How we handle your data, in plain language.
This page states only what is true today: what Kovmere collects, what it deliberately does not collect, where data is processed, how long it is kept, who else sees it, and how to have it deleted. For the full contract-facing version, see the privacy policy; this page is its short summary, not a separate promise.
Who operates this
Content Commerce Labs LLC, doing business as Kovmere, is a company registered in Washington State, USA — the same operating entity and state named on the About page.
What we collect
The site URL, category, brand name, and competitor names you enter to start a scan, and your email address if you leave one. If you buy a Fix Pack, the facts you type on its form (offers, prices, differentiators, buyer questions). The sampled answers each engine returns, every URL those answers cite, and what we found when we fetched your own pages. IP address, timestamps, and request counts, used only for rate limiting and spend caps. The Stripe checkout and order identifiers for what you bought — never your card number.
What we never collect
- No site credentials. There is no step in the free scan or a paid Check that asks for your website's admin, hosting, or CMS login.
- No CMS access at all, right now. The product's optional CMS-draft feature is switched off in this deployment (behind the
CMS_PUSH_ENABLEDflag) — there is nowhere in the live product to type a CMS credential in today. - No access to your own analytics. Where a report points you at your own Google Analytics (GA4) to see AI referral traffic, that is Google's free report on your own property: we have no access to it, we collect none of it, and no number in your Kovmere report comes from it.
Where your data is processed
Cloudflare fronts the network layer in front of the service — the same subprocessor named below. We have not yet published a specific hosting provider or region for the servers and database behind Kovmere itself; the privacy policy states that gap the same way, and this page will be updated once it is closed.
How long we keep it
We do not run an automatic, time-based deletion job for most of what we hold — each kind of data is kept until you ask us to delete it, not a fixed expiry enforced in code. Paid orders are kept indefinitely as a financial and tax record. Operational logs are kept indefinitely as an audit trail, but a deletion request scrubs your email address out of every row that carries one. Nightly backups keep roughly the last 14 days before the oldest is rotated out, so a deletion request can still exist inside a backup made just before it until that backup ages out. The full breakdown, kind by kind, is in the privacy policy's Retention and deletion section.
Deleting or exporting your data: go to Find my reports, enter your email, open the link we send you, then choose Delete my data or get a copy of everything under that address. No account or password is needed.
Who else touches your data
Running a measurement and taking payment means a few outside services see parts of what you send us — the same list About publishes:
- OpenAI, Perplexity, Google, Anthropic, and SerpApi — the search APIs used to sample attributable answers when available.
- Stripe — checkout, subscriptions, and payment records; we never see your card details.
- Resend — delivery of report, receipt, renewal, and cancellation messages.
- Cloudflare — the network layer in front of the service.
Who can see a report
A report's URL is an unguessable, single-purpose link, not a password — anyone holding it can open it, the same as any unlisted link elsewhere in this product. Taking an action on a report (minting or revoking a white-label share link, re-running a missing engine) needs one of three proofs: a signed, single-purpose action link scoped to that report and that action; the magic-link token emailed to the address the report belongs to; or the operator's own admin key (env: ADMIN_KEY). White-label share links are revocable — turning one off invalidates every copy of it at once, and a link can be minted with its own expiry.
Payments
Checkout, card entry, and billing run on Stripe's own hosted pages. Your card number and billing details go directly to Stripe; they never reach us. Payment records come back from Stripe — we never see or store your card details.
Certifications
We do not hold a SOC 2 or ISO 27001 certification. We will not claim one here unless a real audit report exists to back it.
Questions about any of this? Contact us or email claire@kovmere.com. To request deletion or an export by hand, use the "Delete my data" subject on the contact form or Find my reports directly.