MINERVA
Privacy policyTerms of useSecurity

Legalupdated 2026-09-14

Privacy policy

Plain language on purpose. Every sentence describes the software as built on the date above.

01About this document

A template for review by counsel before publication. It describes the software as built on the date above, and it will change when the software does.

02What we collect

Your account: your name, your work email address, and a hash of your password — never the password itself.

Your workspace: what you and your teammates record in it — sheets, strings, facts, pages, files, messages, proposals and decisions — and who recorded each, and when.

Sign-in: the path you used (a password, or your organisation's directory) is written to the record. Your address and your browser's name are kept with your session so you can see where you are signed in; they also slow down repeated sign-in attempts, and they are used for nothing else.

03Where it lives

In one database file on the deployment's own volume. For a Canadian institution that volume is in Canada unless you choose otherwise.

Your browser talks only to the deployment's own address. Cursors and typing are relayed while you are connected and are not part of the record.

04What leaves the deployment

Nothing, by default. Your administrator can configure four things: your organisation's directory, for single sign-on; a language-model provider, which receives a question only when a person presses "ask an expert" — and then only the question and the part of the record that person could already read; a mail provider, which receives the address and the notice when something waits on you; and one or two time-stamp authorities, which receive one hash of the record and nothing else.

05No sale, no training

We do not sell your data. We do not use it to train any model, and no provider we send a question to may either.

There is no advertising and there are no trackers.

06Cookies

One cookie: your session. It is httpOnly, ends after eight hours without a visit (your workspace can set the limit) and after thirty days at most, and only a hash of it is stored on the server. Single sign-on uses a second cookie for ten minutes while you are sent to your directory and back. Nothing else.

07Retention and deletion

The record is kept for as long as your workspace exists. A deleted sheet is marked, not removed, so the deletion can be undone — and the undo is recorded too.

When your organisation's agreement ends, the workspace — the file, its companions and its backups — is deleted inside the window the agreement sets, and we confirm the date in writing.

You can export the record at any time: the gap report, the binder, the register as CSV, the dossiers, the evidence extract and the ledger itself.

08Your rights

Ask your workspace owner to see, correct or export what is held about you; the product's own search and exports are how they answer. Under PIPEDA — and under Quebec's private-sector privacy law where it applies — you may also complain to the Privacy Commissioner of Canada or to the Commission d'accès à l'information du Québec.

09Contact

Questions about this policy go to minerva@minerva.studio. The person in charge of the protection of personal information at Minerva Software Inc. answers at the same address.

MINERVA issues no certification, attestation or opinion. Management still writes its own assertion; your auditor still selects, tests and concludes. What is shown is evidence about this workspace only.

© 2026 Minerva Software Inc. · minerva@minerva.studio