Privacy policy
Effective September 18, 2026
This policy covers corwenco.com and the Corwen dashboard, the client platform at dashboard.corwenco.com, both run by Corwen LLC, Salt Lake City, Utah. Helen is the marketplace tab inside the dashboard; helen.corwenco.com redirects there. If you have a question about anything here, email stiles@corwenco.com.
Summary
The marketing site has no forms and sets no cookies. If you email us, we keep your email. The dashboard stores what you and your firm put into it and what we record about our work for you, so we can do the work you hired us for. We do not sell your information and we do not run advertising. We share it with the services listed below that help us run the site, the dashboard and your projects, with other clients only as described under Helen listings, with our lawyers and accountants, with a buyer of the business as described below, and when the law requires it.
corwenco.com
The marketing site has no forms, no account and no cookies. It asks you to email us with your company's name, roughly how many people work there, and one problem you want solved. If you do, we receive your name, your email address and whatever you write. We use it to reply to you and to plan the backlog review. We keep it in our mailbox with our email provider. Ask us and we will delete it.
Our hosting provider, Cloudflare, processes technical information about each visit, including your IP address, browser type, the page requested and the time, to deliver the site and protect it from attacks. If a page fails to load, your browser may send Cloudflare an error report. We do not receive a record of individual visits. Cloudflare shows us only totals, such as how many requests the site received.
The site loads its typefaces from Google Fonts, so Google receives your IP address and browser details when a page loads. Google Fonts does not set cookies.
We do not run advertising, analytics or tracking scripts on the site.
The Corwen dashboard
The dashboard is for clients of Corwen. You get an account because your firm hired us, and we create it for you.
What we store
- About you: your name, work email, job title, your role on your firm's account (admin or user), whether your account is active, and when it was created.
- Your password, as a bcrypt hash. We never store the password itself and cannot see it. We set your first password when we create your account, and you change it on the Account page.
- Two-step sign-in, if you set it up: its secret, stored encrypted from the moment setup starts, whether it is on, and the time step of the last code used, so each code works only once. The secret stays stored if you stop before turning it on, and it is shown only to you, once, during setup.
- A counter that signs out your other sessions when your password or sign-in settings change.
- Your firm's name, industry and city, a short identifier for your firm, whether your firm is a current client, the date it stopped being one, and the date we created the record.
- Requests you submit: the title, the problem, how it works today and the systems involved, plus who submitted it and when, its status, our reason if we decline it, the build it led to, and the Helen listing it refers to, if any.
- Messages between your firm and Corwen, who wrote each one and when, and the last time each person at your firm opened the message thread.
- For each build: its name, status, phase, owner, next milestone and start date; build notes; live work sessions and progress updates, with the name of the person working; links to preview versions; the name of its code repository; and our internal notes.
- Work logs: the date, hours and summary of each piece of work, technical notes, who logged it, its status, and who reviewed it and when.
- The hours ledger: approved hours with the name of the person who did the work, adjustments with their reasons, and referral credits owed to your firm. Ledger entries cannot be edited or deleted, except when all of your firm's records are deleted. Corrections are added as new entries.
- Data-flow records: for each build, every system it touches, the kinds of data, whether it reads or writes, why, the vendor, how long the data is kept and who can reach it.
- Records of contracts between your firm and Corwen: the title, type, date and who added the record. Files are not stored.
- Links between Helen listings and your firm, if a listing came out of your project, and whether that listing names your firm or is anonymous.
- A record of changes made in the dashboard: who made the change, to which record and when, for some changes the new values, and when we download a copy of your firm's records. It does not record sign-ins, page views or messages.
- Chat with Corwen conversations: what you and the chat wrote, when, which category each message was sorted into, and the request it filed, if any.
- Sign-in attempts: the email address tried, kept in the server's memory only, for 10 minutes, to limit repeated attempts.
- Server error logs, kept by Render for 7 days, which can include the content of the request that failed.
A build's code repository is never shared with another firm. A build's page can show recent code changes from that repository: the first line of each commit message and the name of the person who made it, read from GitHub. That is turned off today.
We do not store your IP address. Our hosting providers process it to deliver each page.
What we use it for
Doing your projects, showing you what we did and how many hours it took, answering your requests and messages, keeping your account accurate and secure, and keeping records we need for accounting or legal reasons. If a workflow we build for your firm becomes a Helen listing, its description is also shown to other clients, as described below. We do not use your information for anything else.
Helen listings
Helen is the marketplace tab of the dashboard, where clients see workflows we can license or rebuild for them. A workflow that came out of your build may be listed there. A listing shows your firm's name, or your firm's industry and city, only if your firm has agreed in writing. Otherwise it says nothing about your firm. In a small market, industry and city may be enough to identify you. A listing never includes your firm's data. If a workflow from your build is licensed to another client, your hours ledger shows the referral credit and the listing name, not who licensed it.
Cookies
The dashboard sets two cookies when you sign in: helen, which holds your user ID and sign-in state, and helen.sig, a signature that shows we issued it. Both are HttpOnly, Secure and SameSite=Lax. If your account uses two-step sign-in, the cookie set at the password step holds only a pending user ID until you enter the code. They expire 14 days after you sign in, change your password or turn on two-step sign-in, and are removed when you sign out. Nothing is set if you do not sign in. They are required for the dashboard to work. There are no analytics or advertising cookies.
Who can see it
Everyone at your firm with a dashboard sign-in sees all of your firm's information in the dashboard, including hours, referral credits, contracts, requests, data-flow records and the full message thread. There is no per-person restriction: the admin and user roles see the same things. Our internal notes, technical notes, repository names, work logs we have not approved and the record of changes are not shown to your firm. You can ask us for a copy of all of it.
People at Corwen with a dashboard account can see every client's information, because they are doing the work. Every Corwen account must use two-step sign-in. Before anyone new at Corwen gets a dashboard account, we tell our clients by email.
No client can see another client's builds, hours, requests, messages, contracts or data-flow records. The only thing other clients can see about your firm is a Helen listing, as described above.
Signing in
You change your own password on the Account page. Two-step sign-in, a code from an authenticator app, is available to every user on the same page. A Corwen founder can set a new password for you or reset your two-step sign-in, for example if you are locked out. Either one signs you out everywhere and is recorded.
Who else handles it
- Render runs the dashboard, in the United States. Render routes all traffic through Cloudflare's network, so Cloudflare handles each request, including your IP address.
- Neon (Databricks) runs the dashboard's database, on Amazon Web Services in Ohio. Neon keeps a change history for recovery, 6 hours back today.
- Render and Neon handle this data under their standard data processing terms, which limit their use of personal data to providing their services to us. They also keep their own operational, usage and security records.
- GitHub holds the source code for the dashboard and for the builds we make for you, in private repositories. Client data does not go in them, by rule. When a build's page shows recent code changes, it reads them from GitHub.
- Google Fonts serves the dashboard's typefaces, so Google receives your IP address and browser details when a page loads.
- Anthropic provides the Claude models Corwen's founders use as tools to build your project, the way a developer uses an editor. Today that is a Claude subscription under Anthropic's consumer terms. We are moving it to Anthropic's commercial terms, which do not allow training on the data; until then, we do not put your firm's dashboard data, your customers' records, tax return information or patient information into those tools. The dashboard itself sends nothing to Anthropic or any other AI provider today. We do not have zero data retention with any provider.
- Our email provider holds the email you send us.
When we share it
We share your information with the services above, and with other clients only as described under Helen listings. We may also disclose it when the law requires it, such as under a subpoena or court order, and to our lawyers and accountants, who must keep it confidential. If Corwen is sold or merges, client information would pass to the new owner under this policy, and we would tell you before it does.
We do not sell personal information and have not in the past. We do not share it for cross-context advertising.
How long we keep it
For as long as your firm is a client, and up to two years after. When your firm stops being a client, we record the date. The dashboard lists firms two years past that date as due for deletion, and a Corwen founder deletes them. Nothing is deleted automatically.
If you want your firm's records removed sooner, email us. Within 30 days we send you an export of all of your firm's dashboard records as a file and then delete them from the dashboard. Deletion removes everything the dashboard holds about your firm, including the hours ledger, except a record that your firm's records were exported and deleted, which holds no name and no details. Helen listings that came from your builds stay in Helen, with no link to your firm. Invoices and signed agreements are kept outside the dashboard, for as long as tax and legal rules require.
Some copies remain for a short time after deletion: the database's recovery history (6 hours today), server error logs (7 days), what a provider listed above keeps under its own retention, working files on our computers, including records of our sessions with AI tools, and the export file until we have delivered it to you.
If someone leaves your firm, email us and we will deactivate their account. We can also anonymize it: their name becomes "Former user", their email address and title are removed, the account can never sign in again, and their message read times are deleted. Messages and requests they wrote stay in your firm's record under "Former user".
Chat with Corwen
The dashboard has a chat box called Chat with Corwen. Today it runs on rules inside the dashboard: it sorts what you write into a category, answers from your firm's records, and files requests for the people at Corwen to review. Nothing you type there goes to any outside AI provider. We store the conversation with your firm's records, and the people at Corwen can read it. If that changes, this page will say so before it does.
Your business data during a project
Doing your project usually means we work inside your systems (your email, files, CRM, books, or industry software) and handle your customers' or clients' information. Before work starts, we agree the scope in writing with your firm: the systems we work in and the kinds of data involved. These are the rules we follow. Project details you put in the dashboard are covered by this page.
- Do not put your customers' personal, health, tax return or financial account information in dashboard requests or messages.
- Every build has a data-flow record before it goes live: what data goes where, why, which vendor, how long it is kept and who can reach it. You can read and print it on the build's page. The dashboard does not let us mark a build live without one.
- Where a build sends your data to a language model, we use commercial API access, never a consumer chatbot subscription, and the build's data-flow record names the provider and how long it keeps the data. We do not have zero data retention with any provider.
- Patient health information: none goes into any Corwen system until business associate agreements (BAAs) are in place with your practice and with every vendor involved. None are in place today, so do not send us patient health information by any channel.
- Tax return information: we use it only to do the work your firm asked for, and never for our own purposes, for marketing, in Helen listings or to train any model.
- Law firms: we work at your direction and under your supervision, keep what you share confidential, and treat privileged material as privileged.
Your choices
- You can ask us what we hold about you or your firm, ask us to correct it, or ask us to delete it. Email stiles@corwenco.com.
- You can change your password and turn on two-step sign-in on the Account page.
- You can stop using the dashboard at any time. Only Corwen founders can deactivate users. To deactivate someone at your firm, email stiles@corwenco.com. It takes effect as soon as we make the change.
- Blocking the
helencookies means you cannot sign in.
Do Not Track
We do not track you across other websites, and neither the site nor the dashboard runs advertising or analytics scripts. Because there is no tracking to turn off, neither one responds differently to a browser's Do Not Track or Global Privacy Control signal. Google (for fonts) and Cloudflare (for hosting) receive your IP address and browser details when you load our pages, as described above.
Children
Our website and dashboard are for business users and are not directed to children. We do not knowingly collect information from anyone under 18 through them. Client data we handle during a project may include information about minors, such as dependents on a tax return, and the rules in the section above govern how we handle it.
Changes
We post every new version of this policy on this page with a new effective date. If we make a material change, we email every active dashboard user from stiles@corwenco.com before it takes effect. Small wording changes will just update the date.
Contact
Corwen LLC, Salt Lake City, Utah
stiles@corwenco.com