Legal

Privacy Policy

This Policy explains what information Navolu handles, why we use it, and the choices available to you.

Last updated August 31, 2026

1. Scope

This Privacy Policy applies to the Service provided by Navolu LLC, including Navolu’s public website, account experience, George and other AI-assisted features, business workspace, projects, Google Calendar connection, Founding 10 application, and subscription-management features.

It does not replace the privacy policies of Stripe, Google, OpenAI, Supabase, Vercel, or other third parties when you interact directly with those services.

2. Information we collect and process

Account and profile information. We process your email address, authentication and email-confirmation status, account identifiers, preferred name, business name, timezone, working-hours preferences, and password-related authentication records managed through Supabase. Navolu does not store your readable password.

Business information. We store information you enter or confirm through onboarding and Business Discovery, such as your business description, stage, offers, ideal customers, strengths, challenges, goals, revenue targets, marketing channels, team size, brand voice, and tools. We also store the history and classification needed to distinguish confirmed facts, preferences, goals, and replaced information.

Projects and daily work. We store projects, purposes, objectives, milestones, lifecycle events, owner notes, blockers you explicitly record, daily priorities, scorecard assessments, evidence summaries, completion, snooze and dismissal choices, and the history needed to provide consistent owner-controlled workflows.

George conversations and saved memories. We store messages exchanged with George and memories you explicitly choose to save, edit, or delete. Recent conversation history, saved memory, verified Business Intelligence, projects, preferences, and available schedule context may be assembled to answer a request or prepare a Morning Brief.

Founding 10 information. If you apply, we process the contact and business details in the application, participation confirmation, founder review status, private founder notes, selected-account linkage, and an event history. Applying does not add the application to George’s business context.

Billing information. We store Stripe customer, product, price, subscription, Checkout, and event identifiers; subscription status and billing periods; cancellation state; payment-failure and grace-period timestamps; entitlement records; and Founding Member slot status. Stripe receives and processes full payment-card details. Navolu does not store full card numbers or card security codes.

Technical and support information. Our hosting, authentication, security, and infrastructure providers process request, device, network, error, and security information needed to operate and protect the Service. If you send feedback or request support, we process the content you provide and, where you give permission, the account email needed to respond.

3. Google Calendar information

Connecting Google Calendar is optional. Navolu requests the read-only Calendar scope and currently reads the connected account’s primary calendar. We process an encrypted refresh credential, granted scopes, connection status, calendar timezone, access/error timestamps, and calendar event identifiers, titles, start and end times, and all-day status needed to create schedule summaries.

Navolu uses calendar information to provide visible, user-facing schedule context, such as today’s event count, open work blocks, conflicts, and schedule-aware assistance from George. We do not use the connection to create, edit, or delete Google Calendar events.

Calendar events are fetched when relevant features load or when you request a refresh; the current implementation does not persist a copy of the fetched event list in Navolu’s database. Derived calendar context may be included in an OpenAI request when needed to provide a schedule-aware feature.

You can disconnect Google Calendar from Settings. Navolu attempts to revoke provider access and deletes the locally stored connection credential. If provider revocation is unavailable, you can also remove Navolu through your Google Account permissions.

Navolu’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. AI processing

Navolu sends the information needed to answer a request or prepare an AI-assisted feature to OpenAI. Depending on the feature, that may include your prompt, recent conversation messages, business profile, confirmed Business Intelligence, saved memories, preferences, projects, Daily Intelligence, and relevant schedule context.

Navolu configures its OpenAI Responses API requests with application storage disabled. OpenAI may still process and retain information under its API data controls and abuse-monitoring practices. Navolu does not treat raw AI prose as confirmed business evidence and does not allow billing state to become business intelligence.

5. Cookies and performance measurement

Navolu uses essential cookies for authentication sessions, password recovery and email confirmation, security, and the Google OAuth connection flow. These cookies are needed for the Service to recognize a signed-in user and safely complete requested actions.

Navolu uses Vercel Speed Insights to receive performance measurements such as route, page URL, network speed category, browser, device type, operating system, country, Web Vitals, attribution, and event time. Vercel describes these measurements as anonymous and not tied to an identifiable visitor or reconstructed cross-page browsing session.

Optional marketing measurement. With your prior permission, Navolu may use Meta Pixel to measure advertising and campaign effectiveness through a limited set of marketing and conversion events, such as visits to approved public pages, completed signup, viewing the Founding Member offer, starting Checkout, and a verified paid purchase. Meta may set or read browser identifiers after you consent. Navolu does not enable automatic advanced matching.

Marketing tracking is optional. Declining marketing cookies does not prevent normal use of Navolu. You can accept, decline, or later withdraw your choice through Cookie preferences in the public footer. Navolu does not initialize Meta Pixel while a choice is absent or declined.

Navolu does not intentionally send George conversations or responses, saved Memories, Business Discovery content, Projects, customer or client information, calendar data, business-profile content, Access Codes, email addresses, names, account identifiers, Stripe identifiers, or payment-method details to Meta. Pixel placement is restricted to approved marketing and conversion points and rejects unknown or query-bearing URLs and sensitive workspace routes.

Meta processes information under its own practices. You can review Meta’s Privacy Policy for more information.

6. How we use information

We use information to:

  • create, authenticate, secure, and support accounts;
  • operate Business Discovery, Business Intelligence, projects, priorities, scorecards, memory, conversations, and connected-calendar features;
  • generate George responses and Morning Brief content;
  • process Founding 10 applications and administer selected participation;
  • create and manage subscriptions, entitlements, cancellations, payment-failure grace, and read-only status;
  • measure and improve reliability, performance, accessibility, and product usefulness;
  • prevent fraud, abuse, unauthorized access, and security incidents;
  • respond to feedback, support, and privacy requests; and
  • comply with law and enforce our agreements.

7. How information is shared

We disclose information only as reasonably necessary for the purposes described here:

  • Supabase provides authentication, database, and server infrastructure for account and owned workspace data.
  • OpenAI processes prompts and selected context to provide AI-assisted features.
  • Google provides the optional Calendar API and OAuth connection.
  • Stripe processes payments, subscriptions, invoices, and Customer Portal activity and returns billing metadata to Navolu.
  • Vercel hosts the application and provides deployment, request, security, and performance infrastructure.
  • Meta may receive limited website and conversion-event information for advertising measurement only after marketing-cookie consent.
  • Professional advisers and authorities may receive information when reasonably necessary to obtain advice, comply with law, protect rights and safety, or investigate abuse.
  • A successor organization may receive information as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice where required.

Navolu does not currently sell personal information for money or use personal information for cross-context behavioral advertising. Some privacy laws define “sale” or “sharing” more broadly; you may contact us with a jurisdiction-specific request.

8. Data retention and account deletion

We retain account and workspace information while your account is active and afterward as needed to keep your workspace available, provide the Service, resolve disputes, maintain security and audit history, comply with law, and enforce agreements. Project event history and certain billing-processing records are designed to remain auditable.

Cancellation, payment failure, or an expired entitlement does not itself delete business data. Inactive customers retain read-only access under the current product model.

There is not currently a self-service account-deletion button. You may request deletion by contacting us. After verifying the request, deletion of the Supabase authentication account is designed to cascade through owner-scoped profiles, Business Intelligence, conversations, memories, preferences, calendar credentials, projects, project events, priorities, and owner-linked billing projections. Fixed Founding Member inventory remains but is cleared of the deleted owner’s identifiers.

Some information may remain where it is not owned solely by the account or must be retained for legal, security, fraud-prevention, tax, payment, or audit reasons. This may include sanitized Stripe webhook processing records, a Founding 10 application and its review history, backups pending normal rotation, and records maintained independently by Stripe or another provider.

9. Security

Navolu uses measures designed to protect information, including authenticated server actions, owner-scoped Row Level Security, server-only privileged credentials, encrypted Google refresh tokens, signed Stripe webhooks, and separation of test and live billing environments.

No security measure can guarantee absolute protection. Please use a strong password, protect your email account and devices, and notify us if you suspect unauthorized access.

10. Your choices

You can review and update profile, Business Discovery, preference, project, priority, and saved-memory information through the Service. You can delete individual saved memories, disconnect Google Calendar, manage billing through Stripe’s Customer Portal, cancel at the end of the paid period, or stop using the Service.

You can decline optional Calendar access and optional marketing cookies. Use Cookie preferences in the public footer to change or withdraw marketing consent without affecting essential authentication or normal Navolu functionality. You may also contact us to request access, correction, deletion, or other assistance that is not available through the interface.

11. Privacy rights

Depending on where you live, applicable law may give you rights to request access, correction, deletion, portability, restriction, or an explanation of certain processing, and to appeal a denied request. These rights may have exceptions.

We will verify requests and respond as required by applicable law. Navolu will not discriminate against you for exercising an applicable privacy right. Authorized agents may submit requests where local law permits and appropriate authorization can be verified.

12. Children’s privacy

Navolu is intended for business owners who are at least 18 years old. The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. Contact us if you believe a child has provided information to the Service.

13. International users

Navolu and its providers may process information in the United States and other countries where they operate. Those locations may have data-protection laws different from those where you live. By using the Service, you understand that information may be processed in those locations subject to applicable safeguards and law.

14. Changes to this Policy

We may update this Policy as the Service, providers, or law changes. We will post the revised Policy with a new “Last updated” date and provide additional notice when a change is material and notice is reasonably required.

15. Contact us

Privacy questions and requests may be sent to account@navolu.com.

For other terms governing the Service, read the Terms of Service.