Privacy policy

What we hold, why we hold it, and who else can see it.

Short, specific, and true of the product as it is built today rather than of a product we might build later. Effective August 26, 2026.

Who is responsible

Corven & Ashby LLC, a Wyoming limited liability company, trading as Costwitness, at Corven & Ashby LLC, 5830 E 2nd St, Ste 7000, Casper, WY 82609, United States. Contact info@costwitness.com for anything on this page, including a request to see, correct or delete what we hold.

The free tools on this website

The calculators on costwitness.com run in your browser, and nothing you type leaves it while you are using them. If you ask a tool to send you the result, then the figures you entered, the result itself and your email address are sent to us, because there is no other way to put them in the message. They are used to send you that result and to answer you, and for nothing else.

This website carries one advertising tag, the LinkedIn Insight Tag, described in the section on cookies below. It carries no analytics and no other third party tracking. There is no cookie banner; the section below says what the tag does and how to keep it from loading.

The films on this website

The films on this website are hosted on YouTube. They sit on the watch page and one to a page on the module pages, and nothing is requested from YouTube while you read any of them. Each film sits behind a still image served from this website. When you press play, and only then, the film is loaded from youtube-nocookie.com, the variant that sets no advertising cookie until a film is played. From that moment YouTube sees the request under its own privacy policy, as it would on any site. We are told nothing about it: there is no analytics on those films, and a viewing is never connected to an account, a form or an email address.

What the application holds

When you open an account and run a project in costwitness.app, we hold:

  • Account details. Your name, your email address, and your password stored as a one way hash, which means we cannot read it.
  • Project content. Everything you enter or upload: contract terms, baseline versions, ledger entries, change orders, allowances, packages, messages, and the documents you attach.
  • A record of what happened. Sign ins, grants of access and revocations, and every change to a figure or a classification with the person and the time. This record is the point of the product and it is not optional.
  • Server logs. Your internet address and the time of a request, kept so that we can investigate a fault or an attack.
  • Openings of a shared report. When you send a report to somebody outside the application, we record the link and every opening of it: the date, the time, and the internet address it was opened from. That is how you know a lender read what you sent, and how you notice a link that has traveled further than you meant it to. It also means we hold a little information about people who never signed up here. Those records are deleted with the project, the link expires on a date you choose, and you can withdraw it at any moment. We never store the link address itself, only a fingerprint of it, so a copy of our database hands nobody a working link.

Why we hold it

To run the service you asked for, to keep it secure, to support you when something goes wrong, and to invoice you. We do not profile you, we do not advertise to you, and we do not make automated decisions about people.

Cookies

The application sets one cookie, a session cookie that keeps you signed in. It carries no personal information, it is marked so that scripts cannot read it, and it is removed when you sign out. Some pages remember a display preference in your own browser's storage; that never leaves your device.

This website uses one advertising tag, the LinkedIn Insight Tag. When you visit, it may set cookies, including a cookie on this website's own domain, so that LinkedIn can tell us how many people who saw one of our LinkedIn ads went on to create an account. We receive totals and campaign statistics, not the names of individual visitors. LinkedIn processes this data under its own privacy policy and may connect the visit to your LinkedIn account if you are signed in. You can limit this in your LinkedIn advertising settings, or prevent it by blocking third party scripts in your browser.

We also remember, in a cookie set by this website, which advertisement or link brought you here, and we pass that to the sign up form so that we know which campaign an account came from. It holds three short labels and no personal information.

Where the data lives, and for how long

On infrastructure we control, hosted in the United States. Uploaded documents are stored outside the public web directory and are served only to a signed in person with access to that project.

We keep project data for as long as your account is open, and after it closes, so that you can still take a copy. We delete it when the account owner asks us in writing to delete it: from live systems at once, and from backups as those backups age out. Server logs are kept for a short period and then discarded.

Who else can see it

Three groups, and no others:

  • People you grant access to. That is your decision, recorded with a time and a name, and you can revoke it.
  • Us, narrowly. Our own staff read a project during setup and during a review you have asked for, and that access is recorded.
  • The two suppliers who run our infrastructure. Hostinger holds the servers, the database and the backups, in the United States. Google delivers the messages the system sends, such as an invitation or a notice that an RFI was raised, and sees only what is inside those messages. Neither is permitted to use your content for anything else, and no other company touches it. If that list ever changes, this page changes with it.

Your documents are not sent to any artificial intelligence service, analytics service or advertising network. We do not sell personal information, and we do not share it for cross context behavioural advertising, as those terms are used in California law.

Your rights

Ask us and we will tell you what we hold about you, correct it if it is wrong, give you a copy in a structured format, or delete it. We answer within thirty days and we do not charge for it. We will ask you to confirm who you are first, because these rights are worth nothing if anyone can use them.

If you are in California, the same rights are yours under the California Consumer Privacy Act, and we will not treat you differently for using them. If you are in the European Union or the United Kingdom, we honor the equivalent rights, and you may complain to your supervisory authority.

Note one limit that is deliberate. Where you ask us to delete an entry from a project's record, we can remove the project and everything in it, but we cannot quietly delete a single row from the audit history while the project is running, because a record that can be edited without trace is not a record. If that is an issue, tell us and we will explain the options before you start.

If something goes wrong

If a security incident affects your data, we tell you by email within seventy two hours of confirming it: what happened, what was affected and what we did. We tell you even when the answer is uncomfortable.

Children

The service is for businesses and public bodies. It is not directed at anyone under eighteen and we do not knowingly hold their data.

Changes

If this policy changes in a way that materially affects you, we email you at least thirty days beforehand. Smaller corrections appear here with a new effective date.

Effective August 26, 2026. See also Security and data for how the system is built, and the terms of service for the commercial agreement.