Data practices
Privacy Policy
How Konvoa handles account, application, license, device, session, billing, security, reseller, and owner-controlled release-link data.
Effective
Scope and roles
This Policy describes personal information handled through konvoa.com, the Konvoa console, management APIs, reseller automation, and the desktop authentication protocol. It does not cover an application owner’s website, application, payment page, support process, or external download host.
For workspace account and site-operation data, the Operator determines why the information is processed. For customer-account, license, device, and release-access data submitted for an owner’s application, the application owner determines the customer relationship and instructs Konvoa through product configuration. Owners must provide their own privacy notice and lawful instructions to their customers.
Information Konvoa handles
Workspace and relationship data
Konvoa stores an account email address, display name, password hash, plan state, account and workspace identifiers, login times, team invitation email addresses, roles, application scopes, reseller usernames, permission grants, and credential metadata. Complete passwords, invitation tokens, browser-session nonces, and reseller API secrets are not stored in recoverable form by the current service.
Application and customer authentication data
Depending on an owner’s integration and settings, Konvoa handles application names and identifiers, customer usernames, password hashes, license and subscription records, access expiration, account status, device or installation identifiers, device public keys, hardware-binding values, session identifiers, application versions, executable hashes, signed request metadata, request identifiers, timestamps, and nonces.
Release and file data
Konvoa stores owner-supplied file IDs, labels, direct HTTPS URLs, expected SHA-256 digests, release notes, versions, channels, and subscription scopes. Konvoa does not upload, fetch, proxy, inspect, or store the application bytes at those URLs.
Network, browser, and security data
Requests necessarily expose an IP address to Konvoa’s edge and origin infrastructure. The application database uses masked IP hints for browser-session display and keyed or one-way IP hashes in security events rather than retaining a full IP in those records. Konvoa also handles user-agent strings, request timing, authentication outcomes, revocation activity, and bounded audit details. Web-server, edge, and provider logs may separately process network metadata.
Billing data
When billing is enabled, Konvoa sends Stripe the workspace email, account reference, selected plan, and checkout metadata. Konvoa stores Stripe customer and subscription identifiers, verified subscription state, checkout identifiers, and a sanitized invoice-event history including currency, amount, status, and billing period. Card numbers, payment-method details, and hosted invoice URLs are handled by Stripe and are not stored in Konvoa’s application database.
How information is used
Konvoa uses information to create and secure accounts; authenticate users and devices; evaluate current application, license, subscription, version, file, and network policies; issue and revoke sessions; operate team and reseller permissions; process subscriptions; prevent replay, fraud, abuse, and credential misuse; investigate failures; maintain audit trails; enforce limits; and comply with legal obligations.
Konvoa does not currently include an advertising or cross-site analytics tracker, and does not sell personal information or use it for targeted advertising.
Legal bases
Where data-protection law requires a legal basis, processing may be necessary to perform the service agreement, pursue legitimate interests in providing and securing Konvoa, comply with law, establish or defend legal claims, or act on consent where consent is specifically requested. Application owners are responsible for identifying the basis that applies to data they direct Konvoa to process about their customers.
Retention
Konvoa keeps account, application, license, release, workspace, and billing records while they are needed to provide the service and afterward when necessary for security, fraud prevention, disputes, legal obligations, backups, and referential integrity. Certain reseller delivery, balance, published-version, and verified invoice histories are intentionally immutable so later changes cannot rewrite the audit record.
Active application security events are bounded in the service database and are configured to prune after approximately 30 days or when the table exceeds its configured row limit. Expired console sessions are purged, and revoked console-session records are eligible for removal after 24 hours. Those application-level schedules do not by themselves define retention in edge logs, operational backups, billing systems, or a customer’s own systems.
There is not yet a self-service account-deletion workflow. A verified deletion or closure request must use the contact channel below. Konvoa may retain records that cannot lawfully or safely be deleted, and will explain applicable limits when responding to a request.
Security
Konvoa uses measures including password hashing, protected license-key storage, one-way session and token digests, scoped authorization, a public HTTPS endpoint, signed application messages, request replay controls, bounded input, rate limits, revocation, and audit logging. Edge-to-origin encryption and certificate validation depend on the Operator’s production infrastructure configuration and must be verified before launch. No system is completely secure, and client software running on a customer-controlled device can be inspected or modified.
Your choices and rights
You can update a workspace display name and password, review and end browser sessions, revoke team or reseller access, and manage application customer records through available controls. Depending on your location, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to appeal or complain to a regulator.
For data associated with a third-party application, contact that application’s owner first because the owner controls the customer relationship and can identify the relevant account. For Konvoa workspace data, contact the Operator below. Konvoa may verify identity and authority before acting on a request.
International processing
Konvoa and its providers may process information in locations different from where a user lives. No hosting country or transfer mechanism has been inferred from the source code. The Operator must document the actual hosting locations, service-provider terms, and any transfer safeguards required for the jurisdictions served before commercial launch.
Children
Konvoa is a business service for software operators and is not directed to children. Application owners must not use Konvoa to collect children’s personal information unless they have established every consent, notice, and protection required by applicable law.
Changes to this Policy
Changes will be reflected by a revised effective date. Material changes will receive additional notice through the service or another available account channel when required by law.
Contact
The configured legal operator is Konvoa. Contact [email protected] for privacy requests and legal questions.
The Operator must additionally document its legal identity, privacy jurisdiction, physical notice address if required, hosting locations, subprocessors, and request-handling procedure with qualified counsel. Konvoa does not claim a certification or regulatory status that has not been established.