Legal
Privacy Policy
Effective date August 25, 2026
Scope and operator
This policy explains how Corvid handles personal information on the public website and in account, organization, and enterprise features. Corvid is an independent project operated by Ayan Mishra in Massachusetts, United States, who is the controller or business responsible for the information described here.
Corvid is a U.S.-focused, area-level planning service. This policy does not cover third-party public-data websites linked from Corvid or information those publishers independently collect.
Information collected
- Identifiers and account data: email address, Supabase authentication identifier, verification and recovery events, account status, and security events. Supabase processes passwords and session credentials; Corvid does not display or store readable passwords.
- Saved coarse location: one state, county name, and county FIPS code as an account location preference. Corvid does not request a street address or precise GPS location.
- Organization data: organization name, membership, roles, invitation email addresses, invitation status, and saved state or county regions.
- Agreement records: Terms and Privacy Policy versions, acceptance timestamps, an account identifier, and a one-way hash of the account email retained as evidence of agreement.
- Technical data: IP address, request time and path, browser or user-agent information, cookie/session events, and error or security logs that hosting, authentication, and network systems generate to deliver and protect the service.
- Communications: information you choose to send in support, privacy, security, or enterprise inquiries.
Corvid does not ask for a legal name, phone number, street address, payment card, Social Security number, precise geolocation, or individual health history in the current product.
Sources and purposes
We receive information directly from you, from organization administrators who invite you, automatically from your browser and service infrastructure, and from service providers that support authentication and hosting.
We use it to create and secure accounts; maintain account location preferences and organization workspaces; manage access, invitations, and saved regions; remember legal and theme choices; communicate about requests; diagnose errors and abuse; maintain source and system integrity; enforce the Terms; comply with law; and establish, exercise, or defend legal claims.
Corvid does not use personal information to infer an individual health condition or to make a decision producing legal or similarly significant effects about a person.
Service providers and disclosure
Supabase provides authentication, database, session, and related infrastructure. Render provides application hosting and may process request and security logs. Sentry receives privacy-minimized application error reports; Corvid disables session replay, user identity, request bodies, cookies, headers, query strings, and performance tracing in that integration. Authentication email delivery may be performed by Supabase and its configured email provider. These providers process information to provide services to Corvid and under their own security and legal obligations.
Official public-data requests are made by Corvid's server. We do not intentionally send your account identity or saved county to a health-data publisher.
We may disclose information when required by valid legal process; to investigate abuse or protect the rights, safety, and security of users, the public, Corvid, or others; with professional advisers under duties of confidentiality; or in a financing, reorganization, sale, or transfer of the service with appropriate notice and safeguards.
Corvid does not sell personal information, share it for cross-context behavioral advertising, use targeted advertising, or disclose it to data brokers.
Health-data boundary
A saved county is an account preference and does not state that you live there. Population-health reports use the region selected for that report, not a personal health profile. Corvid does not use either selection to infer your health. The service is not designed to receive protected health information, maintain medical records, or create a personal health record.
Do not send symptoms, diagnoses, treatments, patient identifiers, insurance information, or other individual health information through account fields, organization names, invitations, support email, or any other Corvid channel. If you accidentally send such information, contact us and identify the message without repeating the sensitive content.
Retention
- Active account, saved county, organization membership, and saved regions: kept while needed to provide the active account or organization, then deleted through the account-deletion process unless a narrow legal exception applies.
- Invitations: links expire after 14 days. Related records may remain while the organization is active to prevent replay, document administration, and resolve disputes; they are deleted when the governing organization or inviting account deletion rules remove them.
- Agreement evidence: a pseudonymous account identifier, one-way email hash, policy versions, and acceptance time are retained for six years, matching the period in which contractual claims may need to be established or defended.
- Support and enterprise correspondence: kept while the request or relationship is active and afterward only as reasonably needed for follow-up, legal obligations, or claims.
- Security, access, and error logs: kept for the shortest period supported by the relevant provider and reasonably needed to detect abuse, investigate incidents, maintain reliability, or comply with law.
- Backups: deleted or overwritten on the provider's normal backup cycle. Information isolated in a backup is not returned to active use except for disaster recovery, security, or legal necessity.
We review retention when the purpose, product, provider, or law changes and delete or de-identify information that is no longer reasonably necessary.
Security and breach notice
Corvid uses least-privilege access, row-level database authorization, password reauthentication for account deletion, encrypted network transport, restricted security headers, dependency and code checks, versioned migrations, and provider safeguards. Administrative, technical, and physical measures are reviewed in proportion to the service's size, resources, and information. No internet service can guarantee absolute security.
If a security incident requires notice, Corvid will notify affected people and regulators as required by applicable law. Depending on the information and circumstances, those laws may include Massachusetts General Laws chapter 93H and 201 CMR 17.00, California's breach-notification law, and the FTC Health Breach Notification Rule. Report a suspected vulnerability through security.txt or email security@corvid.health. Do not include exploited data.
Account and data deletion
If you can sign in, open Account settings and use Delete account. The control requires your current password and an explicit DELETE confirmation. Signing out only ends the browser session; it does not delete information.
Deletion removes the active authentication record, saved county, membership, and invitations created by the account. A sole-member organization and its saved regions are also deleted. If other members remain, another administrator must exist before an owner can delete the account. Limited agreement evidence, provider backups, security records, or logs remain only for the periods and purposes described above.
If you cannot sign in or want help with information outside the active account, email privacy@corvid.health with “Corvid data deletion request” in the subject. Provide enough information to locate the account, but do not send a password or health information. We will verify the request before acting.
Privacy rights
You may request access to or a portable copy of personal information, correction, deletion, restriction, or an explanation of processing by emailing privacy@corvid.health. You may appeal a denied request through the same address with “Privacy appeal” in the subject. Authorized agents may submit requests where law permits; we may verify the authorization and your identity.
We will use request information only for verification and fulfillment, will not discriminate against you for exercising a right, and will respond within the period applicable to the request. We aim to acknowledge requests within 10 business days. When the California Consumer Privacy Act applies, verified access, correction, deletion, and portability requests generally receive a substantive response within 45 days, subject to a lawful extension.
Rights have legal exceptions, including security, fraud prevention, free expression, legal obligations, and establishing or defending claims. We will explain a denial where required.
California notice
California's Online Privacy Protection Act applies to commercial online services that collect personally identifiable information from California consumers. The disclosures in this policy identify the categories collected, uses, recipients, review and deletion methods, tracking response, effective date, and change process.
If Corvid becomes a “business” subject to the California Consumer Privacy Act, California residents may exercise rights to know, access, correct, delete, and obtain a portable copy; opt out of sale or sharing and certain automated decision-making; limit certain uses of sensitive personal information; and receive equal service. Corvid currently extends access, correction, and deletion request channels regardless of whether statutory thresholds apply.
During the preceding 12 months, Corvid has collected the categories described above: identifiers, coarse location, account and organization activity, internet or electronic-network activity, communications, and agreement/security records. The service has disclosed those categories to infrastructure providers for business purposes. It has not sold or shared them for cross-context behavioral advertising. Corvid does not have actual knowledge that it sells or shares information of anyone under 16.
County-level location is not precise geolocation. Account credentials are processed as sensitive personal information only to authenticate and secure the requested service. Corvid does not use sensitive personal information to infer characteristics about a person. There is therefore no current “Limit the Use of My Sensitive Personal Information” activity beyond the service purposes described here.
Children
Corvid is a general-audience service for adults and is not directed to children. Accounts require confirmation that the user is at least 18. We do not knowingly collect personal information from a child under 13. If you believe a minor created an account, contact us so we can investigate and delete it.
Changes and contact
We may update this policy when data practices, providers, the product, or law changes. The effective date identifies the current version. Material changes will receive additional notice and, where appropriate, a new acknowledgment before protected product access continues. Prior versions and acceptance records are retained only as needed for legal and audit purposes.
Questions, privacy requests, and complaints may be sent to privacy@corvid.health. You may also contact the relevant state attorney general or privacy regulator. Do not include passwords, patient records, or other sensitive health information.