Short version: Your business data is stored in our secured Firebase infrastructure, isolated to your business so only you and the people you invite can read or write it. We don't sell your data, we don't mine it, and we don't look at it in the normal course of running the Service. We collect only what's necessary to run the service and process your subscription.
Covenant Works Operating System is a product of Covenant Works LLC, owned and operated by John Sydnor, Harlem, Georgia.
Contact for privacy questions: support@covenantworks.app
This app uses an architecture designed to keep your business data yours:
| Data | Purpose | Stored where |
|---|---|---|
| Email address | Account creation, login, billing notices | Our Firebase Authentication + Firestore |
| Subscription status and tier | Controlling which features you can access | Our Firebase Firestore (users collection) |
| Stripe customer ID | Linking your account to your subscription | Our Firebase Firestore (stripe collection) |
| Your business data | Running your business management tools | Our Firebase Firestore, isolated to your account — only you can read or write your own records |
| AI prompts and inputs | Generating AI responses via Claude API | Sent to Anthropic — see their privacy policy |
| Product search queries (Inventory Find) | Looking up live Google Shopping prices | Sent to SerpAPI — see their privacy policy |
| In-app feedback submissions | Improving the product during beta | Our Firebase Firestore (feedback collection) |
| Aggregate usage statistics | Understanding which features are used (tab visit counts, action counts, session frequency) — never linked to individual records | Our Firebase Firestore (user_meta collection) |
| Business-tier beta interest submissions (email, one-line business description, optional product opinion) | Reviewing applications to the Business-tier beta program. Submitted via the public form at /business/; an account is not required to submit. |
Our Firebase Firestore (business_beta_interest collection) — retained 12 months, then deleted |
The Service uses the following third-party providers. Each has its own privacy policy:
We use the information we collect to:
We do not send marketing emails without your consent. You can opt out of any non-essential communications at any time.
Account data (email, subscription status) is retained for as long as your account is active. If you close your account, we delete your account data, your business data, and our backups of it within 30 days of your request.
You own your business data and can export a full copy at any time using the in-app Export feature. We recommend exporting a backup before closing your account, because deletion is permanent and cannot be undone.
Business-tier beta interest submissions are retained for up to 12 months, then deleted. To request earlier deletion of a submission you made via the /business/ landing page form, email support@covenantworks.app with the email address you used. No account is required.
We use industry-standard security practices including Firebase Authentication, Firestore Security Rules that enforce per-business data isolation, and HTTPS for all data transmission. However, no system is perfectly secure. We encourage you to use a strong, unique password that you do not reuse on other sites, and to invite teammates with their own logins rather than sharing credentials.
The Service is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we will delete it promptly.
You have the right to:
To exercise any of these rights, email support@covenantworks.app. We will respond within 30 days.
We do not sell data, volunteer shop records, or run lookups across businesses. If we are legally compelled, we produce only what a valid instrument specifically names, and only if we actually store it.
Informal requests (email, phone, a lawyer’s letter that is not a court order) are refused. We will not search all businesses for a name, phone number, address, or keyword. We will not produce “all records,” “any and all data,” or “related accounts” without each account identified.
Valid process must be served on us (original or certified copy to support@covenantworks.app and our registered agent) and must include all of the following:
We then produce only the named categories for the named account and dates. We notify the account owner unless a court or other lawful gag forbids it, or notice would create a documented risk of death or serious harm.
We do not hold payment card numbers. AI prompts are sent to Anthropic (and some design images to Recraft) to generate a response; we do not keep a chat archive in our database. Inventory search words go to SerpAPI. Those providers have their own legal-process channels. Stripe holds payment details we never see.
This section is our public standard. It does not let us ignore a valid warrant or court order for records we hold. It does mean overbroad or informal demands are rejected.
We may update this policy as the Service evolves. We will notify you by email or in-app notice before material changes take effect. The date at the top of this page reflects the most recent update.
Privacy questions or requests: support@covenantworks.app
Covenant Works LLC · Harlem, Georgia
© 2026 Covenant Works LLC · Harlem, Georgia · Veteran-Owned Small Business
← Terms of Service ← Back to app