Privacy Policy

Last updated April 8, 2026

Overview

Covagent (“we,” “us,” “our”) operates an MCP server and web platform that provides covenant monitoring and BDC analytics tools for private credit. This policy explains what data we collect, how we use it, who we share it with, and your rights.

Data we collect

Account information

When you create an account, we collect your name, email address, firm name, and password (stored as a cryptographic hash). Title is optional. After registration we send a verification code to your email.

Portfolio content

If you use the paid tier, you may upload compliance certificate PDFs, covenant thresholds, borrower data, and related documents for extraction and monitoring. We store these along with the structured data we extract from them.

Public market data

The BDC tools query public data from SEC filings. This data does not contain personal information.

Usage and audit trail

We log tool calls (tool name, input parameters, response summary, status, duration, and timestamp) tied to your account. This data powers your firm's audit trail, which you can access through the MCP get_audit_trail tool or the web platform. We also collect page views, session data, and error reports through the analytics services described below.

How we use your data

  • Processing tool requests and running document extraction.
  • Sending transactional emails (verification codes, account updates).
  • Debugging errors and improving extraction accuracy.
  • Aggregated, de-identified usage data for product analytics.

We do not sell your personal data. We do not use your uploaded documents to train AI models.

Data shared with third parties

We share data only as needed to operate the service:

Supabase

Database hosting. Account data, portfolio data, and tool usage logs are stored in Supabase-managed Postgres.

Vercel

Hosting and edge functions. Vercel also collects anonymized web analytics (page views, performance metrics).

Resend

Email delivery. Your email address is shared with Resend to send verification codes and transactional emails.

Google Analytics

Anonymized page views and site usage statistics when configured (cookies: _ga, _gid).

PostHog

Product analytics and session recording for identified users only. PostHog requests are proxied and do not set third-party cookies.

LinkedIn Insight Tag

Ad conversion measurement when configured (cookies: li_fat_id). Used to measure advertising effectiveness, not for ad targeting.

Google Fonts

Font files are loaded from Google's CDN. Your IP address is exposed to Google per their privacy policy.

MCP clients (Claude, Cursor, ChatGPT, etc.)

When you use Covagent through an MCP client, tool responses (account status, portfolio data, BDC results) flow through that client. We do not send passwords, raw API keys, or internal database identifiers to MCP clients.

Data security

All data in transit is encrypted with HTTPS/TLS. Passwords are cryptographically hashed. API keys are generated with cryptographically secure randomness. Supabase access from the application is server-side only; database credentials are never exposed to the browser.

Data retention

We retain your account data and tool usage history for as long as your account is active. If you delete your account, we remove your personal data within 30 days, except where retention is required by law (e.g., financial records for tax compliance).

Your rights

You may:

  • Access your data through the web platform or MCP tools.
  • Correct your account information in settings.
  • Delete your account and associated data by contacting us.
  • Export your data by contacting us.

For any of these requests, email hello@covagent.io.

Cookies and tracking

We use cookies and similar technologies to operate the service and measure usage:

  • Google Analytics cookies (_ga, _gid) for anonymized usage statistics.
  • PostHog for product analytics and session recording. Requests are proxied through our domain.
  • LinkedIn Insight Tag cookies for ad conversion measurement.
  • Vercel Analytics for anonymized web performance data.

You can opt out of analytics cookies by using a browser extension, disabling cookies, or adjusting your browser's privacy settings.

Children

Covagent is not intended for use by anyone under 18. We do not knowingly collect data from minors.

Changes to this policy

We may update this policy. Material changes will be communicated via email to the address on your account. Continued use after changes take effect constitutes acceptance.

Contact

Questions about this policy or your data? Email hello@covagent.io.