Skip to content
Legal

Privacy Policy

What does Cuvy do with my data?

Cuvy collects the account you create, the lists you build in your workspace, and enough usage data to run the service and bill it. The extension reads only the LinkedIn or Sales Navigator page you already have open. Business contact data is held on a legitimate-interest basis. Lists a customer builds are not sold. Ask for deletion and it is done within 30 days.

Last updated
6 September 2026
Deletion honoured within
30 days
Your lists
Never sold or licensed
Free, Starter, Growth
Findings join the shared index
Cookies on this website
None until you open the chat

Last updated · Covers cuvy.io, app.cuvy.io, the browser extension and the API

On this page

This policy covers Cuvy: the site at cuvy.io, the app at app.cuvy.io, the browser extension and the API. It is written to be read rather than survived. Where a sentence had to choose between sounding good and being accurate, it is accurate.

What we collect

Four kinds of thing. They are worth keeping apart, because they are held for different reasons and for different lengths of time.

Account data

Your name, your email address, and a password stored as a hash that cannot be read back out. If you are on a team, we hold which workspace you belong to and what you are allowed to do in it.

Workspace data

Everything you put into Cuvy or build with it: the people and companies on your lists, the list names, the tags and notes you add, the CSVs you upload, your saved searches, your exports, and the token that connects your workspace to HubSpot. This is your material. We process it to run the service for you, and for nothing else.

Usage and billing

Which runs you started, how many people they looked at, what each one spent, and the errors and timings that tell us whether the service is working. Credits are recorded in an append-only ledger, because an invoice you cannot reconcile is not an invoice. Card details are handled by our payment processor and never reach us; we hold the customer reference, the plan and the invoice history.

Support correspondence

If you write to us, we keep the thread. If you send a file so we can reproduce a problem, we delete it once the problem is fixed.

What the extension reads, and what it cannot

This is the part people ask about most, so here is all of it. When you open the Cuvy panel on a LinkedIn or Sales Navigator page, it reads what is on that page — the name, headline, employer, job title and profile address of the person or the people shown — and sends that to Cuvy's own API to ask what we know about them. It goes nowhere else.

Looking is read-only. Opening the panel on a profile creates no record and spends no credit. A row appears in your workspace when you reveal an address or save the person to a list.

What it cannot do, as a matter of what it is permitted to see:

  • It cannot read your other tabs, or any site other than the ones it asks permission for at install.
  • It cannot read your LinkedIn messages, your notifications or your connection list. It reads the page in front of it, not the account behind it.
  • It does not sign in as you. It carries its own token, issued when you signed in to Cuvy, kept in the browser's extension storage.
  • It sends nothing from your account: no messages, no invitations, no profile views beyond the page you opened yourself.

Business contact data, and why we hold it

Separately from anything a customer does, Cuvy maintains its own index of business contact details: names, employers, job titles, work email addresses and, for some people, a phone number or a personal email address. It comes from licensed datasets, from sources published openly on the web, and from what our own lookups establish.

We hold it on the basis of legitimate interest — telling one business how to reach another at work — rather than consent, which there is no honest way to collect at this scale. That interest has limits, and they are drawn where they belong. The index is about working life. It holds no health data, no financial data, nothing political or religious, no home address and nothing about anybody's private life.

We do not write to every person in the index to tell them we hold their details. The effort would be disproportionate to the intrusion, and this page is the public notice that stands in its place. If you are in the index and would rather not be, the route is short and open to anyone: see do not sell or share my information, which works whether or not you live in California.

What is yours and what is ours

The lists a customer builds are not sold, not licensed, not shared with another customer and not offered to anybody as a dataset. Your list names, your tags, your notes, the columns you imported, which people you picked and the fact that you were interested in them stay inside your workspace. There is no version of Cuvy in which somebody buys your prospect list.

The half most policies leave out is the other one. An email address is a fact about a person, not property of the customer who paid to see it. On the Free, Starter and Growth plans, an address a lookup you ran established may stay in our index and may later be returned to a different customer who looks the same person up — that is part of what those plans are paid with, and part of why they cost what they do. On Pro and Scale it does not: what Cuvy finds for those workspaces stays in them. On every plan, an address you typed in or imported yourself is never pooled. The terms set out which plans contribute.

This website

cuvy.io runs no analytics, no advertising pixel and no session recorder. It sets no cookie either, until you open the live chat. The chat is deliberately not loaded with the page: the button in the corner is plain markup, and pressing it is what fetches the widget. From that point our chat provider sets a cookie and keeps the conversation on your device so it survives a reload. If you never press it, nothing is stored and nothing about your visit reaches the chat provider at all — which is why nothing asked you to agree to anything when you arrived.

Our servers keep ordinary request logs. The page does load its typefaces from Google Fonts, so Google's servers see the IP address of anyone who loads it. Those two, plus the chat once you open it, are the only third parties involved in showing you this page.

The app at app.cuvy.io sets one cookie, which keeps you signed in. It is strictly necessary, and there is nothing to opt out of there without also opting out of being signed in.

Who else touches the data

We use other companies to run parts of the service. Each processes on our instructions, under contract, and none may use what it holds for its own purposes. By category:

  • Payments. Taking payment and issuing invoices.
  • Application hosting and the managed database. Where the app runs and where workspace data sits.
  • Object storage and content delivery. Exports, backups and the files this site is made of.
  • Email verification. Checking whether an address is reachable before it is handed to you.
  • Email delivery. The mail Cuvy itself sends: sign-in links, receipts, and the notice that a run has finished.
  • Live chat. The conversation you start from the button on this site or inside the app, and — in the app, where you are signed in — the name, address and workspace it is attached to, so whoever answers knows who is asking.

We have not published a named list yet. Write to support@cuvy.io and we will send the current one. The data processing agreement covers how a new one is added and what notice you get.

How long we keep things

  • Workspace data — while the account exists. Dormant workspaces are not deleted automatically today. If you have stopped using Cuvy and would rather we no longer held your lists, ask, and we will delete them.
  • Billing records — as long as tax and accounting rules require, which is years rather than months. These survive a deletion request, because they have to.
  • Operational logs — a short window. They exist to diagnose a failure, they age off, and nothing in them is used to build a picture of you.
  • Suppression records — kept indefinitely, deliberately. If somebody has asked us not to hold their address, we keep the minimum needed to stop a later dataset quietly putting it back.

Deleting your data

Write to support@cuvy.io from the address on the account and ask. Within 30 days, and usually within a few working days, we delete the workspace and everything in it: the people, the lists, the uploads, the exports, the saved searches and the integration tokens. Copies inside backups go as those backups turn over, and are not restored into the running service in the meantime.

Two things survive, and you should know which. The billing records described above, and any contact detail our index held independently of you. The second is not a workspace record, so closing an account does not reach it — the opt-out route does.

Your rights, and how to use them

Depending on where you live you may have the right to ask what we hold about you, to have it corrected, to have it deleted, to object to our holding it, to receive a copy in a portable form, or to opt out of its sale. We apply all of these to everybody who asks rather than working out first which statute covers you.

There is one route, and it is an email:support@cuvy.io. No charge, and you do not need an account. We will ask enough to be sure we are answering the right person, which for an email address usually means writing from it. We will not ask you for a photograph of your passport.

If you are in the UK or the EEA and think a request was handled badly, you may complain to your data protection authority. We would rather hear it first, but it is your right either way.

Children

Cuvy is a tool for reaching people at work. It is not for anyone under 16, we do not knowingly hold personal information about children, and if we learn that we have some, we delete it.

Changes to this policy

The date at the top is the date this text last changed. If we change what we do with your data rather than how a sentence reads, we will say so at the top of the page and, if you are a customer, by email. We will not make a material change quietly and rely on you having re-read the page.

Who to write to

support@cuvy.io reaches the people who can act on a privacy request. There is no separate privacy inbox that routes to the same desk more slowly. Cuvy is operated from Delaware and Toronto, and support will send the contracting entity's full name and registered address on request.

Questions

What people ask about this policy

Does the Cuvy extension read my LinkedIn inbox or my other tabs?

No. It reads the profile or search results page you have open on LinkedIn or Sales Navigator, and only while the panel is open on it. It cannot see your messages, your notifications, your other tabs or any other site. It never signs in as you, and it sends nothing from your account.

You have my work email and I never gave it to you. What is your basis for holding it?

Legitimate interest: telling one business how to reach another business at work. We do not rely on consent for that, and we do not email everybody in the index to say we hold their details, because the effort would be disproportionate to the intrusion. This page is the public notice that goes in its place. You can object at any time and we will suppress the address.

If I delete my workspace, does the address you found for someone vanish from Cuvy entirely?

No, and it is worth being plain about it. Deleting your workspace removes your lists, uploads, notes and exports within 30 days. An address our own index already held, or established while running your lookup, stays in the index; it was never only yours. Suppressing an address itself is a separate request, and anyone can make it.

Where is Cuvy data held, and can I pick a region?

Not today. There is one production environment and every workspace is in it, so there is no EU-only or Canada-only option to select. If a procurement review needs the current hosting locations in writing, ask support and we will send them rather than print a map here that goes stale.

Do you publish your sub-processors by name?

Not yet. This page describes them by category: payments, hosting and the managed database, object storage, email verification, the live chat, and the mail we send you. The current named list exists and support will send it on request. That is better than publishing a list nobody keeps up to date.

Does cuvy.io set cookies or run analytics?

It runs no analytics, no advertising pixel and no session recorder. It sets no cookie either, until you open the live chat: the chat is not loaded with the page, and pressing the button for it is what fetches it. From that point the chat provider sets a cookie and keeps the conversation on your device so it is still there when you come back. Never press it and nothing is stored, which is why there is still no consent banner. The page does load its typefaces from Google Fonts, so Google sees the IP address of anyone who loads it. The app at app.cuvy.io sets one cookie, which keeps you signed in.