Privacy Policy
Effective: August 24, 2026
KovaIO is a software platform for small and mid-sized businesses ("tenants"). It has two sides: content — planning, generating, and publishing brand content, primarily to social media — and commerce — bookkeeping, invoicing, inventory, and financial reconciliation for merchants selling on platforms such as Shopify and Amazon. This policy describes what data we collect, how we use it, who we share it with, and the rights you have over it. We do not sell or rent personal data to third parties.
1. What "personal data" means in this policy
We use "personal data" to mean information that identifies a specific individual. For KovaIO that includes account holder names and email addresses, IP addresses captured in access logs, the Instagram username and account ID for connected social accounts, and — for tenants using our commerce features — the names, email addresses, phone numbers, and shipping or billing addresses of that merchant's own customers, as they appear on orders, invoices, and related records. Much of what KovaIO stores — brand profiles, content libraries, post drafts, generated images, chart-of-accounts structures — is business data that doesn't identify a specific individual on its own.
2. Who this policy covers
KovaIO serves distinct audiences, and it's important to be clear about each:
- KovaIO users — the people at a tenant company who log into our platform (founders, marketing staff, agency operators, bookkeepers). This policy describes how we handle their data.
- Customers of merchants using our commerce features — the buyers who place orders with a merchant that uses KovaIO for bookkeeping. We do process personal data about these individuals: their names and contact details reach us through the merchant's connected sales channel and appear on the invoices and accounting records we produce for that merchant. Section 8 describes exactly what we receive, why, and what we do not do with it.
-
End users of social platforms — followers, viewers, and other audience members on Instagram, Facebook, and similar platforms who interact with content published through KovaIO. We do not collect data about these individuals. We do not access follower lists, likes, comments, direct messages, or profile data. The scopes we request from Instagram (currently
instagram_business_basicandinstagram_business_content_publish) do not grant access to that data, and we do not request scopes that would. This applies to our social publishing features only and does not describe the commerce features covered in Section 8.
3. Data we collect
From KovaIO users:
- Account information — name, email address, hashed password, tenant slug, role within the tenant workspace.
- Connected social account credentials — when you connect an Instagram account, we store the Instagram username, the Instagram Business Account ID, and an encrypted long-lived OAuth access token. The token is encrypted at rest using AES-256-GCM. We never log or display the token.
- Connected commerce account credentials — when you connect a Shopify store, an Amazon Seller account, or a bank account, we store an encrypted access token issued by that platform. Tokens are encrypted at rest and are never logged or displayed. We never receive or store your password for any connected platform.
- Content and creative assets — your brand profile (voice, products, hashtag defaults, visual strategy notes), uploaded files (product photos, videos, brand documents, exemplar posts you've previously published), AI-generated images and captions, post drafts, approval history, and published post metadata (caption sent, time published, returned post URL).
- Tenant operational data (commerce features only) — for tenants who use KovaIO's commerce features, we additionally store information about your products, customers, orders, invoices, vendors, purchase orders, bank transactions, and financial accounts. This includes personal data about your customers, as described in Sections 1, 2, and 8. These features and the data they collect are optional. If you only use KovaIO for content and social publishing, none of this commerce data is collected.
- Usage telemetry — counts of API calls made on your behalf, estimated costs per external service call (used for internal billing analytics).
4. How we use your data
- To generate content variants (captions, images) using AI based on your inputs.
- To publish content you have approved to the social platforms you have connected.
- To produce bookkeeping records for tenants using our commerce features — invoices, purchase orders, ledgers, financial statements, and bank reconciliation.
- To display your content history, drafts, books, and account state in your dashboard.
- To send transactional emails on your behalf and to you (sign-in, password reset, drafts-ready notifications, and invoices or purchase orders you choose to send).
- To respond to support requests you initiate.
- To monitor service health and per-tenant costs internally.
We do not sell or rent personal data to third parties.
5. Cookies and similar technologies
KovaIO uses a small set of essential cookies to operate. We do not use third-party advertising cookies, marketing cookies, or cross-site tracking.
- Session cookie (HTTP-only, secure) — issued after sign-in to keep you authenticated across requests. Cleared on sign-out or expiry.
- Tenant context cookies (HTTP-only where possible) — remember which tenant workspace you last accessed so we can route you to the right dashboard on return.
We do not currently use third-party analytics products (Google Analytics, Plausible, etc.) in the KovaIO application. If we add one in the future, we will update this policy and notify tenant administrators in advance.
6. Automated processing and AI
KovaIO uses third-party AI services to produce content variants based on your inputs:
- Anthropic Claude for text generation. Per Anthropic's API terms, customer inputs and outputs are not used to train Anthropic's models.
- fal.ai image models (currently FLUX Pro Kontext and Google Gemini 3 Pro Image / "Nano Banana Pro") for image generation and composition. Per fal.ai's terms of service, fal.ai may use anonymized or aggregated usage data to improve their services. We do not send fal.ai any personal data beyond what is in the prompts and reference images you provide.
- In-app assistance. Our commerce app includes an in-app assistant that answers questions about how to use the product. It transmits only the message you type and the preceding conversation. It has no access to your database and does not read or transmit your customers, invoices, ledgers, or any other business records.
Final decisions about which generated content is published are made by you (or the team member you designate) through an explicit approval step. We do not make automated decisions that produce legal or similarly significant effects about any individual.
7. Third-party processors
We use the following third-party services to deliver KovaIO. Each is listed with what data flows to them and what they do with it. All are based in the United States.
Infrastructure and hosting:
- Render — application hosting, managed PostgreSQL database, and persistent disk storage for uploaded assets — all in Render's US-Ohio region. All KovaIO user data, content, and credentials are stored on Render-hosted infrastructure.
- Cloudflare — CDN, DNS, and HTTPS proxy in front of our application. Request metadata (IP address, User-Agent, requested URL) passes through Cloudflare to reach our servers.
Content generation (see "Automated processing and AI" above for data handling specifics):
- Anthropic — text generation via the Claude API. Receives your brand profile and content prompts to produce caption variants, and receives the messages you type into the in-app assistant. It does not receive your commerce records.
- fal.ai — image generation. Receives reference images and generation prompts to produce composed brand images.
Publishing and integrations:
- Meta / Instagram — the publishing target. We use the Instagram Graph API with tokens you grant during the Connect Instagram OAuth flow. Posts you approve are sent to Meta to be published on the Instagram account you connected.
- Ayrshare — alternative social publishing aggregator, used as a fallback path when a direct Instagram credential is not available. Receives post content and target platform on send.
- Inngest — durable workflow orchestration. Used to schedule and retry publish operations. Receives event payloads referencing post IDs and tenant slugs (no credentials).
- Mailgun — transactional email delivery. Receives recipient email addresses and message contents for sign-in, password reset, drafts-ready notifications, and any invoices or purchase orders you send from KovaIO. Where you send a document to your own customer, that customer's email address and the document contents pass through Mailgun for delivery.
Commerce platforms and processors (only applicable to tenants who use KovaIO's commerce features):
- Shopify — the merchant's sales channel. We read order, product, inventory, location, payout, and customer data from the Shopify Admin API using a token you grant at install. See Section 8. Data flows from Shopify to us; we do not send your customers' personal data back to Shopify beyond what is required to operate the app.
- Amazon Selling Partner API — settlement and financial event data for merchants who connect an Amazon Seller account. See Section 9.
- Plaid — bank account aggregation. Tenants who use KovaIO for finance reconciliation connect their bank accounts via Plaid. We never see or store bank login credentials; only transaction data returned by Plaid.
- Stripe — payment processing for tenant subscriptions to paid KovaIO plans. Receives the billing details you enter at checkout and the subscription events needed to keep your plan active. Where you install a KovaIO application from a third-party marketplace (such as the Shopify App Store), that marketplace handles billing instead and Stripe is not involved.
8. Shopify merchant and customer data
For tenants who install our app on a Shopify store, we access data from the Shopify Admin API using an access token granted by the merchant at install. This section describes that access specifically, because it includes personal data about the merchant's own customers.
What we access, and why:
- Customer records — name, email address, phone number, shipping and billing address, and customer tags. Used to identify the customer on an invoice, to address the invoice document correctly, and to send that document to the customer when the merchant chooses to send it.
- Order records — order contents, totals, taxes, discounts, refunds, and fulfillment status. Used to recognize revenue and produce accounting entries.
- Product and inventory records — variants, prices, costs, and stock levels. Used for inventory valuation and cost of goods sold.
- Payout and payment records — Shopify Payments payouts and balance transactions. Used to reconcile deposits against the merchant's bank account.
- Location records — store locations. Used as the destination on purchase orders.
The single purpose of all of the above is to produce accounting records and business documents for the requesting merchant's own business.
What we do not do with it. We do not use Shopify merchant or customer data for advertising or marketing. We do not use it to benchmark one merchant against another. We do not use it to train machine learning models, and it is not sent to any AI service. We do not sell, rent, or share it with any third party beyond the processors listed in Section 7, and we do not use it for any purpose beyond the requesting merchant's own bookkeeping.
Retention and deletion. Shopify customer data is retained for as long as the merchant's account is active, because it forms part of the merchant's financial records. We honor Shopify's three mandatory privacy requests:
- Customer data request — when a merchant's customer asks the merchant for their data, we compile the records we hold for that individual — the invoices they appear on and the messages sent to them — and provide them to the store owner, who responds to their customer. We respond within 30 days.
- Customer redaction — when a merchant requests erasure on a customer's behalf, we remove that individual's personal data from our records. This includes their name, email address, and address on every invoice, and their address and the contents of every message we sent them. The underlying financial transaction is retained, without personal data, because deleting it would misstate the merchant's books and their obligations to tax authorities; the individual is no longer identifiable from it.
- Shop redaction — when a merchant uninstalls and requests erasure, we delete the merchant's data in full, including all customer records, invoices, ledgers, bank transaction history, and message history associated with that store.
9. Amazon Information (Selling Partner API)
For tenants who connect an Amazon Seller account through our Books app, we retrieve settlement and financial event data via Amazon's Selling Partner API (SP-API). This data — including order-linked sales figures, fees, refunds, and adjustments — is used exclusively to produce accounting records (chart of accounts, profit and loss, reconciliation) for that merchant's own business. We do not use Amazon Information for advertising, marketing, benchmarking against other sellers, or any purpose beyond the requesting merchant's own bookkeeping. Amazon Information is stored under the same infrastructure and encryption practices described elsewhere in this policy and is not shared with any third party beyond those listed in Section 7.
10. Where your data is stored
All KovaIO infrastructure and third-party processors listed above operate from the United States. By using KovaIO, you understand and consent to your data being transferred to and stored in the United States. Where required (for example, for tenants in jurisdictions covered by GDPR), we rely on standard contractual clauses with our processors for cross-border transfers.
11. Data retention
- Account data and content — retained while your account is active. If you close your account, we delete your data within 90 days, with the exception of records we are legally required to retain (e.g., billing records for paid plans).
- Merchant and customer commerce data — retained while the connected store remains installed and the account is active, because it constitutes the merchant's financial records. Erased on request as described in Section 8. A merchant who uninstalls and requests erasure has their data deleted in full.
- OAuth credentials for connected accounts — deleted immediately when you disconnect the account in KovaIO, when a store is uninstalled, or when we receive a revocation signal from the platform (for example, Meta's deauthorize webhook firing because you removed KovaIO from your Instagram settings).
- Database backups — our hosting provider (Render) retains automatic database backups according to its standard policy. Backed-up data containing deleted records ages out of backup retention per that schedule.
12. Data deletion requests
You can request deletion of your personal data at any time by emailing privacy@kovaio.ai. We respond to deletion requests within 30 days of receipt.
If you are a customer of a merchant that uses KovaIO, the merchant is the controller of your data and we act as their processor. Please direct your request to the merchant you purchased from. They can submit it through their sales platform — for Shopify merchants, through Shopify's customer data request and redaction flows — which we honor automatically as described in Section 8. You may also contact us at privacy@kovaio.ai and we will work with the merchant to resolve it.
For deletion requests submitted through Meta's data deletion flow (typically when a user removes KovaIO from their Instagram account settings), our automated endpoint processes the request immediately and returns a confirmation URL where you can verify completion.
13. Your rights
Depending on where you live, you may have additional rights under laws like GDPR (EU/UK) or CCPA (California), including the right to access, correct, export, or delete your personal data, and the right to object to or restrict certain processing. To exercise any of these rights, email privacy@kovaio.ai. Where we act as a processor on behalf of a merchant, see Section 12.
14. Security
We protect data in transit with TLS (HTTPS) for all connections to KovaIO and to our third-party processors. Data at rest is stored on encrypted infrastructure. We additionally encrypt OAuth access tokens at rest using AES-256-GCM with a key stored separately from the database, and we never log or display them. We restrict access to production systems to personnel who need it for operations and support. Test and production environments are fully separate, with separate databases and separate application credentials; production data is never copied into a test environment.
No security measure is perfect. If we become aware of a security incident affecting your data, we will notify affected tenants without undue delay and in compliance with applicable law.
15. Children's data
KovaIO is not directed to children under 13 (or 16 in jurisdictions where that is the applicable age threshold). We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, contact privacy@kovaio.ai and we will delete it.
16. Changes to this policy
We may update this policy as KovaIO evolves. Material changes will be emailed to tenant administrators at least 14 days before they take effect. The "Effective" date at the top of this page indicates the most recent revision.
17. Contact
For privacy questions, exercise of your rights, or to report a concern, email privacy@kovaio.ai.
For general questions about KovaIO, email hello@kovaio.ai.