Last updated October 7, 2026
Privacy Policy
Covo helps creators and businesses publish an AI Concierge. This policy explains what RedRooster Technologies collects, why we use it, who receives it, how long it is kept, and the choices available to you.
Who is responsible
RedRooster Technologies operates the Covo platform and is responsible for Covo account, billing, security and marketing-site data. A creator or business that publishes a Concierge decides what that Concierge knows, which integrations it uses and how it follows up with visitors. For those interactions, that creator or business may also be a data controller. Questions for RedRooster Technologies can be sent to michael.westbrooks@redroostertec.com.
Information we collect
- Account and workspace data: email address, password hash, name, workspace settings, profile content, links, offers, knowledge and files you add.
- Visitor and conversation data: messages, conversation summaries, optional contact details, bookings, clicked actions, the Place that opened the conversation and source/UTM information.
- Operational data: authentication sessions, security audit events, AI usage, request identifiers, device class and transient network information used for abuse prevention. Covo does not store visitor IP addresses in marketing analytics.
- Billing data: subscription state and Stripe customer or subscription identifiers. Covo does not receive full payment-card details.
- Optional marketing analytics: only after consent, a random browser identifier, random tab-session identifier, page path, section and scroll events, CTA actions, referral host, campaign parameters, viewport and time on page. We do not collect form-field values, prompts, conversation text, email addresses or account identifiers in this analytics stream.
How and why we use information
We use information to provide requested services and accounts, answer through a configured AI provider, restore conversations, deliver bookings and leads, operate subscriptions, secure and troubleshoot the platform, comply with legal obligations, and improve Covo. Depending on where you live, the legal basis may be performance of a contract, legitimate interests in operating and securing the service, compliance with law, or consent. Optional marketing analytics relies on consent and stays off until you opt in.
AI processing and service providers
A Concierge sends the context needed for the current turn to the inference provider configured by the operator: OpenAI, LANA Forge in sovereign mode, or another compatible model server. Covo may also use Railway for hosting, PostgreSQL for application storage, Stripe for payments, an email delivery provider, and optional human-verification providers. Creator-connected services such as webhooks, Slack, HubSpot, Cal.com or Calendly receive data only when that creator enables the integration. These providers process data under their own terms and applicable agreements.
Cookies and local storage
| Technology | Purpose | Typical duration |
|---|---|---|
cc_admin | Necessary creator sign-in session. | Up to 14 days |
cc_v | Necessary signed random key that lets a visitor return to their conversation. No fingerprinting. | Up to 400 days |
covo_privacy and covo_privacy_v1 | Remembers your privacy choice. | 180 days |
covo_analytics_visitor_v1 and session storage | Optional first-party analytics identifiers, created only after consent and removed when consent is withdrawn. | Until browser storage is cleared; tab session ends when the tab closes |
You may reopen at any time. Global Privacy Control is treated as a rejection when no prior choice exists.
Retention and deletion
Creator sessions expire after 14 days of inactivity. Optional marketing analytics events are deleted after 400 days. Tenant-configured policies can remove old conversations, anonymous visitors and inferred memories; the default inferred-memory period is 180 days. Visitors can delete their conversations and details from the Concierge menu, which also clears their device cookie. Account, billing, fraud-prevention, audit and backup records may be retained as reasonably necessary for contractual, security and legal obligations.
Your privacy rights
Depending on your location, you may request access, correction, deletion, restriction, portability, or object to certain processing. You may withdraw consent at any time without affecting processing already performed. You may also complain to your local data-protection authority. To exercise a right, use the visitor deletion control when available or contact us at the address above. We may need to verify the request before acting.
International transfers, security and children
Providers may process information in countries other than your own. Where required, appropriate contractual transfer safeguards are used. Covo uses access controls, encryption in transit, hashed or encrypted credentials, tenant isolation, log redaction and data-retention controls, but no system can guarantee absolute security. Covo is not directed to children under 13, and accounts may not knowingly collect children’s personal data without the required authority.
Changes
We may update this policy as Covo, its providers or applicable requirements change. Material changes will be dated here and, when appropriate, shown in the product.