Recovea Privacy Policy
Last updated: 2026-08-05
> How to read this document. This is the external-facing Privacy Policy for Recovea, Inc., a Delaware corporation — the notice Recovea publishes about personal data for which Recovea is the controller (website visitors, prospects, account users, billing contacts, support correspondents). It is written to match the actual deployment (United States; Amazon Web Services us-east-1, N. Virginia) and the actual data model of the Services, and it holds the same honesty bar as the rest of the Recovea legal pack: it states the real data practices, the real (honest) security posture, and the honest deletion model — including the immutable, content-free Ledger carve-out that a less careful company would paper over. > > This Policy governs Recovea-as-controller data only. Personal data inside the Customer's inference traffic that Recovea processes on the Customer's behalf ("Customer Personal Data," handled as Inference Content) is governed by the Data Processing Agreement (the "DPA") — see data-processing-agreement.md — under which the Customer is the controller and Recovea is the processor. Where Recovea Processes Customer Personal Data on the Customer's behalf, the DPA is automatically incorporated into and forms part of the agreement between the parties. Where this Policy and the DPA appear to conflict on processor-side processing, the DPA controls. Where this Policy and security-statement.md appear to disagree about the live security posture, the Security Statement controls (it is the conservative anchor).
Contents
- Who we are, and the scope of this Policy
- Two roles — controller vs. processor (read this first)
- What we collect (controller-side), and the precise data model
- How we use your data, and our lawful bases
- What we never do
- Aggregated / De-identified Data
- Sharing and Sub-processors
- Retention, and the honest immutable-Ledger deletion carve-out
- Security (stated honestly)
- Where your data is processed; international transfers
- Your privacy rights (US state laws; GDPR/UK pointer)
- Cookies, analytics, GPC and Do-Not-Track
- Children
- Law-enforcement and legal-process requests
- Electronic communications and marketing choices
- Third-party links and services
- Changes to this Policy
- How to contact us
- Regulatory and capability outlook (informational)
1. Who we are, and the scope of this Policy
1.1 Controller. Recovea, Inc., a Delaware corporation ("Recovea," "we," "us," "our"), with a notice address at 2810 N Church St STE 89986, Wilmington, DE 19802, operates the website at recovea.ai, the Recovea gateway, the dashboard, the recoveactl command-line tooling, and the managed service (together, and including any related features Recovea makes available, the "Services"). Recovea is a United States company; it hosts the Services in the United States on Amazon Web Services in the us-east-1 (N. Virginia) region; and it sells to US business customers only. Recovea is a bootstrap-funded US company; nothing in this Policy concerns investment or securities.
1.2 What this Policy covers. This Policy explains, for the personal data for which Recovea is the controller:
- what personal data we collect, and where it comes from (§3);
- how and why we use it, and the lawful bases we rely on (§4);
- what we never do — never sell or "share" personal data; never train any AI model on Customer Data, Inference Content, Service outputs, or the Ledger (§5);
- how we use Aggregated/De-identified Data (§6);
- who we share it with — our Sub-processors (§7 and
subprocessors.md), and the BYO-Key distinction for Providers; - how long we keep it, and the honest immutable-Ledger deletion carve-out (§8 and
data-retention-and-deletion-policy.md); - how we secure it, stated honestly (§9 and
security-statement.md); - where it is processed and how international transfers are handled (§10);
- your rights under US state privacy laws (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA and others), with a pointer to GDPR/UK GDPR terms in the DPA (§11 and
data-rights-request-procedure.md); - cookies and similar technologies (§12 and
cookie-policy.md); - children (§13); legal process (§14); communications choices (§15); third-party links (§16); changes (§17); contact (§18).
1.3 Plain-language scope note. Recovea is an AI-spend gateway — a neutral, in-path proxy for large-language-model (LLM) API traffic. The Customer changes one base_url to route its inference calls through Recovea (api.recovea.ai) using the Customer's own Provider API keys ("BYO-Key — Bring Your Own Key"). Recovea does not resell, rebill, sponsor, fund, or mark up Provider tokens; the Customer contracts with, and pays, its Providers directly. Billing for the Services is subscription-based today. The Services may include optimization, additional features and capabilities Recovea may offer; any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this Policy unless Recovea expressly states otherwise. Recovea may offer subscription, usage-based, and savings-/outcome-based pricing models; any savings-based model applies only on the Customer's separate, affirmative election. See terms-of-service.md and ai-output-and-no-guarantee-disclaimer.md.
2. Two roles — controller vs. processor (read this first)
Recovea handles personal data in two distinct roles, and this Policy only governs the first.
2.1 Recovea as controller — governed by this Policy. Data about website visitors, prospects, Authorized Users, and billing/support contacts — names, work emails, company and role, account and authentication data, billing-contact details, support correspondence, and site analytics. Recovea decides why and how this data is processed. This Policy applies to it.
2.2 Recovea as processor — governed by the DPA, not this Policy. Customer Personal Data contained inside the Customer's inference traffic routed through the gateway — the request/response content proxied in-path (defined as "Inference Content"), plus the per-request Usage Data (cost metadata) generated to meter that traffic. For this data the Customer is the controller and Recovea is the processor acting on the Customer's documented instructions. This processing is governed by data-processing-agreement.md, not this Policy; the DPA is automatically incorporated into the agreement between the parties.
2.3 If your personal data reached us inside a Customer's traffic (for example, you are an end user of a Recovea Customer's application), the Customer is the controller. Please direct access, deletion, and similar requests to that Customer first; we will assist the Customer in responding, as required by the DPA and applicable law.
3. What we collect (controller-side), and the precise data model
3.1 Categories of personal data we collect as controller
| Category | Examples | Source |
|---|---|---|
| Information you provide | When you request an Assessment or scan, book a call, create an account, or contact us: name, work email, company, role, estimated/actual AI spend, and any log samples or notes you choose to share. | You |
| Account & authentication data | Account identifiers; Authorized User seat/role assignments; authentication identifiers via AWS Cognito. Recovea uses an opaque server-side session at the browser edge — raw Cognito tokens are not exposed to the browser. | You, at signup |
| Billing data | Plan, Subscription status, invoices, billing-contact details, invoicing history. Card details go directly to our payment processor, Stripe; Recovea never stores full card numbers. | You / Stripe |
| Your BYO Provider Key | Your OpenAI / Anthropic / OpenRouter (etc.) API key, supplied to enable routing. Handled per §3.4 and byo-key-and-provider-terms.md. | You |
| Usage Data (cost metadata) | Per-request metering needed to run the gateway and the Ledger: model, token counts, finish_reason, computed cost, latency, timestamps, Levers applied, and any savings deltas — recorded on the content-free, hash-chained, append-only Ledger. | Generated by the gateway |
| Inference Content (request/response content) | The actual content of prompts and completions proxied in-path on the paid tier. Processor-side data (Customer Personal Data) governed by the DPA, not this Policy. See §3.3. | Customer traffic (paid, in-path) |
| Site and product analytics | On the marketing website: page views, referrers, approximate region (derived from IP), device/browser type, collected as anonymous, aggregate interaction metrics. In the authenticated dashboard: which product features and onboarding steps you reached, keyed to your pseudonymous account identifier with your workspace identifier and plan tier. Both run on cookieless analytics — nothing is stored on your device on either surface — with session recording off, and neither carries your prompts, completions, spend figures, or key material. | Your browser — see §12 and cookie-policy.md |
| Support data | What you send us at support@, privacy@, security@, or legal@recovea.ai, including any attachments. | You |
We collect this data from the sources named in the table above: directly from you; automatically from your browser/device; and from our payment processor (Stripe) for billing status. We do not enrich, buy, or build marketing profiles from third-party data brokers.
3.2 Free tier — observe-only, in-path (metered; metadata only)
On the Free tier, the Services are observe-only and in-path: the Customer's inference traffic routes through the gateway so the Services can meter it, but Recovea applies no optimization Levers and no spend-control enforcement, and persists cost metadata only (model, token counts, computed cost, usage patterns, timestamps). Because the Free tier is in-path, request and response payloads transit Recovea in memory to be served and metered (see "transit vs. storage" below); however, on Free Recovea does not cache or otherwise persist prompt or completion bodies by default — only Usage Data metadata is retained, and the inbound Recovea key (rcv_ / rcva_) is stripped before the upstream call. Pricing for each tier is stated in the Order Form / terms-of-service.md.
3.3 Paid in-path plans — transit vs. storage stated honestly
On the paid, in-path plans — the in-path gateway plus control surface, the cache/dedup Levers where enabled on the plan, and the Ledger — the Services are in-path: the Customer's traffic routes through Recovea so the Services can meter it and, where enabled, apply cache/dedup Levers. Because the Services are in-path, they process Inference Content — which may contain the Customer's confidential data and the personal data of the Customer's own end users. We are precise and honest about transit vs. storage:
- Transit (always, on in-path requests). Recovea receives the request payload in memory, applies its Levers, signs the upstream call to the Customer's chosen Provider with the Customer's Provider Key, and returns the Provider's response payload to the Customer. This in-memory transit is inherent to being an inline gateway — it is the request being served. The inbound Recovea key (
rcv_/rcva_) is stripped before the upstream call. - Metering metadata (always persisted). For every in-path request, Recovea persists content-free cost metadata (model, token counts, finish_reason, timestamps, computed cost, Levers applied) on the Ledger — an append-only, hash-chained record. The Ledger contains no prompt or completion content.
- What is persisted by default. On the default in-path path, Recovea persists only content-free metadata; it does not persist full prompt or response bodies by default. The only response content stored on a routine basis is the paid-tier cache/dedup store described in the next bullet. Capture of full request/response bodies is off by default and occurs only where the Customer affirmatively enables it; any such opt-in captured-body retention is limited to a 24-hour TTL, after which it is evicted.
- paid-tier cache/dedup (response content keyed by request hash). On the paid tier, to serve byte-identical repeats, the cache/dedup Levers store response content keyed by a request hash for the cache time-to-live (TTL) — by default up to 24 hours — then evict it. This is the one routine path on which response content is stored; it exists solely to serve identical repeat requests at lower cost, is tenant-isolated, is never used to train any model, and is processor-side data governed by the DPA. Cached responses are byte-identical to the Provider's original response — Recovea never synthesizes or alters response content.
Inference Content and the cache are processor-side Customer Personal Data and governed by the DPA. This Policy describes them here only so controllers and individuals understand the full data model.
3.4 BYO Provider Keys — handling (honest current state)
The Services are bring-your-own-key. The Customer supplies its own Provider account and API key (OpenAI, Anthropic, OpenRouter, etc.); Recovea passes requests through using the Customer's key, does not resell or mark up Provider tokens, and the Customer pays its Providers directly.
- Provider Keys are encrypted at rest with AES-256-GCM, using the tenant (customer) UUID as additional authenticated data (AAD); they are decrypted in memory only to sign the Customer's own upstream calls, are never returned to the client, and are shown in plaintext only once at entry.
- Strict per-tenant isolation applies, and an egress allowlist limits the gateway to Provider and AWS domains.
- Honest current-state disclosure. Stored Provider Keys are protected with AWS KMS envelope encryption (live) under per-tenant KMS encryption contexts; customer-managed keys (BYO-CMK) are planned, not live.
security-statement.mdcontrols on the live posture.
See byo-key-and-provider-terms.md for full Provider-Key handling and the Customer's Provider-terms responsibilities.
3.5 Fail-open and the re-point escape hatch
The Services are designed to fail open: any fault in a Recovea-added layer is designed to fall back to plain upstream passthrough, and a full outage is reversible by the Customer re-pointing base_url back to its Provider — a one-line, reversible change. Fail-open is a design objective and a reversible exit, not an availability or correctness warranty; there is no uptime guarantee and no service-credit SLA at launch. Where a fault occurs after tokens begin streaming, it surfaces as a clean error rather than a silent splice; we do not claim mid-stream failover. See availability-and-sla-statement.md.
3.6 What we do not collect (controller-side)
We do not knowingly collect or use sensitive personal information (as that term is defined under the CCPA/CPRA and other US state laws) for any purpose that would trigger a right to limit it. We treat account-authentication credentials (handled via AWS Cognito) solely to authenticate you; we do not use them for inference, profiling, or any purpose triggering the right to limit, and we do not collect passwords or financial-account access codes for inference or profiling. We do not collect children's data (§13). We do not run advertising trackers, and we do not build advertising profiles.
4. How we use your data, and our lawful bases
We use controller-side personal data for the purposes below. Where the GDPR / UK GDPR applies to a visitor or prospect (see §11.3), the lawful basis is shown in italics.
- To provide, meter, and bill the Services — route/meter usage on paid tiers; operate the Ledger; manage your Subscription via Stripe; and operate the Services' measurement methodologies. Performance of a contract.
- To communicate with you about your request, engagement, account, or Subscription, including service and security notices you cannot opt out of while you hold an account. Performance of a contract; legitimate interests.
- To operate, secure, debug, and improve the Services, and to prevent abuse — security, fraud prevention, abuse handling, service integrity. Legitimate interests.
- For product analytics and improvement, using Aggregated/De-identified Data where feasible (see §6). Legitimate interests.
- To send product updates and marketing you signed up for. Every such email has an unsubscribe link. Consent (where required).
- To comply with law — tax, accounting, valid legal process, and record-keeping. Legal obligation.
We maintain a documented legitimate-interests balancing assessment for the processing we characterize as legitimate-interests-based, and we rely on consent where applicable law requires it.
5. What we never do
- We never train any AI model on your data — not on Customer Data, not on Inference Content (prompts or completions), not on Usage Data, and not on Service outputs or the Ledger. This is a contractual commitment, repeated in
data-processing-agreement.mdandterms-of-service.md. - We never sell personal data, and we do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA and equivalent US state laws — including through our analytics, which run measurement-only (§12).
- We do not run advertising trackers or build advertising profiles.
- We do not resell, rebill, sponsor, fund, or mark up your Provider tokens (BYO-Key; you pay Providers directly).
- Inference Content is processed only to serve that Customer's own traffic — to proxy it, meter it, and (on the paid tier) serve byte-identical cache repeats — and is never repurposed.
6. Aggregated / De-identified Data
6.1 Recovea may create and use Aggregated/De-identified Data — de-identified, aggregated usage metrics derived from operating the Services (for example, statistical patterns of model usage, token volumes, cache-hit rates, latency, and Lever effectiveness across the platform) — to operate, secure, benchmark, and improve the Services and their measurement methodologies.
6.2 The hard rules on this data:
- It is content-free — derived from Usage Data (cost metadata), never from Inference Content (prompt/completion content).
- It is aggregated and/or de-identified to a standard intended to meet CCPA §1798.140(m) de-identification and GDPR anonymization thresholds, so that it does not identify, and cannot reasonably be linked to, any individual or any single Customer.
- Recovea makes a no-reidentification commitment: we maintain Aggregated/De-identified Data in de-identified form, do not attempt to re-identify it, and contractually obligate recipients (if any) not to re-identify it.
- It is never sold on a per-Customer basis. Recovea does not sell, license, or disclose identifiable per-Customer data or analytics to third parties.
- Recovea does not use Customer Data or Inference Content to train any AI model (§5). Aggregated/De-identified Data is not Customer Data and not Inference Content.
The IP allocation aligns with terms-of-service.md (Customer owns Customer Data and Inference Content; Recovea owns the Services, the Ledger format, and Aggregated/De-identified Data, never sold per-Customer). Recovea takes no position on ownership of Provider Output.
7. Sharing and Sub-processors
We share personal data only:
7.1 With the Sub-processors listed in subprocessors.md, under contract and only as needed to run the Services. As of the date above, these are: Amazon Web Services, Inc. — hosting / compute / storage / authentication (Amazon Cognito) and Amazon SES, the active transactional and account email sender, which receives your account email address and the message content; us-east-1, USA; Stripe, LLC (successor by conversion to Stripe, Inc., effective 2026-01-03) — payments / Subscription billing, USA; and PostHog, Inc. — cookieless product analytics (US data region) on two surfaces: on the marketing website it is anonymous and aggregate and does not identify the visitor, and inside the authenticated dashboard it is product analytics keyed to a pseudonymous account identifier, with the workspace identifier, plan tier, product-event names, and the dashboard page an event occurred on. PostHog receives no spend or cost values, no Inference Content, no Usage Data records, no Provider Keys and no Ledger data; session recording is off and nothing is stored on your device on either surface. Functional Software, Inc. d/b/a Sentry — browser error reporting for the website and the dashboard, Engaged since 2026-08-05 (US data region), which receives error events: the exception and its stack trace, the release and environment identifiers, browser and operating system, and the named route the error occurred on. No session replay, no performance tracing, and no IP-address storage — the last is disabled org-wide at the vendor — and error text is redacted for keys, tokens and email addresses before it leaves your browser. Sentry runs on the browser surfaces only, never in the gateway that carries Inference Content. It was pre-listed as Planned before any reporting endpoint existed and the change-notice below ran before it began Processing (subprocessors.md §2.7 and §12). Health-check and cron monitoring is AWS-native (CloudWatch/SNS) and engages no external monitoring Sub-processor. subprocessors.md is the authoritative, controlling inventory of identity, purpose, location, and engagement status; this summary is for convenience and may lag it. We give at least 30 days' prior notice before adding or replacing a Sub-processor, with an emergency carve-out under which we give as much notice as practicable. The bounded exclusive remedy if you reasonably object to a new Sub-processor is to terminate the affected portion of the Services and receive a pro-rata refund of prepaid Fees for the terminated portion. This notice period, the emergency carve-out, and the bounded remedy read consistently with subprocessors.md, data-processing-agreement.md, and refund-cancellation-policy.md.
7.2 Where required by law or valid legal process — see §14.
7.3 In connection with a merger, acquisition, financing, reorganization, or sale of assets, in which case this Policy's protections continue to apply to the transferred data and we will notify you of any change in controller.
7.4 With your consent, or at your direction.
7.5 BYO-Key Providers are NOT Recovea's Sub-processors. The upstream LLM Providers the Customer chooses to route to (OpenAI, Anthropic, OpenRouter) are reached under the Customer's own Provider accounts and keys, at the Customer's direction. They are the Customer's processors / customer-directed recipients / independent controllers, with Recovea acting as a neutral conduit — not Recovea's Sub-processors — and so are not listed on subprocessors.md. Where Providers offer zero-retention or data-handling options, Recovea passes those settings through where available. The Customer is responsible for its Providers' terms and data handling. See byo-key-and-provider-terms.md. This conduit / customer-processor characterization reads identically across the DPA, subprocessors.md, byo-key-and-provider-terms.md, this Policy, security-statement.md, and the export documentation.
8. Retention, and the honest immutable-Ledger deletion carve-out
data-retention-and-deletion-policy.md is the controlling retention/deletion document; this section summarizes it and must stay consistent with it.
8.1 Retention periods
- Prospect data (Assessment/scan requests, contact inquiries): kept while the conversation is live and deleted on request, and in any event no later than 24 months after last contact.
- Account & billing data: kept while your account is active and for 90 days after closure for legal/tax/audit, then deleted or anonymized; statutory billing records are retained for approximately 7 years as required by tax/accounting law.
- Usage Data (Ledger metadata): Free 30 days / Developer 90 days / Team 365 days / Growth 365 days / Scale 1,095 days (Enterprise: per Order Form), after which it is deleted or de-identified, subject to the immutable-Ledger carve-out in §8.3.
- Stored Inference Content / paid-tier cache (response content keyed by request hash): paid tiers only; retained only for the cache TTL (by default up to 24 hours), then evicted. The Free tier carries no Inference Content.
- Opt-in captured request/response bodies: off by default; where enabled, retained only for the 24-hour body TTL, then evicted.
- Support data: retained as needed to handle and document your request, generally no longer than 24 months after resolution.
8.2 What is deletable
On account closure or a verified deletion request, the following are deletable: account PII (Authorized User / admin email, account identifiers); the stored Provider Key (ciphertext); any stored Inference Content / cached response content; and most Usage Data tied to your account. We use commercially reasonable efforts to delete these within the windows in §8.4 and data-retention-and-deletion-policy.md.
8.3 What is immutable — the honest carve-out (stated verbatim across the pack)
Recovea maintains a content-free, hash-chained, append-only Ledger (and append-only key-lifecycle audit records) as an integrity discipline — it is how metering and the cost record are kept tamper-evident and offline re-derivable. Because tamper-evidence requires immutability, these records are not edited or deleted on request. Honestly stated:
- The Ledger rows contain no prompt or completion content and no account PII in the chained rows.
- Where a row references a customer identifier, on erasure that identifier is severed to null (
customer_id → null) and a content-free tombstone is written; the row persists in de-identified form. Erasure is performed through a sanctioned operator path (recoveactl erase-customer), and the immutable integrity record is retained as permitted by law. - We therefore do not promise blanket erasure of all data. We promise erasure of the deletable categories (§8.2) and de-identification of the content-free immutable Ledger, which we retain for integrity, financial-record, and legal-compliance purposes.
recoveactl erase-customeris operator-run and partly manual at v1; audit-verifiable, time-bound automated erasure is planned.
This carve-out reads identically across this Policy, data-processing-agreement.md, data-retention-and-deletion-policy.md, security-statement.md, and the AUP. The DPA governs the controlling erasure terms for processor-side data.
8.4 Deletion windows and backups (honest, partly manual at v1)
- Export availability: 30 days after termination.
- Deletion of the deletable categories (§8.2): within 90 days of termination or of a verified deletion request — except the immutable Ledger/audit chain (§8.3), our own content-free financial/business records, and data the law requires us to retain.
- Backups: deletable personal data in operational backups is removed on the ordinary backup-rotation cycle (nightly
pg_dump), not by targeted purge from each backup; the cycle does not exceed 35 days (matchingdata-retention-and-deletion-policy.md§6.6/§7.1). Honest DR disclosure: restore from backup has not been tested at production scale, and we make no RTO/RPO commitment (seesecurity-statement.md). - Erasure tooling is early/partly manual at v1; automated time-bound purge machinery is planned. We commit only to the windows above. Written confirmation of actions taken is available on request.
These 30-day / 35-day / 90-day windows are harmonized to a single number set across this Policy, data-retention-and-deletion-policy.md, data-processing-agreement.md, terms-of-service.md, and refund-cancellation-policy.md, and are subject to applicable legal holds.
9. Security (stated honestly)
We protect personal data with technical and organizational measures, stated honestly at current state. security-statement.md is the controlling, conservative description and governs on any conflict about the live posture; no surface may exceed it.
Live measures include:
- Encryption in transit (TLS) and at rest (AES-256-GCM under AWS KMS envelope encryption, with a per-tenant KMS encryption context, and the tenant (customer) UUID as AAD for Provider Keys). Customer-managed keys (BYO-CMK) are PLANNED, not live — no surface implies BYO-CMK is operational.
- Provider Keys decrypted in memory only to sign your upstream calls; never returned to the client; shown once at entry; inbound
rcv_/rcva_key stripped before the upstream call. - Verified per-tenant isolation; egress allowlist (Provider + AWS domains); a closed SSRF class; opaque server-side, fail-closed session auth (Cognito verified once at the edge, then our own session minted; raw Cognito tokens never reach the browser); scoped, least-privilege access; role-based access control enforced server-side across five workspace roles (Owner, Admin, Member, Billing, Viewer) by one capability matrix applied to every console route, with the acting role re-resolved from the authoritative membership on every request; an append-only key-lifecycle audit; nightly
pg_dump; and Ledger export with offline re-derivation.
Planned (never stated as live): BYO-CMK kill switch (Recovea-managed AWS KMS envelope encryption is live — see the encryption disclosure above); SSO/SAML/SCIM and automated user provisioning (role-based access control itself is live — see the live measures above); HA / multi-AZ; tested DR (no RTO/RPO commitment; restore untested); SOC 2 / ISO 27001 / PCI (roadmap / "aligned to" only — never held); region pinning beyond the single region; an independently third-party-verifiable artifact (export ships now; independent verification is a later milestone); automated, probe-driven status monitoring (a human-maintained status page is live at status.recovea.ai; it does not probe the Service and carries no availability commitment).
No method of storage or transmission is 100% secure. If a breach affects your personal data, we will notify you without undue delay as required by applicable law, consistent with the DPA breach clause.
Full detail, including the planned-vs-live posture, is in security-statement.md.
10. Where your data is processed; international transfers
10.1 Location. Production data is hosted in AWS us-east-1 (N. Virginia), United States. Recovea, Inc. is a US (Delaware) corporation. Region pinning beyond the current single us-east-1 deployment is planned, not live; we do not represent data residency that is not real.
10.2 US customers — no cross-border transfer. For customers and visitors established in the United States, processing occurs domestically and there is no cross-border transfer of personal data. Recovea operates US-only and is built for US business customers.
10.3 International-transfer mechanics live in the DPA and are dormant at launch. Where a Customer (or its end users) is established in the EEA, UK, or Switzerland and personal data is transferred to the United States, the applicable transfer mechanism — the EU Standard Contractual Clauses (Module 2, controller-to-processor), the UK International Data Transfer Addendum / IDTA, and Swiss amendments — lives only in the DPA / a standalone transfer addendum, attached as executable exhibits (Customer = data exporter, Recovea = data importer). This Policy is a pointer to the DPA on transfers and makes no independent transfer representation. These mechanics are dormant at launch but kept executable so the first non-US signer is covered. Nothing in this Section implies hosting outside the United States.
11. Your privacy rights
How to exercise any right below: see data-rights-request-procedure.md, or email privacy@recovea.ai. We verify requests using information associated with your account (e.g., your email address) and respond within the period required by applicable law. We will not discriminate against you for exercising a right.
11.1 California (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know / access the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it;
- Delete personal information we collected from you, subject to legal exceptions (including the immutable-Ledger carve-out in §8.3 and required record-keeping);
- Correct inaccurate personal information;
- Opt out of "sale" or "sharing" of personal information — note: Recovea does not "sell" or "share" personal information as defined under the CCPA/CPRA, including through our analytics (measurement-only; §12). We honor the Global Privacy Control (GPC) as a valid opt-out signal;
- Limit use of sensitive personal information — we do not collect or use sensitive personal information for purposes that trigger this right. We treat account-authentication credentials (handled via AWS Cognito) solely to authenticate you, and we do not collect passwords or financial-account access codes for inference or profiling (§3.6);
- Opt out of profiling / automated decision-making — see §11.2;
- Non-discrimination — we will not discriminate against you for exercising any right.
Categories collected, sources, purposes, disclosures, and retention (CCPA notice at collection). In the preceding 12 months Recovea has collected the following categories of personal information. We do not sell or share any category, and we have not disclosed any category for monetary or other valuable consideration.
| CCPA category | Examples | Source | Purpose | Disclosed to | Retention |
|---|---|---|---|---|---|
| Identifiers | Name, work email, account IDs, IP address, first-party session-cookie ID (strictly necessary) | You; your browser | Provide/secure the Services; communicate; analytics | AWS, Stripe, PostHog (cookieless analytics — anonymous on the marketing website; keyed to a pseudonymous account identifier in the authenticated dashboard; IP processed to derive approximate region) (Sub-processors) | Account-linked identifiers: while account is active + 90 days after closure. Analytics events (nothing stored on your device on either surface): up to 14 months. |
| Sensitive personal information — account log-in credentials (Cal. Civ. Code §1798.140(ae)(1)(D)) | Cognito-managed login identifiers; session state | You, at signup | Authenticate you and maintain your session (sole purpose — see §3.6; no use triggering a right to limit) | AWS (Cognito) | While account is active + 90 days after closure |
| Commercial information | Subscription/billing records, plan, invoices | You; Stripe | Billing, account management | AWS, Stripe | While active; statutory billing records ≈ 7 years |
| Internet/network activity | Site analytics, clickstream, session logs, Usage Data (cost metadata) | Your browser; gateway | Operate, secure, improve the Services | AWS; PostHog (cookieless — aggregate and anonymous on the marketing website; product events keyed to a pseudonymous account identifier in the authenticated dashboard; never Inference Content, Usage Data records, or spend values) | Site and product analytics events: up to 14 months. Usage Data (Ledger metadata): Free 30 days / Developer 90 days / Team 365 days / Growth 365 days / Scale 1,095 days (Enterprise: per Order Form) |
| Geolocation (approximate) | Country/region derived from IP | Your browser | Security, analytics, approximate region | AWS | Derived per request; retained with the related analytics/Usage Data record (above) |
| Professional/employment info | Company, role/title, business contact details | You | Account management; communications | AWS, Stripe | While account is active + 90 days after closure |
Recovea acts as a "service provider" under the CCPA/CPRA with respect to personal information it processes on a Customer's behalf (Inference Content / Usage Data), and processes such information only for the business purposes specified in the contract. We do not retain, use, or disclose that information for any purpose other than performing the Services or as otherwise permitted by the CCPA. The CCPA/CPRA service-provider terms are included in the DPA by default.
11.2 Profiling, automated decision-making, and other US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others)
Residents of states with comprehensive privacy laws — including Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA), and others as they take effect — have comparable rights: access, correction, deletion, portability, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. As stated above, Recovea does not sell personal data, does not engage in targeted advertising, and does not profile individuals in furtherance of decisions producing legal or similarly significant effects.
Right to opt out of profiling / automated decision-making. Consistent with the CPRA's automated-decision-making-technology (ADMT) regulations and the profiling opt-outs in Colorado, Connecticut, and other states, you have the right to opt out of any profiling in furtherance of decisions that produce legal or similarly significant effects, and of solely automated decision-making about you. Recovea does not conduct such profiling or automated decision-making; routing inference traffic is not individual automated decision-making about a person. If this changes, we will update this Policy and provide an opt-out before any such processing begins. To assert this right at any time, email privacy@recovea.ai with "Profiling opt-out" in the subject line.
Appeals. If we decline to act on your request, you may appeal that decision by replying to our response or emailing privacy@recovea.ai with "Appeal" in the subject line. We will respond to your appeal within the time required by your state's law (e.g., 45–60 days). If your appeal is denied, you may contact your state Attorney General.
Authorized agents. You may use an authorized agent to submit a request on your behalf; we may require proof of the agent's authorization and may verify your identity directly.
11.3 GDPR / UK GDPR (dormant pointer)
Recovea operates US-only. Where the GDPR / UK GDPR applies to a visitor or prospect, the corresponding rights (access; rectification; erasure subject to the §8.3 carve-out; restriction; portability; objection to legitimate-interests processing and to direct marketing; and withdrawal of consent) and the lawful bases in §4 apply, and you may lodge a complaint with your supervisory authority. The processor-side GDPR/UK terms and the international-transfer mechanics live in the DPA and are dormant at launch (§10.3). We do not name a DPO or an EU/UK Article 27 representative that does not exist; privacy questions go to privacy@recovea.ai (Privacy Contact).
12. Cookies, analytics, GPC and Do-Not-Track
12.1 Posture. Recovea takes a minimal, US-first cookie posture. We use strictly necessary first-party cookies (to maintain your authenticated, opaque server-side session and CSRF/security state — the Services do not function without these) and measurement-only analytics — "measurement-only" meaning no advertising, no ad personalization and no cross-site tracking, on the marketing website and in the authenticated dashboard alike. It does not mean the dashboard's analytics is anonymous: because you are signed in there, product events are keyed to your pseudonymous account identifier (§7.1, and cookie-policy.md §6.3). We do not use advertising or cross-site tracking cookies, and we do not "sell" or "share" personal information (as defined under the CCPA/CPRA) through cookies.
12.2 Analytics, GPC, and Do-Not-Track. Where we use analytics, it runs in measurement-only mode (advertising features and ad personalization off); our analytics provider acts as our service provider/processor and may not use the data for its own purposes. We honor the Global Privacy Control (GPC) as a valid opt-out signal. We also honor recognized browser Do-Not-Track signals to the extent feasible; because there is no industry consensus on DNT, our practice is to run no cross-site tracking regardless. cookie-policy.md is the controlling, itemized cookie inventory and consent-model document; this section summarizes it.
13. Children
The Services are for businesses, are intended for users 18 and older, and are not directed to children. We do not knowingly collect personal data from anyone under 16, and under 13 for COPPA purposes. If you believe a child has provided us personal data, contact privacy@recovea.ai and we will delete it. This threshold is stated consistently across the Recovea legal pack.
14. Law-enforcement and legal-process requests
If a law-enforcement or government agency requests personal information about a Customer, our practice is to redirect the agency to request that data directly from the Customer, and we may provide the Customer's basic contact information for that purpose. If we are legally compelled to disclose, we will give the affected individual or Customer reasonable advance notice and an opportunity to seek a protective order or other remedy, unless we are legally prohibited from doing so or the request involves an emergency risk to life or safety. We disclose personal information to public authorities only where required by law (including national-security or law-enforcement requirements).
15. Electronic communications and marketing choices
15.1 Consent to electronic communications. By creating an account or contacting us, you consent to receive communications from us electronically (email and in-product notices), and you agree that electronic communications satisfy any legal requirement that a communication be in writing, to the extent permitted by law.
15.2 Service vs. marketing messages. Service, security, billing, and legal notices are part of the Services and are sent while you hold an account; you cannot opt out of them. Marketing and product-update emails are optional — every such email has an unsubscribe link, and you may also email privacy@recovea.ai to opt out. Opting out of marketing does not stop service messages.
16. Third-party links and services
The website and Services may link to third-party sites and services (including your chosen Providers, Stripe's checkout, and documentation links). Those third parties operate under their own privacy policies and practices, which we do not control or endorse. When you follow a link off our site or direct traffic to a Provider, this Policy no longer governs that processing. Your relationship with, and the data handling of, your Providers is governed by your agreements with them (§7.5 and byo-key-and-provider-terms.md).
17. Changes to this Policy
We will post material changes here with an updated version and "Last updated" date, and we will notify customers of significant changes per terms-of-service.md (e.g., by email or a conspicuous in-product notice). Your continued use of the Services after the effective date of a change constitutes acceptance, where permitted by law.
18. How to contact us
- Controller: Recovea, Inc., a Delaware corporation. Notice address: 2810 N Church St STE 89986, Wilmington, DE 19802.
- Privacy requests and questions: privacy@recovea.ai (the "Privacy Contact"). Recovea is US-only and EU obligations are dormant; we do not name a DPO or Article 27 representative that does not exist.
- Security: security@recovea.ai. Legal notices: legal@recovea.ai. Support: support@recovea.ai. Copyright/DMCA: dmca@recovea.ai.
You may also contact your state Attorney General or, in California, the California Privacy Protection Agency (CPPA).
19. Regulatory and capability outlook (informational)
This note flags privacy/AI-law developments on the horizon that this Policy is positioned to absorb. It is informational, not a commitment.
- AI-law characterization. Recovea is an infrastructure/observability conduit and cost tool — not a provider/developer/deployer of a high-risk AI system, nor a GPAI provider, under the EU AI Act, the Colorado AI Act, or US state AI laws. Routing is not individual automated decision-making, and Recovea has no affirmative content-monitoring or moderation duty; deployer duties sit with the Customer. Reassess as these regimes phase in.
- Expanding US state comprehensive privacy laws. New states continue to take effect (§11.2). Keep the rights matrix, opt-out signals (GPC), profiling opt-out, and appeal mechanics current, and add state addenda as needed.
- Measurement and verification capabilities. The Services may include optimization, additional features and capabilities Recovea may offer. Any future verified-measurement capability, if and when Recovea offers it, is governed by the terms in effect when Recovea makes it available, would be measured against a defined counterfactual on the Customer's own traffic net of quality, and is not active or licensed under this Policy unless Recovea expressly states otherwise. The honesty bar is a legal-risk control: we do not state a present-tense or guaranteed savings amount or percentage. Keep this Policy aligned with
ai-output-and-no-guarantee-disclaimer.mdand the savings-claims-substantiation control. - Cookie/ePrivacy and the consent-banner decision. If/when EEA/UK visitors come into scope, the §12 /
cookie-policy.mdconsent posture must be revisited (ePrivacy / PECR prior-consent for non-essential cookies).
This Policy is the controller-side notice and is subordinate, where stated, to data-processing-agreement.md (processor-side processing and the dormant transfer mechanism), subprocessors.md (vendor inventory), and security-statement.md (live security posture).