Privacy policy
This policy explains what Convena collects, how it is used, and how it is protected. We collect what the product needs to work, and nothing we would be uncomfortable explaining to your face.
What we collect
Three kinds of data, each tied to a clear purpose.
How we use it
To run your sessions, keep your history available to you, and improve the quality of the council. We do not sell your data, and we do not train third-party models on your private sessions.
How it is protected
Passwords are cryptographically hashed by our auth provider before storage; we never hold them in plaintext. Session data is encrypted in transit and at rest. Access is limited to what is needed to operate and support the service.
Your choices
From Settings, you can download a JSON copy of your first-party account data or delete your account after signing in again. Active account content and share links are removed immediately.
A deidentified financial ledger is retained for seven years. Raw anonymous page views are retained for 90 days, deidentified aggregates for 25 months, and a pseudonymized security audit trail for one year. Eligible processor deletion or redaction work is tracked for completion within 30 days. A non-reversible tombstone prevents a backup restore from resurrecting a deleted account through the confirmed restore window plus 30 days, with a minimum of 90 days. Identity providers and payment processors can retain independent records where law, safety, fraud prevention, or their documented policies require it.