Legal
Privacy Policy
This policy explains what Kovify collects, why, how it is used and protected, and the choices and rights you have. Last updated: February 2026.
1. Who this policy covers
Kovify ("Kovify", "we", "us") provides AI-powered Accounts Receivable and Invoice-to-Cash automation software available at kovify.pro and the application at app.kovify.pro (the "Service"). This policy applies to visitors to our website and to business users of the Service.
The Service is provided to businesses. When your employer or client subscribes to Kovify, that organization controls its Kovify environment and the receivables data it processes; Kovify processes that data to provide the Service.
2. Information we collect
Account information
Name, work email address, password credentials (stored only as a salted hash), user role and permissions, company or environment membership, and authentication events such as sign-in timestamps.
Business information
Company name, business contact details, billing and subscription details, plan selection, team structure, departments, internal contacts, collection policies, escalation rules, dispute procedures, cash application rules and any documentation you upload to train the Service.
Customer and receivables information
Data you or your connected accounting/ERP system provides about your customers: customer names, AR contact names, email addresses and phone numbers, invoices, invoice amounts and dates, credits, payments, aging, balances, disputes, payment commitments, notes and activity history.
Email data from connected mailboxes
When you connect a mailbox, Kovify accesses email metadata (sender, recipients, subject, timestamps, thread and message identifiers, labels or folders) and message content for messages relevant to AR conversations, so it can read customer replies, continue existing threads and send follow-up on your behalf.
Usage and technical information
Pages and features used, actions taken in the Service, IP address, browser and device type, and log/diagnostic data used for security, troubleshooting and product improvement.
3. OAuth authorization and connected accounts
Mailbox and account connections use the provider's own OAuth consent flow. Kovify never receives or stores your Google or Microsoft password. You see and approve the requested permissions on the provider's consent screen before any access is granted.
Google account access (Gmail / Google Workspace)
Kovify requests the following Google OAuth scopes and no others:
openid,email,profile— to identify the Google account you connected and display it in Kovify.https://www.googleapis.com/auth/gmail.modify— to read AR-related messages and replies, apply or update labels on those messages, and send follow-up messages inside the existing customer thread from your mailbox.
Kovify does not request Google Drive, Calendar, Contacts or any other Google scope, and does not access Google data outside the scopes listed above.
Google API Services User Data Policy. Kovify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically:
- Google user data is used only to provide and improve the AR features you enabled — reading customer replies, maintaining conversation threads and sending follow-up.
- Google user data is not sold, and is not transferred to third parties except as needed to provide the Service (infrastructure and AI processing subprocessors described in section 6), for security purposes, or to comply with applicable law.
- Google user data is not used for advertising, and is not used to train generalized AI or machine-learning models. Message content is processed to generate and interpret AR communications for your account only.
- Humans do not read your Google user data except with your explicit permission for specific messages, where necessary for security purposes such as investigating abuse, to comply with applicable law, or where the data is aggregated and anonymized.
You can disconnect your Google account at any time in Kovify, and you can revoke Kovify's access directly at myaccount.google.com/permissions. Revoking access stops further Gmail access immediately.
Microsoft account access (Outlook / Microsoft 365)
Kovify requests the following delegated Microsoft Graph permissions:
openid,profile,email,User.Read— to identify the signed-in Microsoft account and display it in Kovify.offline_access— to refresh access without asking you to sign in again on every operation.Mail.ReadWrite,Mail.Send— to read AR-related mail, manage message state and send follow-up from your mailbox.Mail.ReadWrite.Shared,Mail.Send.Shared— requested only when you choose to connect a shared AR mailbox, so Kovify can work in that shared mailbox.
Kovify does not request Microsoft Files, Teams, Calendar or directory-wide permissions. You can revoke access at myaccount.microsoft.com or by disconnecting the mailbox in Kovify.
4. How we use information
- Provide the Service: sync receivables, prioritize accounts and work AR items.
- Generate, send and interpret AR communications, including AI-drafted follow-up and analysis of customer replies.
- Detect and manage disputes, payment commitments and cash application exceptions.
- Apply your collection policies, escalation rules and internal routing.
- Produce reporting, aging views, activity logs and audit trails.
- Authenticate users, enforce roles and permissions, and secure the Service.
- Provide support, respond to requests and communicate service notices.
- Bill subscriptions and administer your plan.
- Maintain, troubleshoot and improve the Service.
Kovify does not sell personal information and does not use your customer or email data for advertising.
5. AI processing
The Service uses AI models to draft messages, interpret replies, classify disputes and recommend next actions. Only the data needed for the specific task is sent for processing — for example the relevant invoice context and message thread. Your data is processed to serve your account; it is not used to train generalized, publicly available AI models. AI-generated actions are recorded and reviewable, and your team can intervene at any time.
6. Sharing and service providers
We share information only in these circumstances:
- Service providers that operate the Service under contract, including cloud hosting and database infrastructure, AI model providers used for the processing described above, email delivery through your connected mailbox provider, payment processing for subscriptions, and error/diagnostic tooling.
- Your own organization — other authorized users of your Kovify environment, according to the roles and permissions your administrators set.
- Legal requirements — when required by law, regulation, legal process or enforceable governmental request, or to protect rights, safety and the integrity of the Service.
- Business transfers — in connection with a merger, acquisition or sale of assets, subject to this policy.
7. Storage and security
Data is stored on managed cloud infrastructure. Traffic is encrypted in transit using TLS, and data at rest is encrypted by the underlying storage platform. OAuth access and refresh tokens are stored encrypted and used only to perform the operations you authorized. Access to the Service requires authentication, and data is scoped to your company environment so that one customer's receivables data is not accessible from another. Where roles and permissions are implemented, they restrict what each user can view and do. Internal administrative access is limited to personnel who need it to operate and support the Service.
No system is completely secure. We do not claim any third-party security certification such as SOC 2, ISO 27001 or HIPAA compliance. If we obtain such certifications in the future, this policy will be updated.
8. Data retention
We retain account, business and receivables data for as long as your account is active, because AR history, conversation history and audit trails are part of the Service. Email content and metadata retrieved from a connected mailbox are retained while the connection is active and the related AR activity remains relevant. Logs and diagnostic data are retained for a limited period for security and troubleshooting. When you disconnect a mailbox, its OAuth tokens are deleted and further access stops.
9. Deletion and your rights
Depending on your location, you may have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information.
- Request deletion of your personal information.
- Request a copy of your data in a portable format.
- Object to or restrict certain processing.
- Withdraw a consent you previously granted, such as a mailbox connection.
You can disconnect integrations and delete records inside the Service. To request account deletion or exercise a right, contact info@kovify.pro. If you are an employee of a Kovify customer, we may direct your request to your organization's administrator. On account termination and after any legally required retention period, we delete or anonymize your data.
10. Account termination
When a subscription ends, the environment becomes inaccessible and data is scheduled for deletion. You may export your data before termination; contact us if you need help doing so.
11. Cookies
Our website and application use cookies and similar technologies as described in our Cookie Policy.
12. Children
The Service is a business product and is not directed to individuals under 18. We do not knowingly collect personal information from children.
13. International data
Kovify serves US-based businesses and processes data on infrastructure operated by our cloud providers. Where data is transferred across borders, we rely on appropriate safeguards offered by those providers.
14. Changes to this policy
We may update this policy as the Service evolves. Material changes will be communicated through the Service or by email, and the "last updated" date above will change. Continued use after an update constitutes acceptance of the revised policy.
15. Contact
Privacy questions and requests: info@kovify.pro. We have not published a registered legal entity name or mailing address on this page; if you require those details for a vendor or compliance review, contact us and we will provide them.