Legal

Version 1.0 · Effective 2026-07-16

Document: OS Lite Privacy Notice (including California Notice at Collection)
Version: 1.0
Effective date: July 16, 2026
Entity: COVU, Inc., 370 Convention Way, Redwood City, CA 94063
Privacy contact: dataprotection@covu.com · General: hello@covu.com

COVU OS Lite Privacy Notice

This notice describes how COVU, Inc. ("COVU") processes personal information in COVU OS Lite — the web application at lite.covu.ai, the OS Lite Companion browser extension, and optional Service Network handoffs. It is specific to OS Lite and supplements, and controls over, COVU's general website privacy policy for OS Lite processing. This notice is provided for acknowledgment; it is not a contract and does not waive any statutory right.

1. Our Two Roles

  • Service provider / processor. For customer, policyholder, policy, and communication data that an insurance agency (the "Agency") directs into OS Lite ("Agency Customer Data"), the Agency is the business/controller and COVU processes it only on the Agency's documented instructions under the Data Processing Addendum. Individuals whose data an Agency submits should direct privacy requests to that Agency; we will assist the Agency in responding.
  • Business / controller. For account administration, authentication, security, billing, direct support, product telemetry, and legal compliance data about Agency users, COVU determines the purposes and means and acts as an independent business.

2. What We Collect (Notice at Collection)

CategoryExamples actually processedSourcesPurposesRetention criteria
Identifiers & account dataName, work email, role, agency affiliation, Google account IDUser, Agency, Google sign-inProvide and administer OS Lite; authentication; supportLife of account + legal retention
Agency Customer DataPolicyholder names/contacts, policy and claims-adjacent details, customer communications, workflow/task content, email content and attachments (where Gmail is connected), AMS and carrier-portal content captured by the CompanionThe Agency and its connected systems, at the Agency's directionProvide the services the Agency requests, on its instructionsPer the DPA: term of service + 60-day deletion window, backups by rotation
Credentials & tokensOAuth tokens for connected systemsUser authorization flowsOperate approved connections; we do not ask users to hand over plaintext third-party passwords for storage outside approved flowsWhile connection is active
Device, usage & security dataIP address, browser/user agent, locale, session and audit logs, feature usage, error tracesAutomaticSecurity, fraud/abuse prevention, debugging, product improvementRolling log windows; security records as needed
Inferred / AI dataAI-generated summaries, drafts, and suggestions and the inputs used to produce themGenerated in-productProvide requested AI features for the AgencySame as the underlying data
Communications dataSupport requests, in-product feedback, SMS/email consent and suppression recordsUser, AgencySupport; consent complianceAs required for compliance evidence

We do not intentionally collect payment-card data or protected health information in OS Lite today, and OS Lite is not directed to children under 13 and must not be used by them; Agency records may incidentally reference minors (e.g., household members on a policy), which we process only as Agency Customer Data with heightened minimization.

3. How We Use Information

To provide, secure, support, administer, and improve OS Lite for each Agency; to follow the Agency's documented instructions; to authenticate users and protect accounts; to detect and prevent fraud, abuse, and security incidents; to meet legal obligations; and to communicate service matters. We may use aggregated or de-identified information (which no longer identifies an agency, user, or policyholder, and which we commit not to re-identify) for analytics, benchmarking, security, and product improvement.

AI and model training. OS Lite uses third-party AI providers (currently Anthropic) to generate summaries and drafts. We do not permit providers to train generally available models on identifiable OS Lite content, and we do not use identifiable agency or customer content to train general or cross-customer AI models without the Agency's separate written opt-in.

Human access. COVU personnel, and Service Network personnel where the Agency routes work to them, may view content only as needed for the requested service, support, security, or legal compliance, under confidentiality obligations and least-privilege access. Agencies may authorize their own users in permitted countries outside the U.S.; that access is the Agency's instruction and responsibility.

4. What We Disclose, and to Whom

We disclose personal information only to: (a) the subprocessors listed at /subprocessors (hosting, database, authentication, AI, email, error monitoring), bound by contract to use it only to provide their service to us; (b) the Agency whose tenant the data belongs to; (c) Service Network personnel when the Agency routes a task; (d) professional advisers, and authorities where required by law (we will notify the Agency of legal demands where permitted); and (e) a successor in a corporate transaction, subject to this notice.

We do not sell OS Lite personal information and do not share it for cross-context behavioral advertising. We do not use Agency Customer Data for advertising.

5. Cookies and Tracking

OS Lite currently uses only essential authentication/session storage and operational error and security monitoring. We do not use advertising cookies or non-essential analytics in OS Lite. If that changes, we will complete a consent review and update this notice and any required controls first.

6. Security, Retention, and International Access

We maintain the safeguards described in the Security Exhibit, including tenant isolation, encryption in transit and at rest, role-based access, and logging. Retention follows the criteria in Section 2; when a service or account ends, we delete associated data from active systems within sixty (60) days, subject to legal retention and backup rotation. OS Lite is operated from the United States; Agencies may authorize their own users abroad, and our subprocessors process data in the locations listed on the Subprocessor List.

7. Your California Privacy Rights

If the CCPA/CPRA applies to your information held by COVU as a business, you have the right to: know/access the personal information we hold; delete it; correct it; opt out of sale or sharing (we do neither); limit use of sensitive personal information (we use it only for permitted service purposes); and non-discrimination for exercising rights. Some insurance-transaction information may instead be governed by the Gramm-Leach-Bliley Act or the California Insurance Information and Privacy Protection Act; where an exemption applies we will say so in our response.

Submit requests to dataprotection@covu.com from your account email, or through your Agency administrator. We verify requests using your authenticated account and recent activity; an authorized agent may submit a request with signed permission and verification of your identity. We honor Global Privacy Control signals as an opt-out where an opt-out right applies. We respond within the statutory period, and requests concerning Agency Customer Data are forwarded to the responsible Agency, which we assist.

8. Changes and Contact

We will update this notice as OS Lite evolves and at least review it annually; the version and effective date appear at the top, and material changes are notified in-product. Questions or requests: dataprotection@covu.com, or COVU, Inc., Attn: Privacy, 370 Convention Way, Redwood City, CA 94063.


Change log

  • v0.9-draft (July 16, 2026) — initial complete draft per the approved OS Lite Legal and Compliance Design (2026-07-15); pending counsel review.
  • v1.0 (July 16, 2026) — published to production pending counsel validation; content unchanged from v0.9-draft.