Privacy Policy

Last updated: September 6, 2026

This Privacy Policy explains what Covalent ("the Platform", "we", "us") collects, why, who can see it, and what control you have. We have written it in plain language on purpose: this is a service people use to talk about difficult things, and you should be able to understand exactly what happens to what you write before you write it.

1. What we collect

When you create an account we collect the information you give us:

  • Your email address — used to sign in, verify your account, and send account emails (password resets, verification).
  • A username of your choosing — this is the only identifier other members of your circle ever see.
  • Your name, if you provide one — never shown to other members.
  • The challenge you are facing, and optionally a description of your situation — used to match you with a relevant circle.
  • Optional profile details you may provide, such as preferred languages, location, timezone, gender, date of birth or occupation — used to improve matching.

As you use the Platform we also store the content you create: the messages you send in your circle's chat, your diary entries, and any reports you submit. We record basic technical metadata such as timestamps, and the IP address associated with a password reset request (a security measure against abuse of that flow).

We do not ask for, and you should not share, government identification numbers, financial details, or clinical records. Covalent is free during the launch period and we do not process payments.

2. Your diary is private to you

Your diary is visible only to you. Access is enforced by a database-level security rule that permits reading and writing a diary entry only to the account that created it. No part of the Covalent application — including the moderation and administration tools our team uses — is able to query, display, or export diary entries. There is no staff screen anywhere that shows them.

The one caveat we owe you honestly: your entries are stored in our database, and, like any hosted service, our infrastructure provider and a small number of technical personnel hold credentials capable of direct database access. That access is not used to read diaries, and no product feature exposes them. Your entries are not end-to-end encrypted, which means we cannot claim it is technically impossible for us to read them — only that we do not, and that nothing in the product allows it.

We do not use your diary entries to train machine-learning models, and we do not share them with anyone.

3. Your circle chat

Messages you send in your circle are visible to the other members of that circle — normally 4 to 6 people — and are not public or indexed. Other members see your chosen username, never your real name or email address.

Circle messages can be reviewed by our moderation team. This is a safety measure, not a marketing one, and we would rather state it plainly than imply a privacy we do not provide. Review happens when a member files a report, when our automated safety checks flag a message for possible risk (such as language suggesting someone may be in danger, sharing of contact details, or harassment), and when we investigate a suspected breach of the Terms.

A moderator may remove a message from a circle. Removed messages stop being visible to members but are retained so the action can be reversed if it was a mistake, and so evidence remains available if a safety matter escalates.

4. Who can see what

  • Other members of your circle: your username, and the messages you send in that circle. Nothing else.
  • Our team: your account details (including your email and name if you provided one), your circle messages when reviewed for the safety reasons described above, and any reports you file. Not your diary.
  • Nobody else: we do not sell your personal data, and we do not share it with advertisers or data brokers.

5. Service providers

We rely on a small number of third parties to operate the service: a cloud database and authentication provider that stores your account and content, a hosting provider that runs the application, and an email provider that delivers account emails such as verification and password resets. These providers process data on our behalf, under their own security obligations, and are not permitted to use it for their own purposes.

6. How long we keep your data

We keep your account and its content while your account is open. If you delete your account, we delete your profile, diary entries, circle messages, and associated records. Reports and moderation records connected to a safety matter may be retained where we have a legitimate interest in protecting other members, and we may retain limited records where the law requires it.

Password reset tokens expire 30 minutes after they are issued, and email verification links expire after 24 hours.

7. Your rights and choices

You may request access to, correction of, export of, or deletion of your personal data, and you may object to or restrict certain processing, in accordance with the data-protection rules applicable where you live. Write to admin.covalent@gmail.com and we will respond. You can also change your password from inside the app at any time, and delete your account by contacting us.

8. Safety and legal disclosure

Covalent is peer support, not a clinical or emergency service, and we are not able to monitor circles in real time or intervene in an emergency. If we believe there is a credible risk of serious harm to someone, or if we are required to by a valid legal process, we may disclose relevant information to the appropriate authorities. If you are in crisis, please contact your local emergency services or a crisis line — that is the fastest way to get real help.

9. Security

Data is transmitted over encrypted connections and stored with access controls enforced at the database level. Passwords are stored hashed by our authentication provider and are never visible to us. No system is perfectly secure, and we will not pretend otherwise: if a breach affects your personal data, we will notify you and the relevant authority as required by law.

10. Children

Covalent is not intended for people under 18. We do not knowingly collect data from children. If you believe a minor has created an account, write to us and we will remove it.

11. Changes to this policy

If we make a material change to how we handle your data, we will update the date at the top of this page and notify registered users by email before the change takes effect.

12. Contact

For any question about this policy or your data, write to admin.covalent@gmail.com. Covalent operates under the laws of Uruguay, as set out in our Terms & Conditions.

Covalent is peer support, not a substitute for professional mental health care. If you're in crisis or thinking about harming yourself, please contact your local emergency services or a crisis line right away — you deserve immediate, professional support.