Privacy Policy
Last updated: 17 May 2026 · Applies to all Corvo users in the UK and EU
Plain English summary: Corvo uses your Canvas account to pull your lecture slides, generate AI study notes, and show your timetable. We store your email and course data. We don't sell your data. You can delete everything at any time. We use Supabase, Stripe, and Anthropic to run the service — they're our data processors, not data brokers.
1. Who we are
Corvo is operated as a student-facing study tool. For the purposes of UK GDPR, Corvo is the data controller for personal data collected through this service. If you have any privacy questions, contact us at privacy@corvo.app.
2. What data we collect and why
| Data | Why we collect it | Legal basis |
|---|---|---|
| Email address | Account creation, login, and sending you notifications about your notes and Canvas updates | Contract — necessary to provide the service |
| Canvas API token | Read-only access to your Canvas courses, files, timetable, and announcements on your behalf. Never used to write or modify anything in Canvas. | Contract — necessary to provide the service |
| Course and module data | Displaying your modules, timetable, and organising your notes by course | Contract — necessary to provide the service |
| Lecture slide content | PDF text is extracted and sent to Anthropic's API to generate your AI study notes. The text is not stored permanently — only the generated notes are saved. | Contract — necessary to provide the service |
| AI-generated notes | Storing the notes we generate from your lecture slides so you can access them in the app | Contract — necessary to provide the service |
| Flashcards and review history | Running the spaced repetition system so we know which cards are due for review | Contract — necessary to provide the service |
| Notification email (optional) | Sending you digest emails if you've opted in. You can leave this blank or change it at any time. | Consent — you provide this voluntarily |
| Notification preferences | Knowing which types of alerts you want to receive | Consent — set by you during onboarding |
| Payment information | Processing your subscription. Card details are handled entirely by Stripe — we never see or store your card number. | Contract — necessary to process your subscription |
| Processed file IDs | Keeping track of which Canvas files have already been turned into notes so we don't duplicate them | Legitimate interest — prevents unnecessary reprocessing |
3. What we do not collect
- We do not use tracking cookies or advertising pixels
- We do not collect your Canvas password — only the API token you generate
- We do not read, store, or access your email inbox
- We do not share or sell your data to third parties for marketing
- We do not build advertising profiles
4. Local storage
Corvo uses your browser's localStorage to store your session token (so you stay logged in) and UI preferences (theme, sync history). This data never leaves your device and is not transmitted to us. It is not a cookie and does not require a consent banner under PECR, but we disclose it here for transparency.
You can clear this at any time by signing out or clearing your browser's site data for corvo.app.
5. Who we share your data with
We use the following third-party services to run Corvo. Each acts as a data processor under a data processing agreement with us:
| Processor | What they handle | Where |
|---|---|---|
| Supabase | Database and authentication — stores your profile, courses, notes, flashcards, and review history | EU (AWS eu-west-1) |
| Anthropic | AI note generation — receives extracted lecture slide text and Canvas announcement content to generate summaries and notes. Anthropic does not train on API data by default. | USA (standard contractual clauses apply) |
| Stripe | Payment processing — handles your subscription and card details. PCI-DSS Level 1 certified. We receive only a subscription status, not card details. | USA / EU (standard contractual clauses apply) |
| Vercel | Hosting and serverless functions — processes all requests to the app | USA / EU edge network |
We do not share your data with any other parties. Your university (Canvas/NCL) is a data source — we read from it, but do not send data back to it.
6. How long we keep your data
- While your account is active: all data is retained to provide the service
- After you delete your account: all data is permanently deleted within 30 days, including from Supabase backups
- After subscription cancellation: your account and data remain until you choose to delete them
- Payment records: Stripe retains transaction records for 7 years as required by UK financial law — this is outside our control
7. Your rights under UK GDPR
You have the following rights regarding your personal data:
- Right of access — request a copy of all data we hold about you
- Right to rectification — ask us to correct inaccurate data
- Right to erasure — delete your account and all associated data instantly from inside the app (Settings → Delete Account), or email us at privacy@corvo.app
- Right to data portability — request your data in a machine-readable format
- Right to object — object to processing based on legitimate interest
- Right to restrict processing — ask us to pause processing while a dispute is resolved
- Right to withdraw consent — for any consent-based processing (e.g. notification emails), you can withdraw at any time from your account settings
To exercise any of these rights, email privacy@corvo.app. We will respond within 30 days.
If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection authority.
8. Data security
- All data is transmitted over HTTPS
- Your Canvas API token is stored server-side only — it is never sent to or stored in your browser
- All API endpoints require authentication — there is no unauthenticated access to user data
- Row-level security is enforced in the database — users can only access their own data
- We do not log request bodies or API tokens
9. Children
Corvo is intended for university students aged 18 and over. We do not knowingly collect data from anyone under 16. If you believe we have inadvertently collected data from a minor, please contact us immediately at privacy@corvo.app.
10. Changes to this policy
If we make material changes to this policy, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of Corvo after changes constitutes acceptance of the updated policy.
Questions? Email privacy@corvo.app