Privacy Policy
Last updated: August 4, 2026
NavvyAI is an AI agent platform: bots that answer WhatsApp and Instagram, voice agents that make phone calls, automations, and a note-taker that joins your meetings and turns them into notes.
This policy explains what data we process, why, who we share it with, where and how long we keep it, and how you revoke and delete it. It is written to be read, not to cover us.
1. Who processes your data
NavvyAI is the controller of the data described here. For any privacy matter, and to exercise your rights, write to us at fabian@zensavvy.com.
NavvyAI operates from Mexico. This policy is governed by Mexican personal data protection law.
2. If you connect your Google account: which permissions we ask for and why
Connecting Google is optional and is only needed for the meeting note-taker and for the voice agent to book appointments. You can use the rest of NavvyAI without it, and you can disconnect whenever you want (section 9).
These are all the permissions we request. Each one is here because a specific feature does not work without it:
calendar.events.readonlyView the events on your primary calendarEvery few minutes we read the events on your primary calendar that start within the next hour, for two things: to know which meeting the note-taker should join, and at what time. It is read-only: with this permission the app cannot create, modify, or delete anything on your calendar, and it does not access your other calendars. From each event we only look at the title, start time, whether it is cancelled, whether you declined the invitation, how many guests there are, the guests’ domains (not their email addresses), and the video call link. We do not store a copy of your calendar: events are read in memory and discarded; the only thing stored is the bot session that gets scheduled (meeting title, link, and code).
meetings.space.readonlyRead information about Google Meet conferencesLets us read conference data: the meeting code (
abc-defg-hij) to title the meeting, and the names of the people who took part, so the notes can say who said what. If your Google Workspace account produces Meet’s native transcript, this permission is what lets us read that text and turn it into notes. It is read-only.calendar.app.createdCreate a separate calendar and manage only its eventsCreates a separate calendar in your account named "Navvy AI" and allows managing only the events the app itself creates there: the appointments booked by the voice agent. It gives no access to the rest of your calendar, nor to events created by you or by other applications. A separate calendar is deliberate: you can tell at a glance what the AI booked, hide or share it separately, and disconnecting the account does not wipe your history. This feature is in development; the permission is declared because it is part of the same connection.
userinfo.email · userinfo.profile · openidIdentify the connected accountSo we know which Google account is connected and can show it in the app. We store the account’s stable identifier, your email, and your display name (section 3).
We request offline access (a refresh token) because the note-taker has to be able to join a 9 a.m. meeting without you having the app open.
3. What we store from your Google account
- The stable identifier of the Google account, your email address, and your display name.
- The OAuth access and refresh tokens, so we can keep doing what section 2 describes.
- The identifier of the Google Meet notification subscription and its expiry date, which is how we find out a transcript is ready.
- The date of the last calendar sweep, only so we can show you whether the integration is alive.
We do not store your calendar. Not the events, not the descriptions, not your guests’ email addresses.
4. The meeting bot joins as a visible participant and records audio
- How it joins: it asks to join like any guest and waits in the lobby. If it is denied, it leaves. If nobody admits it within the waiting period, it leaves and the session is marked as failed.
- What it records: the meeting audio only. It does not record video or shared screens.
- When it leaves: when the meeting ends, when it is left alone in the room, when you cancel it from the app — and then nothing is transcribed — or when the maximum duration is reached.
- What happens to the recording: the audio file lives only inside the ephemeral container running that bot and disappears when the container ends. It is not stored in our databases, not archived, and not offered for download.
- How it is transcribed: the audio is sent to the Google Gemini API, which turns it into text separating who said what. Google automatically deletes the uploaded file after 48 hours.
- What reaches our servers: only the transcript text and the meeting duration. Never the audio.
There is a second path, without a bot. If your Google Workspace account produces Meet’s native transcript, Google notifies us when it is ready and we read that text using meetings.space.readonly. In that case the recording is Google’s and is governed by your Workspace settings: we only read the resulting text.
5. What we do with the transcript
From the meeting text we generate the notes: an executive summary, the topics covered, decisions, agreements, questions left open, risks, and a list of action items with owner and priority, plus a draft follow-up email.
The notes are generated by an Anthropic (Claude) model. The transcript and notes are stored under your company, and only users of your company can see them.
6. Other data we process
- Account and company: name, email, hashed password, company, time zone, and the users you invite.
- Messaging channels: if you connect WhatsApp Business or Instagram, we process the messages, comments, contacts, and files needed to answer them. Your use of those channels is also subject to Meta’s policies.
- Voice agent calls: the call audio, its transcript, and the details the prospect provides (name, interest, preferred time).
- Billing: plan, usage, and the data handled by our payment processor. We never see or store your card details.
- Usage and technical logs: platform metrics and error logs, needed to operate and debug the service.
7. Limited Use of Google data
Specifically, and without exception:
- We do not sell data obtained from Google APIs to anyone, nor transfer it to data brokers.
- We do not use it for advertising, ours or anyone else’s, nor for targeting, profiling, or personalizing ads.
- We do not use it to train AI models, neither we nor our providers. The models we use process your data to give you a result and do not incorporate it into their training.
- We only use it to provide the features you turned on, as described in this policy.
- No human reads your Google data, unless you expressly authorize it (for example, to solve a support issue), it is strictly necessary for security or to comply with the law, or the data is aggregated and anonymized.
9. Where it is stored and for how long
Our infrastructure runs on Google Cloud in the us-central1 region (United States). If you write to us from another country, your data is processed there.
- Meeting audio recording: not retained. It exists only while the bot is in the meeting and is destroyed with the container. The temporary file on the Gemini API is deleted by Google after 48 hours.
- Transcript and notes: while your account is active and for up to 24 months after the meeting, or until you delete it sooner from the app. Deleting a meeting removes it along with its transcript and notes.
- Google connection tokens and data: until you disconnect the account, at which point they are deleted (section 10).
- Account and billing data: while the account is active and, afterwards, 5 years to meet applicable tax and accounting obligations.
- Technical logs: up to 12 months, as needed to operate the service and investigate incidents.
10. How to disconnect Google and what gets deleted
You can cut off our access to your Google account two ways, and both work:
- From NavvyAI: in the Google integration settings, click Disconnect. We cancel the Meet notification subscription, revoke the token with Google, and delete the whole connection: access and refresh tokens, account identifier, email, and name.
- From your Google account: go to myaccount.google.com/permissions and remove the app’s access. From that moment we can no longer read anything, and the first time the app tries to renew the token, the failure makes it delete the connection automatically and ask you to reconnect.
11. Your rights
You have the right to access your data, rectify it, cancel it, and object to its processing (ARCO rights under Mexican law), as well as to withdraw your consent. From the platform itself you can view and delete your meetings and disconnect your integrations at any time.
To exercise any of these rights, or if you want your account fully deleted, write to us at fabian@zensavvy.com from the address associated with your account. The details are on the data deletion page.
12. Security
- All traffic travels encrypted over HTTPS.
- Data is isolated per company: every query is scoped to the company of the user making it.
- Credentials and tokens live in Google Cloud’s secret manager, not in the code.
- Team access to production systems is restricted to those who need it to operate them.
No system is infallible. If we detect a breach that affects you, we will tell you and notify the relevant authority where the law requires it.
13. Minors
NavvyAI is a work tool aimed at businesses and professionals. It is not intended for anyone under 18, we do not knowingly collect their data, and if we find that an account belongs to a minor we delete it.
14. Changes to this policy
If anything changes, we will publish the new version on this page with the date updated above. If the change materially affects how we handle your data, we will tell you inside the platform before it takes effect.
15. Contact
Questions about this policy or your data? Write to us at fabian@zensavvy.com.
