---
title: "Privacy Policy | Recovea"
description: "What we collect, what we never collect, and how long we keep it."
canonical: "https://recovea.ai/policies/privacy-policy/"
source: "https://recovea.ai/policies/privacy-policy/"
---

[Policies](https://recovea.ai/policies/)

# Recovea Privacy Policy

**Last updated: 2026-09-25**

---

> **How to read this document.** This is the external-facing **Privacy Policy** for **Recovea, Inc.**, a **Delaware** corporation — the notice Recovea publishes about personal data **for which Recovea is the controller** (website visitors, prospects, account users, billing contacts, support correspondents). It is written to match the **actual deployment** (United States; Amazon Web Services `us-east-1`, N. Virginia) and the **actual data model** of the Services, and it holds the same honesty bar as the rest of the Recovea legal pack: it states the **real** data practices, the **real** (honest) security posture, and the **honest** deletion model — including the immutable, content-free Ledger carve-out that a less careful company would paper over.
>
> **This Policy governs Recovea-as-controller data only.** Personal data inside the Customer's inference traffic that Recovea processes **on the Customer's behalf** ("**Customer Personal Data**," handled as Inference Content) is governed by the **Data Processing Agreement** (the "**DPA**") — see `data-processing-agreement.md` — under which the **Customer is the controller and Recovea is the processor**. Where Recovea Processes Customer Personal Data on the Customer's behalf, the DPA is automatically incorporated into and forms part of the agreement between the parties. Where this Policy and the DPA appear to conflict on processor-side processing, **the DPA controls.** Where this Policy and `security-statement.md` appear to disagree about the **live** security posture, the **Security Statement controls** (it is the conservative anchor).

---

## Contents

1. Who we are, and the scope of this Policy
2. Two roles — controller vs. processor (read this first)
3. What we collect (controller-side), and the precise data model
4. How we use your data, and our lawful bases
5. What we never do
6. Aggregated / De-identified Data
7. Sharing and Sub-processors
8. Retention, and the honest immutable-Ledger deletion carve-out
9. Security (stated honestly)
10. Where your data is processed; international transfers
11. Your privacy rights (US state laws; GDPR/UK pointer)
12. Cookies, analytics, GPC and Do-Not-Track
13. Children
14. Law-enforcement and legal-process requests
15. Electronic communications and marketing choices
16. Third-party links and services
17. Changes to this Policy
18. How to contact us
19. Regulatory and capability outlook (informational)

---

## \1. Who we are, and the scope of this Policy

**1.1 Controller.** **Recovea, Inc.**, a **Delaware** corporation ("**Recovea**," "**we**," "**us**," "**our**"), with a notice address at **2810 N Church St STE 89986, Wilmington, DE 19802**, operates the website at **recovea.ai**, the Recovea gateway, the dashboard, the `recoveactl` command-line tooling, and the managed service (together, and including any related features Recovea makes available, the "**Services**"). Recovea is a **United States company**; it hosts the Services in the **United States** on Amazon Web Services in the **`us-east-1` (N. Virginia)** region; and it sells to **US business customers** only. Recovea is a bootstrap-funded US company; nothing in this Policy concerns investment or securities.

**1.2 What this Policy covers.** This Policy explains, for the personal data **for which Recovea is the controller**:

- what personal data we collect, and where it comes from (§3);
- how and why we use it, and the lawful bases we rely on (§4);
- what we **never** do — never sell or "share" personal data; never train any AI model on Customer Data, Inference Content, Service outputs, or the Ledger (§5);
- how we use **Aggregated/De-identified Data** (§6);
- who we share it with — our Sub-processors (§7 and `subprocessors.md`), and the BYO-Key distinction for Providers;
- how long we keep it, and the honest immutable-Ledger deletion carve-out (§8 and `data-retention-and-deletion-policy.md`);
- how we secure it, stated honestly (§9 and `security-statement.md`);
- where it is processed and how international transfers are handled (§10);
- your rights under **US state privacy laws** (CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, TDPSA and others), with a pointer to **GDPR/UK GDPR** terms in the DPA (§11 and `data-rights-request-procedure.md`);
- cookies and similar technologies (§12 and `cookie-policy.md`);
- children (§13); legal process (§14); communications choices (§15); third-party links (§16); changes (§17); contact (§18).

**1.3 Plain-language scope note.** Recovea is an **AI-spend gateway** — a neutral, in-path proxy for large-language-model (LLM) API traffic. The Customer changes one `base_url` to route its inference calls through Recovea (`api.recovea.ai`) using the Customer's **own** Provider API keys ("**BYO-Key — Bring Your Own Key**"). Recovea does **not** resell, rebill, sponsor, fund, or mark up Provider tokens; the Customer contracts with, and pays, its Providers directly. Billing for the Services is **subscription-based** today. The Services may include optimization, additional features and capabilities Recovea may offer; any such capability is governed by the terms in effect when Recovea makes it available and is not active or licensed under this Policy unless Recovea expressly states otherwise. Recovea may offer subscription, usage-based, and savings-/outcome-based pricing models; any savings-based model applies only on the Customer's separate, affirmative election. See `terms-of-service.md` and `ai-output-and-no-guarantee-disclaimer.md`.

---

## \2. Two roles — controller vs. processor (read this first)

Recovea handles personal data in **two distinct roles**, and **this Policy only governs the first.**

**2.1 Recovea as controller — governed by this Policy.** Data about **website visitors, prospects, Authorized Users, and billing/support contacts** — names, work emails, company and role, account and authentication data, billing-contact details, support correspondence, and site analytics. Recovea decides why and how this data is processed. **This Policy applies to it.**

**2.2 Recovea as processor — governed by the DPA, not this Policy.** **Customer Personal Data** contained **inside the Customer's inference traffic routed through the gateway** — the request/response content proxied in-path (defined as "**Inference Content**"), plus the per-request **Usage Data** (cost metadata) generated to meter that traffic. For this data the **Customer is the controller** and **Recovea is the processor** acting on the Customer's documented instructions. This processing is governed by `data-processing-agreement.md`, **not** this Policy; the DPA is automatically incorporated into the agreement between the parties. **For an Assessment the same split applies to Tap Events** — the envelope metadata the passive tap in the Customer's own application reports about calls that application makes directly to a Provider (never Inference Content, which does not reach Recovea for an Assessment because nothing routes through Recovea for one) — and to the tag the Customer declares: the Customer is the controller and Recovea the processor, under the DPA. *(Added 2026-09-18.)*

**2.3 If your personal data reached us inside a Customer's traffic** (for example, you are an end user of a Recovea Customer's application), the **Customer** is the controller. Please direct access, deletion, and similar requests to **that Customer first**; we will assist the Customer in responding, as required by the DPA and applicable law.

---

## \3. What we collect (controller-side), and the precise data model

### 3.1 Categories of personal data we collect as controller

| Category | Examples | Source |
| --- | --- | --- |
| **Information you provide** | When you book a call, create an account, start a Baseline (the install answer, the tag you name, and any invoice total you declare), or contact us: name, work email, company, role, and any notes you choose to share. | You |
| **Account & authentication data** | Account identifiers; Authorized User seat/role assignments; authentication identifiers via **AWS Cognito**. Recovea uses an **opaque server-side session** at the browser edge — raw Cognito tokens are not exposed to the browser. | You, at signup |
| **Billing data** | Plan, Subscription status, invoices, billing-contact details, invoicing history. **Card details go directly to our payment processor, Stripe; Recovea never stores full card numbers.** | You / Stripe |
| **Your BYO Provider Key** | Your OpenAI / Anthropic / OpenRouter (etc.) API key, supplied to enable routing. Handled per §3.4 and `byo-key-and-provider-terms.md`. | You |
| **Usage Data (cost metadata)** | Per-request metering needed to run the gateway and the Ledger: model, token counts, finish_reason, computed cost, latency, timestamps, Levers applied, and any savings deltas — recorded on the **content-free, hash-chained, append-only Ledger**. | Generated by the gateway |
| **Inference Content (request/response content)** | The actual content of prompts and completions proxied in-path on the paid tier. **Processor-side data (Customer Personal Data) governed by the DPA, not this Policy.** See §3.3. | Customer traffic (paid, in-path) |
| **Tap Events (the Baseline and the Assessment)** | For the **free Baseline**, the **free Assessment** and a paid plan's continued reporting alike *(extended 2026-09-21; restated 2026-09-23: nothing on this path is purchased and no card is taken)*, the envelope of each call your own application makes directly to your Provider, reported by the passive tap you add beside your client: provider and model, the request identifier, token counts, stop reason, tool-call count, HTTP status, retry count, latency, rate-limit headers, timestamp, and the **tag** you chose. **Never a prompt, a completion, or any content**, by the published schema at recovea.ai/docs/passive-tap; the server refuses anything outside it. The tag is the only free-text field and is yours; do not put personal data in it. **Processor-side data governed by the DPA**, whether or not anything was paid — a free feature is not a lesser standard of care. *(Added 2026-09-18; extended to the free Baseline 2026-09-21.)* | Your own software, out of path |
| **Tap key** | The `rcv_tap_` credential issued when you create a Baseline, which goes on serving your Assessment and any plan you start *(extended 2026-09-21; restated 2026-09-23)*. Stored as a keyed hash with its first twelve characters readable. The response that creates your Baseline is the one showing and no clear copy is kept, of any key *(restated 2026-09-23, rulings 65 and 81: the path on which a key was held in clear until first read is retired)*. See `security-statement.md`. *(Added 2026-09-18.)* | Generated by Recovea |
| **Site and product analytics** | On the **marketing website**: page views, referrers, approximate region (derived from IP), device/browser type, collected as **anonymous, aggregate interaction metrics**. In the **authenticated dashboard**: which product features and onboarding steps you reached, keyed to your **pseudonymous account identifier** with your workspace identifier and plan tier. Both run on **cookieless** analytics — **nothing is stored on your device on either surface** — with session recording **off**, and neither carries your prompts, completions, spend figures, or key material. | Your browser — see §12 and `cookie-policy.md` |
| **Support data** | What you send us at support@, privacy@, security@, or legal@recovea.ai, including any attachments. | You |

We collect this data from the **sources** named in the table above: directly from you; automatically from your browser/device; and from our payment processor (Stripe) for billing status. We do not enrich, buy, or build marketing profiles from third-party data brokers.

### 3.2 Free tier — observe-only, **in-path** (metered; metadata only)

On the **Free** tier, the Services are **observe-only and in-path**: the Customer's inference traffic **routes through the gateway** so the Services can meter it, but Recovea **applies no optimization Levers and no spend-control enforcement**, and persists **cost metadata only** (model, token counts, computed cost, usage patterns, timestamps). Because the Free tier is in-path, request and response payloads **transit Recovea in memory** to be served and metered (see "transit vs. storage" below); however, on Free Recovea **does not cache or otherwise persist prompt or completion bodies by default** — only Usage Data metadata is retained, and the inbound Recovea key (`rcv_` / `rcva_`) is stripped before the upstream call. Pricing for each tier is stated in the Order Form / `terms-of-service.md`.

### 3.3 Paid in-path plans — transit vs. storage stated honestly

On the **paid, in-path plans** — the in-path gateway plus control surface, the cache/dedup Levers where enabled on the plan, and the Ledger — the Services are **in-path**: the Customer's traffic routes through Recovea so the Services can meter it and, where enabled, apply cache/dedup Levers. Because the Services are in-path, they **process Inference Content** — which may contain the Customer's confidential data and the personal data of the Customer's own end users. We are precise and honest about **transit vs. storage**:

- **Transit (always, on in-path requests).** Recovea **receives the request payload in memory**, applies its Levers, signs the upstream call to the Customer's chosen Provider with the Customer's Provider Key, and returns the Provider's response payload to the Customer. This in-memory transit is inherent to being an inline gateway — it is the request being served. The inbound Recovea key (`rcv_` / `rcva_`) is **stripped before the upstream call**.
- **Metering metadata (always persisted).** For every in-path request, Recovea persists **content-free cost metadata** (model, token counts, finish_reason, timestamps, computed cost, Levers applied) on the **Ledger** — an append-only, hash-chained record. The Ledger contains **no prompt or completion content**.
- **What is persisted by default.** On the **default in-path path, Recovea persists only content-free metadata; it does not persist full prompt or response bodies by default.** The only response content stored on a routine basis is the paid-tier cache/dedup store described in the next bullet. Capture of full request/response bodies is **off by default** and occurs only where the Customer affirmatively enables it; any such opt-in captured-body retention is limited to a **24-hour TTL**, after which it is evicted.
- **paid-tier cache/dedup (response content keyed by request hash).** On the paid tier, to serve byte-identical repeats, the cache/dedup Levers **store response content keyed by a request hash for the cache time-to-live (TTL) — by default up to 24 hours** — then evict it. This is the one routine path on which response content is stored; it exists solely to serve identical repeat requests at lower cost, is tenant-isolated, is **never** used to train any model, and is processor-side data governed by the DPA. Cached responses are **byte-identical** to the Provider's original response — Recovea never synthesizes or alters response content.

Inference Content and the cache are **processor-side** Customer Personal Data and governed by the DPA. This Policy describes them here only so controllers and individuals understand the full data model.

### 3.4 BYO Provider Keys — handling (honest current state)

The Services are **bring-your-own-key**. The Customer supplies its **own** Provider account and API key (OpenAI, Anthropic, OpenRouter, etc.); Recovea passes requests through using the Customer's key, does **not** resell or mark up Provider tokens, and the Customer **pays its Providers directly**.

- Provider Keys are **encrypted at rest with AES-256-GCM**, using the tenant (customer) UUID as additional authenticated data (AAD); they are decrypted **in memory only** to sign the Customer's own upstream calls, are **never returned to the client**, and are shown in plaintext **only once at entry**.
- Strict **per-tenant isolation** applies, and an **egress allowlist** limits the gateway to Provider and AWS domains.
- **Honest current-state disclosure.** Stored Provider Keys are protected with **AWS KMS envelope encryption (live)** under per-tenant KMS encryption contexts; **customer-managed keys (BYO-CMK) are planned, not live.** `security-statement.md` controls on the live posture.

See `byo-key-and-provider-terms.md` for full Provider-Key handling and the Customer's Provider-terms responsibilities.

### 3.5 Fail-open and the re-point escape hatch

The Services are **designed to fail open**: any fault in a Recovea-added layer is designed to fall back to plain upstream passthrough, and a full outage is reversible by the Customer **re-pointing `base_url` back to its Provider** — a one-line, reversible change. Fail-open is a **design objective and a reversible exit, not an availability or correctness warranty**; there is **no uptime guarantee** and no service-credit SLA at launch. Where a fault occurs after tokens begin streaming, it surfaces as a clean error rather than a silent splice; we do not claim mid-stream failover. See `availability-and-sla-statement.md`.

### 3.6 What we do **not** collect (controller-side)

We do **not** knowingly collect or use **sensitive personal information** (as that term is defined under the CCPA/CPRA and other US state laws) for any purpose that would trigger a right to limit it. We treat **account-authentication credentials** (handled via **AWS Cognito**) **solely to authenticate you**; we do not use them for inference, profiling, or any purpose triggering the right to limit, and we do not collect passwords or financial-account access codes for inference or profiling. We do not collect children's data (§13). We do not run advertising trackers, and we do not build advertising profiles.

---

## \4. How we use your data, and our lawful bases

We use controller-side personal data for the purposes below. Where the **GDPR / UK GDPR** applies to a visitor or prospect (see §11.3), the lawful basis is shown in *italics*.

- **To provide, meter, and bill the Services** — route/meter usage on paid tiers; operate the Ledger; manage your Subscription via Stripe; and operate the Services' measurement methodologies. *Performance of a contract.*
- **To communicate with you** about your request, engagement, account, or Subscription, including service and security notices you cannot opt out of while you hold an account. *Performance of a contract; legitimate interests.*
- **To operate, secure, debug, and improve the Services, and to prevent abuse** — security, fraud prevention, abuse handling, service integrity. *Legitimate interests.*
- **For product analytics and improvement**, using **Aggregated/De-identified Data** where feasible (see §6). *Legitimate interests.*
- **To send product updates and marketing you signed up for.** Every such email has an unsubscribe link. *Consent (where required).*
- **To comply with law** — tax, accounting, valid legal process, and record-keeping. *Legal obligation.*

We maintain a documented legitimate-interests balancing assessment for the processing we characterize as legitimate-interests-based, and we rely on consent where applicable law requires it.

---

## \5. What we never do

- **We never train any AI model on your data** — not on Customer Data, not on Inference Content (prompts or completions), not on Usage Data, and not on Service outputs or the Ledger. This is a contractual commitment, repeated in `data-processing-agreement.md` and `terms-of-service.md`.
- **We never sell personal data**, and we do **not** "sell" or "share" personal information as those terms are defined under the **CCPA/CPRA** and equivalent US state laws — including through our analytics, which run measurement-only (§12).
- **We do not run advertising trackers** or build advertising profiles.
- **We do not resell, rebill, sponsor, fund, or mark up** your Provider tokens (BYO-Key; you pay Providers directly).
- **Inference Content is processed only to serve that Customer's own traffic** — to proxy it, meter it, and (on the paid tier) serve byte-identical cache repeats — and is never repurposed.

---

## \6. Aggregated / De-identified Data

**6.1** Recovea may create and use **Aggregated/De-identified Data** — de-identified, aggregated usage metrics derived from operating the Services (for example, statistical patterns of model usage, token volumes, cache-hit rates, latency, and Lever effectiveness across the platform) — to **operate, secure, benchmark, and improve** the Services and their measurement methodologies.

**6.2 The hard rules on this data:**

- It is **content-free** — derived from Usage Data (cost metadata), **never** from Inference Content (prompt/completion content).
- It is **aggregated and/or de-identified** to a standard intended to meet **CCPA §1798.140(m)** de-identification and **GDPR** anonymization thresholds, so that it does not identify, and cannot reasonably be linked to, any individual or any single Customer.
- Recovea makes a **no-reidentification commitment**: we maintain Aggregated/De-identified Data in de-identified form, do not attempt to re-identify it, and contractually obligate recipients (if any) not to re-identify it.
- **It is never sold on a per-Customer basis.** Recovea does not sell, license, or disclose **identifiable per-Customer** data or analytics to third parties.
- Recovea does **not** use **Customer Data or Inference Content** to train any AI model (§5). Aggregated/De-identified Data is not Customer Data and not Inference Content.

The IP allocation aligns with `terms-of-service.md` (Customer owns Customer Data and Inference Content; Recovea owns the Services, the Ledger format, and Aggregated/De-identified Data, never sold per-Customer). Recovea takes no position on ownership of Provider Output.

---

## \7. Sharing and Sub-processors

We share personal data only:

**7.1 With the Sub-processors listed in `subprocessors.md`**, under contract and only as needed to run the Services. As of the date above, these are: **Amazon Web Services, Inc.** — hosting / compute / storage / authentication (Amazon Cognito) and **Amazon SES**, the active transactional and account email sender, which receives your account email address and the message content; `us-east-1`, USA; **Stripe, LLC** (successor by conversion to Stripe, Inc., effective 2026-01-03) — payments / Subscription billing, USA; and **PostHog, Inc.** — cookieless product analytics (US data region) on **two** surfaces: on the **marketing website** it is anonymous and aggregate and does not identify the visitor, and inside the **authenticated dashboard** it is **product analytics keyed to a pseudonymous account identifier**, with the workspace identifier, plan tier, product-event names, and the dashboard page an event occurred on. PostHog receives **no** spend or cost values, **no** Inference Content, **no** Usage Data records, **no** Provider Keys and **no** Ledger data; session recording is off and nothing is stored on your device on either surface. **Functional Software, Inc. d/b/a Sentry** — browser error reporting for the website and the dashboard, **Engaged since 2026-08-05** (US data region), which receives error events: the exception and its stack trace, the release and environment identifiers, browser and operating system, and the named route the error occurred on. **No session replay, no performance tracing, and no IP-address storage** — the last is disabled org-wide at the vendor — and error text is redacted for keys, tokens and email addresses **before it leaves your browser**. Sentry runs on the **browser surfaces only, never in the gateway** that carries Inference Content. It was pre-listed as Planned before any reporting endpoint existed and the change-notice below ran before it began Processing (`subprocessors.md` §2.7 and §12). Health-check and cron monitoring is AWS-native (CloudWatch/SNS) and engages no external monitoring Sub-processor. `subprocessors.md` is the **authoritative, controlling** inventory of identity, purpose, location, and engagement status; this summary is for convenience and may lag it. We give at least **30 days'** prior notice before adding or replacing a Sub-processor, with an emergency carve-out under which we give **as much notice as practicable**. The bounded exclusive remedy if you reasonably object to a new Sub-processor is to **terminate the affected portion of the Services and receive a pro-rata refund** of prepaid Fees for the terminated portion. This notice period, the emergency carve-out, and the bounded remedy read consistently with `subprocessors.md`, `data-processing-agreement.md`, and `refund-cancellation-policy.md`.

**7.2 Where required by law or valid legal process** — see §14.

**7.3 In connection with a merger, acquisition, financing, reorganization, or sale of assets**, in which case this Policy's protections continue to apply to the transferred data and we will notify you of any change in controller.

**7.4 With your consent**, or at your direction.

**7.5 BYO-Key Providers are NOT Recovea's Sub-processors.** The upstream LLM Providers the Customer chooses to route to (OpenAI, Anthropic, OpenRouter) are reached under the **Customer's own** Provider accounts and keys, **at the Customer's direction**. They are the **Customer's processors / customer-directed recipients / independent controllers**, with Recovea acting as a **neutral conduit** — **not** Recovea's Sub-processors — and so are not listed on `subprocessors.md`. Where Providers offer zero-retention or data-handling options, Recovea passes those settings through where available. The Customer is responsible for its Providers' terms and data handling. See `byo-key-and-provider-terms.md`. This conduit / customer-processor characterization reads identically across the DPA, `subprocessors.md`, `byo-key-and-provider-terms.md`, this Policy, `security-statement.md`, and the export documentation.

---

## \8. Retention, and the honest immutable-Ledger deletion carve-out

`data-retention-and-deletion-policy.md` is the controlling retention/deletion document; this section summarizes it and must stay consistent with it.

### 8.1 Retention periods

- **Prospect data** (call bookings, contact inquiries): kept while the conversation is live and deleted on request, and in any event no later than **24 months** after last contact.
- **Tap Events, Baseline data and Assessment data** (the install answer about whether clients or your own customers pay for what your AI does, any invoice total you declared, unit, tag, and the computed pages): kept for the life of your workspace and deleted in full on account closure or a verified deletion request, through the operator-run erasure path described in this Section (for this data a single operator-run action that deletes the Tap Events, clears what you typed, and revokes the tap key; the record of any Subscription transaction is kept, and a Baseline or an Assessment leaves none, because nothing was bought); they are **not** Ledger rows and the §8.3 carve-out does not reach them; no tier window applies. *(Added 2026-09-18.)*
- **Account & billing data:** kept while your account is active and for **90 days** after closure for legal/tax/audit, then deleted or anonymized; statutory billing records are retained for approximately **7 years** as required by tax/accounting law.
- **Usage Data (Ledger metadata):** **Free 30 days / Developer 90 days / Team 365 days / Growth 365 days / Scale 1,095 days (Enterprise: per Order Form)**, after which it is deleted or de-identified, subject to the immutable-Ledger carve-out in §8.3.
- **Stored Inference Content / paid-tier cache (response content keyed by request hash):** **paid tiers only**; retained only for the **cache TTL** (by default up to 24 hours), then evicted. The Free tier carries no Inference Content.
- **Opt-in captured request/response bodies:** **off by default**; where enabled, retained only for the **24-hour body TTL**, then evicted.
- **Support data:** retained as needed to handle and document your request, generally no longer than **24 months** after resolution.

### 8.2 What is deletable

On account closure or a verified deletion request, the following are **deletable**: **account PII** (Authorized User / admin email, account identifiers); the **stored Provider Key** (ciphertext); any **stored Inference Content / cached response content**; and **most Usage Data** tied to your account. We use commercially reasonable efforts to delete these within the windows in §8.4 and `data-retention-and-deletion-policy.md`.

### 8.3 What is immutable — the honest carve-out (stated verbatim across the pack)

Recovea maintains a **content-free, hash-chained, append-only Ledger** (and append-only key-lifecycle audit records) as an integrity discipline — it is how metering and the cost record are kept tamper-evident and offline re-derivable. **Because tamper-evidence requires immutability, these records are not edited or deleted on request.** Honestly stated:

- The Ledger rows contain **no prompt or completion content and no account PII** in the chained rows.
- Where a row references a **customer identifier**, on erasure that identifier is **severed to null** (`customer_id → null`) and a content-free **tombstone** is written; the row persists in **de-identified** form. Erasure is performed through a sanctioned operator path (`recoveactl erase-customer`), and the immutable integrity record is retained as permitted by law.
- We therefore **do not promise blanket erasure of all data**. We promise erasure of the **deletable** categories (§8.2) and **de-identification** of the content-free immutable Ledger, which we retain for integrity, financial-record, and legal-compliance purposes.
- `recoveactl erase-customer` is **operator-run and partly manual at v1**; audit-verifiable, time-bound automated erasure is **planned**.

This carve-out reads **identically** across this Policy, `data-processing-agreement.md`, `data-retention-and-deletion-policy.md`, `security-statement.md`, and the AUP. The DPA governs the controlling erasure terms for processor-side data.

### 8.4 Deletion windows and backups (honest, partly manual at v1)

- **Export availability:** **30 days** after termination.
- **Deletion of the deletable categories (§8.2):** within **90 days** of termination or of a verified deletion request — **except** the immutable Ledger/audit chain (§8.3), our own content-free financial/business records, and data the law requires us to retain.
- **Backups:** deletable personal data in operational backups is removed on the ordinary backup-rotation cycle (nightly `pg_dump`), not by targeted purge from each backup; the cycle does not exceed **35 days** (matching `data-retention-and-deletion-policy.md` §6.6/§7.1). **Honest DR disclosure:** restore from backup has not been tested at production scale, and we make no RTO/RPO commitment (see `security-statement.md`).
- **Erasure tooling is early/partly manual** at v1; automated time-bound purge machinery is **planned**. We commit only to the windows above. Written confirmation of actions taken is available on request.

These **30-day / 35-day / 90-day** windows are harmonized to a single number set across this Policy, `data-retention-and-deletion-policy.md`, `data-processing-agreement.md`, `terms-of-service.md`, and `refund-cancellation-policy.md`, and are subject to applicable legal holds.

---

## \9. Security (stated honestly)

We protect personal data with technical and organizational measures, stated **honestly** at current state. `security-statement.md` is the controlling, conservative description and governs on any conflict about the **live** posture; **no surface may exceed it.**

**Live measures include:**

- **Encryption in transit** (TLS) and **at rest** (**AES-256-GCM** under **AWS KMS envelope encryption**, with a **per-tenant KMS encryption context**, and the tenant (customer) UUID as AAD for Provider Keys). **Customer-managed keys (BYO-CMK) are PLANNED, not live** — no surface implies BYO-CMK is operational.
- **Provider Keys** decrypted **in memory only** to sign your upstream calls; never returned to the client; shown once at entry; inbound `rcv_` / `rcva_` key stripped before the upstream call.
- **Verified per-tenant isolation**; **egress allowlist** (Provider + AWS domains); a **closed SSRF class**; **opaque server-side, fail-closed session** auth (Cognito verified once at the edge, then our own session minted; raw Cognito tokens never reach the browser); **scoped, least-privilege access**; **role-based access control enforced server-side across five workspace roles** (Owner, Admin, Member, Billing, Viewer) by one capability matrix applied to every console route, with the acting role re-resolved from the authoritative membership on every request; an **append-only key-lifecycle audit**; nightly `pg_dump`; and **Ledger export with offline re-derivation**.

**Planned (never stated as live):** BYO-CMK kill switch (Recovea-managed AWS KMS envelope encryption is live — see the encryption disclosure above); SSO/SAML/SCIM and automated user provisioning (role-based access control itself is live — see the live measures above); HA / multi-AZ; tested DR (no RTO/RPO commitment; restore untested); SOC 2 / ISO 27001 / PCI (roadmap / "aligned to" only — **never held**); region pinning beyond the single region; an independently third-party-verifiable artifact (export ships now; independent verification is a later milestone); automated, probe-driven status monitoring (a **human-maintained** status page is live at `status.recovea.ai`; it does not probe the Service and carries no availability commitment).

No method of storage or transmission is **100% secure**. If a breach affects your personal data, we will notify you **without undue delay** as required by applicable law, consistent with the DPA breach clause.

Full detail, including the planned-vs-live posture, is in `security-statement.md`.

---

## \10. Where your data is processed; international transfers

**10.1 Location.** Production data is hosted in **AWS `us-east-1` (N. Virginia), United States**. Recovea, Inc. is a US (Delaware) corporation. Region pinning beyond the current single `us-east-1` deployment is **planned**, not live; we do not represent data residency that is not real.

**10.2 US customers — no cross-border transfer.** For customers and visitors established in the **United States**, processing occurs **domestically** and there is **no cross-border transfer** of personal data. Recovea operates **US-only** and is built for **US business customers**.

**10.3 International-transfer mechanics live in the DPA and are dormant at launch.** Where a Customer (or its end users) is established in the **EEA, UK, or Switzerland** and personal data is transferred to the United States, the applicable transfer mechanism — the **EU Standard Contractual Clauses (Module 2, controller-to-processor)**, the **UK International Data Transfer Addendum / IDTA**, and **Swiss amendments** — lives **only** in the DPA / a standalone transfer addendum, attached as executable exhibits (Customer = data exporter, Recovea = data importer). This Policy is a **pointer** to the DPA on transfers and makes **no independent transfer representation**. These mechanics are **dormant at launch** but kept executable so the first non-US signer is covered. Nothing in this Section implies hosting outside the United States.

---

## \11. Your privacy rights

How to exercise any right below: see `data-rights-request-procedure.md`, or email **privacy@recovea.ai**. We verify requests using information associated with your account (e.g., your email address) and respond within the period required by applicable law. **We will not discriminate against you for exercising a right.**

### 11.1 California (CCPA / CPRA)

If you are a **California resident**, you have the right to:

- **Know / access** the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it;
- **Delete** personal information we collected from you, subject to legal exceptions (including the immutable-Ledger carve-out in §8.3 and required record-keeping);
- **Correct** inaccurate personal information;
- **Opt out of "sale" or "sharing"** of personal information — **note: Recovea does not "sell" or "share" personal information** as defined under the CCPA/CPRA, including through our analytics (measurement-only; §12). We **honor the Global Privacy Control (GPC)** as a valid opt-out signal;
- **Limit use of sensitive personal information** — we do not collect or use sensitive personal information for purposes that trigger this right. We **treat account-authentication credentials (handled via AWS Cognito) solely to authenticate you**, and we do not collect passwords or financial-account access codes for inference or profiling (§3.6);
- **Opt out of profiling / automated decision-making** — see §11.2;
- **Non-discrimination** — we will not discriminate against you for exercising any right.

**Categories collected, sources, purposes, disclosures, and retention (CCPA notice at collection).** In the preceding 12 months Recovea has collected the following categories of personal information. We do **not** sell or share any category, and we have **not** disclosed any category for monetary or other valuable consideration.

| CCPA category | Examples | Source | Purpose | Disclosed to | Retention |
| --- | --- | --- | --- | --- | --- |
| **Identifiers** | Name, work email, account IDs, IP address, first-party session-cookie ID (strictly necessary) | You; your browser | Provide/secure the Services; communicate; analytics | AWS, Stripe, PostHog (cookieless analytics — anonymous on the marketing website; keyed to a pseudonymous account identifier in the authenticated dashboard; IP processed to derive approximate region) (Sub-processors) | Account-linked identifiers: while account is active + 90 days after closure. Analytics events (nothing stored on your device on either surface): up to 14 months. |
| **Sensitive personal information — account log-in credentials (Cal. Civ. Code §1798.140(ae)(1)(D))** | Cognito-managed login identifiers; session state | You, at signup | Authenticate you and maintain your session (sole purpose — see §3.6; no use triggering a right to limit) | AWS (Cognito) | While account is active + 90 days after closure |
| **Commercial information** | Subscription/billing records, plan, invoices | You; Stripe | Billing, account management | AWS, Stripe | While active; statutory billing records ≈ 7 years |
| **Internet/network activity** | Site analytics, clickstream, session logs, Usage Data (cost metadata) | Your browser; gateway | Operate, secure, improve the Services | AWS; PostHog (cookieless — aggregate and anonymous on the marketing website; product events keyed to a pseudonymous account identifier in the authenticated dashboard; never Inference Content, Usage Data records, or spend values) | Site and product analytics events: up to 14 months. Usage Data (Ledger metadata): Free 30 days / Developer 90 days / Team 365 days / Growth 365 days / Scale 1,095 days (Enterprise: per Order Form) |
| **Geolocation (approximate)** | Country/region derived from IP | Your browser | Security, analytics, approximate region | AWS | Derived per request; retained with the related analytics/Usage Data record (above) |
| **Professional/employment info** | Company, role/title, business contact details | You | Account management; communications | AWS, Stripe | While account is active + 90 days after closure |

Recovea acts as a **"service provider"** under the CCPA/CPRA with respect to personal information it processes on a Customer's behalf (Inference Content / Usage Data), and processes such information only for the business purposes specified in the contract. We do **not** retain, use, or disclose that information for any purpose other than performing the Services or as otherwise permitted by the CCPA. The CCPA/CPRA service-provider terms are included in the DPA by default.

### 11.2 Profiling, automated decision-making, and other US state privacy laws (Virginia, Colorado, Connecticut, Utah, Texas, and others)

Residents of states with comprehensive privacy laws — including **Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Texas (TDPSA)**, and others as they take effect — have comparable rights: **access, correction, deletion, portability**, and the right to **opt out of targeted advertising, the sale of personal data, and certain profiling**. As stated above, **Recovea does not sell personal data, does not engage in targeted advertising, and does not profile individuals in furtherance of decisions producing legal or similarly significant effects.**

**Right to opt out of profiling / automated decision-making.** Consistent with the CPRA's automated-decision-making-technology (ADMT) regulations and the profiling opt-outs in Colorado, Connecticut, and other states, you have the right to opt out of any profiling in furtherance of decisions that produce legal or similarly significant effects, and of solely automated decision-making about you. **Recovea does not conduct such profiling or automated decision-making**; routing inference traffic is not individual automated decision-making about a person. If this changes, we will update this Policy and provide an opt-out before any such processing begins. To assert this right at any time, email **privacy@recovea.ai** with "Profiling opt-out" in the subject line.

**Appeals.** If we decline to act on your request, you may **appeal** that decision by replying to our response or emailing **privacy@recovea.ai** with "Appeal" in the subject line. We will respond to your appeal within the time required by your state's law (e.g., 45–60 days). If your appeal is denied, you may contact your state Attorney General.

**Authorized agents.** You may use an authorized agent to submit a request on your behalf; we may require proof of the agent's authorization and may verify your identity directly.

### 11.3 GDPR / UK GDPR (dormant pointer)

Recovea operates **US-only**. Where the **GDPR / UK GDPR** applies to a visitor or prospect, the corresponding rights (access; rectification; erasure subject to the §8.3 carve-out; restriction; portability; objection to legitimate-interests processing and to direct marketing; and withdrawal of consent) and the lawful bases in §4 apply, and you may lodge a complaint with your supervisory authority. The **processor-side** GDPR/UK terms and the **international-transfer mechanics** live in the **DPA** and are **dormant at launch** (§10.3). We do **not** name a DPO or an EU/UK Article 27 representative that does not exist; privacy questions go to **privacy@recovea.ai** (Privacy Contact).

---

## \12. Cookies, analytics, GPC and Do-Not-Track

**12.1 Posture.** Recovea takes a **minimal, US-first** cookie posture. We use **strictly necessary** first-party cookies (to maintain your authenticated, opaque server-side session and CSRF/security state — the Services do not function without these) and **measurement-only analytics** — "measurement-only" meaning no advertising, no ad personalization and no cross-site tracking, on the marketing website and in the authenticated dashboard alike. It does **not** mean the dashboard's analytics is anonymous: because you are signed in there, product events are keyed to your **pseudonymous account identifier** (§7.1, and `cookie-policy.md` §6.3). We do **not** use advertising or cross-site tracking cookies, and we do not "sell" or "share" personal information (as defined under the CCPA/CPRA) through cookies.

**12.2 Analytics, GPC, and Do-Not-Track.** Where we use analytics, it runs in measurement-only mode (advertising features and ad personalization off); our analytics provider acts as our service provider/processor and may not use the data for its own purposes. We **honor the Global Privacy Control (GPC)** as a valid opt-out signal. We also honor recognized browser **Do-Not-Track** signals to the extent feasible; because there is no industry consensus on DNT, our practice is to run no cross-site tracking regardless. `cookie-policy.md` is the controlling, itemized cookie inventory and consent-model document; this section summarizes it.

---

## \13. Children

The Services are for **businesses**, are intended for users **18 and older**, and are **not directed to children**. We do not knowingly collect personal data from anyone **under 16, and under 13 for COPPA purposes**. If you believe a child has provided us personal data, contact **privacy@recovea.ai** and we will delete it. This threshold is stated consistently across the Recovea legal pack.

---

## \14. Law-enforcement and legal-process requests

If a law-enforcement or government agency requests personal information **about a Customer**, our practice is to **redirect the agency to request that data directly from the Customer**, and we may provide the Customer's basic contact information for that purpose. If we are legally compelled to disclose, we will give the affected individual or Customer **reasonable advance notice and an opportunity to seek a protective order or other remedy, unless we are legally prohibited** from doing so or the request involves an emergency risk to life or safety. We disclose personal information to public authorities only where required by law (including national-security or law-enforcement requirements).

---

## \15. Electronic communications and marketing choices

**15.1 Consent to electronic communications.** By creating an account or contacting us, you consent to receive communications from us **electronically** (email and in-product notices), and you agree that electronic communications satisfy any legal requirement that a communication be in writing, to the extent permitted by law.

**15.2 Service vs. marketing messages.** **Service, security, billing, and legal notices** are part of the Services and are sent while you hold an account; you cannot opt out of them. **Marketing and product-update emails** are optional — every such email has an **unsubscribe** link, and you may also email **privacy@recovea.ai** to opt out. Opting out of marketing does not stop service messages.

---

## \16. Third-party links and services

The website and Services may link to third-party sites and services (including your chosen **Providers**, Stripe's checkout, and documentation links). Those third parties operate under their **own** privacy policies and practices, which we do not control or endorse. When you follow a link off our site or direct traffic to a Provider, this Policy no longer governs that processing. Your relationship with, and the data handling of, your **Providers** is governed by your agreements with them (§7.5 and `byo-key-and-provider-terms.md`).

---

## \17. Changes to this Policy

We will post material changes here with an updated version and "Last updated" date, and we will **notify customers of significant changes** per `terms-of-service.md` (e.g., by email or a conspicuous in-product notice). Your continued use of the Services after the effective date of a change constitutes acceptance, where permitted by law.

---

## \18. How to contact us

- **Controller:** **Recovea, Inc.**, a **Delaware** corporation. **Notice address:** **2810 N Church St STE 89986, Wilmington, DE 19802**.
- **Privacy requests and questions:** **privacy@recovea.ai** (the "**Privacy Contact**"). Recovea is US-only and EU obligations are dormant; we do not name a DPO or Article 27 representative that does not exist.
- **Security:** **security@recovea.ai**. **Legal notices:** **legal@recovea.ai**. **Support:** **support@recovea.ai**. **Copyright/DMCA:** **dmca@recovea.ai**.

You may also contact your state Attorney General or, in California, the **California Privacy Protection Agency (CPPA)**.

---

## \19. Regulatory and capability outlook (informational)

This note flags privacy/AI-law developments on the horizon that this Policy is positioned to absorb. It is informational, not a commitment.

- **AI-law characterization.** Recovea is an **infrastructure/observability conduit and cost tool** — not a provider/developer/deployer of a high-risk AI system, nor a GPAI provider, under the EU AI Act, the Colorado AI Act, or US state AI laws. Routing is not individual automated decision-making, and Recovea has no affirmative content-monitoring or moderation duty; deployer duties sit with the Customer. Reassess as these regimes phase in.
- **Expanding US state comprehensive privacy laws.** New states continue to take effect (§11.2). Keep the rights matrix, opt-out signals (GPC), profiling opt-out, and appeal mechanics current, and add state addenda as needed.
- **Measurement and verification capabilities.** The Services may include optimization, additional features and capabilities Recovea may offer. Any future verified-measurement capability, if and when Recovea offers it, is governed by the terms in effect when Recovea makes it available, would be measured against a defined counterfactual on the Customer's own traffic net of quality, and is **not active or licensed under this Policy unless Recovea expressly states otherwise**. The honesty bar is a legal-risk control: we do not state a present-tense or guaranteed savings amount or percentage. Keep this Policy aligned with `ai-output-and-no-guarantee-disclaimer.md` and the savings-claims-substantiation control.
- **Cookie/ePrivacy and the consent-banner decision.** If/when EEA/UK visitors come into scope, the §12 / `cookie-policy.md` consent posture must be revisited (ePrivacy / PECR prior-consent for non-essential cookies).

---

*This Policy is the controller-side notice and is subordinate, where stated, to `data-processing-agreement.md` (processor-side processing and the dormant transfer mechanism), `subprocessors.md` (vendor inventory), and `security-statement.md` (live security posture).*
