Privacy Policy
Chatcove is built so that we cannot see your messages, and this page is the detailed version of that claim. It also lists, honestly, the small amount of data we do hold.
Last updated: 9 September 2026
The short version
- Your WhatsApp history, your media, your contacts and your exports stay on your Mac. They are never uploaded, and we have no way to read them.
- Chatcove makes exactly two kinds of network call: an update check, and a licence check. Neither carries any part of your chat data.
- If you buy, we hold your email address and your licence record. That is the whole customer database.
- This site uses Cloudflare Web Analytics, which sets no cookies and stores no identifier in your browser. There is nothing to consent to, so there is no banner.
- We have never sold personal information and we do not run advertising.
Who we are
Chatcove is made and sold by Codama Advanced Engineering, Inc., a Delaware C-Corporation with its registered office at 8 The Green, Ste A, Dover, DE 19901, USA. For data protection purposes we are the controller of the personal data described below. Reach us at hello@chatcove.app.
Part 1: the app on your Mac
Your chats never leave your Mac
Chatcove asks your iPhone to make a standard encrypted backup, decrypts it locally, reads the WhatsApp databases, and writes your export to a folder you choose. Every one of those steps happens on your machine. No message text, no photo, video or voice note, no contact name, no phone number and no export file is ever transmitted to us or to anyone else.
This is not a policy commitment we could quietly break. There is no upload code and no server that could receive your history. The only network calls in the app are the two below, and their contents are fully listed.
Network call 1: the update check
Chatcove checks for a new version on launch and once a day after that, and immediately if you ask it to. The check downloads a small version file from the public GitHub repository we publish releases to. It carries no chat data, no licence key and no email address.
It does carry one identifier, and we would rather spell it out than let you find it yourself. The update library we use attaches a random identifier that it generates once per installation and keeps in a file on your Mac. Its purpose is to let a release be rolled out to a percentage of installs at a time. It is random, it is not derived from your hardware, and it is not linked to your licence, your email or anything else we hold. GitHub also sees the IP address the request came from, as it would for any download.
If you would rather Chatcove made no automatic requests at all, you can turn automatic update checks off in Settings. With them off, no check is made on launch or on a timer, and Chatcove only contacts GitHub if you click the check button yourself.
Network call 2: the licence check
Chatcove is licensed for up to 2 Macs, and enforcing that needs a small server. When you activate a licence, and periodically afterwards to confirm the Mac is still one of yours, the app contacts our licence server. The entire request body is these four fields, and nothing else:
- Your licence key. The key you were emailed. It is signed by us and carries your email address, your tier and the date it was issued.
- A device id. A random identifier generated once when you first activate, and stored encrypted on your Mac. It is not derived from your hardware: not a serial number, not a MAC address, not a fingerprint of your machine. It identifies an installation, not a person or a computer.
- A device name. Your Mac's name, so that when you hit the 2-Mac limit we can show you a list you actually recognise and let you free a slot. Worth being blunt about this one: macOS usually names a Mac after its owner, so this field often contains your real name. If you would rather it did not, rename your Mac in System Settings before you activate.
- The app version. For example 0.1.0, so we can tell which build a licence is running.
You can browse your entire history, and use the app day to day, without the network. After a successful activation Chatcove keeps working offline for a grace period and re-checks quietly when you are online again. Activating a new licence for the first time does need a connection.
What Chatcove stores on your Mac
All of this stays local and none of it is sent anywhere.
- The iPhone backup, the decrypted databases and the search index, in a private folder inside Chatcove's application support directory. This is the bulk of your data, and you can delete it from inside the app at any time. You can also move the backup folder to an external drive.
- Extracted media, and your exports, written to the folder you pick. Exports default to your Downloads folder.
- Your licence key, your activation record and your device id, each encrypted with macOS safeStorage, which means they are protected by your Keychain. Your email address is never written to disk in the clear: it is read back out of the encrypted key when it is needed.
- Your iPhone backup password, if you let Chatcove remember it, also encrypted with safeStorage. If encrypted storage is not available on your Mac, Chatcove refuses to save it rather than storing it in the clear.
- A small trial usage file holding a single number: how many trial exports you have used. It records a count, not content.
- App preferences, which include your iPhone's name and identifier, the folders you chose, and your export settings.
- Diagnostic logs. The main log is stripped as it is written, so message text, names, phone numbers and file paths do not reach it. The separate log from the backup step is the raw output of the backup tool and contains file paths, which include your macOS username. Neither is ever sent to us. If you attach one to a support email, you are sending it deliberately, and you can read it first.
Uninstalling Chatcove and deleting its application support folder removes all of it.
Part 2: this website
Analytics
chatcove.app uses Cloudflare Web Analytics. It records page views and coarse technical facts such as the page URL, referrer, country, browser and device type. It sets no cookies, stores nothing in your browser, and does not build a profile or track you between sites or across visits. We use it to see which pages people find useful. That is the only measurement on the site.
Cookies
This site sets no cookies of its own, and writes nothing to local storage or session storage. There is no advertising pixel, no social tracker, no session replay, no CAPTCHA and no third-party font service: the fonts are served from our own domain. Cloudflare, which serves the site, may set a strictly necessary cookie of its own to filter automated traffic. It carries no profile and we do not read it.
That is why you have not been shown a cookie banner. A banner exists to collect consent for storing or reading non-essential things on your device, and nothing here does that.
Links off the site
The buy button goes to Stripe, the download button goes to GitHub, and the footer links to codama.dev. Once you follow one of those, that company's own privacy policy applies.
Part 3: when you buy
Payment
Checkout runs entirely on Stripe, which is the merchant of record for the sale. Stripe collects your email address and payment details, plus a billing country and any details it needs for tax, and it calculates and remits any VAT, GST or sales tax. We never see or hold your card number. We do not ask for your phone number and Stripe does not collect one for us.
From the completed sale our server reads only these fields from Stripe: the checkout session id, your email address, your billing country, the amount and the currency.
What we store
Buying creates one record in our licence database. In full, that record is:
- a licence id, your email address, the tier, and the seat limit;
- your licence key, and the date it was issued;
- the Stripe checkout session id, so a repeated webhook cannot issue you a second key;
- the date the key was emailed to you;
- the created and updated timestamps, and a status flag we can set if a licence has to be revoked.
Your licence key is stored as issued, and the key itself contains your email address. We keep it so that we can re-send it when someone loses it, which is the single most common support request we get.
Each Mac you activate adds one row: the device id, the device name, the app version, when it was activated and when it was last seen. Removing a licence from a Mac deletes that row.
The amount, currency and country from your purchase are used to send our own team a notification that a sale happened. They are not written to the database.
Your licence key is emailed to you through Infobip, our email delivery provider. They receive your email address and the message. The same notification described above, which contains your email address, the amount, the currency and your country, goes through Infobip to our own team addresses.
Mail you send to any address at chatcove.app is forwarded by Cloudflare Email Routing into a Google mailbox that we read. Support conversations therefore sit in an email inbox for as long as we keep them, like any other company's support email.
Server logs
Our own application logs record a licence id and the buyer email address when a licence is issued. They do not record IP addresses. Separately, the hosting platform in front of our server keeps its own access logs, which do include the IP address and browser user agent of every request, including the licence checks your app makes. We do not use those logs for analytics or profiling.
Where the data lives, and who processes it
We keep the list of processors short on purpose. These are all of them.
- Stripe (payments, merchant of record). Receives your email, payment details, billing country and tax details.
- Railway (hosting for the licence server, in the United States). Sees request traffic including IP addresses and user agents, and our application logs.
- Supabase (the Postgres database, hosted in Switzerland). Holds the licence and device records listed above.
- Infobip (email delivery). Receives your email address, your licence key, and the sale notification.
- Cloudflare (website hosting, Web Analytics, and email routing for chatcove.app). Sees site traffic and forwards inbound support email.
- Google (the mailbox that receives forwarded support email).
- GitHub (public hosting for the app download and the update feed). Sees the IP addresses of download and update requests.
Because our server is in the United States and our database is in Switzerland, buying Chatcove involves a transfer of your email address out of the EEA and the UK. We rely on the standard contractual clauses offered by these providers for that transfer. None of your chat content is involved, because none of it ever leaves your Mac.
Why we are allowed to hold it
For readers in the EU, the UK and similar jurisdictions, our legal bases are:
- Performance of a contract for your email address, licence record and device records. Without them we cannot deliver your key, honour the 2-Mac licence, or re-send a lost key.
- Legitimate interests for the update check, the seat check that stops one key being shared endlessly, and the aggregate site analytics. We think these are proportionate: the update check identifies nobody, the seat check holds an installation id and a machine name, and the analytics store nothing on your device.
- Legal obligation for the transaction records Stripe keeps for tax and accounting.
How long we keep it
We will describe this as it actually is rather than inventing a schedule we do not run.
We have no automatic deletion. Licence records, including your email address and your key, are kept for as long as the licence exists, because a perpetual licence has to stay redeemable for the same reason it has to keep working. If you ask us to delete your data we will do it by hand, promptly, and confirm it to you. Device rows are deleted as soon as you remove a licence from a Mac. Support email is kept in our mailbox until we clear it. Our hosting provider and Stripe apply their own log and record retention periods, which we do not control, and Stripe is required to keep transaction records for tax purposes even after we delete ours.
Your rights
Wherever you live, you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, or object to how we use it. In the EEA and the UK these are your rights under the GDPR, including the right to data portability and the right to complain to your national data protection authority. In California, the CCPA gives you the right to know, to delete, to correct, and to opt out of sale or sharing.
On that last one: we do not sell personal information, and we do not share it for cross-context behavioural advertising. We never have. There is no opt-out to offer because there is nothing to opt out of. We will never treat you differently for exercising any of these rights.
To exercise any of them, email hello@chatcove.app from the address you bought with, or tell us which address you used. We will respond within 30 days. We do not need identity documents, because the only thing we hold is tied to an email address.
Children
Chatcove is not designed for or directed at children, and we do not knowingly collect personal data from anyone under 16.
Changes to this policy
If the product changes, this page changes with it, and the date at the top moves. If we ever make a change that materially affects what we collect, we will say so clearly rather than quietly editing a paragraph.
Contact
Codama Advanced Engineering, Inc., 8 The Green, Ste A, Dover, DE 19901, USA. Email hello@chatcove.app. Our Terms of Service cover the rest of the relationship.
