Who this app is for
Covey is for adults 18 and older: parents, guardians, and trusted caregivers. Children do not create accounts or use the app directly. Any information about children is entered and managed entirely by an authorized adult. We do not knowingly collect personal information directly from children under 13.
What we collect
We collect only what is necessary to operate the service:
- Account information: your name, email address, and authentication credentials, managed via our authentication provider (Clerk).
- Household and role data: the household you belong to and your role (keeper or watcher).
- Children’s information: names, optional birthdays, optional care notes (e.g., allergies, bedtime), and optional photos, entered by a parent or guardian. This information is visible only to members of the household’s Covey.
- Coordination data: Whistles (scheduled care needs), availability blocks, and responses.
- Google Calendar connection data, only if you choose to connect Google Calendar: an encrypted Google OAuth refresh token, the email address of the Google Account you connected, the date you connected, and the identifiers of the calendar events Covey created on your behalf. See Google user data below.
- Push notification tokens: device/browser subscription tokens so we can deliver alerts when you need them.
- Usage and log data: standard server logs (IP address, browser type, pages accessed, timestamps) used for security monitoring and diagnosing errors. We do not use this data to build profiles or target advertising.
Google user data
Connecting Google Calendar is entirely optional. Covey works fully without it. If you choose to connect it, this section describes exactly what Covey accesses, how it is used, how it is stored, and how it is shared.
The permission we request, and why
Covey requests the Google Calendar scope described by Google as View and edit events on all your calendars (https://www.googleapis.com/auth/calendar.events). This scope technically permits viewing events. Covey uses it only to create, update, and delete Covey-managed events on the connected account’s primary calendar; Covey’s implementation does not send requests to read, list, or open calendar events.
Covey also requests the non-sensitive openid and email scopes so it can identify and display the Google Account you connected. We do not request access to Gmail, Drive, Contacts, Photos, or any other Google service.
How we use it
Covey uses this access for one purpose only: keeping the calendar events it created in sync with the shifts in your Covey. Specifically, Covey:
- If you are a keeper, creates one event on your primary Google Calendar for each non-cancelled shift in your household.
- If you are a caregiver, creates one event while a shift is claimed by you.
- Updates that event when the shift’s details change.
- Deletes that event when the shift is cancelled or no longer applies to you.
Covey addresses each event by an identifier it assigned when creating it. Covey does not send Google Calendar API requests to read, list, download, or open calendar events, and does not create, delete, or share calendars or modify calendar sharing permissions.
How we store it
Covey stores the Google OAuth refresh token issued when you connect, encrypted at the application layer using AES-256-GCM before it is written to our database. It is used solely to obtain short-lived access tokens for the calendar operations described above; access tokens are not persisted. We also store your Covey account identifier, the connected Google Account’s email address, connection timestamps, and a mapping between Covey shift identifiers and the Google event identifiers Covey created. The signed OAuth state used during connection expires after ten minutes and is not stored in our database. Because Covey does not request calendar-event contents, it does not store contents returned from other calendar events.
How we share it — and how we don’t
Covey’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
We use Google user data only to provide the calendar-sync feature that you choose to enable. We transfer it only as needed to provide or improve that visible feature with your consent, for security purposes, to comply with applicable law or regulation, or as part of a merger, acquisition, or asset sale after obtaining your explicit prior consent. We do not sell Google user data or use or transfer it for advertising, creditworthiness or lending decisions, or to create, train, or improve machine-learning or artificial-intelligence models.
We do not allow humans to read Google user data unless you have given and we have documented your explicit consent to view specific data, the data is aggregated and anonymized for lawful internal operations, access is necessary for security purposes, or access is required to comply with applicable law or regulation.
Revoking access and deletion
You can disconnect Google Calendar at any time from Settings inside Covey. When Google access is usable, Covey first removes each linked event; if an event deletion fails temporarily, Covey reports that the disconnect could not be completed and keeps the connection so you can retry. When disconnect completes, Covey deletes its local event-link records and the stored encrypted refresh token. If Google access was already revoked or the stored token cannot be used, Covey deletes the local connection but cannot remove the calendar events for you.
You may also revoke Covey’s access at any time from your Google Account at myaccount.google.com/permissions. Revoking there prevents Covey from removing previously created events; you can delete those events directly in Google Calendar. If you prefer not to grant any Google permission, Covey also offers a read-only calendar subscription URL that works with Google Calendar, Apple Calendar, and Outlook and requires no Google sign-in. Anyone with that URL can read the feed, so keep it private.
Children’s information (COPPA)
Covey is not directed at children. Children do not use the app. Any child data, such as a name, birthday, notes, or photo, is submitted by an adult who is the child’s parent, guardian, or authorized caregiver.
We collect the minimum necessary to coordinate care. We do not share children’s information with any third party beyond the infrastructure providers required to run the app (listed below), and we never use children’s information for advertising or any purpose beyond service operation. Child information is visible only to the adults a keeper has invited into that household’s Covey; keepers control that membership and can remove a member at any time. Parents can delete all child information at any time from the Covey tab. We do not apply facial recognition or biometric processing to any photos stored in the app.
How we use your data
- To operate the service: showing Whistles, delivering notifications, managing your Covey.
- To send transactional notifications and emails: invites, alert deliveries, schedule changes.
- To keep your connected calendar in sync, if you have connected one.
- To maintain and improve the service: diagnosing errors, monitoring security, understanding how features are used in aggregate.
- To comply with legal obligations.
We do not sell your data. We do not use your data for advertising. There are no advertising trackers or third-party analytics SDKs in Covey.
Who we share data with
We share data only with the infrastructure providers required to run the app. We select providers that publish security and data-protection commitments, and we configure them to process data only for the purposes described in this policy:
- Clerk: authentication and account management (clerk.com)
- Neon: database hosting (neon.com)
- Vercel: web hosting and file storage for photos (vercel.com)
- Resend: transactional email (resend.com)
- Sentry: error monitoring (sentry.io) — receives technical error reports so we can fix crashes; before a report is sent we strip identifying fields (names, emails, session tokens, and similar) from it
Google Calendar. If you connect Google Calendar, Covey sends the events it creates to your own Google Account. Google is not acting on Covey’s behalf in that exchange: Google processes that data as the provider of your Google Account, under Google’s own terms and privacy policy. Covey sends only the events it creates.
If you enable push notifications, they are delivered through your device platform’s push service (Apple, Google, or Mozilla, depending on your device), which receives the notification content and a delivery token for your device.
We do not share personal data with any other third party, except when required by law or to protect the safety of our users.
Cookies and tracking
Covey uses strictly necessary cookies only: session tokens set by Clerk to keep you signed in. We do not use advertising cookies, cross-site tracking cookies, or third-party analytics cookies. We do not honor or respond to Do Not Track (DNT) browser signals because we do not track users across sites in the first place.
Your rights
You have the right to:
- Access your data: everything you’ve added is visible within the app.
- Correct or delete: edit or remove children, Whistles, Covey members, or blocked times at any time within the app.
- Export your data: email us at support@thecovey.app and we will send you a structured data export within 30 days.
- Delete your account: email us and we will permanently delete your account, your household data, and associated records within 30 days. Push notification subscriptions are removed immediately. Before account deletion continues, Covey removes its linked Google Calendar events and revokes access. The stored refresh token is always deleted, even if a Google outage prevents some calendar events from being removed.
- Withdraw push notification consent: disable notifications at any time in your browser or device settings.
- Disconnect Google Calendar: at any time from Settings in the app, or from your Google Account.
Where Covey is offered. Covey is offered in the United States and is not directed to residents of the European Economic Area or the United Kingdom. We do not market or target the service outside the United States.
California residents. CalOPPA applies to Covey, and this policy is published in part to satisfy it. Covey does not currently meet the thresholds that make the CCPA/CPRA applicable to a business. Regardless of that, we honor requests to know what personal information we hold about you, to correct it, and to delete it. We do not sell or share personal information. To exercise any right, email us at support@thecovey.app.
Data security
Data is encrypted in transit using TLS. Our database and file-storage providers encrypt data at rest. Google OAuth refresh tokens are additionally encrypted at the application layer using AES-256-GCM before they are written to the database. Child photos stored in Vercel Blob are accessible only to authenticated members of the household that uploaded them; they are not publicly accessible.
No security system is perfect. If we become aware of a breach affecting your personal data, we will notify affected users without undue delay, and within the timeframes required by applicable law (including South Carolina’s breach notification statute and GDPR’s 72-hour supervisory authority notification requirement where applicable).
Data retention
We keep your data for as long as your account is active. When you delete your account, we purge personal data within 30 days. A completed Google Calendar disconnect deletes the stored encrypted refresh token immediately. Account deletion always deletes it, even if a Google outage prevents Covey from removing some calendar events. Server logs are retained for a limited period for security and debugging, in line with our hosting provider’s retention settings. Aggregated, anonymized usage statistics may be retained for product analysis and contain no personal information.
International users
Covey is operated and hosted in the United States. The infrastructure providers listed above store and process data in the United States. If you access the service from outside the US, your data is transferred to and processed in the United States.
Changes to this policy
We will update this page when the policy changes and notify active users of material changes by email before they take effect. The “last updated” date at the top of this page reflects the most recent revision.
Privacy questions or data requests:
support@thecovey.app