Coven Privacy Policy
Last updated: September 25, 2026
Coven Platform ("Coven", "we", "our", or "us"), developed and operated by Third Millennium Software, is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Coven Android application and associated services (collectively, the "Platform").
Please read this Privacy Policy carefully. By creating an account or using Coven, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
A. Information You Provide Directly
- Account Credentials: Email address, chosen developer username, hashed passwords, and authentication tokens managed securely via Supabase Auth.
- Developer & Application Metadata: Application names, Android package identifiers (e.g.,
com.example.app), Google Play Closed Track / Internal Test opt-in URLs, promotional codes, app descriptions, test instructions, and uploaded app icons. - Bug Reports & Community Feedback: Bug reproduction descriptions, tester reviews, feedback notes, and rating evaluations submitted within testing lounges and review queues.
B. Information Collected Automatically & Proof-of-Work Telemetry
- Proof-of-Work Screen Recordings: When you explicitly initiate an attestation session to test an assigned application, Coven records a timed screen capture (typically 30 seconds) of the target application in action.
- Device Hardware & Model Telemetry: Device manufacturer, hardware model designation (e.g.,
Build.MANUFACTURERandBuild.MODEL), Android OS version, unique device fingerprint hash, and hardware integrity/attestation signals to evaluate device compatibility and prevent emulator fraud, botting, and sybil attacks. - Network & Diagnostic Data: IP address, internet connectivity status, and structured application error logs.
- Push Notification Tokens: Firebase Cloud Messaging (FCM) registration tokens to deliver task notifications and status updates.
2. Android Permissions & Sensitive Data Declarations
In strict accordance with Google Play Developer Policies, below are the sensitive device capabilities Coven requests and the exact justifications for each:
| Permission | Technical Name | Purpose & Usage Justification |
|---|---|---|
| Screen Recording / Media Projection | FOREGROUND_SERVICE_MEDIA_PROJECTION | Used strictly and exclusively during user-initiated 30-second testing sessions to record video proof that the assigned app was tested on a genuine physical device. Recording only occurs after an explicit system consent prompt and displays an ongoing foreground notification. Coven never records in the background or outside active test sessions. |
| Push Notifications | POST_NOTIFICATIONS | Used on Android 13+ to send real-time alerts regarding daily cohort testing deadlines, task review approvals, escrow releases, and dispute resolutions. |
3. Device Model Collection & Usage Policy
To maintain testing authenticity, evaluate technical compatibility across Android’s diverse device ecosystem, and protect developers from botting and fraud, Coven collects and processes device model data (specifically, hardware manufacturer and model designation, such as Google Pixel 8 Pro or Samsung Galaxy S24).
- Developer Review & UI Compatibility: When a tester submits a test video recording for task completion, the tester's device model is presented directly to the application developer on the task video review screen. This allows developers to observe how their UI layouts render, identify aspect-ratio or screen-density bugs, and evaluate performance on specific hardware configurations.
- Anti-Fraud & Sybil Defense: Coven binds the device model and cryptographic device identifier to registered device records. This prevents malicious actors from operating multiple accounts or orchestrating automated bot farms on duplicate or spoofed hardware, ensuring cohort escrow and token integrity.
- Targeted Testing Compatibility: Hardware model information enables the platform to verify that testing assignments are distributed across authentic physical devices representing diverse hardware profiles.
- No Third-Party Sale or Tracking: Device model information is used strictly for internal platform verification, quality assurance, and security attestation. We never sell, lease, or license device specifications to third-party data brokers or advertising networks.
4. How We Use Your Information
We use the collected information for the following operational, security, and verification purposes:
- Automated Attestation & Proof of Work: To analyze and store screen recordings and hardware verification records verifying legitimate testing of target apps.
- Cohort Reciprocity & Task Marketplace: To coordinate 20-tester closed testing cohorts, match developers with testers, and manage task lifecycles.
- Escrow & Virtual Economy Management: To calculate strike counts, reputation scores, track Coven Coin balances, lock escrow for posted tasks, and release rewards upon verified completion.
- Anti-Fraud & Hardware Integrity: To enforce single-device limits per cohort, detect emulator farms, and ensure genuine physical Android hardware is utilized.
- Customer Support & Dispute Resolution: To review contested submissions where developers or testers disagree on test validity.
5. Third-Party Services & Sub-Processors
We do not sell, rent, or trade your personal information. We share data only with the following trusted service providers necessary to operate the Platform:
- Supabase, Inc. (Backend, Database & Storage): Hosts user authentication sessions, PostgreSQL database tables, and secure cloud storage for app icons and proof-of-work video submissions.
- Google LLC (Firebase Cloud Messaging & Android OS): Provides push notification routing (FCM) and Android platform runtime attestation APIs.
- DiceBear API: Used to render deterministic, auto-generated profile avatar artwork using anonymized name/email hash seeds.
6. Data Sharing Between Platform Users
- Between Testers and App Developers: When a tester completes an assigned test, the app developer receives the proof-of-work video recording, testing feedback, verification timestamp, and the tester's hardware device model (e.g., manufacturer and model name) on the task review interface to assess visual rendering and hardware-specific compatibility. Private credentials, email addresses, and underlying cryptographic device hashes are never disclosed to developers.
- Public/Cohort Visibility: Within a cohort or leaderboard, other verified cohort members can view your public developer name, verification streak, and completed test counts. Your password, private email, and device hardware hashes are never exposed to other users.
7. Data Retention & Account Deletion Policy
We retain your data only for as long as your account remains active or as needed to maintain platform attestation integrity:
- Active Accounts: User profiles, app registration details, and coin balances are maintained while your account is active.
- Test Video Proofs: Screen recording submissions are stored in cloud storage for developer verification and dispute windows, after which they may be purged according to storage lifecycle policies.
- Account Deletion (Google Play Compliant): You can initiate account deletion at any time directly through the Coven Platform application under your Profile settings or visit our Account Deletion Page. When requested, your account enters a scheduled deletion grace period (
scheduled_deletion_at), after which all personal identifiers, auth records, active sessions, and registered apps are permanently erased or anonymized from our primary databases.
8. Security Safeguards
We implement industry-standard production safeguards to protect your personal information:
- Encrypted Transmission: All network communications between Coven and our backend use TLS 1.3 encryption (HTTPS/WSS).
- Hardware-Backed Protection: Device attestation uses secure Android KeyStore and OS-level signature verification.
- Row-Level Security (RLS): Database records in Supabase are enforced with strict Row-Level Security policies, ensuring users can only read and mutate authorized records.
9. International Data Transfers & Children's Privacy
- International Transfers: Your data may be processed on servers located outside your home country. By using the platform, you consent to the transfer of information to jurisdictions where our cloud infrastructure providers operate.
- Children's Privacy: Coven is designed exclusively for software developers and Android app testers aged 18 and older (or the age of majority in your jurisdiction). We do not knowingly collect personal data from children under 13 (or under 16 in the EU).
10. Your Rights (GDPR & CCPA / CPRA)
Depending on your geographic location, you may have the following rights regarding your personal information:
- Right to Access / Portability: Request a copy of the personal data we maintain about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure / Deletion: Request the permanent deletion of your personal data.
- Right to Withdraw Consent: Revoke permissions (such as Notifications or Media Projection consent) at any time via your Android device system settings.
To exercise any of these rights, contact us using the information provided in Section 12.
11. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect enhancements to our testing features, attestation mechanisms, or regulatory requirements. We will notify you of material changes by updating the "Last Updated" date at the top of this document and via in-app push notifications when appropriate.
12. Contact Us
If you have questions, concerns, or data protection inquiries regarding this Privacy Policy, please contact us at:
Entity: Third Millennium Software / Coven Test Platform
Privacy Email: privacy@covenplatform.com
Developer Support: support@covenplatform.com
Developer Website: school-and-stuff.me