Privacy policy

What Chovy keeps, and what it doesn't.

Written in plain language, because a policy you can't read protects nobody. If anything here is unclear, ask and we'll fix the wording.

Last updated .

Who is responsible

chovy.com is operated by Profullstack (profullstack.com). For anything in this policy, email hello@profullstack.com.

What we collect, and why

  • Your account. An email address and a password, stored as a hash. That is the whole account record. We do not ask for a name, a phone number, or a company.
  • Your workspace. What you type into Chovy: the idea, the notes, the plan and the decisions you make on it, the code and previews built for you, and the invitations you send to developers. This is what the service is, so it is stored for as long as the workspace exists.
  • An AI account or key you connect. If you bring your own model provider, the key or the sign-in token is stored encrypted and used only to run your workspace's own requests. The browser never receives it.
  • Payment. Card and crypto payments are handled by CoinPay's checkout, with cards processed by Stripe. Chovy receives confirmation that a payment for a given app succeeded. It never sees or stores a card number.
  • Campaign attribution. If you arrived from one of our own advertising links, a cookie records which campaign brought you, so we can count sign-ups per campaign. It lasts seven days.
  • Visits. Pages load a visit counter served from crawlproof.com, which records page views. It is used to see which pages are read. Its own policy describes what it stores.
  • Server logs. Like every web service, the hosting layer keeps request logs (address, browser, page, time) for a short period for security and debugging.

Cookies

  • chovy_session keeps you signed in for 30 days. It is HttpOnly, Secure, and SameSite.
  • A short-lived cookie holds the state of a provider sign-in while it is in progress, for about ten minutes.
  • The campaign cookie described above, only if you arrived from a campaign link.

None of these are used to track you across other sites.

Where your data goes

  • The model provider for your workspace receives the text needed to do the work: your idea, notes, plan, and the code being changed. That is either the provider included with your workspace or the one you connected yourself, in which case their terms apply to what you send.
  • The managed build host holds an isolated workspace and repository per app, where builds run and previews are served.
  • The payment processor receives what it needs to take a payment.
  • Developers you invite see only the projects you assign to them.

We do not sell your data, we do not show you advertising, and Chovy never sends email to your customers. Your idea is not used to train anything.

How long we keep it

Account and workspace data are kept while your account exists. Ask us to delete the account and we delete the account, its workspaces, and their build spaces, keeping only the records of payments that accounting rules require. Because the code, repository, and domain are yours, export them first; they leave with you.

Your rights

You can ask to see the data we hold about you, correct it, receive a copy, or have it deleted. Email hello@profullstack.com and a person will handle it. If you are in a jurisdiction that gives you further rights over your personal data, those rights apply and we will honour them.

Security

Everything is served over HTTPS. Passwords are hashed. Provider keys are encrypted at rest. Session cookies cannot be read by scripts. If you find a weakness, email hello@profullstack.com and see /.well-known/security.txt.

Children

Chovy is a tool for building products and is not directed at children under 16.

Changes

When this policy changes, this page changes and the date at the top moves. Material changes are announced inside your workspace.