Legal

Clovyr.app Privacy Policy

Last updated: Aug 6, 2026

Your privacy is important to Clovyr, and so is being transparent about our privacy practices. This Privacy Policy explains how Clovyr Co. ("Clovyr," "we," "us," or "our") collects, uses, stores, and shares information in connection with clovyr.app, the Clovyr.app browser-based platform, Clovyr-provided hosting, and applications developed and operated by Clovyr, including Clovyr AI Cloud (collectively, the "Services").

This Privacy Policy does not govern the Clovyr corporate website at clovyr.io, which has a separate privacy policy. It also does not govern the independent data practices of third-party applications, cloud providers, or AI model providers that a user chooses to connect to or deploy through the Services, except to the extent Clovyr itself processes information as described here.

We designed Clovyr.app so that Clovyr does not possess the credentials needed to access customer servers and cannot read customer application data. We do not, and will not, sell personal information.

1. How Clovyr.app Works

Clovyr.app operates as a browser-based control plane. Deployment and management instructions are generated and sent from the user's browser directly to the infrastructure and application selected by the user. Clovyr servers do not sit in the communication path between the user's browser, the user's cloud provider, the customer's server, or an application running on that server.

When launching an application, a user may choose Clovyr-provided hosting or may bring an account with a supported cloud provider, such as Amazon Web Services, DigitalOcean, or Linode.

For Clovyr-provided hosting, Clovyr provisions and hands off a server for the user's exclusive control. Clovyr systems and personnel do not retain administrative credentials that allow them to enter the server or inspect the applications and data on it.

For bring-your-own-cloud deployments, the user supplies access credentials or completes authorization with the selected cloud provider. Those credentials are encrypted within the user's browser and are sent directly from the browser to the selected provider as needed. Clovyr servers do not receive those credentials in readable form and cannot use them.

After a server is launched, the browser communicates directly with that server to deploy and maintain applications. Clovyr systems and personnel cannot access customer servers, applications, or application data, including for troubleshooting or debugging.

2. Information We Collect

We may collect a limited amount of information from or about users and their devices as described below.

Information You Provide

Account and communications information. If you create an account, purchase a Service, request support, or contact us, we may receive information such as your name, email address, organization, role, subscription or billing status, and the contents of messages or attachments you choose to send.

Payment information. Payments may be processed by a payment service provider. Clovyr may receive transaction identifiers, subscription status, billing contact information, and limited payment-related metadata, but does not need to receive complete payment-card credentials from the payment processor.

Information Collected When You Use Clovyr.app

Device and request information. The systems that deliver clovyr.app may receive standard technical information such as IP address, browser type, operating system, request date and time, and security or error information.

Usage information. We may receive limited information about interactions with the Clovyr.app interface to operate, secure, and improve the Services. This does not include the contents of customer servers, applications, documents, conversations, prompts, model responses, or cloud credentials.

Cookies and local browser storage. We may use cookies or browser storage for authentication, preferences, security, and core functionality. Some essential browser storage is necessary for the Services to function.

Deployment and Hosting Information

To provide an account, subscription, or hosting service, Clovyr may maintain limited administrative metadata such as the selected plan, infrastructure region, server identifier, provisioning state, service status, timestamps, and encrypted backup or recovery objects. This metadata does not give Clovyr the ability to enter the server or read application data.

3. Credentials, Encryption, and Customer-Controlled Data

Credentials and secrets used by Clovyr.app are kept in an encrypted, user-controlled vault. Encryption and decryption occur in the user's browser, and the keys required to decrypt the vault are held by the user. Clovyr does not receive those keys and cannot recover or decrypt the vault.

Clovyr may store encrypted backups, archives, or opaque data blobs when that functionality is enabled. Clovyr cannot read their contents because it does not possess the user's decryption keys.

Customer application data - including files, databases, messages, prompts, model responses, application credentials, and other content processed on a customer server - remains within the infrastructure and applications controlled by the user. Clovyr does not collect or have access to that data.

Because Clovyr cannot access customer servers or decrypt customer vaults and backups, Clovyr personnel cannot inspect customer data for support, maintenance, troubleshooting, or debugging. Users are responsible for retaining their keys and maintaining access to their environments. If a user loses the only available decryption key, Clovyr may be unable to restore access.

4. Third-Party Applications

Clovyr.app allows users to discover and launch applications developed by Clovyr and applications developed by independent third parties. Unless an application is expressly identified as developed or operated by Clovyr, Clovyr does not develop, control, or determine that application's data-handling practices and may have no relationship with its developer.

This Privacy Policy governs information Clovyr processes in providing the Clovyr.app platform and Clovyr-provided hosting. It does not govern information that an independently developed application processes within the user's server or sends to services selected by the user.

Users should review an application's documentation, privacy policy, license, and terms before launching it or connecting accounts. Launching an application through Clovyr.app does not mean that Clovyr endorses, audits, or assumes responsibility for that application's privacy or security practices.

5. Clovyr AI Cloud

Clovyr AI Cloud is developed by Clovyr and can be deployed through Clovyr.app into an environment controlled by the user. The application may process documents, indexes, embeddings, conversations, prompts, model responses, configuration information, and credentials within that environment. Clovyr servers and personnel do not receive or have access to that content.

Users may configure Clovyr AI Cloud to use locally hosted models or third-party AI model services. When a user selects a third-party service, supplies the user's own credentials, and requests an operation, Clovyr AI Cloud may send the information necessary to perform that operation directly from the user's deployment to the provider selected by the user. The request does not pass through Clovyr servers, and Clovyr cannot see the user's provider credentials, prompts, documents, or responses.

A user may instead select a self-hosted or offline model. In that configuration, model processing occurs within the user's own isolated environment and the information is not sent to the model's developer or an external model API.

Third-party AI providers have their own privacy policies, contractual terms, retention practices, and model-training practices. Because users independently select and authenticate to those providers, users should confirm that the selected provider and service tier meet their privacy and compliance requirements before sending information to it. Clovyr does not authorize any provider acting on Clovyr's behalf to use customer data to create, train, or improve a generalized or foundational AI or machine-learning model.

6. Google Workspace API Data

A user may choose to connect Clovyr AI Cloud to Google Workspace. With the user's authorization, the application may access user-selected Google Drive files, related file metadata, and supported document content, including Google Docs, Sheets, and Slides, solely to provide the document search, retrieval, indexing, summarization, question-answering, and other user-facing features requested by the user.

Google authorization credentials and Google Workspace data are handled within the user's browser and user-controlled Clovyr AI Cloud deployment. They are not transmitted to or accessible by Clovyr servers or personnel. Any copies, indexes, or derived representations created by Clovyr AI Cloud are stored in the user's environment and remain under the user's control.

If a user explicitly configures a third-party AI provider with user-owned credentials, selected Google Workspace content may be sent directly from the user's deployment to that provider only as necessary to perform the user-requested feature. If the user selects a self-hosted or offline model, the content remains within the user's environment and is not shared with the model provider.

Clovyr AI Cloud's use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Clovyr does not access, use, transfer, sell, or permit services acting on its behalf to use Google Workspace API data - including raw, aggregated, anonymized, or derived data - to create, train, or improve generalized or non-personalized artificial intelligence or machine-learning models. Clovyr does not use Google Workspace API data for advertising, retargeting, creditworthiness, or lending.

Clovyr does not allow humans to read Google Workspace API data because Clovyr does not have access to it. A user controls access within the user's own deployment and may remove a Google connection, delete imported or derived data, or delete the deployment using the controls available in the applicable application and infrastructure.

Clovyr AI Cloud requests access to Google Workspace data only when a user initiates the connection and grants the requested permissions. Users may revoke Clovyr AI Cloud's access through their Google Account settings and may remove the corresponding credentials and data from their Clovyr AI Cloud deployment.

7. How We Use Information We Collect

We use the limited information Clovyr receives:

  • To provide, maintain, secure, and improve Clovyr.app and Clovyr-provided hosting;
  • To create and administer accounts, subscriptions, and transactions;
  • To provision infrastructure and display service status;
  • To communicate with users, respond to requests, and provide customer support that does not require access to customer servers or application data;
  • To detect fraud, abuse, security incidents, and technical failures;
  • To comply with applicable law and enforce our legal rights; and
  • For another purpose disclosed when the information is collected and, where required, with the user's consent.

We may create aggregated or de-identified information from platform information that Clovyr lawfully receives. We do not create aggregated or derived datasets from customer application data or Google Workspace API data because Clovyr does not have access to that data.

8. How We Share Information

Vendors and service providers. We may share limited account, payment, website-delivery, communications, security, and infrastructure-administration information with vendors that help us provide the Services. These vendors are permitted to process the information only for the services they provide to Clovyr and subject to appropriate obligations.

User-directed providers. A user's browser or customer-controlled application may communicate directly with a cloud provider, third-party application, identity provider, data source, or AI model provider selected by the user. Those direct communications do not pass through Clovyr systems. The selected provider's terms and privacy practices apply.

Legal and safety disclosures. We may access, preserve, or disclose information that Clovyr possesses if we reasonably believe disclosure is required to comply with law or legal process, protect rights or safety, investigate abuse, or secure the Services. This does not expand our technical ability to access encrypted or customer-controlled data.

Corporate transactions. Information Clovyr possesses may be disclosed to service providers, advisers, and transactional parties in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law and required consent.

Consent. We may share information with a third party at the user's direction or with the user's permission.

Clovyr does not sell personal information.

9. Data Retention and Deletion

Clovyr retains account, billing, communications, security, and operational information only for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and protect the Services.

Customer application data is retained within the user's server and applications according to the settings and retention choices controlled by the user. Clovyr cannot independently view or delete that data.

Encrypted backups or opaque blobs stored by Clovyr are retained only while needed to provide the enabled backup or recovery feature, or as otherwise required by law. Users may delete supported backups or terminate the associated Service through the available controls. Because Clovyr lacks the decryption keys, retained encrypted objects remain unreadable to Clovyr.

Users may delete data inside their applications, disconnect third-party services, revoke Google authorization, delete deployments, or close their Clovyr account using the available controls. Users may also submit an account or data-deletion request through the contact method below. We may retain limited records when required by law or for legitimate security, fraud-prevention, accounting, or dispute-resolution purposes.

10. Security

Clovyr uses technical and organizational safeguards designed to protect information it maintains. The Clovyr.app architecture limits Clovyr's access by keeping credential encryption and decryption in the browser, routing management communications directly between the browser and user-selected infrastructure, and placing customer applications and data under user control.

No method of electronic transmission or storage is entirely secure. Users are responsible for protecting their devices, vault keys, cloud accounts, deployed servers, applications, and third-party credentials. Clovyr cannot reset or recover user-held encryption keys that it does not possess.

11. Your Choices and Rights

Users may manage browser settings, disconnect integrations, revoke third-party authorizations, delete deployments, and control information stored inside their own applications. Marketing communications may be unsubscribed from using the link included in the message, although administrative or service-related communications may still be sent.

Depending on location, users may have rights to request access to, correction of, or deletion of personal information that Clovyr maintains. Clovyr can respond only with respect to information it possesses; it cannot retrieve readable information from encrypted vaults, encrypted backups, or customer-controlled servers.

13. Children's Privacy

The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided Clovyr with personal information in violation of this Policy, please contact us.

14. International Users

Clovyr is based in the United States. Information that Clovyr receives may be processed in the United States and other locations where Clovyr or its service providers operate. Customer application data remains in the infrastructure and region selected or controlled by the user, subject to the practices of the selected infrastructure and application providers.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the revised version at clovyr.app and update the date above. If we materially change how we use or share personal information previously collected, we will provide notice through the Services, by email, or by another appropriate method and obtain consent when required.

16. Contact Information

Questions, concerns, or requests concerning this Privacy Policy or Clovyr's processing practices may be submitted through Clovyr's contact page or by writing to:

Clovyr Co.
228 Park Ave S., Suite 60793
New York, NY 10003