Privacy
Last updated 2026-09-06. Version 1.0.
Who controls your information
Kovmere is a service of Content Commerce Labs LLC, doing business as Kovmere. Content Commerce Labs LLC controls the information described on this page. You can reach us through /contact, by replying to any receipt, order, or report email you have received from us, or by mail at Content Commerce Labs LLC, 100 North Howard Street STE R, Spokane, WA 99201, US.
What we collect
You give us: the website URL, the one-line category, competitor names, the brand name, and — if you enter one — your email address. If you buy a Fix Pack, you also give us the facts on the fix-pack form: offers and prices, differentiators, buyer questions, objective numbers and any notes.
We produce about your site: the sampled answers from the AI engines, every URL those answers cited, what we found when we fetched those pages, and the fetch results for your own pages (status codes, robots rules, page text size).
We collect automatically: IP address, timestamps and request counts, used for rate limiting, spend caps and abuse prevention.
Order and account records: the Stripe checkout/transaction identifiers for what you bought, your subscription status, the one-time start-link token issued for an order, and — if you unsubscribe or delete your data — a record that your address should not be emailed again. Payment records themselves come back from Stripe; we never see or store your card number.
If you connect a CMS: the credentials you enter on the CMS page (for example a WordPress application password, a Ghost Admin API key, a Webflow or Shopify token) are stored against that one scan so the "create a draft" button can work. They are encrypted at rest with a key held outside the database, used for nothing else, are never written to our logs, and are deleted when you press Disconnect or when the scan's data is deleted. We only ever ask your CMS to create an unpublished record; we never publish.
If you use an Agency workspace: the workspace name, the brand name and logo URL you want shown to your clients, the owner email, and the client sites you add. The workspace owner key is what grants access — anyone holding the dashboard URL holds that key.
If you use the API: the webhook URL you register, and the fact of each API call. Webhook deliveries send the job id, site, headline counts and report URL to the URL you chose; once it leaves us it is governed by your own system's privacy practices.
If you contact us: whatever you enter on the /contact form — your email, the subject you chose, your message, and (if you came from a report or receipt) the job or order it relates to.
What we do with it
We use it to: run and deliver your scan; send you the report link, receipts, order confirmations, alerts and re-test summaries; enforce rate limits and spend caps; respond to messages you send us; and operate, secure and improve the service itself. We do not use your submitted content to train a model of our own. Aggregated, de-identified figures may appear in published research studies; we will not identify a specific customer, brand, or domain in a public study without that customer's separate permission.
We do not sell your personal information, and we do not use it for targeted advertising.
Who else processes it
- OpenAI (United States) — buyer questions and the brand/category context, for sampling and judging answers, and for generating fix-pack drafts. We do not instruct OpenAI to use what you submit to train its general-purpose models; its own retention and data-use terms depend on the API account plan we hold with it, which we have not separately re-verified for every claim on this page.
- Perplexity (United States) — buyer questions, for sampling answers on the second engine (paid tiers), under the same no-training instruction and the same caveat above.
- Stripe (United States) — checkout, subscriptions and payment records. Card details go to Stripe directly and never reach us.
- Resend (United States) — delivery of service and promotional email.
- Cloudflare — the tunnel and network layer in front of the service; it sees request metadata in transit across its global network.
- Your CMS provider — only if you connect one, and only for the specific draft you press a button to send it.
Each of the above processes what we send it under its own applicable terms and data-protection commitments; we disclose to each only what is reasonably necessary for the purpose above. We have not yet named a specific hosting provider or region on this page for the servers and database behind Kovmere itself — Cloudflare's tunnel is the only network layer disclosed today, and that gap will be closed here once finalized.
Email tied to something you started — your report link, receipts, order confirmations, alerts on a site you subscribed for, re-test summaries — is part of the service and is sent as long as your account has an email on file. Promotional follow-up email offering an upgrade is sent only if you tick the box offering it at the point we collect your address; it is never required to unlock a report. Every promotional message carries a postal address and a working unsubscribe link; unsubscribing suppresses that address permanently for promotional mail, and we do not send it to any list again — that suppression record is itself kept indefinitely, precisely so a deleted or unsubscribed address is never re-added.
Retention and deletion
We do not currently run an automatic, time-based deletion job for most of what we hold — the descriptions below are how long each kind of data is actually kept until you ask us to delete it, not a fixed expiry we enforce in code today:
- Free-scan email address, scans, reports, sampled answers, source ledgers, and Fix Pack drafts: kept until you delete them through /my, described below.
- CMS credentials: kept until you press Disconnect on that scan, or until you delete your data — whichever comes first. There is no automatic inactivity-based expiry yet.
- Paid orders: kept indefinitely as our financial and tax record; deleting your data removes the email address from the order but keeps the order itself, as described below.
- Contact messages you send us through /contact are kept so we can follow up on billing, safety, or delivery issues, until you delete them through the deletion flow below (or ask us to delete one by hand sooner).
- Checkout consent records (which version of these documents you agreed to, and when) are kept for as long as the order they belong to, and are removed by the deletion flow below along with everything else.
- Operational logs (rate-limiting counters and our internal event log, which can include an IP address or email tied to an action you took) are kept indefinitely as an audit trail — the deletion flow below does not delete these rows, but it does scrub your email address out of every one that carries it, replacing it with a placeholder, so the count of past activity survives without your address in it.
- Backups: our nightly backup script keeps the 14 most recent backups of the database and report files (roughly the last 14 days, if the daily schedule it is designed for is what is actually running) before deleting the oldest one. Data you asked us to delete can still exist inside a backup made before your request until that backup is rotated out.
Deleting your data: go to /my, enter your email, and open the link we send you, then choose Delete my data. That erases every scan tied to that address — the scan record, its results and sources, its source ledger, any Fix Pack drafts and stored CMS credentials, share links, sites and their alerts, unspent tokens, any contact messages you sent us, your checkout consent records, and the record of your having given us your email on a free report — and cannot be undone. It also scrubs your address out of our internal event log (see above) and adds your address to our permanent do-not-email list.
What survives a deletion request: the order record itself (financial record, with your email removed from it); Stripe's own copy of your payment history, kept under Stripe's privacy practices, not ours; our internal event log, with your email address scrubbed out of every row that carried it (see above); and backups already made, until they age out on the schedule above (roughly 14 days).
Links are the access control
Report, fix-pack, share and workspace URLs are unguessable but unauthenticated: anyone you send one to can open it. There are no passwords in this product. Do not forward a link you would not forward the contents of.
Cookies and tracking
We do not currently set cookies or use analytics, advertising pixels, or cross-site tracking technologies on this site. Stripe's own checkout pages, which are hosted by Stripe and separate from ours, may use their own technologies once you leave our site, as described in Stripe's own privacy materials.
Do Not Track and US state privacy rights
We do not sell your personal information, and we do not use it for targeted advertising. Because we do not use tracking cookies or cross-site tracking technologies in the first place, we do not respond to browser Do Not Track signals — there is nothing here for such a signal to turn off.
International visitors
Kovmere is operated from the United States, and the processors listed above are US companies. If you are located outside the United States, including in the EU or UK, your information will generally be processed in the United States. We have not completed a full assessment of every cross-border data-protection requirement that may apply to a specific country, so if you require a particular data-protection commitment before you can use the service (for example, a signed data-processing agreement or a documented transfer mechanism), contact us through /contact before you buy.
Contact
Reply to any email you have received from us, to your receipt, or use /contact.