Privacy policy

What we collect, why we collect it, and how to make us delete it. Short, because we deliberately collect very little.

Last updated 27 September 2026

The short version. This website sets two first-party cookies, one of them only if you say yes, and runs no advertising or analytics scripts. The contact and campus forms send what you type to our inbox and nowhere else; the newsletter form opens your own email client. The product stores infrastructure metadata, never your application data.

1. Who we are

Coverops Private Limited operates coverops.dev and the CoverOps product. For questions about this policy or to exercise any right described below, contact office@coverops.dev.

2. What this website collects

Very little. The site is a set of static pages. It does not set analytics or advertising cookies, does not embed third-party trackers, and does not build a profile of you. The two cookies it can set are described below.

Our hosting provider records standard server logs (IP address, timestamp, requested path, and user agent) for security and reliability. These are retained briefly and are not used to identify individuals.

Cookies

The first time you visit, a banner asks before anything optional is stored. Accepting and refusing take one click each, and you can change your answer at any time from Cookie settings in the footer. If your browser sends a Global Privacy Control signal, we treat it as a refusal and do not ask.

  • co_consent (strictly necessary, 6 months): records your answer, the date you gave it, and the version of this list you answered. Storing a consent choice does not itself require consent. It is how we can show later what you agreed to.
  • co_meter (preferences, 12 months, only after you allow it): the number of seconds the idle meter on the home page has run, so it continues across refreshes and visits instead of starting again at zero. It counts only while a CoverOps page is visible in your browser. Refusing, or withdrawing consent later, deletes it.

Both cookies are first-party, are sent only to coverops.dev, and are never shared with or sold to anyone. Our lawful basis is your consent for co_meter (GDPR Art. 6(1)(a), India DPDP Act s.6) and necessity for co_consent. Our host may also set short-lived, strictly necessary security cookies to block abusive traffic.

Contact and newsletter forms

The contact form and the campus application form send only what you type into them when you press Send. Our server turns it into an email to office@coverops.dev (delivered through Google Workspace) and does not keep a separate copy. The newsletter form composes a message in your mail client, and we receive nothing unless you send it.

Once a message reaches us, we hold the message the way any business holds email it has been sent: to reply to you, and to keep a record of the conversation.

3. What the product collects

If you use CoverOps to manage infrastructure, we process:

  • Account data: the names, work email addresses, and roles of people on your team who use the product.
  • Infrastructure metadata: resource identifiers, configuration, plan output, policy results, and change history for the environments you connect.
  • Operational telemetry: metrics, logs, and traces you explicitly route to CoverOps for monitoring.
  • Usage data: which features are used and when, so we know what to improve.

We do not read your application data, your database contents, or the payloads in your object storage. The access role is not permitted to, as described in the security overview.

4. Why we process it

  • To provide the service you asked for: performance of our contract with you
  • To keep the service secure and investigate incidents: our legitimate interests
  • To reply to you when you contact us: our legitimate interests
  • To send product updates you opted into: your consent, withdrawable at any time

5. Who else sees it

We do not sell your data, and we do not share it for advertising. We use a small number of sub-processors to run the business (cloud hosting, email delivery, and error monitoring), each bound by contract to protect it.

The current sub-processor list is available on request, and we will give notice before adding one that processes customer data. Ask us at office@coverops.dev and we will send the current list.

6. How long we keep it

  • Account data: while your account is active, then up to 90 days
  • Infrastructure metadata: while the environment is connected, then up to 90 days
  • Operational telemetry: for the retention window you configure
  • Email correspondence: as long as needed for the business relationship

After termination we delete or anonymise what we hold. Your own infrastructure and repositories are untouched by this, because they were never ours.

7. Your rights

Depending on where you live you may have the right to access the personal data we hold about you, correct it, delete it, object to processing, restrict it, or receive a portable copy.

To exercise any of these, email office@coverops.dev. We will respond within one month. You will never need to pay, and we will not make it deliberately difficult. If you want your data gone, say so plainly and we will action it.

If you are unhappy with how we handled your request, you may complain to your local data protection authority.

8. How it is protected

Data is encrypted in transit and at rest. Access within our team is limited to the people who need it, and access to customer cloud accounts uses short-lived credentials rather than stored keys. More detail on the security page.

9. Changes to this policy

When this policy changes materially we will update the date at the top and, for account holders, tell you by email. We will not quietly broaden what we collect.

10. Contact

Anything at all about privacy: office@coverops.dev, or via the contact form.