Skip to content

Privacy Policy

Effective September 30, 2026

This policy explains how Dyad Tech, Inc., doing business as Kovo (“Kovo”, “we”, “us”), handles information when you use the Kovo website at kovo.sh, the Kovo dashboard, the Kovo GitHub App, the Kovo API and the emails we send (together, the “Service”). Questions or requests: privacy@kovo.sh.

Kovo is a service for businesses. It finds dangerous vulnerabilities in the npm dependencies of GitHub repositories, prepares and verifies fixes, and opens pull requests. When an organization connects its repositories, that organization decides what Kovo can access, and we process its repository content only to provide the Service it enabled.

Information we collect

From your GitHub sign-in

Kovo has no passwords: you sign in with GitHub. We receive your GitHub user ID, username, display name, profile image URL and verified email address. We store the GitHub access and refresh tokens that let Kovo check your current repository permissions, encrypted at rest. For each sign-in session we record its IP address and browser user agent for security.

From the Kovo GitHub App

When an organization or person installs the Kovo GitHub App, we receive information about that installation and the repositories it covers:

  • account, organization and repository names and IDs;
  • the GitHub usernames, IDs and permission levels of organization members and repository collaborators, which we use to decide who may see or change what in Kovo (this can include people who have never used Kovo);
  • branch protection and required-check settings, pull request and check status;
  • your dependency manifests and lockfiles, from which we build an inventory of the packages and versions each repository uses, and the security findings that apply to them.

Repository source code

To prepare and verify a fix, Kovo checks out your repository in an isolated, temporary sandbox and runs its install, build and test commands. Source code is processed there and is not kept in Kovo's database, logs, error reports, analytics or emails. The only source Kovo stores is an encrypted copy of a proposed patch while it waits to be published as a pull request, deleted on publication or after 72 hours, whichever comes first. See How we handle source code and AI.

Configuration you give us

Verification recipes (including the install, build and test commands they run), repository policies, notification settings, webhook endpoints, invitations and API keys. We store only a hash of each API key.

Billing information

Your plan, subscription, invoices, spending limits and the usage and cost records behind any charge. Stripe collects and holds your payment card details; Kovo never receives the full card number.

Operational and security records

Request metadata (such as IP address, time, route and response status) in our logs; error reports with personal data and request bodies removed; and an audit trail of security- and permission-relevant actions, such as who approved a recipe or authorized autopilot.

Product analytics

If you allow analytics, we record a small set of product events, such as which Kovo pages were opened and when sign-in started, linked to your Kovo user ID. We also count account milestones, such as a first pull request or an upgrade. If you decline, nothing is collected in your browser and those milestones are counted for the Kovo account only, never linked to you. Analytics never includes page URLs, repository names, email addresses or code, and there is no session recording.

Messages you send us

The content of emails and support requests you send us, and our replies.

How we use information

Purpose Legal basis (where GDPR or UK GDPR applies)
Signing you in, checking repository permissions, finding vulnerabilities, preparing and verifying fixes, opening and (when authorized) merging pull requests, and sending alerts, digests and notifications you rely on Performance of our contract with you or your organization
Charging for subscriptions and approved usage; keeping accounting records Contract; compliance with legal obligations
Keeping the Service secure, preventing abuse, investigating errors and auditing sensitive actions Our legitimate interest in operating a secure, reliable service
Improving Kovo using aggregated, de-identified statistics, such as fix success rates by advisory or package Our legitimate interest in improving the Service
Product analytics in your browser and linked to your user ID Your consent, which you can withdraw at any time

We do not sell personal information, share it for cross-context behavioral advertising, or use it for automated decisions that have legal or similarly significant effects on you.

How we handle source code and AI

  • Isolated sandboxes. Your code runs in a temporary sandbox that holds no Kovo, GitHub, cloud or AI credentials. Each sandbox is destroyed when its step ends and cannot live longer than 60 minutes.
  • Free never uses AI. Fixes on the Free plan are made deterministically and your code is never sent to an AI model.
  • AI on Kovo Plus. On Plus, Kovo can use AI to help prepare a fix or discover how to verify your repository. Relevant parts of your repository are then sent to third-party AI model providers. A provider may keep prompts and outputs for up to 30 days to monitor for abuse, and may not use them to train models. Kovo itself does not keep raw prompts, model responses or tool output.
  • No training on your code. Neither Kovo nor our AI providers use your code to train AI models.
  • Pull requests stay yours. Pull requests Kovo opens, including their diffs, live in your GitHub repository under GitHub's terms, and Kovo does not delete them.

Cookies and browser storage

Kovo uses essential cookies to keep you signed in and to protect sign-in and forms against attack. Your analytics choice is stored in your browser's local storage. Analytics cookies and storage are used only after you allow analytics. If your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a refusal. You can change your choice at any time from the site footer or your Kovo profile settings. We do not use advertising cookies.

Who we share information with

We share information only as needed to run the Service, with these service providers acting on our behalf:

  • Google Cloud: hosting, storage, encryption keys, secrets and logs;
  • PlanetScale: the Kovo database;
  • GitHub: sign-in and the repository integration you install;
  • Daytona: isolated sandboxes that run your repository's code;
  • third-party AI model providers (Plus only), which may keep prompts and outputs for up to 30 days for abuse monitoring and never use them for training;
  • Stripe: payments, subscriptions and invoices;
  • Resend: transactional email;
  • Sentry: error reporting, with personal data and request bodies removed;
  • PostHog: browser and user-linked product analytics with your permission, and account-only milestone analytics.

We may also share information:

  • within your Kovo account: people see repositories, findings and fixes only while they have access to those repositories on GitHub, and billing managers see billing information;
  • when you direct it, for example to webhook endpoints or API clients you configure (you are responsible for those destinations);
  • when required by law, or to protect the rights, safety and security of our users, the public or Kovo;
  • with a successor if Dyad Tech, Inc. is involved in a merger, acquisition or sale of assets, subject to this policy.

How long we keep information

Information Kept for
Encrypted proposed patches Until the pull request is published, at most 72 hours
Sandboxes and the code in them Until the step ends, at most 60 minutes
Verification evidence, dependency-change history and inventory history 30 days
Current dependency inventory While the repository is protected, then up to 30 days
Recipes, policies and account configuration While the account exists, then up to 30 days
Email delivery records 30 days
Server logs 30 days
Error reports Up to 90 days
Prompts and outputs at AI model providers (Plus only) Up to 30 days, for abuse monitoring
Security and permission audit records 1 year
Product analytics (consented browser/user-linked events and account-only milestones) Up to 7 years
Invoices and financial ledger records 7 years, for accounting and tax purposes

When an account is deleted, its non-financial operational data is removed within 30 days; audit and financial records follow the periods above. Uninstalling the GitHub App starts the 30-day cleanup of that installation's repository data. Database backups expire on their own schedule, currently within a few days, and are not restored without reapplying deletions first. Stripe keeps its own records under its policies and legal obligations.

Where information is processed

Kovo is hosted in the United States. Some of our service providers, including AI model providers, may process information in other countries. Where data protection law requires it, we rely on appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses and the UK International Data Transfer Addendum.

Security

We encrypt data in transit and at rest, encrypt stored OAuth tokens and patches with separately managed keys, run untrusted code only in isolated sandboxes, keep secrets out of logs, limit staff access, and keep an audit trail of sensitive actions. No system is perfectly secure; if a breach affects your personal information, we will notify you and the authorities as the law requires.

Your choices and rights

  • Change your analytics choice at any time in the site footer or your profile settings.
  • Pause Kovo, remove repositories or uninstall the GitHub App from GitHub at any time. You can also revoke Kovo's sign-in access in your GitHub settings.
  • An account owner can delete a Kovo account in its settings once billing is settled.

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, to restrict or object to how we process it, and to withdraw consent. To make a request, email privacy@kovo.sh. We will verify your identity and respond within the time the law requires, and we will not treat you differently for exercising your rights. If your information is part of an organization's Kovo account, we may involve that organization's administrators. We may keep information we are legally required to keep, such as accounting records, and will tell you when that applies. If you are in the EEA or UK, you may also complain to your local data protection authority.

Children

Kovo is a business service and is not directed to anyone under 16. We do not knowingly collect personal information from children.

Changes to this policy

We will post changes here and update the effective date. If a change is material, we will tell you by email or in the dashboard before it takes effect.

Contact

Dyad Tech, Inc., doing business as Kovo. Privacy questions and requests: privacy@kovo.sh. Everything else: support@kovo.sh. See also our Terms of Service.