Privacy Policy
This policy describes how Qivion (the web dashboard, the MCP server, the work application and the Telegram and WhatsApp assistants, together called Cortex) handles personal data. It was written from what the system actually does.
Cortex is a work tool hired by a company. Under Brazil's data protection law (LGPD), the hiring company decides why and how its team's data is processed (controller); Qivion acts as processor, handling data as contracted. For account and billing data, Qivion is the controller.
1. What data is processed
Account and access
- Email and name. They identify the person in the system.
- Password. Stored only as a hash — the system cannot read the original password.
- Sign in with Google (optional). If used, we store the Google account identifier, the email and the profile picture address. Signing in with Google does not create an account: the email must have been invited first.
- Phone and WhatsApp number, when filled in on the person's profile.
- Open sessions. A short device description (for example, "Chrome · Android"), the creation date and the last access, so the person can review and end sessions.
- Machines linked to the MCP token, by an installation identifier and a label.
We do not store IP addresses or the full browser user agent. Of the device identification, only the short description above is kept.
Work content
- Projects, demands, tasks, checklists, deadlines, reminders, notes and messages between team members.
- Text and audio captured by the person (dashboard, Telegram or WhatsApp) and what the AI suggested from it.
- Documents and images uploaded, with the file name.
- The link between a Telegram or WhatsApp conversation and the person (chat identifier, username or profile name).
Usage records
- Activity. Who did what and when (action, project, task, source and duration). It does not store work content. The hiring company can switch this off, and when off nothing is recorded.
- AI usage. Model used, token counts, cost, status and which person and task it belongs to. We do not store the content of AI conversations in this record.
2. Who data is shared with
Only with those needed for the service to work, and always as part of an action:
| Recipient | What is sent, and when |
|---|---|
| AI provider chosen by the company | The text of the conversation or request, when someone uses an AI feature. The provider and endpoint are configured by the hiring company — Cortex does not impose any. |
| Telegram | If the person connects the bot: chat identifier and the reply text; files, when sent. |
| WhatsApp (Meta) | The same, for those using the WhatsApp assistant. |
| File storage (Oracle Object Storage) | Uploaded documents and images, in a private area. There is no public link: downloads always go through the API, which checks permission. |
| Only what the sign-in flow requires, when the person chooses to sign in with Google. | |
| Email server | Address and content of invitation, password reset and system notice messages. |
We do not sell personal data and do not use it for advertising.
3. When AI sees your content
Never on its own. Always from someone's action:
- Audio. In the bot, audio is transcribed only when the person taps "Transcribe"; in the dashboard, when the capture is sent for transcription. We do not keep the audio file — only the text comes back.
- Documents and images. AI analysis is optional and explicitly marked: without a request, the bytes do not leave storage. Each analysis is recorded with who asked, when and with which model.
- Captured text. Sent to the AI to suggest where it fits in the project.
- Conversation with the assistant on Telegram or WhatsApp.
The text the AI produces about a document is stored with that document, so the team can read it later.
4. How long data is kept
- Activity record: 365 days by default, adjustable by the hiring company.
- Deleted reminders, backlog items, events and requirements: hidden immediately and permanently removed 30 days later.
- Documents: once unlinked, the file is removed from storage 30 days later. The record that it existed remains, without the content.
- Password reset requests: removed 7 days after use or expiry.
- Browser session: valid for 30 days, renewed on use; the access token lasts 8 hours.
- Backups: the local copy is deleted according to the configured period (14 days by default).
- Work content (projects, tasks, messages): for as long as the company keeps the contract.
- Removing a person's access revokes the membership but does not erase what they recorded — the work history stays with the company. There is currently no automatic permanent deletion of an account or company from the dashboard: it is done on request, as per section 5.
- Backups sent to external storage have no automatic expiry configured. Until that exists, they are removed on request.
5. Your rights and how to exercise them
The LGPD gives you the right to confirm whether we process your data, access it, correct it, request anonymization, blocking or deletion, request portability and know who we share it with.
Write to admin@qivion.com.br. We answer within the legal deadline. If the data was entered by the company you work for, we forward the request to them — decisions about work content are theirs, and we support them in complying.
6. Security
- Each company sees only its own data, isolated at the database level.
- Passwords and tokens are stored only as hashes.
- Encrypted traffic (HTTPS), a session cookie unreachable by scripts, and rate limits against bulk attempts.
- Documents live in a private area, with no public address.
No system is immune to incidents. In a relevant incident we notify the hiring company and, where required, the authority and the data subjects.
7. Children
Cortex is a work tool, intended for people over 18. We do not knowingly collect children's data.
8. Changes to this policy
When something relevant changes, we update the date on this page and notify the hiring company. The version in force is always the one published here.