Privacy Policy
CoveKit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy ("Policy") describes how we collect, use, and disclose information when you use our video/audio developer platform, API services, client SDKs, developer console, and media plane infrastructure (collectively, the "Service").
Please note that our Service is designed for developers ("Customers") who build real-time communication tools in their own applications. In this context, we process information both as a Data Controller (for our Customers' account information) and as a Data Processor (for the end-users of our Customers' applications).
1. Information We Collect
A. Developer Account and Organization Data (As a Controller)
When you register a CoveKit developer account or configure an organization:
- Account Information: We collect your name, email address, password hash, and organization profile.
- Credentials: We generate and store API keys and project configuration tokens associated with your account.
- Billing Information: Payments and subscription transactions are processed securely by our third-party merchant of record. We do not store raw credit card details on our servers; however, we receive transaction records, credit wallet top-up amounts, and subscription statuses to update your account's Credit Wallet balance.
B. Usage, Telemetry, and Stream Metadata (As a Processor)
When your application interacts with our media plane infrastructure, we automatically generate and collect logs necessary to run and bill the Service:
- Session Metadata: We record participant connection times (join and leave timestamps), room identifiers, participant capacity, and active room statuses.
- Telemetry Data: We collect ingest volume and bandwidth consumption (in Megabytes) per session to calculate billing.
- Webhook Delivery Logs: We log dispatch metrics (such as destination endpoint URLs, HTTP response status codes, and response timestamps) to help you troubleshoot event integrations.
- Media Streams: Audio and video packets routed through our media plane infrastructure are transmitted in real-time. We do not record or store the raw audio/video content of your communications unless you explicitly activate recording features on your account.
2. How We Use the Information
We use the collected data to:
- Provide and Maintain the Service: Operate the media plane servers, route real-time audio/video streams, and authenticate API calls.
- Calculate Usage and Billing: Process participant-minutes and billing metrics, apply wallet credit deductions, and manage grace thresholds.
- Monitor System Health: Analyze uptime, identify media plane degradation, and troubleshoot webhook delivery errors.
- Security and Abuse Prevention: Monitor for malicious activity, rate-limit API calls, and prevent abuse of our media infrastructure.
3. How We Share Information
We do not sell your personal information or telemetry data. We share data only with trusted service providers to run our platform:
- Payment Processors: We use secure third-party payment processors and merchants of record to process your payments, manage subscriptions, and verify billing transactions.
- Hosting and Infrastructure Providers: We host our databases and media routing servers on secure cloud infrastructure providers.
- Legal Compliance: We may disclose data if required to do so by law, or to protect the safety, rights, or security of our Service, users, or the public.
4. Data Security
CoveKit employs industry-standard administrative, technical, and physical security measures to protect your credentials, telemetry data, and account information from unauthorized access, loss, or alteration.
API keys are stored securely using cryptographic hashing. It is your responsibility to secure your project keys and ensure that client-side tokens are issued securely.
5. Data Retention
- Account Information: We retain developer account data for as long as your account remains active.
- Telemetry & Session Logs: We retain historical stream allocations, billing logs, and webhook delivery records to support accounting reviews and diagnostic operations.
- Media Stream Content: Real-time audio and video tracks are processed ephemeral-only. They exist only in-transit and are deleted immediately upon packet delivery.
6. Your Rights and Choices
As a developer, you may update, correct, or delete your account information at any time by logging into the CoveKit Developer Console. If you wish to delete your entire developer profile or organization, you can contact us at support@covekit.net.
If you are an end-user of an application built using CoveKit, you must contact that application's developer to exercise any privacy rights regarding your session data.
7. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by an updated "Last Updated" date. We encourage you to review this Policy periodically to stay informed about how we protect your information.
8. Contact Us
If you have any questions or concerns regarding this Privacy Policy or our privacy practices, please contact us:
- General Inquiries: info@covekit.net
- Developer & Privacy Support: support@covekit.net