Privacy policy
We collect the data needed to run the inbox—and treat customer conversations as sensitive.
Effective 2026-08-17. This policy explains how Omnichannel Inbox handles information when you use CorvoDesk.
1. Information we process
We process account information such as name, email address, authentication events, legal acknowledgements, workspace membership, and security-session information. Workspaces may contain social account identifiers, customer profiles, message content, attachments, notes, tags, assignments, saved replies, automations, pipeline records, and audit history.
Early-access applicants may provide a name, email, business name, team size, primary channel, and intended use. We also process support and feedback requests, account-deletion review records, limited operational information such as connection health, delivery state, retry history, usage counts, browser and server request metadata, and sanitized diagnostics. Payment-provider identifiers and subscription state may be stored when billing is enabled; full card details are handled by Stripe and are not stored by CorvoDesk.
2. Why we use information
We use information to authenticate users, deliver and organize messages, support team collaboration, maintain security, prevent abuse, diagnose failures, measure usage, provide requested exports or deletion actions, and operate subscriptions when billing is enabled.
3. Connected platforms and service providers
When a workspace connects Meta services, information is exchanged with Meta to authorize accounts, receive webhooks, import permitted recent history, and send replies. We use Supabase for authentication, database, and server functions; a production deployment provider hosts the web application; and Stripe is the planned subscription processor. Each provider processes information under its own terms and privacy commitments.
4. Security and access
Workspace access is isolated with role checks and row-level database security. Provider credentials are kept in a server-side encrypted vault and are not sent to browser code. Sensitive service operations re-check the signed-in user and workspace role. No internet service is risk-free, so users should protect their accounts and report suspected unauthorized access promptly.
5. Retention, exports, and deletion
Workspace owners and administrators can create audited exports and configure message-content retention. Authorized users can redact a contact, and account holders can submit a password-verified deletion review from Account settings. The review checks workspace ownership, other members, subscriptions, export needs, and applicable retention before destructive action. Some limited records may be retained where needed for security, legal obligations, dispute handling, or financial recordkeeping. See the Data Deletion page for request instructions.
6. Choices and rights
Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal information. A workspace customer should normally direct customer-record requests to the business that controls that workspace. Account holders may contact us directly.
7. Children
The service is intended for businesses and adults and is not directed to children.
8. Changes and contact
We may update this policy as the product or legal requirements change and will publish a new effective date. Questions can be sent to stonergoldfish84@gmail.com.
