Last updated September 13, 2026
This privacy notice explains how Milnerva LLC ("Milnerva," "we," "us," or "our") collects, uses, stores, and discloses information when you use our website, web application, mobile application, and related services (collectively, the "Services").
Milnerva is a privately owned company. We are not affiliated with, sponsored by, or endorsed by the United States Government, the Department of Defense, the United States Army, or any other government entity.
The Services are not designed to receive classified information, controlled unclassified information, protected health information, or other information subject to special government, regulatory, or contractual handling requirements. Do not submit that information to the Services.
Depending on the features you use, we may collect:
When you register, sign in, refresh or end a session, or otherwise use an authenticated feature, we collect and generate records used to operate and protect your account. These records may include:
Authentication access and refresh tokens are stored server-side as cryptographic digests. Some security logs use a one-way keyed digest of an email address instead of logging the address itself. Session details may be shown to you so that you can review and revoke sessions associated with your account.
When you use the Services, our systems may automatically collect technical and usage information such as your IP address, browser and device characteristics, operating system, referring URL, pages or features used, request and error logs, approximate location inferred from IP address, and dates and times of access.
If you consent to analytics cookies on the web application, Heap may collect interactions, events, session details, device and browser information, IP address, and usage patterns. Heap is not loaded through our application unless analytics consent is enabled.
We may receive information from:
We use information to:
The Services use artificial intelligence to help draft, edit, search, summarize, and organize content. When you use an AI feature, the information needed to fulfill your request may be sent to OpenAI, including your prompt, relevant saved content, conversation context, and tool results. AI-generated output may be inaccurate and should be reviewed before use.
When you send a chat message with a file, we store the original privately and send it to OpenAI so the assistant can interpret it. Files are reference material and are not malware-scanned. We do not offer previews or downloads of uploaded originals. Authorized administrators reviewing saved chats can see attachment metadata and the conversation, but cannot download the original files.
Attachments in saved chats are retained until you delete the chat, its associated document, or your account. Unsent uploads and files used in temporary chats, including email chats, expire after the inactivity period shown by the upload service (24 hours by default). Deletion removes access immediately; background cleanup removes stored files and temporary provider copies, retrying if a storage service is unavailable. OpenAI processing is also subject to its own data-retention policies.
Your chats on the assistant screen and on the award, counseling, evaluation, and memorandum editors are saved to your account so that you can reopen, continue, rename, or delete them and so that a chat you start on one device is available on another. The email drafting assistant never saves conversation history; those drafts are held only in your browser or app while you work on them. Uploaded email-chat files are stored temporarily as described above.
Alongside the messages, we store operational details about each request — timing, model and configuration identifiers, token counts, retries, and which document actions ran — so that we can diagnose problems and improve reliability. Our operational logs record identifiers and these counters only; they do not record your messages, the assistant's replies, the titles of your chats, or the contents of your documents.
Authorized Milnerva administrators may review saved chats to respond to a support request, investigate a defect or abuse, and improve the quality and safety of the assistant. That access is read-only — an administrator cannot edit, add to, or send a message in your chat — and it is recorded in our internal audit log. Opening a chat or its request history records the administrator's account, your account, the identifier of the chat that was opened, and how much of it was shown. Browsing the administrative list of chats is recorded separately, with the administrator's account, the filters used, and the identifiers of the chats on the page they were shown; the list shows chat titles, so the audit record identifies which chats an administrator could see even when none was opened. Audit records carry these identifiers and counts rather than the messages themselves. Administrators do not review saved chats for advertising, and we do not use them to build profiles about you.
You control this content. Deleting a saved chat removes its messages permanently, deleting a document removes the chats attached to it, and deleting your account removes all of them. See Section 9.
Do not enter classified, controlled, health, financial, authentication, or other sensitive personal information into an AI feature. Only provide personal information about another person when you have the authority and a valid reason to do so.
We use cookies and similar technologies that are necessary for sign-in, security, preferences, and core application functions. With your consent, we also use Heap for product analytics. You can decline or change optional analytics consent through the cookie controls we provide. Blocking necessary cookies may prevent parts of the Services from working.
We use Google reCAPTCHA on certain public forms and authentication pages to help distinguish legitimate activity from automated abuse. Google may receive technical information through reCAPTCHA under its own privacy policy and terms.
Some browsers offer a Do Not Track setting, but there is no consistently adopted standard for interpreting it. We therefore do not currently respond to Do Not Track signals. Optional Heap analytics remain controlled by the consent choice described above.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising. We may disclose information in the following circumstances:
Third-party services process information under their own terms and privacy notices. You can review the notices for OpenAI, Amazon Web Services, Stripe, Google, Heap, and Expo.
We retain information for as long as reasonably necessary to provide the Services, maintain your account, fulfill the purposes described in this notice, comply with legal and accounting requirements, resolve disputes, and enforce our agreements. Retention periods vary based on the type of information and why we use it.
Authentication sessions have idle and absolute expiration limits, but related session and security records may remain after a session expires or is revoked when needed for account history, security, abuse prevention, auditing, or legal compliance. We may retain de-identified or aggregated information that can no longer reasonably identify you.
Saved assistant chats have no automatic expiry. They are kept until you delete the chat, delete the document it is attached to, or delete your account. Archiving a chat only hides it from your active list and does not delete it. Operational logs and audit records about a chat are kept on their own schedule for security, reliability, and accountability purposes, and contain identifiers and counters rather than message content.
We use administrative, technical, and organizational safeguards designed to protect personal information. These measures include short-lived access credentials, hashed server-side token storage, session expiration and revocation, rate limiting, security event logging, and controls for administrative access. No transmission or storage system is completely secure, so we cannot guarantee absolute security.
You are responsible for maintaining the confidentiality of your credentials, reviewing your active sessions, signing out of devices you no longer use, and notifying us if you suspect unauthorized access.
Milnerva is based in the United States, and the Services and our providers may process information in the United States and other countries. Those countries may have data protection laws that differ from the laws where you live. Where required, we use appropriate safeguards for international transfers.
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal information; to object to or restrict certain processing; or to withdraw consent. You may also have the right to appeal a decision about a privacy request or complain to a data protection authority.
You can update certain account information and manage active sessions in the Services. You can rename, archive, and permanently delete individual saved assistant chats from the chat history on the web and mobile applications; deleting a document or your account also deletes the chats attached to it. You can control optional analytics cookies through our consent controls and mobile notifications through your device settings. To make another privacy request, email support@milnerva.com. We may need to verify your identity before completing a request. Some information may be exempt from a request or retained where permitted by law.
In the preceding 12 months, we may have collected the categories of personal information described above, including identifiers; customer-record information; commercial and subscription information; internet or electronic network activity; approximate location inferred from IP address; professional or employment-related information you include in the Services; and inferences used to operate, secure, or improve the Services.
We collect and disclose these categories for the business purposes described in Sections 2 and 5. We do not sell personal information or share it for cross-context behavioral advertising. Subject to applicable law, residents of certain states may exercise the rights described in Section 9 without unlawful discrimination.
The Services are intended for people who are at least 18 years old. We do not knowingly collect personal information from children under 18. If you believe a child has provided personal information to us, contact support@milnerva.com so that we can investigate and take appropriate action.
We may update this notice as our Services and practices change. The "Last updated" date shows when this version became effective. If a change is material, we may provide additional notice through the Services or by email where appropriate.
For questions, concerns, or privacy requests, contact support@milnerva.com or write to:
Milnerva LLC
5900 Balcones Drive, STE 100
Austin, TX 78731
United States