure your account and administer your organization.
- Device and session metadata: device identifiers, public keys for your devices, login history, IP address at the time of connection, approximate location derived from IP, browser or app version and session tokens, used for security, device authorization and revocation.
- Encrypted content: messages, files and voice notes, stored solely as ciphertext that we cannot decrypt.
- Operational and audit logs: rate-limit, error, delivery and administrative audit records that capture actions and system events (never message content) for security, reliability and compliance.
- Billing data: plan, subscription status and invoices. Card and payment-instrument data is collected and stored by our payment processors; we never store full card numbers.
- Support communications: the content of messages you send to our support or sales teams.
3. What we never do
- We never sell or rent your personal data to anyone.
- We never serve advertising or run behavioral or cross-site tracking.
- We never read message content. It is technically impossible for us to do so.
- We never build profiles of you for advertising or engagement optimization.
- We never use your content to train machine-learning models.
4. How and why we use information
We use the limited data above only to:
- Authenticate you and secure your account and devices.
- Operate, maintain, troubleshoot and improve the service.
- Route and deliver encrypted content between authorized devices.
- Provide customer support and respond to your requests.
- Process payments and manage subscriptions.
- Detect, prevent and investigate abuse, fraud and security incidents.
- Comply with legal obligations and enforce our terms.
We do not use your data for advertising of any kind.
5. Legal bases for processing (GDPR Article 6)
Where the EU or UK General Data Protection Regulation applies, we rely on the following legal bases:
- Performance of a contract: to provide the service you or your organization have signed up for.
- Legitimate interests: to secure the platform, prevent abuse and improve reliability, balanced against your rights.
- Legal obligation: to comply with applicable laws, tax requirements and lawful requests.
- Consent: where required, for example optional communications, which you may withdraw at any time.
6. International data transfers
We may process data in countries other than your own. Where we transfer personal data out of the European Economic Area, the United Kingdom or Switzerland, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses (SCCs) and equivalent UK and Swiss mechanisms, together with supplementary technical measures such as encryption in transit and at rest.
7. Data retention and deletion
We retain data only as long as needed for the purpose it was collected:
- Encrypted content: retained according to your configured retention policy, including disappearing messages and ephemeral rooms that expire automatically.
- Account data: retained while your account is active and removed when you delete your account.
- Security and audit logs: retained for a limited period (typically up to 12 months) for security and compliance, then deleted or anonymized.
- Billing records: retained as required by tax and accounting law.
Deleting your account. You can permanently delete your account and all of your data at any time, directly from the app or the web app under Settings > Account > Delete account. Deletion takes effect immediately and is irreversible: your profile, credentials, devices, messages, calls history, status, media, channels and communities are removed, and your end-to-end encrypted content is destroyed together with your account. Because that content can only be decrypted with keys held on your devices, once your account is deleted it cannot be recovered by you or by us. A limited amount of information may be retained only where the law requires it or to prevent fraud and abuse, and is never used to reconstruct your conversations. If you cannot access your account, you can still request deletion from the delete account page or by contacting us. See how to delete your account for full details.
8. Your rights and choices
Depending on your jurisdiction, you may have the right to access, rectify, erase, restrict or object to the processing of your personal data, to data portability, and to withdraw consent. You also have the right to lodge a complaint with a supervisory authority. Because content is encrypted with keys only you control, some data is only ever accessible to you and not to us. You can exercise several of these rights yourself at any time:
- Download my data: from Settings > Account you can export a copy of the account information we hold, including your profile details, account and plan information, your linked devices and their public keys, and the channels and communities you belong to. Your end-to-end encrypted messages and files are readable only on your devices and are not included in a server-side export in readable form.
- Delete your account: from Settings > Account > Delete account you can permanently and immediately erase your account and all of its data, as described above.
To exercise any other right, or to request deletion when you cannot sign in, email privacy@coveton.com or use the delete account page. If your data is controlled by your organization, we will direct your request to them.
9. Children’s privacy
Coveton is intended for use by organizations and the adults working within them. The service is not directed to children under 16, and we do not knowingly collect personal data from them. Where a school or similar institution uses Coveton, it is responsible for obtaining any consents required for student accounts. If you believe a child has provided us data without authorization, contact us and we will delete it.
10. Security
We protect data with end-to-end encryption of content, encryption in transit (TLS) and at rest, strict access controls and least-privilege access for staff, device authorization and revocation, comprehensive audit logging, and regular security review. No system is perfectly secure, but our zero-knowledge design means even a breach of our infrastructure does not expose the plaintext of your conversations.
11. Infrastructure providers
We rely on a small number of reputable infrastructure providers to host the service, process payments and deliver transactional email. They act strictly on our instructions under written contracts that require confidentiality and appropriate data protection. Because Coveton is zero-knowledge, none of them ever receive your decryption keys: any content they handle is ciphertext that we cannot read, and neither can they.
12. Cookies
We use only strictly necessary cookies and local storage for authentication and saving your theme preference. We do not use advertising or third-party tracking cookies. See our Cookie Policy.
13. Changes to this policy
We may update this policy as the service and the law evolve. We will post the updated version here with a new effective date, and we will give reasonable advance notice of material changes.
14. Contact
Questions about privacy or this policy? Email privacy@coveton.com or our general team at hello@coveton.com.