Korva Connect/SupportPrivacyTerms

Privacy

Privacy Policy

This policy explains what Korva Connect collects, how it is used, and how account and group access controls protect user content.

Last updated August 20, 2026

Information we collect

Korva Connect stores account information such as your name, email address, password hash, email verification status, account role, account status, sign-in session records, and ChatGPT account-linking records.

Korva Connect stores account-security records such as email verification tokens, password reset tokens, group invitation codes, group join codes, OAuth authorization codes, OAuth access tokens, and MCP session tokens. These tokens and codes are stored as hashes where practical, not as plain reusable secrets.

Korva Connect may store operational records such as request logs, moderation status, processing status, retrieval metadata, usage analytics categories, tool names, route names, latency, result counts, success or failure status, and error kind so the service can operate, diagnose issues, improve reliability, and understand feature use.

Content and group data

Korva Connect stores content you create or upload, including documents, original file names, content types, file sizes, uploaded file bytes, extracted document text, searchable text chunks, embeddings, group posts, comments, signup forms, signup lines, signup responses, poll titles, poll questions, poll options, and anonymous poll vote records.

Korva Connect stores group information such as group names, descriptions, member lists, member roles, invitation records, join codes, group activity events, posts, documents, and group-level permissions.

Private content is intended for the owning account. Group content is intended for active members of the group. Public or published content may be available more broadly through Korva according to its configured visibility.

Korva app and on-device data

Korva Connect is separate from the Korva iOS app's local-first chat, health, and on-device Bible SQL data. Korva Connect does not move that on-device app data into Korva Connect cloud storage unless you intentionally upload, submit, or connect content through Korva Connect or the Korva ChatGPT plugin.

The cloud Bible and cloud knowledge services used by the ChatGPT plugin are separate from the Korva app's on-device Bible SQL version.

ChatGPT plugin and AI processing

When you use Korva through ChatGPT, Korva Connect may receive your ChatGPT tool request, linked account context, and the information needed to answer that request. Korva may return answers, source references, scripture references, interactive UI tiles, signup summaries, poll summaries, and permitted group or document information back to ChatGPT.

Korva Connect AI features use large language models and related AI services provided by OpenAI and, where enabled, other AI model providers. These providers may process prompts, permitted source snippets, uploaded text, post text, comments, signup content, poll content, and related metadata when needed to generate AI responses, create embeddings, run safety moderation, classify usage, or render ChatGPT plugin experiences.

When you use Korva Connect inside ChatGPT, OpenAI and ChatGPT may process and have access to the text, files, instructions, tool requests, and interactions you type or provide in ChatGPT. This is separate from the information Korva Connect receives through authorized Korva tool calls.

Documents and user-provided content are treated as untrusted source material for AI retrieval. Korva Connect does not intentionally follow instructions embedded inside uploaded documents, posts, comments, signup responses, or other source content as if those instructions came from the user.

Service providers

Korva Connect does not sell user content or account information.

Korva Connect uses Google Cloud to host the backend, database, secrets, and related infrastructure. Google Cloud may process account data, documents, source text, embeddings, logs, and operational data as needed to provide infrastructure services.

Korva Connect uses Resend to send transactional emails such as email verification and password reset messages. Resend receives the email address, message content, sender information, and delivery metadata needed to send and track those messages.

Korva Connect uses OpenAI, ChatGPT, and, where enabled, other AI model providers to provide large language model features, plugin experiences, AI-generated responses, moderation, embeddings, OAuth/plugin account linking, and interactive ChatGPT UI tiles.

Korva Connect is hosted through ChatGPT Sites/OpenAI hosting infrastructure for the public Korva Connect website pages and web experience.

How information is used

Korva Connect uses account and group information to authenticate users, control access, manage groups, enforce roles, process invitations, retrieve relevant sources, and return responses through the Korva ChatGPT plugin.

Uploaded documents, posts, comments, signup responses, and poll summaries may be searched and retrieved only according to their visibility and the requesting user's account permissions.

Email addresses are used for account sign-in, password reset, email verification, group invitations, service-related account messages, and support or plugin review contact when needed.

Korva Connect uses moderation and safety review to detect content that may be hateful, vulgar, lewd, abusive, or otherwise unsafe. Flagged content is not served for retrieval until corrected and uploaded again.

Analytics and diagnostics

Korva Connect records limited analytics about ChatGPT plugin usage, including prompt category, category confidence, prompt length, word count, hashed prompt, tool name, route, response mode, reference counts, scripture reference counts, private/group/published knowledge counts, search method, latency, success or failure status, and error kind.

Korva Connect analytics are designed to understand how the tool is used without storing the raw prompt text in analytics usage events.

For app performance and reliability, Korva Connect may temporarily retain anonymized prompt records so they can be compressed into privacy-safe topic labels and usage patterns; raw prompt text is deleted within 24 hours after that daily processing.

Korva Connect may store diagnostic events for account linking, OAuth, MCP calls, and other operational flows to troubleshoot bugs, security checks, and failed requests.

Visibility and sharing

Group content is shared with active members of that group based on their roles and permissions. Group admins may manage group descriptions, members, documents, posts, and group settings according to the app's role rules.

Signup responses show responder names to active group members so groups can coordinate events, tasks, and shared plans.

Poll responses are stored and returned as anonymous aggregate counts. Korva Connect does not display voter names in poll results.

Published or public content may be available more broadly through Korva and ChatGPT retrieval than private or group content.

Retention and deletion

Uploaded content, posts, group records, and account records are generally kept until they are deleted, disabled, superseded, or no longer needed to provide Korva Connect.

When you delete your account, Korva Connect removes or anonymizes your account access, personal uploads, group uploads you own, group posts you authored, comments, signup responses, poll votes, hidden-item settings, sessions, and account-linking tokens. The account record is anonymized and disabled rather than hard-deleted so shared groups and records belonging to other users are not accidentally removed.

If a deleting account owns an active group, Korva Connect transfers ownership to an active Group Admin when one exists. If the group has no active Group Admin, the group is archived and no longer appears as an active group.

Password reset links expire after 30 minutes. Email verification links expire after 24 hours. Manual MCP link codes expire after 10 minutes. MCP sessions expire after 10 days of inactivity and have a 30-day absolute maximum age. OAuth access tokens expire after 30 days unless revoked earlier.

When users delete permitted documents, posts, or accounts, Korva Connect removes the primary records and associated searchable chunks or embeddings according to the app's deletion behavior. Some data may remain temporarily in backups, security logs, provider logs, transaction records, or operational records for a limited period as needed for security, compliance, accounting, debugging, or service reliability.

User controls

Users can create an account, verify their email, reset their password, sign out, delete their account, delete permitted documents and posts, download permitted documents, respond to signup forms, vote in polls, and manage their own permitted Korva Connect content.

Users can revoke Korva MCP or ChatGPT account-linking sessions where the app exposes that control. Password resets also invalidate Korva Connect sessions and revoke active OAuth access tokens.

Group owners and admins can manage group members, member roles, group descriptions, group posts, group documents, invitations, join codes, and group deletion according to current Korva Connect role permissions.

To request access, correction, deletion, or account support, contact support@korvaconnect.com.

Security

Korva Connect uses HTTPS for data in transit and stores API credentials through managed secrets rather than in the public site code.

Korva Connect stores passwords as password hashes and stores reset, verification, OAuth, MCP, invitation, and join-code secrets as hashed values where practical.

Korva Connect uses account authentication, group membership checks, role-based permissions, visibility rules, moderation status checks, and retrieval filtering to limit access to private and group content.

No online service can guarantee perfect security. If you believe your account or group content has been accessed improperly, contact support@korvaconnect.com.

Children

Korva Connect is not intended for children under 13. Do not create an account or submit personal information if you are under 13.

Contact

For privacy, plugin review, or operational questions about Korva Connect, contact support@korvaconnect.com.