Privacy Policy
This policy explains what personal data Covert Signals LLC (“Covert Signals”, “we”, “us”) collects, why, and for how long. It covers covertsignals.com, Covert.IM, and every other service we host for you (together, the “Services”). It forms part of our Terms of Service.
Our approach
We are a privacy and security provider. That is only credible if our own data practices match, so:
- No tracking. No analytics, no tag manager, no third-party scripts, no advertising, no profiling.
- No tracking cookies. The public website sets no cookies at all. Signed-in services set only the cookies needed to keep you signed in.
- No permanent IP logs by default. See Section 3.
- Encrypted at rest. Every server is fully disk-encrypted under a key only we hold. Our hosting provider cannot read our disks.
- No selling. We do not sell, rent, or share personal data for advertising or for anyone else’s marketing.
- No training. We do not use your data to train machine learning models.
- Minimum viable collection. We collect what the Services cannot run without, and we delete it on a schedule.
1. Who we are
Covert Signals LLC is the controller of the personal data described here. Contact us at
2. Account data
To give you an Account we store: your username, your email address, your display name, the groups and entitlements that decide what you can access, and the second-factor authentication methods you enroll. You give us this data; without it we cannot create an Account. We hold it in our own single sign-on system on infrastructure we control.
3. Connection and security logs
We keep no permanent logs of your IP address.
Our servers see your IP address while you are connected, because that is how the internet works. We retain it only as follows:
- Ordinary use: our web servers and reverse proxy do not write your IP address to a durable log. Records used for rate limiting are short-lived and expire automatically within 24 hours. Separately, the Covert.IM homeserver records a last-seen IP address against each of your signed-in devices so that you can review your own active sessions and spot one you do not recognize; we purge those records on a short cycle (Section 7) and they are visible to you in your app.
- Suspected abuse or fraud: we may retain IP addresses temporarily while we investigate a specific incident, and no longer than 30 days unless the investigation is still open.
- Confirmed breach of our Terms of Service: if you use the Services for spam, denial-of-service attacks, or other conduct that breaches Section 3 of the Terms, we may retain the associated IP addresses for as long as necessary to prevent recurrence and to defend legal claims.
We also keep operational logs (request paths, response codes, timings, and error traces) to keep the Services running and secure. We configure these to exclude message content and to exclude or truncate identifiers wherever the system still functions without them.
4. Covert.IM service data
Message content in end-to-end encrypted conversations is encrypted on your device. We hold ciphertext that we cannot decrypt, and we cannot produce it in readable form for you, for ourselves, or for any authority. Our backups contain the same ciphertext and are equally unreadable to us.
We are candid that encryption protects content, not metadata. To route messages and run the service, our homeserver necessarily holds:
- your user identifier (
@name:covert.im) and display name; - which rooms you belong to, and who else belongs to them;
- timestamps and approximate sizes of the events you send;
- your device list, device names, public encryption keys, and each device’s last-seen time and IP address (Section 3);
- encrypted media and attachments, stored as ciphertext;
- call signaling data, meaning who called whom and when. Call media itself is end-to-end encrypted and relayed without being recorded.
Metadata is still personal data. We minimize its retention (Section 7) and protect it under the same legal-process rules as everything else (Section 9).
5. Billing data
For paid Services we store your billing contact, billing address, purchase orders, invoices, and payment records. We keep these for as long as tax and accounting law requires, currently seven years. We do not store full payment card numbers.
6. Cookies
The public website sets no cookies. Signed-in services set a small number of strictly necessary cookies: a session cookie that keeps you signed in, a CSRF token, and a cookie that remembers your sign-in preference. These are first-party, are not used for tracking, and expire when your session ends or shortly after. There is no consent banner because there is nothing to consent to.
7. Retention
| Data | Kept for |
|---|---|
| Account data | While your Account is open, then deleted within 90 days |
| Ephemeral rate-limit records | Up to 24 hours |
| Per-device last-seen IP and time | 7 days, then purged automatically |
| Sign-in and security events | 30 days |
| IP addresses during an abuse investigation | Up to 30 days, or until the investigation closes |
| IP addresses after a confirmed Terms breach | As long as necessary to prevent recurrence |
| Operational and error logs | 30 days |
| Encrypted message content and media | Until you or your room’s policy deletes it |
| Database backups | 14 days, then destroyed |
| Billing records | 7 years, as tax law requires |
Deleted data may persist in encrypted backups until those backups expire on the schedule above.
8. Who we share it with
We do not sell or rent personal data, and we disclose it to no one for advertising. We use a small number of subprocessors:
| Subprocessor | Purpose | Data it handles | Location |
|---|---|---|---|
| GlobalTeleHost Corp. (GTHost) | Bare-metal server hosting | Encrypted disks only; see below | United States |
| AhaSend B.V. | Transactional email delivery | Your email address and the contents of notification emails we send you | Netherlands (EU) |
We keep this list current and will update it before adding a subprocessor that handles personal data.
Our servers are fully disk-encrypted and GTHost does not hold the key. We provision every machine with full-disk encryption and the decryption key is held by us alone. GTHost supplies hardware, power, and network. It cannot read the contents of our disks, and a legal demand served on GTHost for our stored data would produce ciphertext. We are candid about the limit of this protection: while a server is running, its key is in memory, so an adversary with physical access to a live machine is a residual risk that disk encryption alone does not eliminate. This is one reason we also encrypt Covert.IM content end to end and keep everything else to a minimum. A demand can only reach data that exists.
9. Legal demands
- We disclose user data only when compelled by valid, binding legal process. We do not disclose voluntarily.
- We review every demand and challenge those that are overbroad, defective, or served in the wrong jurisdiction.
- Where the law permits, we notify you before disclosing, so that you have an opportunity to object. Where a court order or statute forbids notice, we give it as soon as the prohibition lifts.
- We can only produce what we hold. For end-to-end encrypted conversations that is ciphertext and the metadata listed in Section 4. We cannot decrypt content, and no order can compel us to produce something we do not possess.
10. Your rights
Whatever jurisdiction you are in, you may ask us to:
- Access: get a copy of the personal data we hold about you.
- Correct: fix data that is inaccurate or incomplete.
- Delete: erase your data, subject to legal retention obligations.
- Port: receive your data in a portable format.
- Object or restrict: object to processing, or ask us to restrict it.
Write to
United States residents. If you live in California, Colorado, Connecticut, Virginia, or another state with a comprehensive privacy law, the rights above are the rights that law gives you, and we extend them to everyone rather than gate them by state. We do not sell personal information or share it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not process sensitive personal information for the purpose of inferring characteristics. You may use an authorized agent, and you may appeal a refused request by replying to our decision.
Outside the United States. If you are in the EEA or the UK, we process your data to perform our contract with you (Account and Services), to meet legal obligations (billing records), and for our legitimate interests in keeping the Services secure and free of abuse. You have the rights above under the GDPR or UK GDPR, including the right to complain to your supervisory authority. Our servers are in the United States and our email subprocessor is in the Netherlands. For transfers to the United States we rely on the Standard Contractual Clauses, together with full-disk encryption, end-to-end encryption, and data minimization.
11. Security
We operate the Services on infrastructure we control, with full-disk encryption on every server under keys only we hold, end-to-end encryption for Covert.IM conversations, encryption in transit everywhere, single sign-on with mandatory multi-factor authentication, and least-privilege administrative access. No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authorities within the deadlines the law sets.
12. Children
The Services are not for anyone under 18, and we do not knowingly collect data from children. If you believe a child has given us personal data, write to
13. Changes
We may update this policy. For a material change we will give at least 30 days’ notice by email or in the Services before it takes effect. The effective date at the top always reflects the current version.
14. Contact
Write to
