← All policies

Cookie & Similar-Technologies Policy

Last updated: 2026-08-05


> How to read this document. This is the Cookie & Similar-Technologies Policy ("Policy") of Recovea, Inc., a Delaware corporation ("Recovea," "we," "us," "our") — the published notice describing the cookies, local storage, and similar technologies Recovea uses on its marketing website and authenticated dashboard (recovea.ai, platform.recovea.ai, and related Recovea-operated web properties — together, the "Site"). It explains what each technology is, what it does, how long it lasts, who sets it, the legal basis and consent model, and how you can control it. > > This Policy is the controlling, itemized cookie inventory and consent-model document for the Site. It is referenced by, and read together with, the Privacy Policy (privacy-policy.md). The Privacy Policy is the broader controller-side notice; where this Policy and the Privacy Policy appear to conflict on a cookie or device-storage matter, this Policy controls as the itemized source of truth, and the two are kept aligned (§11, §13). > > This Policy concerns the Site only. It does not govern the Customer's inference traffic routed through the Recovea gateway (api.recovea.ai): that traffic is machine-to-machine API traffic, not browser traffic, and uses no cookies. The personal data inside it ("Inference Content") is governed by the Data Processing Agreement (data-processing-agreement.md), under which the Customer is the controller and Recovea is the processor (§1.2). > > Recovea is a bootstrap-funded US company; nothing in this Policy concerns investment or securities. Recovea takes a deliberately minimal, US-first cookie posture and holds the same honesty bar as the rest of the Recovea legal pack: it lists the real technologies in use, names them honestly, does not claim a consent banner or an analytics integration that is not actually live, and labels anything planned but not yet deployed as such.


1. Scope — what this Policy covers, and the one thing it does not

1.1 Scope. This Policy covers cookies and similar technologies set when you visit or use the Site — Recovea's marketing website and the authenticated dashboard. It applies to website visitors, prospects, Authorized Users, and billing and support contacts — the same people for whom Recovea acts as the controller under the Privacy Policy. Recovea sells to business customers only; the Site and Service are not intended for personal, family, or household use, and not for individuals under 18.

*1.2 The one thing this Policy does not cover — the gateway. Recovea is an AI-spend gateway: the Customer changes one base_url to route its large-language-model API calls in-path through Recovea (api.recovea.ai) using the Customer's own Provider Keys ("BYO-Key"). The Customer brings and owns its Provider accounts and keys (for example, OpenAI, Anthropic, OpenRouter) and pays the Providers directly; Recovea is a neutral conduit and never resells, marks up, sponsors, funds, or takes custody of Provider tokens or Provider spend, and is not a party to the Customer's contract with any Provider. The Service is provided on a fail-open basis and makes no mid-stream-failover claim; outputs are estimates, never represented as independently "verified" by this Policy. That in-path inference traffic is machine-to-machine API traffic — it carries no cookies and runs no browser technologies. Authentication to the gateway is by API key (the inbound rcv_ key), not by a session cookie. Accordingly, nothing in this Policy applies to the gateway or to Inference Content; see the Data Processing Agreement and the BYO-Key & Provider Terms Addendum* (byo-key-and-provider-terms.md).

1.3 Companion documents. Read this Policy alongside the Privacy Policy (controller-side privacy notice), the Data Processing Agreement (processor-side Inference Content), the Subprocessors list (subprocessors.md — the authoritative vendor inventory), and the Security Statement (security-statement.md — the live security posture). This Policy is incorporated into, and governed by the dispute-resolution, governing-law, limitation-of-liability, and other general terms of, the Terms of Service (terms-of-service.md) and any applicable Master Subscription Agreement (§14).


2. Definitions

2.1 Cookie. A small text file that a website asks your browser to store and send back on later requests. A first-party cookie is set by the domain you are visiting (recovea.ai / platform.recovea.ai); a third-party cookie is set by a different domain.

2.2 Similar technologies. Technologies that perform cookie-like functions, including local storage and session storage (key/value data the browser keeps for a site), pixels / web beacons (tiny images used to record that a page or email loaded), and software-development-kit (SDK) identifiers. Where this Policy says "cookies" it means cookies and these similar technologies, unless stated otherwise. Email pixels / web beacons (open- and click-tracking in messages Recovea sends, via Recovea's active transactional email sender) are addressed at §6.5.

2.3 Session vs. persistent. A session cookie is deleted when you close your browser. A persistent cookie remains for a set lifetime (its "max-age") or until you delete it.

2.4 Strictly necessary vs. non-essential. A strictly-necessary (essential) technology is one without which the Site or a feature you requested will not work (for example, keeping you logged in, or protecting a form submission). A non-essential technology is everything else (for example, analytics).

2.5 Defined Terms. Capitalized terms used but not defined in this Policy — including Service, Customer, Authorized User, Provider, Provider Keys, and Inference Content — have the meanings given in the Terms of Service and are used consistently across the Recovea legal pack. "Services" refers to the umbrella offering as defined in the Terms of Service, which may include optimization, additional features and capabilities Recovea may offer; any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this Policy unless Recovea expressly states otherwise. This Policy concerns only the cookies and similar technologies on the Site and does not activate, license, or describe any such capability.


3. Our posture in one paragraph (the honest summary)

Recovea uses strictly-necessary first-party cookies to run the authenticated dashboard — to maintain your opaque server-side session and to protect against cross-site request forgery and similar security threats. The Service does not function without these. On the dashboard's payment pages, the card form is Stripe's embedded PaymentElement, so Stripe's own script runs in the Site's first-party context and sets Stripe's fraud-prevention cookies there (§9.2); those are strictly necessary to a payment you asked us to take, and Recovea neither reads them nor uses them for analytics or advertising. Beyond that, Recovea uses cookieless, measurement-only analytics (PostHog, US region) to understand how the Site is used, run with advertising features and cross-site tracking off and configured so it stores nothing on your device — no cookie and no local storage. It runs on two surfaces, differently: on the marketing website it is anonymous and aggregate and does not identify the visitor; inside the authenticated dashboard it is identified — because you are signed in, product events are keyed to your pseudonymous account identifier, with your workspace identifier and plan tier, so we can tell whether onboarding and the product work (§6.3). Both surfaces stay cookieless and store nothing on your device, session recording stays off, and neither sends your prompts, completions, spend figures, or key material. Recovea does not use advertising, retargeting, or cross-site tracking cookies; does not build advertising profiles; and does not "sell" or "share" personal information (as those terms are defined under the California Consumer Privacy Act, as amended by the CPRA, and analogous US state laws) through cookies. We honor the Global Privacy Control (GPC) signal where applicable law gives it effect, and treat Do-Not-Track (DNT) consistently with GPC (§8); the Site's PostHog analytics honors both signals and is never initialized when either is set. Because everything the Site sets is strictly necessary — Recovea's own session and security cookies, plus Stripe's payment fraud-prevention cookies on the dashboard's payment pages — and the only non-essential technology is cookieless analytics that stores nothing on your device, no consent banner is required at launch (§7.2); that conclusion changes only if consent-dependent, cookie-setting analytics later ships, or if a cookie is set for a purpose other than one you requested.


4. Category 1 — Strictly-necessary (essential) cookies and storage

These are required for the Site and the authenticated dashboard to function. They are all set in the Site's first-party context — by Recovea, except the last row, which Stripe's embedded payment script sets in that same context (§9.2) — cannot be switched off through a preference control without breaking the Service, and are exempt from prior consent because they are necessary to provide a service you have requested.

PurposeWhat it doesTypeSet byApprox. lifetime
Authenticated sessionMaintains your logged-in state via an opaque server-side session at the browser edge. Recovea verifies AWS Cognito once server-side and mints its own opaque session reference; raw Cognito tokens are never exposed to the browser. The cookie carries an opaque session reference — not your credentials and not any Provider Key.Cookie (HttpOnly, Secure, SameSite)First-party (Recovea)Session / short-lived; renewed on use
CSRF / security stateProtects form submissions and state-changing requests against cross-site request forgery and similar attacks.Cookie and/or token in storageFirst-party (Recovea)Session
Essential app stateLocal/session storage the dashboard uses to function (e.g., UI state, in-flight form data, the opaque session reference).Local/session storageFirst-party (Recovea)Session or as noted
Payment fraud-prevention (Stripe)Set when the dashboard's embedded Stripe card form loads, to process and fraud-screen a payment you initiate. Recovea does not read or receive these.Cookie — Stripe names them __stripe_mid and __stripe_sidStripe, in the Site's first-party context (platform.recovea.ai), on payment pages onlyPer Stripe's published lifetimes: __stripe_mid about 1 year; __stripe_sid about 30 minutes

> Cookie-preference / consent-state cookie — not currently deployed. Recovea does not today operate a cookie preference center or consent banner on the Site, so no consent-state cookie is set (consistent with §7.2 and §10.1). If a preference/consent control is ever deployed, the cookie that records your choices would itself be treated as strictly-necessary / consent-exempt — its sole purpose is to store the preference you expressed, which is the kind of "service you requested" that the consent exemption covers — and this Policy would be updated to list its real name and lifetime before it goes live.

> Note on Cognito. Recovea deliberately uses an opaque server-side session (a token-handler / BFF pattern) rather than placing raw Cognito tokens in the browser. This is a security choice — raw identity tokens never reach client-side storage — and it is why the essential session cookie carries only an opaque reference. See the Security Statement and the Privacy Policy.


5. Category 2 — Functional cookies (preferences)

Functional cookies remember choices you make to give you a better experience (for example, a remembered email or organization at the login prompt, UI density, or a dismissed notice). They are not strictly necessary.

Recovea sets no separate functional or preference cookies; essential UI state is kept in first-party local/session storage as described in §4.


6. Category 3 — Analytics cookies (measurement-only)

6.1 What analytics is for. Where used, analytics helps us understand, in aggregate, how the Site is used — which pages are visited, where visitors arrive from, approximate region, and device/browser type — so we can improve the Site. It is used for product and Site measurement only.

6.2 The hard rules on our analytics.

  • Measurement-only configuration. Advertising features, ad personalization, remarketing, and cross-site/cross-device tracking are off. We do not use analytics to build advertising profiles or to target ads.
  • Service-provider / processor terms (where deployed). Where analytics is deployed, the vendor will be engaged as Recovea's service provider / processor under written terms and configured so it may not use the data for its own purposes; we will configure IP anonymization/truncation and the shortest practical retention where the tool supports it. Recovea's live analytics tool is PostHog, configured measurement-only and cookieless so it stores nothing on your device; see §6.3.
  • No "sale" / "share." Configured this way, Recovea does not "sell" or "share" personal information (as defined under the CCPA/CPRA and analogous state laws) through analytics, and we honor GPC (§8).
  • Content-free. Analytics never receives Inference Content, Provider Keys, usage metering data, spend or cost figures, or the contents of your prompts or completions — it sees Site interaction only (which pages, features and steps were reached), on the marketing website and in the authenticated dashboard alike. The property list its events may carry is a closed allow-list in Recovea's own analytics library: a property outside that list is a build failure, and a runtime filter drops values that look like Recovea keys, Provider keys, bearer tokens, email addresses, or JSON Web Tokens.

6.3 Our analytics — PostHog, configured cookieless on both surfaces. The Site uses PostHog, configured cookieless: it runs in memory-only mode and therefore stores nothing on your device — no cookie and no local storage. Autocapture and session recording are off everywhere. The two surfaces differ in one respect and it is the one worth stating plainly:

  • Marketing website. Anonymous and aggregate. No identifier is assigned to you, and the analytics does not identify the visitor.
  • Authenticated dashboard. Identified product analytics. Because you are signed in, product events are keyed to your pseudonymous account identifier, together with your workspace identifier, plan tier, and the dashboard page the event occurred on. That identifier is an internal opaque id — not your email address, your name, your workspace's name, or any label you chose — and it is meaningless to anyone without Recovea's own account records.

Identification here lives in the event, not on your device. The dashboard sets no analytics cookie and no analytics local storage either, which is why §7.2's no-banner conclusion is unchanged. Nothing about your prompts, completions, spend figures, or keys is sent from either surface. PostHog honors the Global Privacy Control (GPC) and Do-Not-Track (DNT) signals on both surfaces — when either is set, PostHog is never initialized and no request is sent. Analytics data is processed in a US data region, and analytics is disabled entirely unless an analytics key is configured.

> Cookieless measurement — nothing is stored on your device; honors GPC/DNT. Because the Site's PostHog analytics is cookieless and stores nothing on your device (no cookie, no local storage), there is no analytics cookie to list — it sits outside the cookie tables above by design. It is anonymous and aggregate on the marketing website; in the authenticated dashboard it is keyed to your pseudonymous account identifier, which travels in the event and is not written to your device. It honors GPC and DNT on both surfaces.

6.4 No advertising or retargeting cookies. Recovea does not deploy advertising, retargeting, social-media tracking, or cross-site ad cookies. If this ever changes, this Policy will be updated before such cookies are set, and (where required) prior consent will be obtained.

6.5 Email open- and click-tracking — not used. Email messages Recovea sends are transactional and are delivered by Amazon SES. Recovea does not enable SES open-tracking or click-tracking: the sending configuration set records delivery outcomes only (bounces and spam complaints, which are the events a sender must handle), and Recovea does not embed open-tracking pixels / web beacons or redirect/click-tracking links. Nothing in Recovea's email records whether a message was opened or which links were followed. This is separate from the Site cookies in §§4–6.4 and sets nothing on the Site. Should Recovea ever enable such tracking, this Policy and the Privacy Policy will be updated before it is switched on.


7. Consent model — US-first, with EEA/UK/Swiss mechanics dormant

7.1 US-first default (the live posture). Recovea operates US-only: it sells to US business customers and hosts in the United States (AWS us-east-1, N. Virginia). For Site visitors, Recovea sets strictly-necessary cookies without a consent prompt (they are required to run the Service) and treats a GPC signal as a valid opt-out of any non-essential analytics on the Site (§8). Under current US state privacy laws, controllers must give clear notice of device-storage technologies and honor applicable opt-out and universal-opt-out-signal obligations — which this Policy and §8 are designed to satisfy. No US state law currently requires a prior-consent "cookie wall" before setting non-essential cookies; the obligation is notice plus an honored opt-out, not opt-in.

7.2 Whether any banner is required (the launch answer). The Site uses only strictly-necessary cookies — Recovea's own first-party session and security cookies (§4), plus the Stripe fraud-prevention cookies that the embedded card form sets in the Site's first-party context on the dashboard's payment pages (§9.2) — plus cookieless PostHog analytics that stores nothing on your device and honors GPC/DNT (§6). Recovea sets no advertising or cross-site-tracking cookie and makes no "sale" or "share" of personal information through cookies. On this posture, no consent banner is required at launch under US law: the payment cookies are necessary to a transaction you initiate, and everything else is either essential or stores nothing on your device. The required mechanism is this notice plus the opt-out/GPC handling in §8. This conclusion is conditional: if consent-dependent, cookie-setting non-essential analytics is later introduced, or if EEA/UK/Swiss visitors come into scope per §7.3, Recovea will deploy a compliant preference control before such cookies are set. No cookie consent banner or preference center is deployed on the Site today (§10.1, §4).

7.3 EEA / UK / Switzerland — DORMANT at launch. Recovea's operations are US-only, and Recovea does not target the EEA, UK, or Switzerland. The international-consent mechanics for those regions — prior opt-in consent for non-essential cookies under the ePrivacy Directive and national implementations (such as the UK Privacy and Electronic Communications Regulations), and the related international-transfer mechanisms (EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and Swiss amendments) — are dormant and live only in the Data Processing Agreement / a standalone transfer addendum, not in this Policy. If and when an EEA/UK/Swiss visitor or signer comes into scope, Recovea's posture is to: set strictly-necessary cookies without consent; obtain prior opt-in consent before setting any non-essential (functional/analytics) cookie, via a control offering a genuine "Reject all" as easily as "Accept," with granular per-category choice and easy later withdrawal; record and honor those choices; and rely on the transfer mechanism in the Data Processing Agreement for any resulting cross-border transfer.


8. Global Privacy Control (GPC) and Do-Not-Track (DNT)

8.1 GPC. Recovea honors the Global Privacy Control (GPC) signal where applicable law gives it effect (notably under the CCPA/CPRA and several US state laws). Because Recovea does not "sell" or "share" personal information through cookies (§6), GPC has limited additional effect here; we nonetheless treat a GPC signal as a valid opt-out of any non-essential analytics on the Site.

8.2 Do-Not-Track (DNT). There is no industry-standard, legally-defined response to browser DNT headers. Recovea treats a DNT signal consistently with GPC — as a request to limit non-essential analytics — and otherwise runs the minimal, measurement-only posture described above.


9. Third parties and where the data goes

9.1 First-party first. The essential cookies (§4) all live in the first-party context (recovea.ai / platform.recovea.ai); Recovea sets all of them except the Stripe payment row, which Stripe's embedded script sets in that same context (§9.2). Some entries may be set by Recovea's infrastructure providers acting as Recovea's sub-processors under contract — for example, an AWS load balancer may set a session-affinity cookie. Recovea's sub-processors are listed in the authoritative inventory at subprocessors.md. The live sub-processors that touch the Site are Amazon Web Services (hosting, compute, storage, and identity (Cognito), us-east-1, USA), Stripe (payments — its script runs embedded in the Site's first-party context on the dashboard's payment pages and sets cookies there; see §9.2), and PostHog (cookieless product analytics on the marketing website and the authenticated dashboard, US data region — §6.3). Transactional email is sent by Amazon SES (§6.5); it does not touch the Site or set anything on it, which is why it does not appear in the tables above. Sentry (browser error reporting, US data region) has been deployed on the Site since 2026-08-05 and is listed as an Engaged Sub-processor on subprocessors.md. It sets no cookie and no local storage, which is why it appears in none of the tables above; it records no session replay and stores no IP address; and it sends only what a crash report needs — the error and its stack trace, the release and environment, the browser, and the named route. It was disclosed here as Planned before it was wired, not after. *Any analytics or monitoring vendor that sets cookies/identifiers on the Site must be added to subprocessors.md and to this Policy before it is deployed.*

9.2 Payments (Stripe) — an embedded card form on Recovea's own page. Recovea uses Stripe as its payment processor, and the card form is Stripe's embedded PaymentElement: Stripe's script (js.stripe.com) is loaded into the authenticated dashboard's own page at platform.recovea.ai, and the card fields render in a Stripe-controlled iframe inside it. There is no redirect to a Stripe-hosted checkout page. Card details therefore still go directly to Stripe and Recovea never receives or stores full card numbers — but because Stripe's script runs in the Site's first-party context, Stripe sets its own cookies there. Stripe publishes these as __stripe_mid (a persistent device identifier, about one year) and __stripe_sid (a short session identifier, about 30 minutes), used for fraud prevention and to process payments. They are Stripe's cookies, governed by Stripe's own cookie and privacy notices, and Stripe may correlate the device identifier across other sites that use Stripe for fraud detection. Recovea does not read, receive, or use them, and does not use them for analytics, advertising, profiling, or cross-site tracking. Recovea loads no Stripe script on the marketing site: these cookies appear only where the payment form loads.

Why this still does not require a banner. These are strictly-necessary cookies as defined in §2.4 — they exist to take and fraud-screen a payment you have asked Recovea to take, they are set only on the dashboard's payment pages, and they are neither analytics nor advertising nor a "sale" or "share" of personal information. Under the US notice-plus-opt-out model in §7.1, the obligation they attract is notice, which this section is. The §7.2 "no banner required" conclusion therefore stands, but it stands on the strictly-necessary-payment ground — not on any claim that no payment cookie is set in Recovea's context, which the embedded form makes untrue. If Recovea ever loads Stripe's script on the marketing site, or uses it for anything other than a payment you initiate, this Policy is updated before that change ships (§11).

9.3 BYO-Key Providers are not in scope here. The LLM Providers the Customer routes to (for example, OpenAI, Anthropic, OpenRouter) are reached over the API, under the Customer's own accounts and keys, at the Customer's direction. They are the Customer's processors/recipients, not Recovea's sub-processors; they set no cookies in your browser through the Service. See the Privacy Policy and the BYO-Key & Provider Terms Addendum.

9.4 International transfers — dormant. Recovea operates US-only and does not, at launch, transfer EEA/UK/Swiss personal data through Site cookies. Should any in-scope analytics vendor ever transfer such data to the United States, Recovea relies on the transfer mechanism in the Data Processing Agreement (EU SCCs / UK IDTA-Addendum / Swiss amendments, plus any required supplementary measures), which is dormant until the first such transfer. This Policy makes no independent transfer representation; the Data Processing Agreement controls.


10. How to control cookies

10.1 In the Site. Recovea does not currently operate a cookie preference center or consent banner on the Site (consistent with the strictly-necessary-only posture in §4 and §7.2). If a preference center is ever deployed, you will be able to review categories and accept or reject non-essential cookies there, and change your choices at any time, and this Policy will be updated to describe it.

10.2 In your browser. You can block or delete cookies, and clear local/session storage, through your browser settings — Chrome, Safari, Firefox, Edge, and others each provide controls and a "private/incognito" mode, and options to "block third-party cookies" or "clear on exit." See your browser's help pages for instructions. Note: if you block or delete strictly-necessary cookies (§4), the dashboard may not work — for example, you may be logged out or unable to submit forms.

10.3 GPC / DNT. You can enable GPC (via a supporting browser or extension) and/or DNT in your browser; we honor these as described in §8.

10.4 Opt-out of analytics specifically. The Site's PostHog analytics is cookieless and stores nothing on your device; it honors GPC and DNT, so enabling either signal (§8) opts you out, and no separate analytics opt-out cookie is needed.

10.5 Email tracking. Where Recovea's email uses tracking (§6.5), you can disable automatic loading of remote images in your email client to limit open-tracking, and use the unsubscribe link in any marketing email to stop those messages.


11. Keeping this Policy accurate (the operational commitment)

11.1 This Policy is the source of truth for the cookie inventory, and we keep it accurate against the running Site. The tables above reflect the actual cookies, storage keys, providers, and lifetimes on the running Site, and any row that does not correspond to a real technology is removed. The inventory covers every cookie set in the Site's context, whether Recovea sets it or an embedded vendor script does (§9.2); it does not list cookies that are never set. We re-check this Policy against the running Site on any material change to the Site.

11.2 Alignment. Keep this Policy aligned with the Privacy Policy (the cookie summary) and with subprocessors.md (any cookie-setting vendor). If a new analytics, monitoring, or support tool that sets cookies is added, run the sub-processor change-notice process in subprocessors.md and update this Policy before the tool goes live.


12. Honesty boundary (why this Policy will never over-claim)

Recovea's whole posture rests on promising only what is real. This Policy therefore states only the cookies and technologies actually deployed on the Site, names a vendor only once it is live, and labels anything planned as planned. This Policy makes no product, savings, quality, or uptime claim, and nothing in it describes, implies, or depends on any such claim; the Service is provided on the no-guarantee, fail-open basis set out in the Terms of Service and the AI-Output & No-Guarantee Disclaimer (ai-output-and-no-guarantee-disclaimer.md), under which outputs are estimates and are not represented as independently "verified." A cookie banner that claimed controls that are not wired, or a vendor list naming a tool not actually deployed, would be a self-inflicted credibility wound; this Policy must always describe only what is real on the Site.


13. Relationship to the Privacy Policy and the rest of the legal pack

This Policy supplements and is incorporated into the Privacy Policy, which describes more fully how Recovea handles personal data, the controller/processor split, and your privacy rights and how to exercise them. The Privacy Policy summarizes this Policy; this Policy controls on any cookie/device-storage matter. This Policy is also incorporated by reference into the Terms of Service and any applicable Master Subscription Agreement, and is read together with the Data Processing Agreement, the Subprocessors list, the Security Statement, and the BYO-Key & Provider Terms Addendum. In the event of a conflict between this Policy and those documents on a non-cookie matter, the order of precedence stated in the Terms of Service governs.


14. Legal terms incorporated by reference (disputes, liability, governing law)

This Policy is a published notice, not a standalone contract, and it does not create or expand any warranty. The general legal terms that govern your use of the Site and the Service — and that apply to any dispute arising out of or relating to this Policy — are set out in the Terms of Service and any applicable Master Subscription Agreement, and are incorporated here by reference. Without limiting those documents:

14.1 No warranty; disclaimer. THE SITE AND THE SERVICE, INCLUDING ALL COOKIES AND SIMILAR TECHNOLOGIES DESCRIBED HERE, ARE PROVIDED ON AN "AS IS" AND "AS AVAILABLE" BASIS, WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING ANY IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT, TO THE FULLEST EXTENT PERMITTED BY LAW (UCC § 2-316). Recovea does not warrant that any cookie control, opt-out, or browser-signal handling will be error-free or uninterrupted. This disclaimer mirrors, and is not narrowed by, the disclaimer in the Terms of Service.

14.2 Limitation of liability. Recovea's aggregate liability arising out of or relating to this Policy is subject to, and capped by, the limitation-of-liability provisions of the Terms of Service / Master Subscription Agreement, and is not enlarged by this Policy. As set out there: neither party is liable for indirect, incidental, special, consequential, exemplary, or punitive damages, or for lost profits, revenue, goodwill, or data, even if advised of the possibility; each party's aggregate liability is capped at the greater of (a) the total Fees paid by Customer to Recovea in the 12 months before the event giving rise to liability and (b) US $25,000, with an enhanced cap of 2× that amount for breaches of confidentiality or of data-protection/security obligations, and with the uncapped carve-outs (indemnification, payment obligations, breach of license/Acceptable Use/IP-ownership terms, and a party's fraud or willful misconduct) stated in the Terms of Service; as stated there, a party's liability for gross negligence remains subject to the caps to the fullest extent permitted by applicable law. These limits apply notwithstanding any failure of essential purpose and form part of the basis of the bargain.

14.3 Dispute resolution; governing law; venue. This Policy is governed by the laws of the State of Delaware, excluding its conflict-of-laws rules (the UN Convention on Contracts for the International Sale of Goods does not apply). Any dispute arising out of or relating to this Policy is resolved under the dispute-resolution provisions of the Terms of Service, which provide for binding arbitration before the American Arbitration Association (AAA) under its Commercial Arbitration Rules, by one arbitrator, seated in Wilmington, Delaware, on an individual basis with a class-action, collective, and representative-action waiver, with judgment on the award enterable in any court of competent jurisdiction. Carve-outs to court (Delaware state or federal courts in Wilmington) cover claims for injunctive or equitable relief for actual or threatened infringement or misuse of intellectual property or breach of confidentiality, and small-claims matters within that court's jurisdiction. This is a business-to-business service, and the parties intend the AAA Commercial Arbitration Rules to apply, subject to the Agreement's Consumer-Rules fallback and mass-arbitration protocol (Terms of Service §24.2 and §24.7 / MSA §23.2 and §23.6): if the AAA or a court of competent jurisdiction determines that the AAA Consumer Arbitration Rules apply to a dispute involving an individual, those rules govern that dispute and Recovea pays the filing, administrative, and arbitrator fees the AAA consumer fee schedule assigns to the business. A website visitor or other person who has not entered into the Terms of Service or a Master Subscription Agreement is not bound by the arbitration provision and may bring any claim in the Delaware state or federal courts in Wilmington — this notice does not, by itself, compel any non-contracting person to arbitrate.

14.4 General. The assignment, force majeure, notices, entire agreement, severability, modification, and electronic-consent provisions of the Terms of Service apply to this Policy. You consent to receive this Policy and updates to it in electronic form. Recovea may assign this Policy as part of a merger, acquisition, reorganization, or sale of assets. The headings in this Policy are for convenience only.


15. Changes to this Policy

We may update this Policy as the Site, our tooling, and the law evolve. We will post the updated version here with a new version number and the "Last updated" date above and, for material changes, note them as described in the Privacy Policy. Where a change introduces a new non-essential cookie for any visitor for whom consent is legally required, we will obtain that consent before setting it.


16. Contact

  • Privacy questions and cookie requests: privacy@recovea.ai. Recovea operates US-only and has not appointed a formal Data Protection Officer or an Article 27 EU representative; this is the correct channel.
  • Controller: Recovea, Inc., a Delaware corporation. Notice address: 2810 N Church St STE 89986, Wilmington, DE 19802.
  • Security: security@recovea.ai. Legal notices: legal@recovea.ai.

For the full picture of how we handle personal data — and for your privacy rights (access, deletion, correction, opt-out, GPC) and how to exercise them — see the Privacy Policy.


17. Forward-looking (24-month) considerations

This note flags developments this Policy is positioned to absorb. It is informational, not a commitment.

  • Expanding US state privacy laws and universal opt-out (GPC) mandates. A growing number of US states (California, Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect) impose notice, opt-out, and universal-opt-out-signal (GPC) obligations. Keep §7 and §8 current and confirm GPC handling satisfies each applicable state. A strictly-necessary-only, measurement-only posture keeps Recovea on the low-risk side of all of them and, on that posture, needs no banner.
  • EEA/UK/Swiss scope (currently dormant). If Recovea ever targets or onboards EEA/UK/Swiss visitors or signers, the §7.3 consent control and the Data Processing Agreement transfer mechanism must be activated before any non-essential cookie is set or any cross-border transfer occurs. The pending EU ePrivacy Regulation may change consent and "cookie wall" rules; reassess when its text and timeline firm up.
  • Browser deprecation of third-party cookies and a privacy-by-default web. As browsers restrict third-party cookies and cross-site tracking, a first-party, measurement-only (or cookieless) analytics posture is both lower-risk and more durable. Prefer it.
  • Consistency with the honesty bar. Recovea's honesty bar makes over-claiming anywhere — including a cookie banner that claims controls that are not wired, or a vendor list naming a tool not actually deployed — a self-inflicted credibility wound. This Policy must always describe only what is real on the Site, and stay aligned with the Privacy Policy and the AI-Output & No-Guarantee Disclaimer.

It is the itemized cookie/consent source of truth referenced by the Privacy Policy, it concerns the Site only, and processor-side Inference Content is governed by the Data Processing Agreement.