Custovia Inc. · Reqify

Privacy Policy

Document version
1.1.0
Effective date
8 May 2026
Last updated
21 August 2026
Contact
[email protected]

1. Overview

Custovia Inc. (“Custovia”, “we”, “us”) operates Reqify (“Service”), a SaaS workspace for business analysis and documentation. This Privacy Policy explains how we collect, use, store, and disclose personal information when you use reqify.ai and related APIs.

2. Data we process

We typically process categories such as:

  • Account identifiers — name, email, authentication IDs from Clerk, avatar URL, organisational affiliation you provide.
  • Uploaded content — documents you add to Projects, embeddings or derived text used strictly to power product features you request (e.g. generation, search, mentorship).
  • Technical telemetry — IP-derived security signals, timestamps, coarse device/browser metadata strictly needed for reliability and audit.
  • Billing snapshots — minimal records required to reconcile payments processed by Stripe where you purchase subscriptions or packs.
  • Support communications — correspondence you voluntarily send through in-product prompts or listed contact channels.

3. Google Workspace data

Where you choose to connect a Google account, Reqify requests only the Google data needed to deliver features you explicitly ask for:

  • Email address and basic profile (openid, userinfo.email) — to identify the connected account and display it in Connected Sources so you can confirm the correct Google account is linked. It is not used to create your Reqify account (authentication is handled by Clerk), nor for marketing.
  • Files you share with Reqify (drive.file) — only files you specifically select, or that Reqify itself creates. Reqify cannot see the remainder of your Drive.
  • Google Meet transcripts (meetings.space.readonly, drive.meet.readonly) — to locate transcripts of meetings you attended and propose them for your review, so that you may add them to a Project. No meeting content is read through the meetings scope; it identifies which transcripts exist.

Nothing from a connected Google account enters a Project without your confirmation. Discovered items are held for review, and their content is retrieved only once you approve a specific item and nominate the Project it belongs to.

Reqify's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, do not use it for advertising, and do not use it — or any other customer content — to train generalised artificial intelligence or machine learning models.

Google data is used solely to provide the features described above. It travels over TLS and is encrypted at rest: connection credentials under AES-256-GCM, and content you add to a Project under server-side encryption at the storage layer. Where a feature you invoke requires it, Google-derived content may be processed by the subprocessors described in section 6 strictly to produce the output you requested, under terms that do not permit them to train their own models on it.

Disconnecting a Google source revokes Reqify’s access at Google and deletes the stored credentials for that connection. Deleting your Reqify account does the same for every source you have connected. Content you already approved into a Project is removed when you delete that content or the Project, subject to the retention and erasure terms in sections 7 and 8.

4. Purpose & legal bases (GDPR / UK GDPR)

Processing is grounded in contractual necessity for paying customers (Art. 6(1)(b)), legitimate interest in securing the Service and preventing misuse (Art. 6(1)(f)), and — where required — your consent for non-essential analytics cookies (Art. 6(1)(a)). Financial records tied to invoicing may be retained under legal obligation exemptions (Art. 6(1)(c)) even after broader erasure workflows complete.

5. Regions, residency & transfers

You select a residency bucket inside the Product. We endeavour to persist primary content in the corresponding supported region unless you expressly opt into a feature that requires cross-region processing. Where lawful transfer mechanisms apply (EU SCCs, UK IDTA equivalents, supplementary measures as updated), subprocessors execute under written agreements with Custovia acting as exporter or processor as appropriate.

6. Sharing & subprocessors

We share limited data with processors who help operate Reqify — e.g. authentication, cloud infrastructure, transactional email, payment processing (Stripe). Each party is contractually bound to confidentiality, security parity requirements, and data processing terms consistent with GDPR Article 28. We do not sell personal information.

7. Retention

Operational data is retained only as long as needed for the lawful purposes outlined here. Custovia applies layered retention: finished generation jobs expire after ninety (90) days, Stripe webhook fingerprints after one hundred eighty (180) days, immutable audit artefacts after thirty-six (36) months unless a longer statute applies. Billing ledgers referencing credit movements may persist where finance regulations require — identifiers are rotated when you invoke account deletion to the extent technically feasible while preserving lawful accounting trails.

8. Your rights

Depending on jurisdiction you may exercise access, correction, portability, objection, restriction, or erasure (“right to be forgotten”). Custovia honours verifiable GDPR requests within statutory timelines subject to narrowly tailored exemptions (billing ledgers where erasure contradicts AML / tax mandates). Residents of California or other US states with parallel privacy statutes may lodge equivalent requests using the email on this page — we reply without discrimination tied to exercising those rights.

Inside the authenticated Product we provide tooling to voluntarily delete projects and — irreversibly — close your Workspace which triggers cryptographic scrubbing workflows for user-generated objects and rotates stored identities.

9. Cookies & analytics

Only strictly necessary authentication cookies activate before you grant consent where required. Deferred analytics instrumentation (currently Posthog) initializes solely when the consent banner expressly records acceptance, ensuring no behavioural profiling prior to opt-in jurisdictions.

10. Security

Custovia employs TLS in transit, least-privilege service accounts, environment-isolated CI secrets, intrusion monitoring, segregated staging, and tabletop incident procedures. Responsibility for endpoint protection on customer devices nonetheless remains jointly with your organisation's administrators.

11. Children

The Service is marketed to professional teams — we do not knowingly collect data about children under sixteen. If you believe we mistakenly processed such data notify us promptly and we will purge it.

12. Changes

We revise this Privacy Policy when features, laws, or risk posture shift materially. Elevated protections apply automatically; punitive reductions prompt advance notice plus, where required, renewed acknowledgement.