CorvaneOS
Sign inGet started
Legal

Privacy Policy

Last updated October 7, 2026

Your company runs on CorvaneOS, so its data has to be handled carefully. This policy explains, in plain language, what we collect, why, and how you stay in control.

On this page
  1. Who we are
  2. Information we collect
  3. How we use information
  4. The HEYAI agent
  5. Connected apps and Instagram
  6. How we share information
  7. Security
  8. Data retention
  9. Deleting your data
  10. Your rights and choices
  11. International transfers
  12. Children
  13. Changes to this policy
  14. Contact us

01Who we are

CorvaneOS (“CorvaneOS”, “we”, “us”) runs the website at corvaneos.com and the CorvaneOS workspace: an operating system for startup teams (projects, tasks, documents, team chat, sales, customer feedback, hiring, investments and the HEYAI agent) and investor workspaces for angels, syndicates and VCs.

This policy explains what information we collect when you use CorvaneOS, how we use it, who we share it with and the choices you have. For questions, write to maulik@corvaneos.com.

02Information we collect

Information you give us

  • Account details — your name, email address and password (stored only as a secure hash by our authentication provider), or your Google account name and email if you sign in with Google.
  • Profile and onboarding — the role you choose (builder, angel investor, syndicate or VC), startup or fund details, and optional links such as LinkedIn, X or Instagram profile URLs.
  • Workspace content — everything you and your team create or upload: projects, tasks, documents and files, chat messages, sales and pipeline records, customer feedback, interview and candidate notes, investor updates, deal and cap-table information.
  • HEYAI conversations — the questions you ask the agent, files or images you attach, voice recordings you send through voice chat, and the agent's replies.
  • Messages to us — demo requests, support emails and feedback.

Information from connected apps

When you or a workspace admin connect an app on the Integrations page (for example Gmail, Google Drive, GitHub, Slack, HubSpot, Notion or Instagram), we receive the access token or API key needed to reach that service and the data the connection is allowed to read. See Connected apps and Instagram for details.

Information collected automatically

  • Sign-in cookies that keep you logged in and protect your session.
  • Local preferences such as your chosen AI model or theme, stored in your browser's local storage.
  • Basic technical data such as IP address, browser type and request logs, kept by our hosting providers for security and reliability.
  • AI usage counts (number of requests and tokens) used to apply your plan's quota.

We do not use advertising cookies or third-party ad trackers.

03How we use information

  • To create and secure your account, verify your email and let you sign in.
  • To run the workspace: store and display your content, share it with the members of your organization, and send the notifications and invites you trigger.
  • To answer HEYAI requests using data from the organization you are working in.
  • To sync and show data from the apps you connect, and to let HEYAI read it when you ask.
  • To apply plan limits, prevent abuse and keep the service secure.
  • To respond to support requests and demo bookings.
  • To send occasional product updates. You can opt out at any time with the unsubscribe link or by emailing us.
  • To meet legal obligations.
We do not sell your personal information, and we do not use your workspace content or connected-app data to train AI models.

04The HEYAI agent

HEYAI reads data only from the organization you are working in. To produce an answer, your question, the relevant workspace context and any attachments are sent to our AI inference provider (Groq) for processing. Voice messages are transcribed by the same provider. The provider processes this data to return a response and does not receive your account password or integration credentials.

Your conversation history is saved so you can return to it. You can delete any conversation from the Agent page, which also deletes its messages.

AI replies can be wrong or incomplete. Check important answers before relying on them.

05Connected apps and Instagram

Integrations are optional and are connected by you or an admin of your workspace. For each connection we store the OAuth token or API key encrypted with AES-256-GCM on our servers. Credentials are never sent to your browser. We may keep a cached copy of the items a connection syncs (for example recent posts, files or issues) so they can be shown in CorvaneOS and used by HEYAI.

Instagram

If you connect an Instagram professional (Business or Creator) account through Instagram Login, we request the instagram_business_basic permission. This lets CorvaneOS read your account's ID, username, profile details, media (posts and their captions) and related comments and insights, so your team can see them in the workspace and ask HEYAI about them. We use this data only to provide those features to your workspace.

  • We do not post, comment, send messages or change anything on your Instagram account.
  • We do not sell Instagram data, share it with advertisers or use it to build profiles of Instagram users.
  • Only members of the workspace that made the connection can see the data.

Your use of a connected service is also governed by that service's own terms and privacy policy, such as Meta's for Instagram and Google's for Google apps. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

06How we share information

We share information only in these cases:

  • Inside your organization. Content in a workspace is visible to its members according to their role and the sharing settings you choose, including startups you choose to share with investors.
  • Service providers that run CorvaneOS for us, under contracts that limit their use of the data:
ProviderPurpose
SupabaseAuthentication, database and file storage
Google Firebase / Google CloudWebsite and application hosting
GroqAI processing for HEYAI, including voice transcription
Our email providerVerification codes, invites and service emails
  • Connected apps you choose to link, when CorvaneOS makes requests to them on your behalf.
  • Legal reasons — when required by law, or to protect the rights, safety and security of our users, the public or CorvaneOS.
  • Business transfers — if CorvaneOS is involved in a merger, acquisition or sale of assets, with notice to you.

07Security

Data is sent over HTTPS. Access to workspace data is restricted per organization with row-level security in our database, integration credentials and similar secrets are encrypted at rest, and administrative access is limited to people who need it. No system is perfectly secure, so please use a strong password and tell us right away at maulik@corvaneos.com if you suspect unauthorized access to your account.

08Data retention

We keep your information for as long as your account or workspace is active. When you disconnect an integration we delete its stored credentials and synced items. When you delete a HEYAI conversation, its messages are deleted. When an account is deleted, we delete or anonymize its personal data within 30 days, except where we must keep limited records for legal, security or billing reasons. Backups are overwritten on a rolling basis.

09Deleting your data

You can remove your data at any time:

  • Connected apps (including Instagram): open Integrations in your workspace and choose Disconnect. This deletes the stored access token and the data synced from that app. You can also remove CorvaneOS from your Instagram account under Settings → Apps and websites.
  • HEYAI conversations: delete them from the conversation list on the Agent page.
  • Your whole account: email maulik@corvaneos.com from the address on your account with the subject “Delete my account”. We will confirm the request and delete your account and personal data within 30 days.

Content you created inside a shared organization workspace may remain available to that organization after you leave, unless the organization deletes it or you ask us to remove personal data that is not needed by the organization.

10Your rights and choices

Depending on where you live (for example under India's Digital Personal Data Protection Act, the EU/UK GDPR or US state laws), you may have the right to access, correct, download or delete your personal data, to withdraw consent, to object to or restrict certain processing, and to complain to a data protection authority.

You can update most profile details yourself in Profile and Settings. For anything else, email maulik@corvaneos.com. We will respond within 30 days and will not discriminate against you for exercising your rights.

11International transfers

Our providers may process data in countries other than yours, including India, the United States and the European Union. Where required, we rely on appropriate safeguards such as standard contractual clauses.

12Children

CorvaneOS is a business tool and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.

13Changes to this policy

We may update this policy as CorvaneOS changes. We will post the new version here and update the date at the top. If the changes are significant, we will also tell you by email or in the app before they take effect.

14Contact us

Questions, requests or complaints about privacy: maulik@corvaneos.com. See also our Terms of Service.

CorvaneOS
HomeDocsPrivacyTermsContact
© 2026 CorvaneOSBuilt for builders