Skip to main content
Colver
How Colver worksPricing
Sign inBuild an agent
Legal centre
  • Legal notice
  • Consumer terms
  • Withdraw from a contract
  • Privacy
  • Cookies
  • Acceptable use
  • Shared agents
  • Report illegal content
  • Credits and plans
  • Referrals
  • Connectors and browser
  • Business terms
  • Data processing
  • Provider categories
  • Data export
  • Security
Legal centre

Core

Privacy Policy

How Colver handles account, agent, file, usage, and payment data.

Last updated
September 5, 2026
Operator
Colver.im

On this page

  1. Browser extension
  2. 1. Controller and scope
  3. 2. Data we process
  4. 3. Why we use data
  5. 4. AI and automated processing
  6. 5. Who receives data
  7. 6. International transfers
  8. 7. Retention
  9. 8. Security
  10. 9. Your rights
  11. 10. Children and changes

Browser extension

The optional Colver Browser Agent extension acts only within a session you start. You choose the current tab, add tabs, or allow all currently open eligible tabs. Page text, control labels, requested screenshots and action results from those tabs are sent to Colver and the configured model providers to perform your task. The extension does not collect an unrelated browsing history or access incognito windows.

Attaching a file transfers the file you selected in Colver to the website receiving the upload. Downloads are saved through your browser. Local file paths, browser cookies and password-manager vaults are not made available to the agent. Passwords, verification codes and payment fields require direct user interaction; automatic detection cannot identify every custom sensitive widget.

A revocable device credential and session metadata are stored in the extension. Results awaiting delivery are held locally until the server acknowledges them or the browser is disconnected or its credential expires. Stopping a session ends control; disconnecting revokes the browser link. It does not automatically erase results already stored with the service. The retention and access, export and deletion procedures below apply to those records.

Browser data is used to provide and secure the requested browser assistance. Colver does not sell this data, use it for advertising or use it to train its own models. Configured model providers process selected context as explained below. Colver's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.

1. Controller and scope

Colver.im is the controller for account, website, billing, support, and direct product-use data. Contact: help@colver.im.

For business content that a customer submits about other people, the customer may be the controller and Colver its processor. The Data Processing Addendum describes that relationship.

2. Data we process

CategoryExamples
Account and profileIdentity account reference, email, name, username, country, preferred language, time zone, interests, discovery source, consent records
Agent and conversationPrompts, responses, saved agent definitions, instructions, memory, evaluations, tool approvals, and session state
Files and contentUploaded files, file metadata, generated artefacts, and content retrieved through an approved connector or browser session
Secrets and connectionsEncrypted secret values, secret metadata, connector identity and authorisations, tool scopes, and revocation state
Billing and creditsPayment customer and subscription references, invoice and plan events, credit grants, reservations, consumption, referrals, and fraud signals
Shared agentsPublication settings, creator identity shown to visitors, authenticated access, visitor sessions, usage totals, and revocation events
Technical and supportIP address, device and request data, security events, minimal telemetry, request identifiers, diagnostics, and support messages

3. Why we use data

PurposeLegal basis
Create and secure your account; provide chats, agents, files, tools, memory, and sharingPerformance of the contract
Process subscriptions, credits, invoices, and referralsPerformance of the contract; legal obligations; legitimate interests in preventing fraud
Operate security, isolate users, prevent abuse, debug failures, and protect the serviceLegitimate interests; legal obligations where applicable
Comply with valid legal requests, accounting, tax, and consumer dutiesLegal obligation
Send product or marketing emailConsent where required; you can withdraw it at any time
Improve reliability and product design using minimised operational informationLegitimate interests, balanced against your rights

We do not sell personal data or use customer content to train a Colver-owned foundation model.

4. AI and automated processing

Prompts and selected context are sent to configured model providers so Colver and created agents can respond. Tools receive only the information needed for the approved action. Generated results are probabilistic and should be reviewed.

Credit reservations, fraud checks, abuse controls, and security rules can operate automatically. They do not make a solely automated decision with legal or similarly significant effects about you. If an automated control blocks legitimate use, contact us for review.

5. Who receives data

We use service providers for identity, hosting, private object storage, model routing, model inference, observability, payments, connectors, and remote browser sessions. The current providers and processing locations are listed in the Subprocessor List.

A connector sends data to the external service you choose. An agent creator does not automatically receive a visitor's private chat, files, secrets, or connected-account data. We may disclose data where required by law, to protect rights and safety, or as part of a business transfer subject to appropriate safeguards.

6. International transfers

Colver selects EU regions where the relevant provider offers and contractually supports them. Some providers operate global networks or process data outside the EEA, and model or connector destinations can depend on your configuration. We do not currently claim that every processing operation remains exclusively in the EU.

Where Chapter V of the GDPR applies, transfers rely on an adequacy decision, the EU Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where appropriate.

7. Retention

We keep account and workspace data while the account or workspace is active and for a limited period afterwards where needed to provide recovery, resolve disputes, enforce agreements, or meet legal duties. Billing and tax records are kept for the period required by law.

Monthly and free credit grants expire at the end of their credit period and do not roll over. Purchased top-ups do not expire. Referral credit grants expire after 90 days. Remote browser sessions are short-lived and are closed after the configured idle or heartbeat period; Colver does not intentionally keep a browser recording. Security and observability data is minimised and kept only as long as needed for operational and legal purposes.

A self-service deletion control is not yet available for every data category. You can request access, deletion, or export by email. We will also account for backups, legal holds, and data that another user is entitled to retain.

8. Security

Colver uses authenticated access, tenant and user isolation, encrypted transport, private object storage, encrypted write-only secrets, scoped connector permissions, short-lived capabilities, approvals for sensitive actions, and scrubbed observability. No system is completely secure.

Do not send secrets in chat. Use the dedicated secret interface, where replacement overwrites the stored value and the existing value is never shown back to a user or model.

9. Your rights

Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or an objection to processing. You may withdraw consent without affecting earlier lawful processing. You may also ask for information about transfer safeguards.

Send a request to help@colver.im. We may need to verify your identity. You may complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority.

10. Children and changes

Colver is not intended for people under 18, and we do not knowingly offer accounts to children.

We will update this policy when product or legal practices materially change. The date at the top identifies the current version. Material changes will be communicated where required.

Questions about this document?help@colver.im
Colver

Agents built for specific work.

  • Legal centre
  • Security
  • Contact
© 2026 colver.imOperated from Barcelona, Spain.
ENEnglishESEspañolITItalianoFRFrançais
TermsPrivacyCookies