Covalentteam

Privacy Policy

What Covalentteam reads from GitHub, what it keeps, for how long, and how to have it erased.

Last updated 10 September 2026

Covalentteam is provided by Green Guava Tree. This policy says what the Service reads, what it stores, how long it keeps it and how to get rid of it. It covers covalentteam.com and the Covalentteam GitHub App.

What we read when you sign in

Signing in uses GitHub OAuth. We ask GitHub for two scopes and no others:

read:user
Your GitHub account id and handle, so we know who you are between visits.
user:email
Your email address, so the Service can write to you.

We never ask for a scope that grants access to your source code. Your session token is held in your own browser and sent to our API to identify you; it is never placed in a URL.

What the GitHub App reads

When you install the Covalentteam GitHub App on an organisation, it receives webhook deliveries for three kinds of event and ignores everything else:

  • Pull requests — repository name, pull request number and title, the handle that opened it, the handles asked to review it, whether it is a draft, its timestamps, and the size of the change.
  • Pull request reviews — who reviewed what, and when.
  • Issues — the same shape of metadata as a pull request.

The App does not read the contents of your repositories, the diff of a change, or anything else in your code. It reads the metadata above, which is what the team view is assembled from.

What you give us directly

  • One-to-one notes and follow-ups you write in the product.
  • Documents you upload, which are stored in object storage under your organisation.
  • Your place on the waiting list, if you asked for one before the product was open.

How long we keep it

Activity read from GitHub lives for one month and then ages out. Expiry is the retention policy rather than a second policy running beside one: nothing outside that window is kept, and nothing outside it enters a calculation. Notes, documents and account records are kept until you erase them.

Erasing it

The admin screen erases rather than hides. Erasing a team removes the records carrying that organisation’s activity; erasing an account does that and then removes the account itself. Neither leaves a marker behind standing in for what was there, and neither is reversible — which is the point of it.

Who else sees it

We do not sell your data and we do not use it to train models. It is not shared with anyone outside the processors that run the Service:

Cloudflare
Hosting, the database, object storage for documents, and the transport that carries our email.
GitHub
Sign-in, and the source of the activity the product reads.

Email we send

We write to the address on your account about things that happened to your account — a place on the waiting list, an invitation, a welcome, and confirmation when you erase a team or an account. We do not send marketing email.

Your colleagues

A team view is assembled from the activity of people who have not themselves signed in. Their GitHub handle and the metadata above is what appears. If you are on a team in Covalentteam and want to know what is held about you, or want it removed, write to us and we will deal with you directly rather than through your manager.

Your rights

Depending on where you live you may have the right to ask for a copy of what we hold, to have it corrected, or to have it erased. The admin screen does the last of these immediately; for the others, write to us.

Changes

The date above is when this policy last changed. A change that alters what we read or how long we keep it will be sent to the address on your account before it takes effect.

Reaching us

Privacy questions, access requests and erasure requests all go to the same address.

support@covalentteam.com