01Who we are
CorvaneOS (“CorvaneOS”, “we”, “us”) runs the website at corvaneos.com and the CorvaneOS workspace: an operating system for startup teams (projects, tasks, documents, team chat, sales, customer feedback, hiring, investments and the HEYAI agent) and investor workspaces for angels, syndicates and VCs.
This policy explains what information we collect when you use CorvaneOS, how we use it, who we share it with and the choices you have. For questions, write to maulik@corvaneos.com.
02Information we collect
Information you give us
- Account details — your name, email address and password (stored only as a secure hash by our authentication provider), or your Google account name and email if you sign in with Google.
- Profile and onboarding — the role you choose (builder, angel investor, syndicate or VC), startup or fund details, and optional links such as LinkedIn, X or Instagram profile URLs.
- Workspace content — everything you and your team create or upload: projects, tasks, documents and files, chat messages, sales and pipeline records, customer feedback, interview and candidate notes, investor updates, deal and cap-table information.
- HEYAI conversations — the questions you ask the agent, files or images you attach, voice recordings you send through voice chat, and the agent's replies.
- Messages to us — demo requests, support emails and feedback.
Information from connected apps
When you or a workspace admin connect an app on the Integrations page (for example Gmail, Google Drive, GitHub, Slack, HubSpot, Notion or Instagram), we receive the access token or API key needed to reach that service and the data the connection is allowed to read. See Connected apps and Instagram for details.
Information collected automatically
- Sign-in cookies that keep you logged in and protect your session.
- Local preferences such as your chosen AI model or theme, stored in your browser's local storage.
- Basic technical data such as IP address, browser type and request logs, kept by our hosting providers for security and reliability.
- AI usage counts (number of requests and tokens) used to apply your plan's quota.
We do not use advertising cookies or third-party ad trackers.
03How we use information
- To create and secure your account, verify your email and let you sign in.
- To run the workspace: store and display your content, share it with the members of your organization, and send the notifications and invites you trigger.
- To answer HEYAI requests using data from the organization you are working in.
- To sync and show data from the apps you connect, and to let HEYAI read it when you ask.
- To apply plan limits, prevent abuse and keep the service secure.
- To respond to support requests and demo bookings.
- To send occasional product updates. You can opt out at any time with the unsubscribe link or by emailing us.
- To meet legal obligations.
04The HEYAI agent
HEYAI reads data only from the organization you are working in. To produce an answer, your question, the relevant workspace context and any attachments are sent to our AI inference provider (Groq) for processing. Voice messages are transcribed by the same provider. The provider processes this data to return a response and does not receive your account password or integration credentials.
Your conversation history is saved so you can return to it. You can delete any conversation from the Agent page, which also deletes its messages.
AI replies can be wrong or incomplete. Check important answers before relying on them.
05Connected apps and Instagram
Integrations are optional and are connected by you or an admin of your workspace. For each connection we store the OAuth token or API key encrypted with AES-256-GCM on our servers. Credentials are never sent to your browser. We may keep a cached copy of the items a connection syncs (for example recent posts, files or issues) so they can be shown in CorvaneOS and used by HEYAI.
If you connect an Instagram professional (Business or Creator) account through Instagram Login, we request the instagram_business_basic permission. This lets CorvaneOS read your account's ID, username, profile details, media (posts and their captions) and related comments and insights, so your team can see them in the workspace and ask HEYAI about them. We use this data only to provide those features to your workspace.
- We do not post, comment, send messages or change anything on your Instagram account.
- We do not sell Instagram data, share it with advertisers or use it to build profiles of Instagram users.
- Only members of the workspace that made the connection can see the data.
Your use of a connected service is also governed by that service's own terms and privacy policy, such as Meta's for Instagram and Google's for Google apps. Our use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
07Security
Data is sent over HTTPS. Access to workspace data is restricted per organization with row-level security in our database, integration credentials and similar secrets are encrypted at rest, and administrative access is limited to people who need it. No system is perfectly secure, so please use a strong password and tell us right away at maulik@corvaneos.com if you suspect unauthorized access to your account.
08Data retention
We keep your information for as long as your account or workspace is active. When you disconnect an integration we delete its stored credentials and synced items. When you delete a HEYAI conversation, its messages are deleted. When an account is deleted, we delete or anonymize its personal data within 30 days, except where we must keep limited records for legal, security or billing reasons. Backups are overwritten on a rolling basis.
09Deleting your data
You can remove your data at any time:
- Connected apps (including Instagram): open Integrations in your workspace and choose Disconnect. This deletes the stored access token and the data synced from that app. You can also remove CorvaneOS from your Instagram account under Settings → Apps and websites.
- HEYAI conversations: delete them from the conversation list on the Agent page.
- Your whole account: email maulik@corvaneos.com from the address on your account with the subject “Delete my account”. We will confirm the request and delete your account and personal data within 30 days.
Content you created inside a shared organization workspace may remain available to that organization after you leave, unless the organization deletes it or you ask us to remove personal data that is not needed by the organization.
10Your rights and choices
Depending on where you live (for example under India's Digital Personal Data Protection Act, the EU/UK GDPR or US state laws), you may have the right to access, correct, download or delete your personal data, to withdraw consent, to object to or restrict certain processing, and to complain to a data protection authority.
You can update most profile details yourself in Profile and Settings. For anything else, email maulik@corvaneos.com. We will respond within 30 days and will not discriminate against you for exercising your rights.
11International transfers
Our providers may process data in countries other than yours, including India, the United States and the European Union. Where required, we rely on appropriate safeguards such as standard contractual clauses.
12Children
CorvaneOS is a business tool and is not meant for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has given us data, contact us and we will delete it.
13Changes to this policy
We may update this policy as CorvaneOS changes. We will post the new version here and update the date at the top. If the changes are significant, we will also tell you by email or in the app before they take effect.
14Contact us
Questions, requests or complaints about privacy: maulik@corvaneos.com. See also our Terms of Service.