Privacy Policy

Last updated September 13, 2026

This privacy notice explains how Milnerva LLC ("Milnerva," "we," "us," or "our") collects, uses, stores, and discloses information when you use our website, web application, mobile application, and related services (collectively, the "Services").

Milnerva is a privately owned company. We are not affiliated with, sponsored by, or endorsed by the United States Government, the Department of Defense, the United States Army, or any other government entity.

The Services are not designed to receive classified information, controlled unclassified information, protected health information, or other information subject to special government, regulatory, or contractual handling requirements. Do not submit that information to the Services.

1. Information we collect

Information you provide

Depending on the features you use, we may collect:

  • Account and profile information, such as your name, email address, password credential, duty title, account preferences, connected sign-in provider, and records showing when you accepted our terms and privacy policy. Passwords are stored in hashed form rather than as readable text.
  • User content, such as awards, evaluations, counselings, memoranda, saved addresses, publications, conversations, prompts, feedback, and other information you enter, upload, generate, or save through the Services. This includes saved assistant chats: the messages you send, the assistant's replies, and a record of the actions the assistant took on the document you had open.
  • Communications, such as messages you send through contact forms or to our support address.
  • Subscription and transaction information, such as your plan, subscription status, transaction identifiers, and billing contact details. Stripe collects and processes payment card details. Milnerva does not store complete payment card numbers.
  • Notification information, such as a mobile push notification token when you choose to enable notifications.

Authentication and security information

When you register, sign in, refresh or end a session, or otherwise use an authenticated feature, we collect and generate records used to operate and protect your account. These records may include:

  • IP address;
  • browser or application user-agent information;
  • device name and client type, such as web or mobile;
  • session identifier, creation time, last-used time, idle and absolute expiration times, and revocation time and reason;
  • sign-in, refresh, sign-out, rate-limit, token-replay, and other security events; and
  • information identifying an authorized administrator when the administrator uses a time-limited impersonation session to provide support or administer the Services.

Authentication access and refresh tokens are stored server-side as cryptographic digests. Some security logs use a one-way keyed digest of an email address instead of logging the address itself. Session details may be shown to you so that you can review and revoke sessions associated with your account.

Information collected automatically

When you use the Services, our systems may automatically collect technical and usage information such as your IP address, browser and device characteristics, operating system, referring URL, pages or features used, request and error logs, approximate location inferred from IP address, and dates and times of access.

If you consent to analytics cookies on the web application, Heap may collect interactions, events, session details, device and browser information, IP address, and usage patterns. Heap is not loaded through our application unless analytics consent is enabled.

Information from third parties

We may receive information from:

  • Google, when you choose Google sign-in, such as a provider account identifier, verified email address, name, and profile image;
  • Stripe, such as subscription, payment status, customer, invoice, and transaction information; and
  • application stores and mobile infrastructure providers, such as information needed to distribute, update, and operate the mobile application and deliver notifications.

2. How we use information

We use information to:

  • create, authenticate, and administer accounts;
  • provide, personalize, maintain, and improve the Services;
  • save, retrieve, generate, format, and export the content you ask us to process;
  • operate subscriptions, billing, and customer support;
  • send transactional, account, security, support, and policy communications;
  • detect abuse, enforce rate limits, prevent fraud, investigate security events, revoke compromised sessions, and protect users and the Services;
  • understand feature usage and improve performance when analytics consent applies; and
  • comply with law, enforce our agreements, and establish, exercise, or defend legal claims.

3. Artificial intelligence features

The Services use artificial intelligence to help draft, edit, search, summarize, and organize content. When you use an AI feature, the information needed to fulfill your request may be sent to OpenAI, including your prompt, relevant saved content, conversation context, and tool results. AI-generated output may be inaccurate and should be reviewed before use.

Chat attachments

When you send a chat message with a file, we store the original privately and send it to OpenAI so the assistant can interpret it. Files are reference material and are not malware-scanned. We do not offer previews or downloads of uploaded originals. Authorized administrators reviewing saved chats can see attachment metadata and the conversation, but cannot download the original files.

Attachments in saved chats are retained until you delete the chat, its associated document, or your account. Unsent uploads and files used in temporary chats, including email chats, expire after the inactivity period shown by the upload service (24 hours by default). Deletion removes access immediately; background cleanup removes stored files and temporary provider copies, retrying if a storage service is unavailable. OpenAI processing is also subject to its own data-retention policies.

Saved assistant chats

Your chats on the assistant screen and on the award, counseling, evaluation, and memorandum editors are saved to your account so that you can reopen, continue, rename, or delete them and so that a chat you start on one device is available on another. The email drafting assistant never saves conversation history; those drafts are held only in your browser or app while you work on them. Uploaded email-chat files are stored temporarily as described above.

Alongside the messages, we store operational details about each request — timing, model and configuration identifiers, token counts, retries, and which document actions ran — so that we can diagnose problems and improve reliability. Our operational logs record identifiers and these counters only; they do not record your messages, the assistant's replies, the titles of your chats, or the contents of your documents.

Authorized Milnerva administrators may review saved chats to respond to a support request, investigate a defect or abuse, and improve the quality and safety of the assistant. That access is read-only — an administrator cannot edit, add to, or send a message in your chat — and it is recorded in our internal audit log. Opening a chat or its request history records the administrator's account, your account, the identifier of the chat that was opened, and how much of it was shown. Browsing the administrative list of chats is recorded separately, with the administrator's account, the filters used, and the identifiers of the chats on the page they were shown; the list shows chat titles, so the audit record identifies which chats an administrator could see even when none was opened. Audit records carry these identifiers and counts rather than the messages themselves. Administrators do not review saved chats for advertising, and we do not use them to build profiles about you.

You control this content. Deleting a saved chat removes its messages permanently, deleting a document removes the chats attached to it, and deleting your account removes all of them. See Section 9.

Do not enter classified, controlled, health, financial, authentication, or other sensitive personal information into an AI feature. Only provide personal information about another person when you have the authority and a valid reason to do so.

4. Cookies and similar technologies

We use cookies and similar technologies that are necessary for sign-in, security, preferences, and core application functions. With your consent, we also use Heap for product analytics. You can decline or change optional analytics consent through the cookie controls we provide. Blocking necessary cookies may prevent parts of the Services from working.

We use Google reCAPTCHA on certain public forms and authentication pages to help distinguish legitimate activity from automated abuse. Google may receive technical information through reCAPTCHA under its own privacy policy and terms.

Some browsers offer a Do Not Track setting, but there is no consistently adopted standard for interpreting it. We therefore do not currently respond to Do Not Track signals. Optional Heap analytics remain controlled by the consent choice described above.

5. When we disclose information

We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We may disclose information in the following circumstances:

  • Service providers. We use providers to host and operate the Services, store files, send email, process AI requests, analyze consented usage, process payments, verify sign-ins and reCAPTCHA results, distribute and update the mobile application, and deliver push notifications. These providers include Amazon Web Services, OpenAI, Stripe, Google, Heap, Expo, Apple, and Google Play, depending on the feature you use.
  • Legal and safety reasons. We may disclose information when we reasonably believe it is required by law, legal process, or a valid government request, or is necessary to protect the rights, safety, property, and security of Milnerva, our users, or others.
  • Business transfers. We may disclose information in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of all or part of our business, subject to appropriate protections.
  • With your direction. We may disclose information when you ask us to or consent to the disclosure.

Third-party services process information under their own terms and privacy notices. You can review the notices for OpenAI, Amazon Web Services, Stripe, Google, Heap, and Expo.

6. Data retention

We retain information for as long as reasonably necessary to provide the Services, maintain your account, fulfill the purposes described in this notice, comply with legal and accounting requirements, resolve disputes, and enforce our agreements. Retention periods vary based on the type of information and why we use it.

Authentication sessions have idle and absolute expiration limits, but related session and security records may remain after a session expires or is revoked when needed for account history, security, abuse prevention, auditing, or legal compliance. We may retain de-identified or aggregated information that can no longer reasonably identify you.

Saved assistant chats have no automatic expiry. They are kept until you delete the chat, delete the document it is attached to, or delete your account. Archiving a chat only hides it from your active list and does not delete it. Operational logs and audit records about a chat are kept on their own schedule for security, reliability, and accountability purposes, and contain identifiers and counters rather than message content.

7. Data security

We use administrative, technical, and organizational safeguards designed to protect personal information. These measures include short-lived access credentials, hashed server-side token storage, session expiration and revocation, rate limiting, security event logging, and controls for administrative access. No transmission or storage system is completely secure, so we cannot guarantee absolute security.

You are responsible for maintaining the confidentiality of your credentials, reviewing your active sessions, signing out of devices you no longer use, and notifying us if you suspect unauthorized access.

8. International data transfers

Milnerva is based in the United States, and the Services and our providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live. Where required, we use appropriate safeguards for international transfers.

9. Your rights and choices

Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; to object to or restrict certain processing; or to withdraw consent. You may also have the right to appeal a decision about a privacy request or complain to a data protection authority.

You can update certain account information and manage active sessions in the Services. You can rename, archive, and permanently delete individual saved assistant chats from the chat history on the web and mobile applications; deleting a document or your account also deletes the chats attached to it. You can control optional analytics cookies through our consent controls and mobile notifications through your device settings. To make another privacy request, email support@milnerva.com. We may need to verify your identity before completing a request. Some information may be exempt from a request or retained where permitted by law.

10. United States state privacy disclosures

In the preceding 12 months, we may have collected the categories of personal information described above, including identifiers; customer-record information; commercial and subscription information; internet or electronic network activity; approximate location inferred from IP address; professional or employment-related information you include in the Services; and inferences used to operate, secure, or improve the Services.

We collect and disclose these categories for the business purposes described in Sections 2 and 5. We do not sell personal information or share it for cross-context behavioral advertising. Subject to applicable law, residents of certain states may exercise the rights described in Section 9 without unlawful discrimination.

11. Children

The Services are intended for people who are at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, contact support@milnerva.com so that we can investigate and take appropriate action.

12. Changes to this notice

We may update this notice as our Services and practices change. The "Last updated" date shows when this version became effective. If a change is material, we may provide additional notice through the Services or by email where appropriate.

13. Contact us

For questions, concerns, or privacy requests, contact support@milnerva.com or write to:

Milnerva LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States