Privacy Policy
Last updated: June 2026
This Privacy Policy describes how Corvi ("Corvi", "we", "us") processes personal data in connection with the Corvi macOS application and the corvi.sh website (together, the "Service"). Corvi is a free, open-source, local-first app: by default your plans and source code stay on your device and are not transmitted to us. We do collect optional, anonymous, content-free usage telemetry (see Section 3) — on by default with a one-click opt-out, and never including your plans, code, prompts, paths, or any identifier.
1.Who we are
Tenwa (registered in Poland), operating Corvi, is the data controller for personal data processed through the Service. Corvi is free — we do not sell it and take no payments. For data-protection questions, contact legal@corvi.sh.
2.Data we process
Depending on how you use Corvi, we may process:
- Workspace & plan content (default): processed locally on your device; not transmitted to Corvi.
- Account data (only if you opt into cloud sync): email and authentication identifiers, so you can sign in and sync across your own devices.
- Synced content (only if you opt into cloud sync): stored only as end-to-end encrypted ciphertext we cannot read.
- Usage metadata (only if telemetry is on): counts, costs, and timings of planning activity (e.g. "a plan of type X was created"). A server-side allowlist ensures this never includes plan content.
When you run the planning engine, requests are sent to the model provider you configure, using your own API key, subject to that provider's terms.
3.Anonymous usage telemetry
To understand how Corvi performs and where to improve it, the app sends a small, content-free event after each planning run. It is on by default (opt out anytime in Settings → General → Privacy). We collect only low-cardinality metadata:
- Plan type (e.g. feature, bugfix) — a category label, not the plan
- Run outcome (completed, cancelled, failed_*) and whether the round limit was hit
- Total duration and a per-pass breakdown (draft / review / synthesize / tighten), in seconds
- Total cost (USD) and token counts (uncached input / cached / output)
- Model IDs used — public names only (e.g. claude-opus-4-8, gpt-5.5)
- Pipeline shape: preset name, review on/off, consensus on/off, quick-mode, round count, evidence count (a number)
- Workspace language bucket (e.g. swift, typescript) — derived from extension counts, not paths
- App version, macOS version, Corvi edition, MCP server count, and the web-research / on-device toggles
We never collect, and the server-side allowlist strips anything outside the above:
- Plan text, prompt text, or any generated content
- File paths, file names, directory structures, code, or citations
- Repository names, URLs, or branch names
- API keys or tokens
- Account email, account ID, or any personal identifier
Identity. Every event uses a random, rotating anonymous install ID (a UUID stored locally, rotated every 90 days) — never linked to your account or email. Retention. Raw events are deleted after 90 days; anonymised aggregates (counts, averages) may be kept longer.
Crash & hang reports. If the app crashes or hangs, macOS's built-in diagnostics framework (MetricKit) hands Corvi a report on the next launch. Under the same consent and anonymous install ID as above (off when you opt out of telemetry), the app sends only:
- A crash call stack as raw machine addresses + binary UUIDs — unsymbolicated, with no source, function names, or paths
- The exception type, code, and signal numbers
- For a hang, its duration in seconds
- App version, macOS version, and the anonymous install ID
We deliberately drop the system's termination-reason and memory-region strings, which can contain a crash message — so a report never carries plan text, prompts, file paths, or any content. We symbolicate later, offline, against our own build artifacts. Crash rows are deleted after 90 days.
4.How we use data
We process data to provide and secure the Service, sync your encrypted content across your devices (when you opt in), provide support, and improve reliability. We do not sell personal data, and we do not use your source code or plans to train models.
5.Legal bases (GDPR)
Where the GDPR applies, we rely on: performance of a contract (to provide optional cloud sync), legitimate interests (to secure and improve the Service), and consent (for optional diagnostics).
6.Your rights
Subject to applicable law (including the GDPR and CCPA/CPRA), you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. California residents may request disclosure of data categories and opt out of "sharing" as defined by the CPRA. To exercise any right, contact legal@corvi.sh; we will respond within the timeframes required by law. You may also lodge a complaint with your supervisory authority (in Poland, the UODO).
7.Retention
If you opt into cloud sync, we retain your account data for as long as your account is active, and encrypted synced content until you delete it or close your account. Local content is retained on your device under your control.
8.International transfers
Where data is transferred outside your region, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. See our Security page for subprocessor regions.
9.Cookies
The corvi.sh website uses no advertising or third-party analytics trackers. If you sign in for cloud sync, the browser sign-in flow uses a single strictly necessary session cookie.
10.Security
We use TLS in transit, end-to-end encryption for synced content, encryption at rest for local credentials, and an auditable egress model. No method of transmission or storage is perfectly secure, but we design to minimise what we hold.
11.Changes & contact
We will post material changes to this policy here and update the date above. Questions: legal@corvi.sh.