Privacy Policy

Last updated: September 19, 2026

This Privacy Policy explains how Niovo ("we", "us") collects, uses and protects information when you use the Service at niovo.app. The short version: your data is yours, we don't sell it, and the AI only sees what it needs to help you.

1. Information we collect

  • Account data — name, email address and a hashed password (we never store passwords in readable form).
  • Workspace content — tasks, projects, documents, labels, comments, time entries, meeting transcripts and notes you create or import.
  • Calendar data — if you connect Google Calendar, we sync event titles, times and attendees for the calendars you authorize, so the scheduler can plan around your real meetings.
  • Usage data — sign-in times, feature usage, AI credit consumption and error logs used to keep the Service healthy.
  • AI context — when you use AI features, your prompt plus the workspace context needed to answer it (e.g. related tasks, docs, calendar events) is processed to generate a response.

2. How we use information

We use your information to operate the Service: scheduling and re-planning your work, syncing integrations, generating AI responses, sending transactional email (invitations, booking confirmations), metering plan limits, and keeping the platform secure. We do not sell your data and we do not use your workspace content to advertise to you.

3. AI processing

AI features send your request and the minimum relevant context to our model providers. Providers are bound by their own data-processing terms. AI output is generated, may be inaccurate, and is always reviewed by you before any proposed change is applied — the AI cannot modify your workspace without your explicit approval. If the Service runs in offline/stub mode, no data leaves the server for AI processing.

4. Google Calendar integration

Niovo's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Calendar data is used only to provide scheduling features inside your workspace, is not transferred to other parties except the model provider where explicitly involved in an AI feature you trigger, and is not used for advertising. You can disconnect the integration at any time in Settings, which also deletes the imported calendar events from our database.

5. Service providers

We share data only with processors needed to run the Service:

  • Hosting — our own servers and Cloudflare (edge network and TLS).
  • Payments — Stripe (card details go directly to Stripe; we store only subscription status).
  • Email — Resend, for invitations and booking confirmations.
  • AI models — the provider configured for the Service, for features you explicitly use.
  • Google — calendar sync, only if you connect your account.

We may disclose data where required by law.

6. Cookies

We use a small number of strictly necessary cookies: a login session cookie (httpOnly) and a short-lived state cookie during Google OAuth connection. We do not use advertising or third-party tracking cookies.

7. Data retention and deletion

We keep your data while your account is active. Disconnecting an integration deletes the data imported through it. When you delete your account or workspace, content is removed from our production database; encrypted backups may retain copies for a limited window (up to 30 days) before being purged.

8. Security

Passwords are hashed with scrypt, sessions are httpOnly cookies served over HTTPS, and access is scoped per workspace so members only see their own workspace's data. No system is perfectly secure — if you believe you found a vulnerability, please tell us at [email protected].

9. Your rights

Where GDPR or similar laws apply, you can request access, correction, export or deletion of your personal data, and object to or restrict certain processing. Workspace features (Settings → export) cover most requests; for anything else, contact [email protected].

10. Children

The Service is not intended for children under 16, and we do not knowingly collect their data.

11. Changes to this policy

We may update this policy as the Service evolves. Material changes will be announced in the app or by email. The "Last updated" date above always reflects the current version.

12. Contact

Privacy questions? Contact us at [email protected].