Collect less. Account for the rest.
Govna separates service records, tool content, restricted secrets, and bounded telemetry so each category has an explicit handling rule.
What enters each boundary
Customer confidential
Stored to operate Govna
Account, organization, connector metadata, policy, grant, billing, and audit records are retained in tenant-scoped managed storage.
Tool content
Processed, not retained by default
MCP arguments and results are processed in memory and excluded from audit, product analytics, and operator telemetry by default.
Restricted
Kept outside product records
Connector tokens, signing material, and provider secrets stay out of PostgreSQL, logs, frontend bundles, infrastructure plans, and state.
Bounded telemetry
Allowlisted and pseudonymous
Product analytics uses fixed events and pseudonymous identifiers. Scrubbed error and service telemetry excludes tool content, credentials, contact data, and raw provider errors.
Your controls
Does this site run analytics before I consent?
No. Marketing analytics start disabled and stay off until you explicitly accept them. Do Not Track and Global Privacy Control override any acceptance: either browser signal suppresses analytics regardless of a stored consent.
Govna does not expose a tenant setting that can override either browser signal. Questions about this draft notice can be sent to hello@govna.io. Formal data-rights procedures require legal approval before commercial launch.