Privacy Policy
What we collect, and what we do with it.
Written to match what the software actually does. Nothing here promises what the code doesn't deliver. Effective August 13, 2026.
Who we are, and whose data this is
Conovo is contract infrastructure for software platforms. Our direct customers are the platforms that embed us. The businesses using those platforms, and the people who sign contracts those businesses send, reach Conovo through a platform. For their data we act as a service provider processing on the platform's instructions. If you signed (or were asked to sign) a contract, the business that sent it decides why your information was collected, not Conovo; this page tells you what we do with it on their behalf.
What we collect
Account data: the name, email address, and password (stored only as a hash) used to open a platform account, plus API keys (also stored only as hashes).
Contract data, on behalf of platforms: the documents businesses upload, the field structure extracted from them, the values filled into each contract, and the name, email address and (where phone-verified signing is used) mobile number of each recipient. Executed contracts and their audit trails are the point of the product, and we treat them as the most sensitive thing we hold.
Operational data: API request metadata (route, status, timing, but never request or response bodies), a content-free audit log of who did what and when, and usage counts for billing. Payment cards are handled by Stripe; card numbers never touch our systems.
Product analytics: our API records content-free product events with PostHog: that a template was confirmed, that a contract was generated, that a batch was sent, that a request failed. They are counted against the platform account, never against the individual people who use a business's workspace. These events carry counts, formats and statuses. They never carry document content, field values, recipient details, or error messages.
Website analytics: our public website counts page views with PostHog so we can tell which pages are useful. It is cookieless: nothing is stored on your device and no profile is built about you, which is why we don't show you a cookie banner. To tell one visit apart from another, PostHog computes a rotating anonymous hash on its own servers rather than putting an identifier in your browser. The signed-in console is not measured at all.
What we don't collect: no advertising pixels, no cross-site trackers, no session recording, and no automatic capture of what you click or type. If a page address contains a one-time link or token, it is stripped before any analytics event leaves your browser. The console stores a short-lived session token in your browser and nothing else.
How AI is involved, precisely
Conovo uses AI models from Anthropic for specific, bounded jobs, and it matters to us that you know exactly which:
At setup, when a business uploads a contract, the document text is analyzed to propose fields, formulas, data bindings, and (on request) a review of gaps and risks. Every proposal goes through human confirmation before it becomes anything. At sending, if a business asks for a drafting suggestion, facts from the record they chose are used to draft text they can edit; spreadsheet uploads are mapped with cell values masked to their shape (a number, not the number); and unattended sends get an optional anomaly check over resolved values, with fields we classify as sensitive redacted, and that check can only hold a contract for review, never change it. At signing, if a recipient asks a question about their contract, the text of that contract is used to answer it, grounded in the document alone.
The send path itself is deterministic: no model output ever becomes a value in a sent contract. We do not train models on your content, and under our agreement with Anthropic, API data is not used to train theirs.
Who we share data with
The platform that brought you: businesses and signers interact with Conovo inside a platform's product, and that platform sees the workspaces and contracts its own customers create. That is the product working as designed, under our agreement with the platform.
Subprocessors: the short list of services that touch data, and why each one does, is published on our security page: e-signature execution, billing, AI analysis, SMS verification, database, storage, and hosting. We notify account owners before adding one. We do not sell personal data, and we do not share it for advertising. There is no advertising.
Legal process: we disclose data when the law requires it, and we tell the affected account unless we are legally barred from doing so.
How long we keep things
Contract files follow the retention window the account chooses (from 7 days to indefinitely). One honest exception: a signed contract is a legal record, so its metadata and audit trail are retained even when the files themselves are purged. The parties to an executed agreement are entitled to a reproducible record that it happened. Request logs are deleted after 30 days. Account data lives as long as the account does.
Your rights
You can ask what we hold about you, ask us to correct it, or ask us to delete it: email privacy@conovo.co. If your data reached us through a platform (you signed a contract, or you use a business account inside someone's product), we may route your request to the business or platform that controls it, and we'll tell you when we do. California residents: the rights above are the CCPA rights to know, correct, and delete; we do not sell or share personal information as those terms are defined there, so there is nothing to opt out of. We do not discriminate against anyone for exercising these rights.
Conovo is not directed at children under 16 and we do not knowingly collect their data.
Changes
When our practices change, this page changes with them, with a new effective date. Material changes get announced to account owners before they take effect. This policy is effective as of August 13, 2026.