CovaSyn Privacy Policy
Effective date: 19 May 2026 · Last updated: 7 October 2026
Deutsche Fassung: Datenschutzerklärung.
1. Who we are
This Privacy Policy applies to the CovaSyn services, including the website covasyn.com, the workspace application at workspace.covasyn.com, our MCP server endpoints, and the CovaSyn application available in the ChatGPT App Directory (collectively, "CovaSyn").
The controller is:
CovaSyn GmbH
Naunhofer Straße 67, 04299 Leipzig, Saxony, Germany
Registered in the German Commercial Register (Handelsregister), Amtsgericht Leipzig, HRB 43655
Managing Director: Dr. Oliver Kraft
Email: support@covasyn.com
Web: https://covasyn.com
For all questions about this policy or your data, contact us at support@covasyn.com.
2. Scope
This policy covers personal data we process when you interact with CovaSyn, including via our MCP server endpoints and via the CovaSyn application inside ChatGPT. It does not cover OpenAI's separate processing of your ChatGPT conversation, which is governed by OpenAI's own privacy policy, nor any other MCP client's processing (e.g., Claude Desktop, Cursor, VS Code) which is governed by its respective vendor's policy.
3. Data we process
When you invoke a CovaSyn tool the following data flows to us:
Scientific input data. Chemical structures (SMILES, InChI, MOL, SDF), biological sequences (protein, RNA, DNA), spectral data (NMR, IR, MS, UV-Vis), experimental measurements, and any other scientific input you provide to a tool. This data may, in rare cases, contain or imply personal information if you include it (for example, patient identifiers in clinical data). We ask users not to submit such data.
Authentication and account data. If you connect a CovaSyn account, access to which is granted only after an initial call or demo call, including for the Free tier: API key (hashed at rest), account email, plan tier, language preference.
Technical metadata. Timestamp, tool name invoked, request size, response status, IP address (truncated to /24 after 24 hours), and, for ChatGPT App invocations, the session identifier provided by ChatGPT. Required for rate-limiting, abuse prevention, billing, and security.
We do NOT collect: ChatGPT conversation history outside of the specific tool invocation, your OpenAI account identity beyond what OpenAI passes us, or content from other ChatGPT apps. We do not collect biometric data, do not run advertising trackers on our application surfaces, and do not sell personal data.
4. Purposes and legal basis (GDPR Art. 6)
| Purpose | Legal basis |
|---|---|
| Providing the requested computational result | Art. 6(1)(b) GDPR, contract performance |
| Rate-limiting, abuse prevention, security | Art. 6(1)(f) GDPR, legitimate interest |
| Billing and account management (paid tiers) | Art. 6(1)(b) GDPR, contract performance |
| Tax and accounting record retention | Art. 6(1)(c) GDPR, legal obligation (§ 147 AO) |
| Aggregated, non-identifying usage analytics | Art. 6(1)(f) GDPR, legitimate interest |
| Scheduling through the initial call and demo call form: confirmation, reminders, rescheduling and cancellation | Art. 6(1)(b) GDPR, pre-contractual step taken at your request |
| Technical update emails unrelated to a booking (only with your explicit opt-in on the form, revocable at any time) | Art. 6(1)(a) GDPR, consent |
4a. Booking form (initial call and demo call)
Qualification form. Before you book an initial call or demo call via /intro-call, we ask for: first and last name, work email address, company, role, area (initial call), your interest, a short description of your request (optional for the demo call), optionally your team size, and your privacy consent. We technically check whether the domain of your email address can receive email and note whether it is a private mailbox. The purpose is preparing the appointment and taking steps prior to entering into a contract; the legal basis is Art. 6(1)(b) GDPR. We store the details with your request and with your contact in our CRM on our infrastructure in Germany. The form is protected by Cloudflare Turnstile (see the section on Cloudflare Turnstile). Retention, email delivery and video meetings are governed by the following paragraphs.
When you request a slot via /intro-call, we process the details you provide: first and last name, work email address, company, role, country, industry, team and company size, your start horizon, your optional description of the use case and, if you pick a phone slot in the German speaking region, your phone number. We also store technical context of the request: time, language, your browser timezone, the origin of the visit (campaign and referrer parameters) and the time of your privacy consent.
We use this to prepare and hold the call and to send the confirmation, the calendar invite and reminders. From your answers we derive automatically whether a call or direct free access is the more sensible path. That classification has no legal effect on you and is not an automated decision in an individual case within the meaning of Art. 22 GDPR; it only controls which content we show you. To prepare the call we additionally retrieve publicly available information from your company website (Art. 6(1)(f) GDPR).
Processing and storage take place on our own infrastructure in Germany (Hetzner, Nuremberg). Confirmation and reminder emails are sent via Microsoft 365. For video meetings we use Microsoft Teams, which generates a meeting link (Microsoft Ireland Operations Limited acting as processor). A calendar entry for the meeting is created in our Microsoft 365 calendar.
Retention: booking-related data is kept for up to 24 months after the last contact and then deleted. If a contract is concluded, commercial and tax retention periods apply (§ 147 AO). You can withdraw your consent to technical update emails at any time via the unsubscribe link in any such email or by writing to support@covasyn.com. Withdrawal does not affect the lawfulness of processing carried out beforehand and does not affect booking emails.
4b. AI maturity check
Answers without contact details. In the maturity check at /reifegrad we store your selected answers after each step, together with a random identifier, the language, the time and the origin of the visit (campaign and referral parameters). We store neither your name nor your IP address; the IP address is only used briefly in memory to prevent abuse. The identifier is also kept in your browser's local storage so you can continue after reloading; "Start over" deletes it. The purpose is to show you your result and to understand where companies stand in their use of AI. The legal basis is our legitimate interest in improving our offering (GDPR Art. 6(1)(f)). Answers without contact details are deleted after 24 months at the latest.
Report by email. If you request the report at the end, we additionally process your first and last name, business email address, company and, optionally, your role. We send the report to you once and store your details and answers with your contact in our CRM on our infrastructure in Germany; the legal basis is GDPR Art. 6(1)(b) (your request). Without your consent we send no further marketing emails. Contact: only if you tick the optional box may we contact you about your result by email or phone (GDPR Art. 6(1)(a)). You can withdraw your consent at any time with effect for the future, for example by email to support@covasyn.com. We use Cloudflare Turnstile to protect the form.
4c. Beginner's guide (free download)
If you request the beginner's guide at /resources/beginners-guide, we process your first and last name, business email address, optionally your company and role, the wording and version of your consent with its time, the language of the page, the origin of the visit (campaign parameters) and the time of confirmation and downloads. The sole purpose is to send you the guide; the legal basis is your consent (GDPR Art. 6(1)(a)). We first send an email with a confirmation link (double opt-in); only after confirmation do you receive a personal download link valid for seven days. We store the details in our CRM (processors listed in section 7); no automated sales or newsletter contact follows from this. We delete unconfirmed requests after 30 days. You can withdraw your consent at any time with effect for the future, for example by email to support@covasyn.com.
5. We do not train models on your data
Scientific inputs you submit are used only to compute the requested result. We do not use customer inputs to train, fine-tune, or otherwise improve our ML models.
CovaSyn tools are deterministic computational functions built on our own chemistry, spectroscopy, and structure engines. Tool execution does not involve any external Large Language Model, foundation model, or other third-party model provider in the data path. Your inputs are processed exclusively by CovaSyn-owned, deterministic engines.
Where we develop our own predictive models internally, training uses only public datasets (for example USPTO, PubChem, ChEMBL) and data we have explicitly licensed for that purpose.
6. Data retention
- Scientific inputs and outputs: processed in memory and not persisted to long-term storage. Short-term operational logs that may include payloads are discarded within 30 days.
- Technical metadata (truncated IP, tool name, timestamp, allowance consumed): 90 days for security and abuse prevention.
- Account data: retained while the account is active and deleted on account deletion, except where legal retention applies.
- Billing records (paid tiers): retained for 10 years per German tax law (§ 147 AO).
- Free-tier interactions: no payload-linked retention beyond the 90-day technical metadata window.
7. Recipients and sub-processors
We share data only with the following categories of recipients, acting as processors under Art. 28 GDPR. Data Processing Agreements (DPA / AVV) are in place with each and are available on request via support@covasyn.com.
- Hetzner Online GmbH (Industriestraße 25, 91710 Gunzenhausen, Germany), primary hosting in Nuremberg (DE) for covasyn.com, workspace.covasyn.com, the MCP gateway, application backend, database servers, and internal systems. EU processing.
- Cloudflare, Inc. (USA, EU presence), authoritative DNS for covasyn.com. No reverse-proxy or web-application-firewall routing through Cloudflare; traffic resolves directly to our Hetzner origin. Also the security service Turnstile, which protects our forms against automated submissions (see section 7a). Transfers to the USA are based on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses (SCCs).
- Supabase Inc. (USA, EU region for our project) - authentication and database for the workspace. Data: email, password hash, profile, tool-call metadata, API key hashes. SCCs in place; data resides in the EU.
- Stripe Payments Europe Ltd. (Ireland), payment processing, invoicing, Stripe Tax. Data: email, billing address, VAT ID (if provided), card data (handled exclusively by Stripe).
- Resend Inc. (USA, sending via EU AWS infrastructure) , transactional email (account confirmation, payment receipts, password reset). Data: email address and message content. SCCs in place.
- Microsoft 365 (Microsoft Ireland Operations Ltd., Dublin), corporate email and internal collaboration. Used only for our own business correspondence, not for processing user payloads.
- Anthropic PBC (USA), language model for the chat assistant in the structure editor and for the interpretation feature in campaign analysis. Transmits the structure being worked on, the conversation history and tool results, respectively statistical evaluations. SCCs in place.
- Twilio SendGrid (USA), fallback path for delivering system messages when Resend is unreachable. Data: email address and message content. SCCs in place.
- Trustpilot A/S (Denmark), collection and display of customer reviews. EU processing.
- Google Ireland Limited (Dublin; onward processing by Google LLC, USA), Google Analytics 4 for reach measurement. We do not use advertising services. Data: truncated IP address, device and browser details, the requested page in sanitised form and, after your consent, an identifier stored in a cookie. SCCs in place; Google LLC is self-certified under the EU-U.S. Data Privacy Framework. See section 7a for details.
We do not sell personal data. We do not share data with advertisers. The processor list is updated when changes occur; the version above reflects the state on the "Last updated" date.
7a. Cookies, analytics and reach measurement
When you visit covasyn.com we first set only strictly necessary cookies (Art. 6(1)(f) GDPR / § 25(2) TTDSG), for example for your language preference and your cookie choice itself. On your first visit we show a cookie notice with a choice between "Reject" and "Accept".
We use Google Analytics 4, provided by Google Ireland Limited, to measure how this website is used. It was switched off temporarily between 7 and 11 September 2026 and has been active again since. We do not use advertising services: Google Ads was removed on 7 September 2026 and has not been re-added; a Meta Pixel was removed on 31 July 2026 and will not return.
We use Google's Consent Mode v2. Until you consent, all consent signals are set to "denied". The Google tag script (gtag.js) is loaded from Google, but performs no measurement before your consent: no cookies are set, no page views or events are reported and no measurement data is sent to Google. When the script is loaded, Google technically receives your device's IP address, as with any file retrieved from a third-party server. The legal basis for this loading is our legitimate interest in technically providing the consent management (Art. 6(1)(f) GDPR); no measurement takes place and no cookies are set. To the extent nothing is stored on or read from your device, we additionally rely on § 25(2) TTDSG.
Only when you choose "Accept" may Google set cookies and attribute your visits to an identifier across devices. The legal basis is then your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG). If you choose "Reject", the refusal is recorded explicitly in the Google tag and no measurement data is sent to Google. If you withdraw consent later, we stop the measurement and delete the Google Analytics cookies (_ga, _ga_*) on this device.
We have technically limited what reaches Google: automatic collection of the full address, the referring page and the page title is switched off and replaced with sanitised values. What is transmitted is the origin and path of the requested page without query parameters. Content you enter (structures in the sketcher, file names, form text) therefore does not reach Google. The IP address is truncated.
If you choose "Accept", we additionally count page views on our own server (dashboard.covasyn.com) so we can see how visitors find us. The legal basis is your consent (Art. 6(1)(a) GDPR, § 25(1) TTDSG). The data does not leave our own infrastructure.
In addition, we run a self-hosted, cookieless measurement layer (Umami) on our own infrastructure in Germany. It does not use cookies or any other identifier stored on your device and does not transmit data to third parties; it runs independently of your cookie choice, based on our legitimate interest in aggregated, non-personal usage statistics (Art. 6(1)(f) GDPR).
Cloudflare Turnstile. To protect our forms (sign-up, password reset, DPA request, contact form, newsletter) against automated submissions, we use the security service Turnstile by Cloudflare, Inc. The script is only loaded when you interact with one of these forms and is retrieved from Cloudflare. On submission our server verifies the token issued by Turnstile with Cloudflare and transmits the token and the IP address of the request for that purpose. The sole purpose is defending against bots and abuse. The legal basis is our legitimate interest in bot defence and abuse protection (Art. 6(1)(f) GDPR).
Overview of cookies and storage entries
As of 13 September 2026. Entries marked "Yes" in the last column are only set after you choose "Accept", and are removed again when you choose "Reject" or withdraw consent.
| Name | Type | Provider | Purpose | Category | Storage duration | Only after consent |
|---|---|---|---|---|---|---|
| cova_cookie_consent | localStorage | covasyn.com | Stores your choice in the cookie notice. | Necessary | Until you delete it in your browser | No |
| NEXT_LOCALE | Cookie | covasyn.com | Remembers the selected language. | Preferences | Session | No |
| ketcher_editor_saved_settings, ketcher-opts | localStorage | covasyn.com (Ketcher) | Settings of the structure editor in the sketcher. Only set when you open the editor. | Preferences | Until you delete it in your browser | No |
| covasyn_utm_v1 | localStorage | covasyn.com | Campaign origin (utm parameters, link token from emails), so a later sign-up or enquiry can be attributed to its source. | Statistics | 90 days | Yes |
| cs_vid | localStorage | covasyn.com | Random visitor ID for counting page views on dashboard.covasyn.com. | Statistics | Until you delete it in your browser | Yes |
| _ga, _ga_* | Cookie | Google Ireland Limited | Google Analytics 4, reach measurement. | Statistics | Up to 2 years (set by Google) | Yes |
| Umami | none | covasyn.com (selbst gehostet) | Cookieless reach measurement. Stores nothing on your device. | Statistics | No storage | No |
You can change or withdraw your cookie choice at any time via "Cookie settings" in the footer of this site (right to object under Art. 21 GDPR, or withdrawal under Art. 7(3) GDPR). Withdrawal takes effect going forward and stops the counting of page views on this device.
8. International data transfers
If you reach CovaSyn through the ChatGPT integration, OpenAI (United States) receives your tool invocation as part of the ChatGPT flow. That transfer is governed by OpenAI's own agreements with you and by the EU-U.S. Data Privacy Framework, under which OpenAI is self-certified.
Where we use US-based processors (for example Stripe, Supabase, Resend, Cloudflare, Anthropic, Twilio SendGrid), transfers are based on Standard Contractual Clauses (SCCs) per Art. 46(2)(c) GDPR and on the EU-U.S. Data Privacy Framework where applicable. The reach measurement of this website does involve a transfer to the USA, to the extent that Google Ireland Limited passes data to Google LLC; this is based on SCCs and the EU-U.S. Data Privacy Framework. Before you consent, no measurement data is sent to Google; for technical reasons Google then only receives the IP address when the script is retrieved. The self-hosted measurement layer (Umami) and our own page-view counter are unaffected: they run entirely on our own infrastructure (see section 7a).
9. Your rights (GDPR Art. 15 to 22)
You have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data (Art. 17), subject to legal retention obligations
- Restrict processing (Art. 18)
- Data portability (Art. 20)
- Object to processing based on legitimate interest (Art. 21)
- Withdraw consent at any time, without affecting prior processing
- Lodge a complaint with a supervisory authority. The competent authority for CovaSyn GmbH is the Saxon Data Protection Commissioner (Sächsischer Datenschutzbeauftragter), Bernhard-von-Lindenau-Platz 1, 01067 Dresden, Germany.
To exercise these rights, email support@covasyn.com. We respond within one month per Art. 12(3) GDPR.
10. Security
All data in transit is encrypted with TLS 1.2 or higher. Authentication uses bearer tokens transmitted over HTTPS; API keys are stored as Argon2id hashes. Internal systems follow the principle of least privilege, full-disk encryption is enabled on all storage volumes, and we perform regular security reviews. We will notify affected users and the competent authority within 72 hours of becoming aware of a personal data breach affecting your data (Art. 33 and 34 GDPR).
More detail on our security posture is available on the Security page.
11. Children
CovaSyn is intended for professional use in chemistry and pharmaceutical R&D. It is not directed at children under 16, and we do not knowingly process data from children.
12. Changes
We will post material changes to this policy on this page at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.
13. Data Protection Officer
CovaSyn GmbH is currently below the statutory thresholds for mandatory designation of a Data Protection Officer under Art. 37 GDPR in conjunction with § 38 BDSG. We have therefore not designated a DPO at this time. All privacy questions and data-subject requests are handled by management at support@covasyn.com. Should we cross the threshold or expand into processing categories that require a DPO, we will appoint one and update this section.
