1. How Clovyr.app Works
Clovyr.app operates as a browser-based control plane. Deployment and management instructions are generated and sent from the user's browser directly to the infrastructure and application selected by the user. Clovyr servers do not sit in the communication path between the user's browser, the user's cloud provider, the customer's server, or an application running on that server.
When launching an application, a user may choose Clovyr-provided hosting or may bring an account with a supported cloud provider, such as Amazon Web Services, DigitalOcean, or Linode.
For Clovyr-provided hosting, Clovyr provisions and hands off a server for the user's exclusive control. Clovyr systems and personnel do not retain administrative credentials that allow them to enter the server or inspect the applications and data on it.
For bring-your-own-cloud deployments, the user supplies access credentials or completes authorization with the selected cloud provider. Those credentials are encrypted within the user's browser and are sent directly from the browser to the selected provider as needed. Clovyr servers do not receive those credentials in readable form and cannot use them.
After a server is launched, the browser communicates directly with that server to deploy and maintain applications. Clovyr systems and personnel cannot access customer servers, applications, or application data, including for troubleshooting or debugging.
2. Information We Collect
We may collect a limited amount of information from or about users and their devices as described below.
Information You Provide
Account and communications information. If you create an account, purchase a Service, request support, or contact us, we may receive information such as your name, email address, organization, role, subscription or billing status, and the contents of messages or attachments you choose to send.
Payment information. Payments may be processed by a payment service provider. Clovyr may receive transaction identifiers, subscription status, billing contact information, and limited payment-related metadata, but does not need to receive complete payment-card credentials from the payment processor.
Information Collected When You Use Clovyr.app
Device and request information. The systems that deliver clovyr.app may receive standard technical information such as IP address, browser type, operating system, request date and time, and security or error information.
Usage information. We may receive limited information about interactions with the Clovyr.app interface to operate, secure, and improve the Services. This does not include the contents of customer servers, applications, documents, conversations, prompts, model responses, or cloud credentials.
Cookies and local browser storage. We may use cookies or browser storage for authentication, preferences, security, and core functionality. Some essential browser storage is necessary for the Services to function.
Deployment and Hosting Information
To provide an account, subscription, or hosting service, Clovyr may maintain limited administrative metadata such as the selected plan, infrastructure region, server identifier, provisioning state, service status, timestamps, and encrypted backup or recovery objects. This metadata does not give Clovyr the ability to enter the server or read application data.
3. Credentials, Encryption, and Customer-Controlled Data
Credentials and secrets used by Clovyr.app are kept in an encrypted, user-controlled vault. Encryption and decryption occur in the user's browser, and the keys required to decrypt the vault are held by the user. Clovyr does not receive those keys and cannot recover or decrypt the vault.
Clovyr may store encrypted backups, archives, or opaque data blobs when that functionality is enabled. Clovyr cannot read their contents because it does not possess the user's decryption keys.
Customer application data - including files, databases, messages, prompts, model responses, application credentials, and other content processed on a customer server - remains within the infrastructure and applications controlled by the user. Clovyr does not collect or have access to that data.
Because Clovyr cannot access customer servers or decrypt customer vaults and backups, Clovyr personnel cannot inspect customer data for support, maintenance, troubleshooting, or debugging. Users are responsible for retaining their keys and maintaining access to their environments. If a user loses the only available decryption key, Clovyr may be unable to restore access.
4. Third-Party Applications
Clovyr.app allows users to discover and launch applications developed by Clovyr and applications developed by independent third parties. Unless an application is expressly identified as developed or operated by Clovyr, Clovyr does not develop, control, or determine that application's data-handling practices and may have no relationship with its developer.
This Privacy Policy governs information Clovyr processes in providing the Clovyr.app platform and Clovyr-provided hosting. It does not govern information that an independently developed application processes within the user's server or sends to services selected by the user.
Users should review an application's documentation, privacy policy, license, and terms before launching it or connecting accounts. Launching an application through Clovyr.app does not mean that Clovyr endorses, audits, or assumes responsibility for that application's privacy or security practices.
5. Clovyr AI Cloud
Clovyr AI Cloud is developed by Clovyr and can be deployed through Clovyr.app into an environment controlled by the user. The application may process documents, indexes, embeddings, conversations, prompts, model responses, configuration information, and credentials within that environment. Clovyr servers and personnel do not receive or have access to that content.
Users may configure Clovyr AI Cloud to use locally hosted models or third-party AI model services. When a user selects a third-party service, supplies the user's own credentials, and requests an operation, Clovyr AI Cloud may send the information necessary to perform that operation directly from the user's deployment to the provider selected by the user. The request does not pass through Clovyr servers, and Clovyr cannot see the user's provider credentials, prompts, documents, or responses.
A user may instead select a self-hosted or offline model. In that configuration, model processing occurs within the user's own isolated environment and the information is not sent to the model's developer or an external model API.
Third-party AI providers have their own privacy policies, contractual terms, retention practices, and model-training practices. Because users independently select and authenticate to those providers, users should confirm that the selected provider and service tier meet their privacy and compliance requirements before sending information to it. Clovyr does not authorize any provider acting on Clovyr's behalf to use customer data to create, train, or improve a generalized or foundational AI or machine-learning model.
6. Google Workspace API Data
A user may choose to connect Clovyr AI Cloud to Google Workspace. With the user's authorization, the application may access user-selected Google Drive files, related file metadata, and supported document content, including Google Docs, Sheets, and Slides, solely to provide the document search, retrieval, indexing, summarization, question-answering, and other user-facing features requested by the user.
Google authorization credentials and Google Workspace data are handled within the user's browser and user-controlled Clovyr AI Cloud deployment. They are not transmitted to or accessible by Clovyr servers or personnel. Any copies, indexes, or derived representations created by Clovyr AI Cloud are stored in the user's environment and remain under the user's control.
If a user explicitly configures a third-party AI provider with user-owned credentials, selected Google Workspace content may be sent directly from the user's deployment to that provider only as necessary to perform the user-requested feature. If the user selects a self-hosted or offline model, the content remains within the user's environment and is not shared with the model provider.
Clovyr AI Cloud's use of information received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Clovyr does not access, use, transfer, sell, or permit services acting on its behalf to use Google Workspace API data - including raw, aggregated, anonymized, or derived data - to create, train, or improve generalized or non-personalized artificial intelligence or machine-learning models. Clovyr does not use Google Workspace API data for advertising, retargeting, creditworthiness, or lending.
Clovyr does not allow humans to read Google Workspace API data because Clovyr does not have access to it. A user controls access within the user's own deployment and may remove a Google connection, delete imported or derived data, or delete the deployment using the controls available in the applicable application and infrastructure.
Clovyr AI Cloud requests access to Google Workspace data only when a user initiates the connection and grants the requested permissions. Users may revoke Clovyr AI Cloud's access through their Google Account settings and may remove the corresponding credentials and data from their Clovyr AI Cloud deployment.
7. How We Use Information We Collect
We use the limited information Clovyr receives:
- To provide, maintain, secure, and improve Clovyr.app and Clovyr-provided hosting;
- To create and administer accounts, subscriptions, and transactions;
- To provision infrastructure and display service status;
- To communicate with users, respond to requests, and provide customer support that does not require access to customer servers or application data;
- To detect fraud, abuse, security incidents, and technical failures;
- To comply with applicable law and enforce our legal rights; and
- For another purpose disclosed when the information is collected and, where required, with the user's consent.
We may create aggregated or de-identified information from platform information that Clovyr lawfully receives. We do not create aggregated or derived datasets from customer application data or Google Workspace API data because Clovyr does not have access to that data.
9. Data Retention and Deletion
Clovyr retains account, billing, communications, security, and operational information only for as long as reasonably necessary to provide the Services, comply with legal obligations, resolve disputes, enforce agreements, and protect the Services.
Customer application data is retained within the user's server and applications according to the settings and retention choices controlled by the user. Clovyr cannot independently view or delete that data.
Encrypted backups or opaque blobs stored by Clovyr are retained only while needed to provide the enabled backup or recovery feature, or as otherwise required by law. Users may delete supported backups or terminate the associated Service through the available controls. Because Clovyr lacks the decryption keys, retained encrypted objects remain unreadable to Clovyr.
Users may delete data inside their applications, disconnect third-party services, revoke Google authorization, delete deployments, or close their Clovyr account using the available controls. Users may also submit an account or data-deletion request through the contact method below. We may retain limited records when required by law or for legitimate security, fraud-prevention, accounting, or dispute-resolution purposes.
10. Security
Clovyr uses technical and organizational safeguards designed to protect information it maintains. The Clovyr.app architecture limits Clovyr's access by keeping credential encryption and decryption in the browser, routing management communications directly between the browser and user-selected infrastructure, and placing customer applications and data under user control.
No method of electronic transmission or storage is entirely secure. Users are responsible for protecting their devices, vault keys, cloud accounts, deployed servers, applications, and third-party credentials. Clovyr cannot reset or recover user-held encryption keys that it does not possess.
11. Your Choices and Rights
Users may manage browser settings, disconnect integrations, revoke third-party authorizations, delete deployments, and control information stored inside their own applications. Marketing communications may be unsubscribed from using the link included in the message, although administrative or service-related communications may still be sent.
Depending on location, users may have rights to request access to, correction of, or deletion of personal information that Clovyr maintains. Clovyr can respond only with respect to information it possesses; it cannot retrieve readable information from encrypted vaults, encrypted backups, or customer-controlled servers.
12. Third-Party Services and Links
The Services may contain links to or interoperate with websites, cloud providers, applications, identity providers, and model providers that Clovyr does not own or operate. Clovyr is not responsible for their privacy practices. Users should review their policies before providing information or credentials.
13. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided Clovyr with personal information in violation of this Policy, please contact us.
14. International Users
Clovyr is based in the United States. Information that Clovyr receives may be processed in the United States and other locations where Clovyr or its service providers operate. Customer application data remains in the infrastructure and region selected or controlled by the user, subject to the practices of the selected infrastructure and application providers.
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the revised version at clovyr.app and update the date above. If we materially change how we use or share personal information previously collected, we will provide notice through the Services, by email, or by another appropriate method and obtain consent when required.
16. Contact Information
Questions, concerns, or requests concerning this Privacy Policy or Clovyr's processing practices may be submitted through Clovyr's contact page or by writing to:
Clovyr Co.228 Park Ave S., Suite 60793
New York, NY 10003