Core
Privacy Policy
How Colver handles account, agent, file, usage, and payment data.
- Last updated
- September 5, 2026
- Operator
- Colver.im
Browser extension
The optional Colver Browser Agent extension acts only within a session you start. You choose the current tab, add tabs, or allow all currently open eligible tabs. Page text, control labels, requested screenshots and action results from those tabs are sent to Colver and the configured model providers to perform your task. The extension does not collect an unrelated browsing history or access incognito windows.
Attaching a file transfers the file you selected in Colver to the website receiving the upload. Downloads are saved through your browser. Local file paths, browser cookies and password-manager vaults are not made available to the agent. Passwords, verification codes and payment fields require direct user interaction; automatic detection cannot identify every custom sensitive widget.
A revocable device credential and session metadata are stored in the extension. Results awaiting delivery are held locally until the server acknowledges them or the browser is disconnected or its credential expires. Stopping a session ends control; disconnecting revokes the browser link. It does not automatically erase results already stored with the service. The retention and access, export and deletion procedures below apply to those records.
Browser data is used to provide and secure the requested browser assistance. Colver does not sell this data, use it for advertising or use it to train its own models. Configured model providers process selected context as explained below. Colver's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including its Limited Use requirements.
1. Controller and scope
Colver.im is the controller for account, website, billing, support, and direct product-use data. Contact: help@colver.im.
For business content that a customer submits about other people, the customer may be the controller and Colver its processor. The Data Processing Addendum describes that relationship.
2. Data we process
| Category | Examples |
|---|---|
| Account and profile | Identity account reference, email, name, username, country, preferred language, time zone, interests, discovery source, consent records |
| Agent and conversation | Prompts, responses, saved agent definitions, instructions, memory, evaluations, tool approvals, and session state |
| Files and content | Uploaded files, file metadata, generated artefacts, and content retrieved through an approved connector or browser session |
| Secrets and connections | Encrypted secret values, secret metadata, connector identity and authorisations, tool scopes, and revocation state |
| Billing and credits | Payment customer and subscription references, invoice and plan events, credit grants, reservations, consumption, referrals, and fraud signals |
| Shared agents | Publication settings, creator identity shown to visitors, authenticated access, visitor sessions, usage totals, and revocation events |
| Technical and support | IP address, device and request data, security events, minimal telemetry, request identifiers, diagnostics, and support messages |
3. Why we use data
| Purpose | Legal basis |
|---|---|
| Create and secure your account; provide chats, agents, files, tools, memory, and sharing | Performance of the contract |
| Process subscriptions, credits, invoices, and referrals | Performance of the contract; legal obligations; legitimate interests in preventing fraud |
| Operate security, isolate users, prevent abuse, debug failures, and protect the service | Legitimate interests; legal obligations where applicable |
| Comply with valid legal requests, accounting, tax, and consumer duties | Legal obligation |
| Send product or marketing email | Consent where required; you can withdraw it at any time |
| Improve reliability and product design using minimised operational information | Legitimate interests, balanced against your rights |
We do not sell personal data or use customer content to train a Colver-owned foundation model.
4. AI and automated processing
Prompts and selected context are sent to configured model providers so Colver and created agents can respond. Tools receive only the information needed for the approved action. Generated results are probabilistic and should be reviewed.
Credit reservations, fraud checks, abuse controls, and security rules can operate automatically. They do not make a solely automated decision with legal or similarly significant effects about you. If an automated control blocks legitimate use, contact us for review.
6. International transfers
Colver selects EU regions where the relevant provider offers and contractually supports them. Some providers operate global networks or process data outside the EEA, and model or connector destinations can depend on your configuration. We do not currently claim that every processing operation remains exclusively in the EU.
Where Chapter V of the GDPR applies, transfers rely on an adequacy decision, the EU Standard Contractual Clauses, or another lawful mechanism, together with supplementary measures where appropriate.
7. Retention
We keep account and workspace data while the account or workspace is active and for a limited period afterwards where needed to provide recovery, resolve disputes, enforce agreements, or meet legal duties. Billing and tax records are kept for the period required by law.
Monthly and free credit grants expire at the end of their credit period and do not roll over. Purchased top-ups do not expire. Referral credit grants expire after 90 days. Remote browser sessions are short-lived and are closed after the configured idle or heartbeat period; Colver does not intentionally keep a browser recording. Security and observability data is minimised and kept only as long as needed for operational and legal purposes.
A self-service deletion control is not yet available for every data category. You can request access, deletion, or export by email. We will also account for backups, legal holds, and data that another user is entitled to retain.
8. Security
Colver uses authenticated access, tenant and user isolation, encrypted transport, private object storage, encrypted write-only secrets, scoped connector permissions, short-lived capabilities, approvals for sensitive actions, and scrubbed observability. No system is completely secure.
Do not send secrets in chat. Use the dedicated secret interface, where replacement overwrites the stored value and the existing value is never shown back to a user or model.
9. Your rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or an objection to processing. You may withdraw consent without affecting earlier lawful processing. You may also ask for information about transfer safeguards.
Send a request to help@colver.im. We may need to verify your identity. You may complain to the Spanish Data Protection Agency (AEPD) or your local supervisory authority.
10. Children and changes
Colver is not intended for people under 18, and we do not knowingly offer accounts to children.
We will update this policy when product or legal practices materially change. The date at the top identifies the current version. Material changes will be communicated where required.