CVMewt
Privacy Terms Contact

Current public-service notice

Privacy statement

Effective September 6, 2026

CVMewt Inc. is a small Connecticut software and research company. This statement describes the information handled by cvmewt.com, its public subdomains, and the hosted Checklist Assistant experiment. A separately contracted or privately deployed service may have different terms.

Information we handle

  • Ordinary web requests. Our hosting and security systems may process an IP address, browser or user-agent information, requested path, referring page, response status, and time of request.
  • Checklist Assistant sign-in. If you choose Google or Microsoft, we request only the OpenID identity scope. We process the provider's issuer and account-specific subject identifier, then retain a one-way fingerprint of that exact pair as the CHAX identity principal. We do not request or store your provider password, files, contacts, email address, display name, provider access token, or provider refresh token for this sign-in.
  • Sessions. We use short-lived login state and essential, host-only cookies to complete sign-in and protect the resulting session. The active CHAX access session normally expires after one hour. Expired or revoked opaque session records may remain until routine database maintenance.
  • Content and local settings. The public prototype can store checklist rows, results, comments, and related identifiers on the server when you deliberately send them there. Drafts, appearance preferences, and some prototype administrator-session data may instead be stored by your browser. The hosted experiment does not yet provide private tenant isolation, so do not submit confidential, regulated, export-controlled, or client-owned material.
  • Messages. If you use a contact form, we process the name, reply address, organization or delivery interest, and message you provide, plus a pseudonymous abuse-prevention fingerprint. Contact records carry a 90-day deletion date and are removed through operational maintenance.
  • Payment lab. The current lab uses Stripe test mode only. If you deliberately use it, we retain test object identifiers, test amount and state, timestamps, and your CHAX entity identifier. It neither collects card details nor moves money.

Why we use it

We use this information to deliver requested pages and application functions, authenticate sessions, associate deliberate prototype actions with a stable entity, answer messages, prevent abuse, diagnose failures, preserve service security, and comply with applicable obligations. We do not sell personal information or use it for targeted advertising.

Service providers and disclosure

Information is disclosed only as needed to operate the service: to infrastructure and security providers such as DigitalOcean and Cloudflare; to Google or Microsoft when you choose that provider; to Cloudflare's email service when you send a message; and to Stripe when you deliberately use the labeled test payment lab. We may also disclose information when required by law, to protect rights or safety, or as part of a lawful business transfer.

Cookies and browser storage

We do not currently use advertising or analytics cookies. Checklist Assistant uses essential cookies for external sign-in, session security, and request-forgery protection. Those cookies are restricted to chax.cvmewt.com; they are not sent to every CVMewt subdomain. Browser storage supports local drafts, theme preferences, and the existing first-party prototype administrator flow. Blocking essential storage can prevent those features from working.

Retention, security, and choices

Short-lived sign-in attempts expire after ten minutes. Session access normally expires after one hour. Content deliberately stored in the prototype, its opaque identity association, and security logs are retained while operationally useful or until deletion and maintenance processes remove them. No system is perfectly secure; we use bounded inputs, TLS, host-only secure cookies, provider signature validation, least-privilege services, and protected credential files to reduce risk.

You can avoid provider sign-in and use the unauthenticated local authoring features. You can sign out to revoke the current external session. To ask about access, correction, or deletion of information reasonably connected to you, use the Checklist Assistant contact form. We may need enough information to verify and locate the record without exposing another person's data.

Children and changes

The service is not directed to children under 13, and CVMewt does not knowingly seek their personal information. We may update this statement when the product or its data handling changes. The effective date above will change, and material changes will be presented before newly using provider data for a different purpose.

CVMewt Inc. Connecticut · 2026 Home · Terms