Legal

Privacy Policy

How Covendri collects, uses and protects information when businesses use our service and website.

Draft — last updated October 11, 2026. This policy is under legal review and may change before it is final.

1. Who we are and what this policy covers

Covendri [legal entity name and address] ("Covendri", "we", "us") provides an AI-assisted IT support service for businesses. The service includes the Covendri Agent, which a business installs on its Mac and Windows computers; the Covendri menu bar and tray app used by employees; the admin dashboard at dashboard.covendri.com; and the assistant features a Customer chooses to use, such as the email assistant for Microsoft 365 (Outlook) and Gmail, WhatsApp Business, quotes, Teach Covendri, image generation, research and optional screen control (together, the "Service").

This policy explains how we handle information processed through the Service and through our website at covendri.com. The Service is intended for businesses, not for personal or household use.

2. Our role and yours

When a business (our "Customer") uses the Service, the Customer decides which computers to enroll and which people use the Service. For information about the Customer's employees and devices processed through the Service ("Customer Data"), the Customer is the controller and Covendri acts as a processor (or "service provider") that processes Customer Data on the Customer's behalf and according to its instructions.

Customers are responsible for giving their employees any notice required by law, and for having a lawful basis to install the Covendri Agent on the devices they enroll.

Covendri is the controller for information we process for our own business purposes, such as account administration, billing, security of the Service, and our website.

3. Information we process

Account information

Name, email address, company name, role (for example, admin or member), department, and identifiers from the sign-in provider you choose (Microsoft, Google, or email and password). For email and password sign-in, we store only a hashed form of the password.

Device diagnostics

Information the Covendri Agent collects from enrolled computers to diagnose problems and monitor health, including:

  • Device name, hardware model, operating system version and the signed-in user's account name.
  • Storage usage, including the names and sizes of large folders, and memory and CPU usage.
  • Running processes (with command-line secrets redacted), installed software and startup items.
  • Network and Wi-Fi diagnostics, such as signal strength, DNS and connection quality.
  • Update status, security settings (for example, firewall and disk encryption), backup status, battery health and printer queues.
  • Recent system log entries relevant to a problem.

Help requests and support content

The text of help requests and conversations with Covendri, screenshots that users choose to attach, the steps and tool results of each request, and knowledge base articles created from resolved requests.

Email and WhatsApp messages (only if connected)

If a Customer connects Microsoft 365, Gmail or WhatsApp Business, we process messages only in the mailboxes and numbers the Customer's admin allows: sender and recipient names and addresses or phone numbers, subject, dates, message text, and the replies Covendri suggests, edits and sends. We read only new incoming messages from the time of connection, and we don't write replies to newsletters or automatic replies. Covendri sends a message only in the mode the admin chose for that mailbox or number (draft only, or send after a person approves).

Teach Covendri imports

If an admin imports past email or exported chats, we copy the selected messages into a temporary working set, automatically remove personal details we can detect (such as names, email addresses, phone numbers and ID, booking, card and bank numbers), and use the result to propose knowledge articles. Proposed articles are used only after an admin approves them.

Quotes, images and research

Example quotes and templates a Customer uploads, the quotes it creates, images it generates, and the questions it asks the research assistant along with the results and their sources.

Approvals and audit records

Records of actions taken on devices, approval requests, decisions and notes, and who made them and when.

Usage and technical information

Plan and usage information (such as number of devices and AI usage), and technical information about sign-in sessions, such as IP address, browser user agent and timestamps, used for security.

Website

Our website does not use analytics, advertising or tracking tools. Our hosting provider may keep standard server logs (such as IP address and pages requested) for security and operations.

Communications

If you email us, we keep the message and your contact details to respond and provide support.

4. What we don't collect

The Covendri Agent does not use the camera or microphone or read stored passwords. It records the screen and controls the keyboard and mouse only if the customer enables the optional screen-control feature and the user approves a specific task; in that case we keep a step log with downscaled screenshots for the period the customer sets (24 hours by default), and text typed by the agent is stored only as its length. We process the contents of email and WhatsApp messages only in the mailboxes and numbers a Customer connects and allows, as described in section 3; otherwise we do not intentionally collect the contents of users' documents, email or messages. Diagnostic information may incidentally include file, folder or application names.

5. How we use information

  • To provide the Service: diagnosing and fixing IT problems, monitoring device health, running proactive health reviews, routing approvals, and keeping the audit log.
  • To suggest and, in the mode the Customer chose, send replies to email and WhatsApp messages; to create quotes and images; and to research questions on the web.
  • To build the Customer's knowledge base from resolved requests and from imports an admin approves, available only within that Customer's workspace.
  • To operate, secure and improve the Service, including preventing abuse, enforcing usage limits, and troubleshooting.
  • To communicate with Customers about their account, the Service, and support requests.
  • To comply with legal obligations and enforce our Terms of Service.

We do not sell personal information, share it for cross-context behavioral advertising, or use Customer Data for advertising.

6. AI processing

To work on a request, the Service sends the relevant parts of it (such as the request text, attached screenshots, diagnostic results and relevant knowledge base articles) to Microsoft's Azure OpenAI Service for processing. We do not use Customer Data to train AI models. Under Microsoft's terms for the Azure OpenAI Service, customer prompts and outputs are not used to train Microsoft's or OpenAI's foundation models.

Images are generated with an image model on Azure OpenAI Service, subject to Azure's content filters.

When web search is on for a Customer's workspace, search queries are sent through the web search tool in Azure OpenAI Service, which uses Grounding with Bing Search. Bing is a separate Microsoft service that handles queries under its own terms, outside the Azure OpenAI commitments above. Covendri is designed to write search queries without names, contact details or other personal data. The Customer's admin can turn web search on or off.

7. Service providers we use

We share information only with service providers that help us run the Service, under contracts that limit how they may use it, or when required by law.

ProviderPurpose
Microsoft Azure (United States)Hosting, databases and transactional email
Microsoft Azure OpenAI ServiceAI processing of requests, email and message drafting, and image generation
Microsoft (Grounding with Bing Search)Web search and research, only when web search is on
Microsoft Graph (Microsoft 365)Reading, drafting and sending Outlook email, only for mailboxes a Customer connects
Google APIsGmail, only for mailboxes a Customer connects
Meta (WhatsApp Business Cloud API)Receiving and sending WhatsApp messages, only for a number a Customer connects
CloudflareDomain name (DNS) services and email routing
Microsoft and GoogleSign-in, only if a user chooses to sign in with that provider

We may also disclose information if required by law, to protect the rights, safety or security of our Customers, users or Covendri, or as part of a merger, acquisition or sale of assets, in which case this policy will continue to apply to the information transferred.

8. Cookies

We use cookies only to keep you signed in to the dashboard. These are strictly necessary, HTTP-only session cookies that expire automatically. We do not use advertising, analytics or tracking cookies, and our website at covendri.com sets no cookies.

9. Retention and deletion

We keep Customer Data for as long as the Customer's workspace is active, unless the Customer deletes it sooner or a shorter period below applies. Unconfirmed sign-ups are removed after 7 days.

  • Email and message text: the text of messages and suggested replies is deleted after 30 days by default (the Customer's admin can choose from 1 to 365 days). Sender, subject, dates and status are deleted about 90 days after that.
  • Teach Covendri working set: deleted when the import ends, and within 48 hours at most. Knowledge articles an admin approves are kept like the rest of the knowledge base.
  • Screen-control screenshots: deleted after 24 hours by default (the admin can choose from 1 hour to 7 days).
  • Detailed device health metrics: 7 days.

Customers can ask us to delete their workspace's data at any time by emailing support@covendri.com. When a workspace is closed, we delete or de-identify Customer Data within [30] days, except for limited records we must keep for legal, billing or security reasons, and data in backups, which is overwritten on our normal backup cycle.

10. Security

We use technical and organizational measures designed to protect information, including encrypted connections, per-company data isolation, per-device credentials stored only as hashes, server-enforced approvals for high-impact actions, and audit logging. No system is perfectly secure, but we work to protect your data and will notify affected Customers of a security incident as required by law. Learn more on our Security page.

11. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete or export personal information, or to object to or restrict certain processing.

  • Employees of a Customer: your employer controls your information in the Service. Please contact your employer first; we will help them respond to your request.
  • Customer admins and other individuals: email support@covendri.com. We may need to verify your identity before acting on a request.

We will not discriminate against anyone for exercising their privacy rights.

12. Where data is stored

Covendri is hosted on Microsoft Azure in the United States. If you use the Service from outside the United States, your information will be transferred to and processed in the United States. Where required, we rely on appropriate safeguards for such transfers.

13. Children

The Service is designed for businesses and is not directed to children. We do not knowingly collect personal information from children under 16.

14. Changes to this policy

We may update this policy from time to time. We'll change the "last updated" date above and, for material changes, notify Customer admins by email or in the dashboard before the changes take effect.

15. Contact us

Questions or requests about privacy: support@covendri.com.