Privacy.
Last updated: 2026-09-30
Genvas is a desktop app. Your work happens on your computer, so we collect very little. This policy explains what we do collect, why, and your rights. The controller of your data is Genvas App, based in the United States.
What stays on your computer
Your boards, files, prompts, outputs and AI provider API keys stay on your device. Keys are stored in your system's keychain or locally on your computer. When you generate something, Genvas sends the request straight from your computer to the provider you chose, under that provider's privacy policy. We never receive it. Agents you connect over MCP, such as Claude Code or Codex, run on your computer under their own terms. Genvas has no accounts and no usage analytics.
What we collect
- Purchase: your email address and the Stripe checkout session id. Stripe collects your payment details; we never see your card.
- Licence: a licence id, a one-way hash of your licence key (not the key itself), the device limit, your updates end date, whether the licence was revoked, and when it was created.
- Devices: for each activated device, a salted one-way hash of its machine id (we cannot recover the hardware id from it), a device label, its platform (Mac, Windows or Linux), and when it was activated. We also keep the dates of deactivations.
- Requests: when the app or a browser contacts our servers (licence checks, update checks, downloads), your IP address and request details are processed to serve the request, rate-limit abuse and keep the service secure. Our own logs contain only shortened licence keys and activation ids and are kept briefly.
- Email: what you send us when you write to us.
Why, and on what legal basis
- To sell you a licence, send you your key, activate your devices and deliver updates: performance of our contract with you.
- To prevent licence sharing, fraud and abuse, and to secure our servers: our legitimate interests.
- To keep records required for tax, accounting and disputes: legal obligation and legitimate interests.
- To answer your emails: legitimate interests, or steps you asked for before a contract.
We do not sell your personal data, share it for advertising, or use it to profile you.
Who processes it
- Stripe processes payments as merchant of record. It handles your payment details, billing address and tax under its own privacy policy.
- Cloudflare hosts genvas.app and our licence and update servers, stores licence records and release files, and may send licence emails for us.
We may also disclose data if the law requires it, or to a successor if Genvas is sold or transferred, under this policy.
How long we keep it
We keep licence and purchase records for as long as the licence exists, and after that only as long as needed for legal, tax and dispute purposes. Device records stay until you deactivate the device; deactivation dates are kept to enforce swap limits. Server logs are kept for a short time. Emails are kept as long as the conversation is useful.
Your rights
Depending on where you live (including under the GDPR, the UK GDPR and California law), you can ask to access, correct, delete or export your data, and object to or restrict how we use it. Email hi@genvas.app from the address you bought with so we can verify you. We will not treat you differently for using these rights. Note that deleting your licence record ends your licence. In the EU and UK you can also complain to your data protection authority.
Cookies
genvas.app sets no cookies of its own and runs no analytics or tracking scripts. Our host Cloudflare may set a strictly necessary security cookie to filter bots. Stripe's checkout runs on Stripe's site and uses its own cookies.
Children
Genvas is not meant for children. You must be an adult, or have a parent or guardian's permission, to buy a licence. We do not knowingly collect data from anyone under 16; if you think we have, email us and we will delete it.
International transfers
Stripe and Cloudflare operate worldwide, so your data may be processed outside your country, including in the United States. Where required, these transfers rely on safeguards such as the European Commission's standard contractual clauses or the EU-US Data Privacy Framework.
Security
We store licence keys and device ids only as one-way hashes, sign licence tokens, and keep what we hold to a minimum. No system is perfectly secure, but there is little here to lose.
Changes
If we change this policy, we will post the new version here with a new date, and tell you by email for material changes.