Privacy policy

Effective September 18, 2026

This policy covers corwenco.com and the Corwen dashboard, the client platform at dashboard.corwenco.com, both run by Corwen LLC, Salt Lake City, Utah. Helen is the marketplace tab inside the dashboard; helen.corwenco.com redirects there. If you have a question about anything here, email stiles@corwenco.com.

Summary

The marketing site has no forms and sets no cookies. If you email us, we keep your email. The dashboard stores what you and your firm put into it and what we record about our work for you, so we can do the work you hired us for. We do not sell your information and we do not run advertising. We share it with the services listed below that help us run the site, the dashboard and your projects, with other clients only as described under Helen listings, with our lawyers and accountants, with a buyer of the business as described below, and when the law requires it.

corwenco.com

The marketing site has no forms, no account and no cookies. It asks you to email us with your company's name, roughly how many people work there, and one problem you want solved. If you do, we receive your name, your email address and whatever you write. We use it to reply to you and to plan the backlog review. We keep it in our mailbox with our email provider. Ask us and we will delete it.

Our hosting provider, Cloudflare, processes technical information about each visit, including your IP address, browser type, the page requested and the time, to deliver the site and protect it from attacks. If a page fails to load, your browser may send Cloudflare an error report. We do not receive a record of individual visits. Cloudflare shows us only totals, such as how many requests the site received.

The site loads its typefaces from Google Fonts, so Google receives your IP address and browser details when a page loads. Google Fonts does not set cookies.

We do not run advertising, analytics or tracking scripts on the site.

The Corwen dashboard

The dashboard is for clients of Corwen. You get an account because your firm hired us, and we create it for you.

What we store

A build's code repository is never shared with another firm. A build's page can show recent code changes from that repository: the first line of each commit message and the name of the person who made it, read from GitHub. That is turned off today.

We do not store your IP address. Our hosting providers process it to deliver each page.

What we use it for

Doing your projects, showing you what we did and how many hours it took, answering your requests and messages, keeping your account accurate and secure, and keeping records we need for accounting or legal reasons. If a workflow we build for your firm becomes a Helen listing, its description is also shown to other clients, as described below. We do not use your information for anything else.

Helen listings

Helen is the marketplace tab of the dashboard, where clients see workflows we can license or rebuild for them. A workflow that came out of your build may be listed there. A listing shows your firm's name, or your firm's industry and city, only if your firm has agreed in writing. Otherwise it says nothing about your firm. In a small market, industry and city may be enough to identify you. A listing never includes your firm's data. If a workflow from your build is licensed to another client, your hours ledger shows the referral credit and the listing name, not who licensed it.

Cookies

The dashboard sets two cookies when you sign in: helen, which holds your user ID and sign-in state, and helen.sig, a signature that shows we issued it. Both are HttpOnly, Secure and SameSite=Lax. If your account uses two-step sign-in, the cookie set at the password step holds only a pending user ID until you enter the code. They expire 14 days after you sign in, change your password or turn on two-step sign-in, and are removed when you sign out. Nothing is set if you do not sign in. They are required for the dashboard to work. There are no analytics or advertising cookies.

Who can see it

Everyone at your firm with a dashboard sign-in sees all of your firm's information in the dashboard, including hours, referral credits, contracts, requests, data-flow records and the full message thread. There is no per-person restriction: the admin and user roles see the same things. Our internal notes, technical notes, repository names, work logs we have not approved and the record of changes are not shown to your firm. You can ask us for a copy of all of it.

People at Corwen with a dashboard account can see every client's information, because they are doing the work. Every Corwen account must use two-step sign-in. Before anyone new at Corwen gets a dashboard account, we tell our clients by email.

No client can see another client's builds, hours, requests, messages, contracts or data-flow records. The only thing other clients can see about your firm is a Helen listing, as described above.

Signing in

You change your own password on the Account page. Two-step sign-in, a code from an authenticator app, is available to every user on the same page. A Corwen founder can set a new password for you or reset your two-step sign-in, for example if you are locked out. Either one signs you out everywhere and is recorded.

Who else handles it

When we share it

We share your information with the services above, and with other clients only as described under Helen listings. We may also disclose it when the law requires it, such as under a subpoena or court order, and to our lawyers and accountants, who must keep it confidential. If Corwen is sold or merges, client information would pass to the new owner under this policy, and we would tell you before it does.

We do not sell personal information and have not in the past. We do not share it for cross-context advertising.

How long we keep it

For as long as your firm is a client, and up to two years after. When your firm stops being a client, we record the date. The dashboard lists firms two years past that date as due for deletion, and a Corwen founder deletes them. Nothing is deleted automatically.

If you want your firm's records removed sooner, email us. Within 30 days we send you an export of all of your firm's dashboard records as a file and then delete them from the dashboard. Deletion removes everything the dashboard holds about your firm, including the hours ledger, except a record that your firm's records were exported and deleted, which holds no name and no details. Helen listings that came from your builds stay in Helen, with no link to your firm. Invoices and signed agreements are kept outside the dashboard, for as long as tax and legal rules require.

Some copies remain for a short time after deletion: the database's recovery history (6 hours today), server error logs (7 days), what a provider listed above keeps under its own retention, working files on our computers, including records of our sessions with AI tools, and the export file until we have delivered it to you.

If someone leaves your firm, email us and we will deactivate their account. We can also anonymize it: their name becomes "Former user", their email address and title are removed, the account can never sign in again, and their message read times are deleted. Messages and requests they wrote stay in your firm's record under "Former user".

Chat with Corwen

The dashboard has a chat box called Chat with Corwen. Today it runs on rules inside the dashboard: it sorts what you write into a category, answers from your firm's records, and files requests for the people at Corwen to review. Nothing you type there goes to any outside AI provider. We store the conversation with your firm's records, and the people at Corwen can read it. If that changes, this page will say so before it does.

Your business data during a project

Doing your project usually means we work inside your systems (your email, files, CRM, books, or industry software) and handle your customers' or clients' information. Before work starts, we agree the scope in writing with your firm: the systems we work in and the kinds of data involved. These are the rules we follow. Project details you put in the dashboard are covered by this page.

Your choices

Do Not Track

We do not track you across other websites, and neither the site nor the dashboard runs advertising or analytics scripts. Because there is no tracking to turn off, neither one responds differently to a browser's Do Not Track or Global Privacy Control signal. Google (for fonts) and Cloudflare (for hosting) receive your IP address and browser details when you load our pages, as described above.

Children

Our website and dashboard are for business users and are not directed to children. We do not knowingly collect information from anyone under 18 through them. Client data we handle during a project may include information about minors, such as dependents on a tax return, and the rules in the section above govern how we handle it.

Changes

We post every new version of this policy on this page with a new effective date. If we make a material change, we email every active dashboard user from stiles@corwenco.com before it takes effect. Small wording changes will just update the date.

Contact

Corwen LLC, Salt Lake City, Utah
stiles@corwenco.com