Privacy Policy
Last updated: July 13, 2026
This Privacy Policy explains how Covira LLC, a Mississippi limited liability company (“Covira,” “we,” “us,” or “our”), collects, uses, shares, and protects information when you use the Covira application and related services (the “Service”).
Covira reads ACORD 25 Certificates of Liability Insurance and reports whether they meet the requirements you configure. To do that, we handle information about you and — importantly — information about your vendors. Please read Section 2 carefully.
1. Information We Collect
We collect the following:
- Account information. Your name and email address, handled through our authentication provider, Clerk, when you create and sign in to your account.
- Company information. Details you provide about your organization, such as company name, industry, size, website, and address.
- Requirement settings. The insurance requirements you configure for Covira to check certificates against.
- Uploaded certificates and extracted data. The certificate files you upload and the information read from them — including personal and business information about your vendors and other third parties (see Section 2), such as vendor business names, addresses, contact names, contact email addresses, policy numbers, coverage types, and coverage limits.
- Basic technical data. Standard information your browser and our hosting provider generate when you use a web application, such as IP address and request logs, used to operate and secure the Service.
2. Data About Your Vendors (Third-Party Information)
When you upload a certificate, you are uploading information about your vendors and other third parties — not just about yourself. That information can include personal data such as contact names and email addresses.
You are responsible for having the right to upload this information. By uploading a certificate or other document, you represent that you have the necessary rights, permissions, and legal basis to provide that third-party information to Covira and to have it processed as described in this Policy. With respect to your vendors' information, you act as the controller of that data and Covira processes it on your behalf to provide the Service.
3. How We Use Information
We use the information we collect solely to provide and operate the Service, including to:
- authenticate you and maintain your account;
- read uploaded certificates and compare them against your configured requirements;
- store your vendors, submissions, results, and settings so you can access them;
- secure, maintain, and troubleshoot the Service; and
- communicate with you about the Service.
We do not sell your information. We do not use your information — including uploaded certificates or the data extracted from them — to train artificial intelligence models. We do not use your information for advertising.
4. Sub-processors — Who Processes Data For Us
We use a small number of third-party service providers to run the Service. They process information only to provide their service to us, under their own terms and privacy commitments:
- Supabase — database and storage for your account data, vendors, submissions, and uploaded files (hosted in the United States).
- Clerk — user authentication and account management (your name, email, and login).
- Vercel — application hosting and delivery.
- Anthropic — document analysis. The content of the certificates you upload is transmitted to Anthropic's API to be read and analyzed. Anthropic processes this content to return the analysis to us; per Anthropic's API terms, submitted content is not used to train its models.
5. How Long We Keep Data, and Deletion
We keep your information for as long as your account is active and as needed to provide the Service. You can delete individual vendors and their associated data from within the app at any time.
You can request deletion of your account and all associated data. To do so, contact us at CONTACT EMAIL — e.g. privacy@covira.io — TO BE CONFIRMED from the email address associated with your account. We are committed to honoring valid deletion requests and will delete your account data from our systems, and instruct our sub-processors to delete it from theirs, within a reasonable period, except where we are required to retain certain information by law.
6. Security
We take reasonable measures to protect the information in the Service. In particular:
- Per-account data isolation. We use database row-level security so that each account can access only its own data.
- Encrypted transit. Data moving between your browser, our Service, and our sub-processors is encrypted using standard TLS (HTTPS).
- Authenticated access. Access to your data requires signing in to your authenticated account.
We want to be honest about the limits of these measures. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security. We do not hold, and do not claim, any formal security or compliance certification — for example, we are not SOC 2 certified and the Service is not HIPAA compliant. If that changes, we will update this Policy.
7. Cookies and Analytics
Covira uses only the essential cookies required to keep you signed in and to operate the Service securely — these are set by our authentication provider, Clerk, to maintain your session.
We do not run third-party advertising or product-analytics tracking (for example, Google Analytics, advertising pixels, or similar). We do not track you across other websites. If we add analytics in the future, we will update this Policy first.
8. Your Choices and Rights
You can access and update much of your account and company information directly in the app. You can delete vendor data in the app, and you can request deletion of your entire account and data as described in Section 5. Depending on where you live, you may have additional rights over your personal information, such as the right to access or correct it; contact us using the details in Section 10 to exercise them.
9. Children
The Service is intended for use by businesses and is not directed to children under 13, and we do not knowingly collect personal information from children.
10. Changes and Contact
We may update this Policy from time to time. When we do, we will revise the “Last updated” date at the top of this page, and we will take reasonable steps to notify you of material changes.
For privacy questions or requests, contact us:
- Email: CONTACT EMAIL — e.g. privacy@covira.io — TO BE CONFIRMED
- Mail: Covira LLC, MAILING ADDRESS — TO BE ADDED