1. Introduction


This Privacy Policy explains how Heurivon Inc. ("we", "us", "Heurivon") collects, uses, stores, and shares personal information when you use our Service. We are committed to protecting your privacy and handling your data transparently and responsibly. This version clarifies Google Drive data collection, scope of access, and current limitations on automatic deletion of Drive-derived artefacts. It also names Twilio as the SMS verification provider for the optional recovery phone feature.


2. Information We Collect


We collect information you provide directly (account details, conversation inputs, memory notes, API keys, and an optional recovery phone number used solely for account-recovery verification), information collected automatically (usage logs, session data, IP addresses, browser type), and information obtained through third-party integrations (Google Calendar event data, Google Drive file names and AI-derived summaries and embeddings from files in folders you link, CRM data from HubSpot, financial data from QuickBooks Online, store data from Shopify, and messages from Slack and Telegram when you subscribe to those integrations). We also collect voice recordings and transcriptions when you use voice input features.


If you add an optional recovery phone number, we share that phone number with Twilio Inc., our SMS verification provider, solely to deliver one-time verification codes — when you confirm ownership of the number, and as a possession check during two-factor authentication recovery. Twilio receives only the phone number and the delivery details needed to send the code; the number is never used for marketing and is never shared with any other party.


3. How We Use Your Information


We use your information to: (a) provide, operate, and personalize the Service; (b) maintain your persistent memory and goal history; (c) execute tasks on third-party platforms (manage files and documents, manage CRM records) at your direction; (d) generate AI responses using your conversation context; (e) display usage and cost metrics; (f) send service notifications; (g) monitor and improve service quality and reliability using aggregated usage metrics that exclude Google Workspace content; and (h) comply with legal obligations.


4. Data Storage & Processing Location


All Heurivon infrastructure is operated with United States data residency:


• Database (PostgreSQL): hosted on Replit infrastructure running on Google Cloud Platform (GCP) in the us-central1 region (Iowa, USA). All user account data, conversation history, persistent memory, and application records are stored here.


• File Storage: uploaded files and generated media are stored in Cloudflare R2 object storage with US-based storage settings enforced at the API level on every request.


• AI Processing: conversation content and voice inputs are processed by AI model providers — OpenAI, Anthropic, Mistral AI, and Groq — each operating on US-based infrastructure. On customer accounts these providers are accessed using API keys you supply, under your own agreement with that provider. We do not send data to non-US AI endpoints.


In summary: all data you provide to Heurivon — files, database records, conversation context, and AI-processed content — is stored and processed in the United States.


5. International Data Transfers


If you access the Service from the European Economic Area (EEA), the United Kingdom, or Switzerland, please be aware that your personal data is transferred to and processed in the United States, which may not provide the same level of data protection as your home country.


We rely on the following mechanisms for such transfers:


• Replit (database hosting): operates under Standard Contractual Clauses (SCCs) as set out in its Data Processing Agreement.


• AI model providers (OpenAI, Anthropic, Mistral AI, Groq): on customer accounts these are accessed under API keys you supply, so your agreement with each provider — including any Data Processing Agreement or Standard Contractual Clauses — is between you and that provider. Links: platform.openai.com, anthropic.com/legal/commercial-terms, mistral.ai/terms, console.groq.com/docs/legal/services-agreement.


• Cloudflare (R2 file storage): operates under Standard Contractual Clauses (SCCs) as set out in its Data Processing Agreement.


You may contact us at legal@heurivon.com for a copy of the applicable transfer mechanisms.


6. Google Workspace Data


When you connect your Google account, Heurivon requests the following Google Workspace access:


• Google Calendar — read your calendar events so Heurivon can answer scheduling questions and use your availability as context. Heurivon requests read-only Calendar access and cannot create, modify, or delete your events.


• Google Drive — Heurivon requests full Drive access (the drive scope) to support document indexing and retrieval. For the Drive knowledge-base feature, Heurivon reads files only within the specific folder you link and stores AI-generated summaries and vector embeddings of those files in our database. For general Drive agent tools, access may be constrained to a root folder you configure in Settings; if no root folder is configured, those tools can access any file in your connected Drive. Raw file content is processed in memory and not persisted; only file names, metadata, summaries, and embeddings are stored. Write access is turned on when you connect your Google account, because the drive scope covering both reading and writing is granted at that point. You can turn write access off at any time in Settings → Drive. Heurivon writes only when you explicitly instruct it to create or update a file; no automated or background process writes to your Drive.


• Google Sheets — read and write spreadsheet data to execute data tasks you explicitly request inside Heurivon.


• Google Docs — read document content and, when you request it, create or append text to documents in your Drive.


• Google Slides — read presentation content and, when you request it, create presentations or update slide text.


• Email address — used to identify your account and for service communications.


Heurivon does not request or use Gmail API access. Email features in Heurivon use IMAP/SMTP with credentials you supply separately (see Section 10).


Google Workspace data is used solely to execute tasks you request and to provide you with relevant context. It is not used for advertising and is not sold or shared with data brokers. It is shared only with the AI providers listed in Section 7, and only as needed to fulfil a request you make; those providers are prohibited from using it to train or improve their models. Google Workspace data is never used to train any AI model. You can revoke Google access at any time via your Google Account settings at myaccount.google.com. See Section 13 for details on data retention and deletion, including current limitations on automatic deletion of Drive-derived artefacts on disconnect.


This data is processed in accordance with Google's API Services User Data Policy (developers.google.com/terms/api-services-user-data-policy).


7. How We Use AI Models


On customer accounts, Heurivon does not operate AI provider accounts. All AI processing runs under API keys you supply, on your own account. An OpenAI key is required, because core services — search, OCR, transcription and image generation — run on OpenAI and are not model-switchable. Supplying additional keys for Anthropic, Mistral AI or Groq makes those providers selectable for chat and reasoning. A small number of internal accounts, limited to Heurivon staff and a handful of early beta testers and never customer accounts, run on Heurivon-operated provider accounts on which sharing of inputs, outputs, evaluation and fine-tuning data with the provider is disabled at the organization level.


Heurivon routes your requests through one or more AI model providers depending on the task. The table below summarises each provider, its purpose, and whether it trains on your data.


Provider: OpenAI (GPT-5.4, GPT-5.4-mini, Whisper, TTS, gpt-image-2)

Purpose: Core conversation, task planning, voice transcription, text-to-speech, image generation

Trains on our data: No — OpenAI's API data is not used to train models per OpenAI's API Terms


Provider: Anthropic (Claude)

Purpose: Alternative reasoning and long-context tasks (when selected by you or required by the task)

Trains on our data: No — Anthropic's API data is not used to train models per Anthropic's Commercial Terms of Service


Provider: Mistral AI

Purpose: Lightweight and fast inference tasks (when selected as a BYOK provider)

Trains on our data: No under Mistral's standard commercial API terms. Mistral Labs models, which may be used for training regardless of plan, are blocked by Heurivon. When you supply your own key, your plan with Mistral governs.


Provider: Groq

Purpose: High-speed inference for latency-sensitive tasks (when selected as a BYOK provider)

Trains on our data: No under the Groq Services Agreement. When you supply your own key, your plan with Groq governs.


When you ask Heurivon to work with your Google Calendar or Google Drive content, that content is sent to the AI provider handling your request so it can generate a response. This is how features like "what's on my schedule today" or "summarise this document" work.


Every AI provider Heurivon supports is subject to terms that exclude customer data from model training. Google Workspace data is never used to train, fine-tune, or improve any artificial intelligence or machine learning model, whether by Heurivon or by any provider we use. We do not build datasets from Google Workspace data.


For a complete list of our AI subprocessors, visit /ai-providers.


8. Using Your Own API Keys (BYOK)


Heurivon runs on API keys you supply. An OpenAI key is required, because core services — search, OCR, transcription and image generation — run on OpenAI and cannot be switched to another provider. Supplying additional keys for Anthropic, Mistral AI or Groq makes those providers selectable for chat and reasoning.


When you use your own key:


• Your data is sent to that provider under your account and your agreement with them, not under a Heurivon account.


• Heurivon does not control your plan or your account settings with that provider. You are responsible for reviewing your provider's terms and confirming your plan and settings meet your requirements.


• Provider account settings. OpenAI and Mistral AI both offer organization-level settings that permit your content to be used for model training — OpenAI's "Share inputs and outputs with OpenAI," which comes with free daily token allowances, and Mistral's "Data usage for improving our services." Both are disabled by default. If you enable either, your content, including any Google Workspace content, will be used to train that provider's models. We recommend leaving both disabled.


• Mistral Labs models may be used for training regardless of plan or opt-out settings. Heurivon blocks Labs models server-side, so they are never used.


• Heurivon does not mark up, resell, or retain copies of data processed through your own API keys beyond what is necessary to display results to you.


9. AI Processing and Personalization


Conversation content and user-provided facts are processed by AI models to generate responses and extract persistent memory items. This personalization data is:


• Scoped to your individual account — it is never pooled across users or shared with other users of the Service.


• Stored in our secure database and visible and editable by you at any time in Settings → Memory.


• Deletable at any time — you can delete individual memory entries or your entire memory via Settings → Memory → Clear All.


• Not used to train external AI models — we do not use your personal conversation data or memory to train any AI model, including models operated by our providers.


When you delete your account, all personalization data (memory, goal history, conversation logs) is permanently deleted from our systems.


10. Email (IMAP)


Heurivon's email features use IMAP and SMTP protocols directly with the email provider of your choice. This means:


• Heurivon does not request or use the Gmail API or any Google OAuth email permission.


• No Gmail OAuth scope is requested when you connect your Google account (see Section 6 for the scopes we do request).


• To use email features, you supply your email account's IMAP/SMTP credentials (server address, username, and password or app-specific password) directly within Heurivon's Settings.


• These credentials are encrypted at rest using industry-standard encryption and are never transmitted to third parties other than the email server you specify.


• Heurivon uses these credentials only to perform email tasks you explicitly request (e.g., reading, summarising, or sending emails on your behalf).


• You can revoke email access at any time by deleting your credentials from Settings → Integrations → Email. When you disconnect email, your credentials are immediately deleted from Heurivon's systems.


11. Shared Projects


Heurivon may support collaborative or shared project features in which more than one user participates. When you contribute data (goals, notes, tasks, files) to a shared project:


• Other participants in the project will be able to view the content you add to the shared space.


• Your real name and email address are never revealed to other participants without your explicit, mutual consent (see also Section 12 on the Social Layer).


• The project owner can delete entries from a shared project. Participants can view all shared memory at any time via "View shared memory," and can request removal of entries derived from their own data by contacting privacy@heurivon.com.


• Data contributed to a shared project may remain visible to other participants until you delete it or until all participants leave the project.


12. Social Layer


Heurivon includes an optional social layer that allows AI-mediated introductions between users. If you participate, your AI agent may broker introductions. Your real name and email are never shared with other users without your explicit, mutual consent. All consents are logged and auditable.


13. Data Retention and Deletion


We retain your data for as long as your account is active or as needed to provide the Service.


When you disconnect a third-party integration (e.g., Google, Slack, HubSpot):

• API credentials and OAuth tokens for that integration are deleted immediately.

• Cached data retrieved from that integration (e.g., cached calendar events) is deleted within 30 days.

• Conversation history referencing that integration's data is retained unless you separately delete it.

• Note: AI-derived artefacts from Google Drive (file summaries and vector embeddings stored in our database) are not automatically deleted when you disconnect Google. To remove these, manually unlink each Drive folder via Settings → Drive before disconnecting your Google account. This limitation is being remediated.


When you delete your account (via Settings → Account → Delete Account or by contacting support@heurivon.com):

• Your profile, credentials, API keys, and all integration connections are deleted immediately.

• Your conversation history, persistent memory, goal history, and all personalization data are permanently deleted within 30 days.

• Most data derived from Google Workspace (cached calendar events, Sheets data, and similar) is deleted along with your account. Note: AI-derived artefacts from Google Drive (file summaries and embeddings) are not currently deleted automatically on account deletion. To ensure these are removed, unlink all Drive folders via Settings → Drive before deleting your account. This limitation is being remediated.

• Backups containing your data are purged within 90 days of account deletion.

• Anonymized, aggregated analytics data (which cannot be linked back to you and which excludes any data derived from Google Workspace) may be retained indefinitely for service improvement purposes.


14. Data Security


We implement industry-standard security measures including encryption at rest and in transit, access controls, and regular security reviews. However, no system is completely secure. You use the Service at your own risk, and you are responsible for maintaining the confidentiality of your credentials.


15. Your Rights


Depending on your jurisdiction, you may have rights to access, correct, delete, or restrict processing of your personal data; data portability; and the right to object to certain processing. To exercise these rights, contact us at legal@heurivon.com. We will respond within 30 days.


16. Children's Privacy


The Service is not directed to children under 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided personal information, we will delete it promptly.


17. Changes to This Policy


We may update this Privacy Policy. We will notify you of material changes via email or in-app notice at least 14 days before the changes take effect. Your continued use of the Service constitutes acceptance of the updated Policy.


18. Google API Services — Limited Use Disclosure


Heurivon's use of information received from Google Workspace APIs will adhere to the Google Workspace APIs User Data Policy, including the Limited Use requirements (developers.google.com/terms/api-services-user-data-policy).


Heurivon's use of Google Workspace data is limited to providing or improving user-facing features that are prominent in the requesting application's user interface. Heurivon will not use Google Workspace data for any purpose unrelated to providing these user-facing features, for serving ads, for developing, improving, or training non-personalized advertising systems or models, or for selling data to data brokers. Heurivon will only transfer Google Workspace data to others as necessary to provide or improve user-facing features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with prior notice to users. Heurivon will not allow humans to read Google Workspace data unless: the user has provided affirmative agreement to access specific messages or files; it is necessary for security purposes such as investigating abuse; it is required to comply with applicable law; or use is limited to internal operations and the data (including derivations) have been aggregated and anonymized.


Heurivon will not use data received from Google Workspace APIs to develop, improve, or train generalized artificial intelligence (AI) or machine learning (ML) models.


19. Contact


For privacy inquiries or to exercise your rights, contact: legal@heurivon.com. For EU/EEA residents, our Data Protection Officer can also be reached at legal@heurivon.com.