Privacy
Cove is a self-check. You submit your own name, email, phone, optional password, optional Social Security number, files, and photos on the check form — after you have seen the sample. Queries are not a look-up of someone else. Looking up someone else voids the purchase.
Stored on this device. The report, receipt, and photos stay in this browser (or the app sandbox) until you wipe them. Cove does not keep an account.
Waitlist. If you ask to be notified for the TestFlight app, we store only that email to send that notice. We do not sell it. You can ask us to remove it from Contact.
Sent off-device during a check. Email goes to a public breach catalog (XposedOrNot) which returns incident names. A 5-character password hash prefix goes to Have I Been Pwned. The email local-part and name spellings are checked against public profile APIs (GitHub, GitLab, Reddit, Hacker News, npm, Chess.com, Keybase) and Gravatar. Quoted name, email, and phone are searched on DuckDuckGo. If you add an SSN, the quoted number and last-four + name are searched the same way — the number is not stored. Photos you attach are sent to public reverse-image indexes (Yandex, Reddit/RepostSleuth). Adult hosts and imageboards are dropped from those results. Optional pixel review uses an on-demand vision model for location clues — not to identify people.
Payment. The full report is a $9.99 USD digital unlock for this check. On the web, Square processes the card and the money lands in the seller’s Square account. On iOS, Apple In-App Purchase. On Android, Google Play Billing. Cove never stores card numbers. Receipt email is used only for the Square/store receipt.
Photos. Camera and library access are used only when you pick a photo. Originals are not uploaded to Cove servers for storage.
Wipe the report when you are done. Contact: the Support page in this app.