corvie

Privacy Policy

Corvie saves and organizes browser tabs at the user's request. Free libraries are stored locally in the user's browser. Paid synced libraries are end-to-end encrypted: corvie's servers store only ciphertext they cannot read. Corvie does not sell user data, use user data for advertising, or collect page body content, keystrokes, financial information, health information, or location.

Last updated: July 21, 2026

Overview

Corvie is a browser extension for saving, organizing, searching, and revisiting browser tabs as structured sessions. This policy explains what data corvie collects, how that data is used, and when it is shared with service providers.

Controller And Contact

Corvie is operated by Corvie LLC. For privacy questions or requests, contact support@corvie.app.

Data corvie Collects

End-to-End Encryption

Free local-only libraries are stored in the browser's extension storage on that device and are not uploaded to Firebase by corvie. They do not sync across browsers or platforms unless the user upgrades to corvie cloud and explicitly uploads the local library.

Saved tab data and user-created organization data are encrypted on the user's device before they sync through corvie cloud. Corvie's servers store only encrypted data and an encrypted ("wrapped") copy of the user's data key; the passphrase that unlocks it never leaves the user's devices, so neither corvie nor its service providers can read a synced library.

How Data Is Used

Lawful Bases

Data Sharing

Corvie uses browser extension storage for free local libraries. For paid cloud features, Corvie uses Firebase and Google Cloud for authentication, syncing, Firestore storage, Cloud Functions, backup storage, and security operations. Corvie uses Stripe for paid subscription checkout, billing management, and subscription status webhooks. Synced library content reaches those services only in encrypted form, except for explicit hosted AI requests as described above. Hosted AI requests use Google Vertex AI (Gemini). Corvie uses Vertex AI, Google Cloud's enterprise AI platform, specifically for the stronger contractual protections it provides: requests are processed under Google Cloud's terms and the Cloud Data Processing Addendum, Google documents that Vertex AI customer prompts and outputs are not used to train its foundation models, and Corvie's access uses a narrowly scoped service identity rather than shared API keys. Hosted AI requests are processed to generate the response and are not retained by Corvie beyond the request. Optional Google Calendar connections use Google's read-only Calendar APIs. Corvie uses Buttondown to deliver optional product updates only to verified users with an active paid subscription who have opted in through their corvie account. The Buttondown API key remains on corvie's servers; the website and extension do not receive it. Buttondown processes the account email address and manages email delivery and unsubscribes. Corvie uses ZeptoMail (Zoho) to deliver account and subscription emails, such as verification, password reset, security notices, and Pro subscription confirmations; these messages carry the recipient's email address, and open and click tracking are disabled. The corvie.app website is served through Cloudflare, which processes visitor IP addresses to deliver the site; website fonts are self-hosted, so pages do not request fonts from third-party servers. Corvie does not sell user data, transfer user data to data brokers or advertising platforms, or use user data for personalized advertising.

Retention And Backups

Free local-only library data remains in the user's browser extension storage until the user deletes it, clears browser data, removes the extension, or loads another backup. Live account and synced library data are kept until the user deletes their data or account. Firestore point-in-time recovery is retained for 7 days, daily managed backups for 14 days, and weekly managed backups for 14 weeks. Disaster backup bucket snapshots are kept according to the bucket lifecycle and retention policy. When a user deletes data or an account, corvie records a minimal erasure tombstone so deleted users can be re-deleted if an older backup is ever restored.

Buttondown keeps a subscriber record only while the user is eligible and opted in. Corvie deletes that record when the user opts out, uses an email unsubscribe link, or no longer has an active paid subscription. Corvie may retain a minimal consent and opt-out record to honor the user's choice and meet legal obligations.

Pro Product Update Choices

Optional product updates are off unless a verified user with an active paid subscription turns them on in corvie. The user can turn them off in the website or extension account settings, and every optional product email includes an unsubscribe link. Product updates stop automatically when the paid subscription ends. These choices do not affect security, billing, verification, password, or other essential service emails.

User Rights

Depending on location, users may have rights to be informed, access their personal data, correct inaccurate data, export data in a machine-readable format, delete data, restrict or object to processing, withdraw consent, and complain to a supervisory authority. Corvie provides in-app export and deletion controls where available. Consent for optional product updates can be withdrawn in account settings or through the unsubscribe link in any such email. Requests can also be sent to support@corvie.app.

Remote Code

Corvie does not execute remotely hosted code. Network requests are used for authentication, syncing, storage, and optional AI/data processing.

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.