Legal

Privacy Policy

Last updated 19 August 2026

Cove is a vault. The guiding rule is that the service should hold as little readable information about you as possible — and for your actual secrets, none at all. This page describes what is stored and how, in the same terms the code uses.

What is stored, and in what form

Three categories of data exist in the system, protected differently:

  • Your secrets — passwords, notes, TOTP secrets, security-question answers, and the contents of uploaded credential files. Every one is encrypted with AES-256-GCM before it reaches storage. Files are encrypted before they are uploaded to object storage, so the bucket holds only ciphertext.
  • Your account password — stored only as a bcrypt hash. It cannot be reversed, and it is never the key used to encrypt vault contents.
  • Metadata — entry names, categories, tags, timestamps, filenames, file sizes, and a SHA-256 checksum of each uploaded file. This is stored unencrypted so the app can list and search your vault. Choose entry names accordingly.

Duplicate detection without reading your passwords

Cove flags reused passwords by comparing one-way SHA-256 hashes, never the values themselves. The same technique verifies that an uploaded file has not been altered between upload and download.

Third parties

Cove has no analytics, no advertising, no trackers, and no third-party scripts. Data is not sold, rented, or shared.

One optional integration exists. If AI features are enabled by the operator, search queries you type and anonymised vault statistics — counts and ratios, never entry contents — are sent to Groq to be processed. With no API key configured, every AI feature reports itself unavailable and no data leaves the server. Vault contents are never transmitted to any AI provider under any configuration.

Where your data lives

Cove is self-hostable. When you run it yourself, the database, the object storage bucket, and the encryption key are all yours, and this policy describes software behaviour rather than a service you are entrusting to someone else. When you use a hosted instance, the operator of that instance controls the infrastructure and is responsible for its jurisdiction, retention, and backups.

Deletion

Deleting an entry moves it to trash, where it stays until you delete it permanently. A permanent delete removes the database rows and issues a delete for the corresponding objects in storage. Deleting your account cascades to every entry, file, category, and tag you own.

Backups, if the operator keeps them, may retain deleted material until they age out on their own schedule.

The limits of this design

Encryption happens on the server, using a key held in the server's environment. This means an operator with access to both the running server and its environment could decrypt vault contents. Cove is not end-to-end encrypted, and this page does not claim otherwise. If your threat model requires that the operator cannot read your data, run your own instance.

Changes

Material changes to this policy will be reflected in the date at the top of this page.

Privacy Policy — Cove