Legal
Privacy Policy
Last updated: June 2026
Who we are
Covenant Lab is operated by an individual data controller based in the United Kingdom. For data enquiries, contact: covenantlab@proton.me
What data we collect
- Email address (provided when you request or redeem an invitation)
- Commitment data (any expressions of interest you make on the platform)
- Usage data (standard server logs — IP address, browser type, pages visited)
Why we collect it
- Email: to provide access to the platform and send platform notifications
- Commitment data: to operate the conditional commitment mechanism
- Usage data: for security and performance monitoring
Legal basis (UK GDPR)
We process your data under legitimate interests (operating the platform) and, where applicable, contract performance.
How long we keep it
- Active user data: retained while your account is active
- Commitment data: retained for 7 years for audit purposes
- Usage logs: 90 days
Your rights
Under UK GDPR you have the right to access, correct, delete, or port your data. To exercise any right, contact us at covenantlab@proton.me. You also have the right to complain to the ICO at ico.org.uk.
Third parties
We use the following third-party services:
- Railway (hosting) — data processed in the USA under standard contractual clauses
- Resend (email delivery) — data processed in the USA
- Neon/PostgreSQL (database) — data stored in the USA
We do not sell your data. We do not use your data for advertising.
Cookies
We use a single session cookie required for authentication. We do not use tracking or advertising cookies.
Changes
We may update this policy. Continued use of the platform after changes constitutes acceptance.