Privacy policy

Effective 2026-10-05.

Publisher: Quovo. Legal controller: Design Studio MS. Registered/contact address: pending Milan/legal confirmation before launch.

What this service processes

The tool receives the website URL and optional migration change type/target platform. It makes bounded public HTTPS requests for robots.txt, sitemaps and approximately ten HTML pages. It temporarily processes status/redirect information, URLs, metadata, headings, canonical/robots directives, static integration fingerprints and form presence to return a compact evidence inventory to ChatGPT or Codex.

Public page content may contain personal information. We minimize extraction and do not return full HTML, form field values or submitted form data. Metadata strings or public paths can still contain personal information. Do not supply sensitive URLs.

What Quovo does not collect

No accounts, login data, credential/cookie forwarding, private-page access or form submissions. Quovo does not harvest prompts or leads, sell user data, add advertising trackers, or retain application scan histories or full page bodies. The MCP input excludes raw conversations and user identifiers. ChatGPT/Codex conversation handling is governed separately by the host provider's policies.

Purpose and temporary processing

Processing provides the requested public migration inventory and protects service availability. Page bodies and scan objects are held in memory during a bounded request and discarded after handling; there is no scan-results database. In-memory processing is not a guarantee of instant physical memory erasure.

Operational metadata and recipients

Vercel hosts the service and may process request IP address, user-agent, method, service path/query, timestamps, HTTP status, request/deployment identifiers, region, duration and network/subrequest metadata. The application does not intentionally log raw prompts, scan targets, page bodies, credentials or scan results. Hosting instrumentation may still record outbound connection details. Target websites and DNS infrastructure see the bounded requests and crawler user-agent; the target may maintain its own logs.

The prepared production protection uses Vercel native fixed-window counters with constant service keys and HMAC-derived target keys. It is not yet configured or validated, and public scanning is disabled. Protection checks are designed to send no raw site URLs, page contents, prompts, cookies or credentials. No separate rate-limit datastore is connected. Vercel may retain operational/security records under its own policies. The tool result is returned to your ChatGPT/Codex host (OpenAI).

Retention and deletion limits

Application scan data is not persisted. The prepared native counter windows are one minute for service admissions and ten minutes for target cooldown. These windows are not a guarantee that all Vercel operational/security records are deleted at their end. HMAC-derived keys remain pseudonymous operational data, not guaranteed anonymous data. Provider logs have provider/plan-controlled retention; the current benchmark's observed one-hour runtime-log window does not describe all Vercel security logs or a future commercial plan. Security, backups and legally required records may be retained separately under provider policies. We do not claim immediate provider-wide deletion.

Final hosting plan/log retention and any enabled rate-limit processor must be checked before publication. This disclosure describes implementation and retention boundaries without promising a provider deletion interval we cannot establish. Support correspondence, if you send it, is handled by the confirmed contact's mail provider to resolve your request; share only minimal information. Ask about access/deletion rights using the privacy contact. Applicable rights and legal bases depend on the confirmed controller and jurisdiction.

Contact

milan@quovo.co

Vercel privacy policy · OpenAI privacy policy