Privacy Policy
Last updated: August 21, 2026
Ervona has two ways of working, and they handle data differently. The short version: the browser extension runs the outreach agent in your own browser, so your CRM and lead data stay on your device. The Ervona Desk is the opposite by design: it is an optional, paid autopilot that runs on our servers with no browser open, so when you turn it on it necessarily processes your CRM records, leads, and outreach on our side. To run any account we also hold your email, your subscription status, a device identifier, and the settings and business profile you save. This page explains all of it in plain language.
At a glance
- The extension keeps CRM and lead data on your device. Its outreach agent reads and writes records inside your own CRM session in your browser. Those records are not sent to us.
- The Ervona Desk is server-side, and off until you turn it on. If you enable the Desk, it runs unattended on our servers. To do that we store the credentials you connect (a mailbox, a texting number, and your CRM sign-in or token) and we process the leads, replies, and CRM records it works. This is the one part of Ervona that does hold lead data on our servers.
- We hold your account email (sign-in), subscription status (billing), a random device identifier (seat enforcement), and the settings, templates, and business profile you save, so they sync across your devices.
- The optional Inbound Agent answers email in a mailbox you connect; we process that email on our servers (via Nylas) to draft or send replies. It is off until you turn it on.
- Email analytics is on by default. We log a limited record of each send plus its reply, so we can build your reply-rate reports; a plain toggle in Settings stops new tracking, and a separate delete control removes the stored analytics anytime. Opens are counted only where an invisible pixel could be put in the message before it left, which is not everywhere: Section 3 lists exactly where it happens and where it cannot. Other customers cannot read this data, and it is never sold.
- Connecting a mailbox also records the email you send from it yourself (the recipient's address, the subject, and the time, never the body), so those sends have a reply rate. Mail to the domains you enter in your inbox settings under "Internal domains" and "Partner domains" is left out entirely, so fill those in when you connect the mailbox. Section 4 has the full list of what is skipped.
- The Desk can answer replies to outreach we did not send (a HubSpot or Salesforce sequence, a Pardot drip, an email a rep typed), but only on a Desk persona you switch it on for, only on a one-to-one thread that mailbox started itself with somebody outside your company, and only with your approval on every reply. Section 5 has the whole rule, and the Desk shows you every thread it looked at and left alone.
- We do not sell your data, run advertising trackers, or share personal data for advertising, and we never use your data to train AI models.
- Questions or requests: privacy [at] ervona.ai. We answer privacy mail personally.
1. Who we are
Ervona LLC ("Ervona", "we", "us") is the data controller for the personal information described in this policy. Our mailing address is 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA. Ervona provides: the Ervona SDR browser extension, which automates outbound outreach inside your CRM in your browser; the Ervona Desk, an optional server-side autopilot that works a list of leads unattended; the optional Inbound Agent, which answers email in a mailbox you connect; the ervona.ai website; and the Ervona mobile app, which is another window onto the same account — it reads and controls the same Desk and settings through the same authenticated APIs and creates no separate data. This policy covers all of them. For anything privacy-related, or general help, email privacy [at] ervona.ai.
2. Data you give us
- Account details. Your email address and a securely hashed password, handled by our authentication provider (Supabase Auth). We never see or store your plaintext password. When you create an account we also record which version of the Terms and this policy you accepted, and when, as evidence of the agreement.
- Business profile. During setup you save a profile describing what your company sells (company name, one-liner, products, tone, guardrails, and similar). We store this on your account so the agents can ground their messages in it. You can also paste a website URL or a past email and have our AI provider draft the profile for you (see Section 4).
- Connected-account credentials (for the Inbound Agent and the Desk). If you enable a feature that runs on our servers, you connect the accounts it needs and we store the credentials for them so the server can act on your behalf: a mailbox connection token (a Nylas "grant"), a texting-provider credential, and, for the Desk's CRM writeback and prospecting, your CRM credentials, which are a HubSpot Private App token, or your Salesforce sign-in and login URL or a linked Connected App. These are held write-only, meaning the app can save and replace them but can never read them back to your browser, and they are read only inside our secured server functions. They are also encrypted at rest (AES-256-GCM) with a key held outside the database, so a copy of the database alone cannot reveal them. We describe exactly how the Desk uses them in Section 5. The same write-only handling applies to any data-vendor API key you choose to save (for finding, enriching, or verifying leads through your own vendor account): the app can save or replace it, and it is read only inside our server functions to run requests you make.
- Billing details. When you subscribe, our payment processor (Stripe) collects and stores your payment information. We never see or store full card numbers. We retain only a Stripe customer reference, your plan tier, and your subscription status.
- Support messages. If you email us, we keep that correspondence so we can help you and improve the product.
3. Data the extension creates and syncs
This section is about the browser extension. Its outreach agent works your CRM in your own browser session, so most of what follows is about configuration and history rather than your leads. Two items are different and are spelled out below: email analytics, and the optional access to Gmail and Outlook on the web that the extension needs before it can track email you type there.
- Device identifier. On first sign-in, the extension generates a random identifier (a UUID that contains no information about you or your hardware) and registers it to your account. We use it for one thing: making sure one subscription is not shared across many computers at once.
- Settings and templates. Your message templates, engine rules, and workspace configuration are saved to your account so they follow you to any computer you sign in on, and so you can edit them on the website. Templates hold the message content you write. They do not contain your leads. A copy is also kept in your browser's extension storage so the tool still works offline.
- CRM field map. If you use "Map My CRM", we store the on-screen spots you point at (element labels and attributes, for example that your Send button reads "Send") on your account. This map describes your CRM's layout, not your leads: it holds no lead names, email addresses, phone numbers, or message content. Each record type (Leads, Contacts, Opportunities) can have its own map.
- Run history and reports. Your outreach history and run reports are stored in your browser's extension storage on your device, so they work offline. You can also turn on optional cloud sync (it is off until you turn it on) to keep a copy of your own run history and reports on your account, so they follow you to any computer you sign in on. That copy is protected by row-level security, so it is not accessible to other customers. It holds your run summaries and reports only, never your lead or customer records, which stay on your device. It is disclosed only to the service providers needed to operate the Service, is never sold, and is removed when you delete your account. Exported reports (PDF, Excel, CSV) are generated on your device and stamped with your account email.
- Email analytics. Email tracking is on by default — a plain toggle in Settings stops new tracking (you are shown a warning when turning it back on), and a separate control lets you delete the stored data anytime — and while it's on, each email you send is logged to your account (the recipient's email address, the subject, the template, and a timestamp), and replies are matched back to the send they answer. Where an open pixel can be added, its loads are recorded against that same send; the note below this list says exactly where that is and where it is not. This powers your reply-rate and open-rate reports. The data is protected by row-level security so it is not accessible to other customers, is never sold, is disclosed only to the service providers listed in Section 10, and is processed solely to provide your reports. Separately from these logs, a bare send meter (a count and a timestamp per send — never an address, subject, or content) enforces your plan's daily sending allowance; meter entries are deleted automatically within 48 hours, and deleting your analytics also clears every meter entry older than the live 24-hour window — plus, only if you also opt into the "How you compare" benchmark, it contributes to the pooled, anonymized peer statistics described in Section 5.
- Gmail and Outlook on the web (optional, and off until you switch it on). The extension can track the email you type in Gmail or Outlook on the web, the same way it already tracks email you write in the Salesforce console. Running on those sites needs your permission, so Chrome asks for it in the extension's own settings at the moment you switch the feature on, one mail service at a time. Until then the extension does not load on those sites at all. Turning it back off, in the extension or in Chrome's own permissions screen, takes effect immediately. When it is on, it does one thing at one moment: as you click Send on a message you wrote, it reads that message's recipient and subject line and appends the open pixel to the body. What is stored on your account is the same limited record as any other tracked send: the recipient's address, the subject, timestamps, and the open and reply events. The body of your message is never read and never sent to us, and neither is anything else in the mailbox: not your inbox, not your other messages, not drafts you have not sent. Mail to a domain on your never-track list gets nothing: no pixel, no record, and no note that it happened. That check runs against your list inside your own browser and the address is then dropped, so nothing about that message ever reaches us. It also leaves alone anything that is not one-to-one outreach: a message addressed to more than one person is skipped.
Where the open pixel goes, and where it cannot. Counting an open means putting an invisible 1x1 image in the message before it is sent, so it can only happen where something of ours is in the compose window at that moment:
- Email the extension sends, and email you write in the Salesforce console: a pixel is added, when email tracking is on.
- Email you write in Gmail or Outlook on the web: a pixel is added, but only if you granted that optional permission (above) and email tracking is on.
- Ervona Desk campaigns: "count opens" is on by default for each campaign and can be switched off per campaign. When it is off, the email goes out as plain text carrying no pixel at all.
- Email you send from your own mail app (desktop Outlook, Apple Mail, your phone): never. Nothing can add to a message before it leaves your mail app, so these sends can have a reply recorded against them, but never an open.
Wherever opens are counted, they over-count, because some email apps and security scanners load images automatically. Replies are the reliable signal.
4. The optional Inbound Agent (a connected mailbox)
The Inbound Agent is a paid feature that is off until you connect a mailbox and enable it. Because it answers email for you, it necessarily processes that email on our servers. Here is exactly what happens. One item below is different and is marked as such: the record of the email you send from that mailbox begins as soon as the mailbox is connected, not when the agent is enabled.
- Connecting your mailbox. You authorize access with your provider's own standard sign-in, and the connection is carried by Nylas, our email-infrastructure provider. Which application you are granting access to depends on the provider: for Google you consent to Nylas's application, and for Microsoft you consent to Ervona's own registered application. Either way Nylas processes the mail on our behalf as a service provider, and we store a connection token (a Nylas "grant") and the connected email address on your account. We never see or store your email password, and you can revoke access at any time from your mail provider or by disconnecting the mailbox here.
- Drafting replies. When a new email arrives, Nylas notifies our server. Our server reads that message and recent thread context and sends it, along with your business profile, to Anthropic's Claude API to draft a reply. The draft is saved in your mailbox for approval, or sent, according to your settings. We store a record of the exchange on your account so you can see what was said and why: up to the first 4,000 characters of the message that came in, and the reply we drafted, up to 20,000 characters. That is what the approval queue and the activity trail read from. It is deleted when you delete your account.
- Sender handling and Stage Sync. The agent sorts senders by email domain (colleague, partner, or client) to adjust its reply, and can flag a status change for a lead. When it detects a milestone such as an application being provided, it stores a short record (the sender's email address, the subject, and a brief snippet) on your account so you can apply the status change in your CRM with one click.
- Email you send yourself from that mailbox. Once a mailbox is connected, we record the one-to-one email you send from it by hand, so those sends get a reply rate of their own. We store the recipient's email address, the subject line, and the time it was sent. We never store the body. Most of what leaves a work mailbox is deliberately left out, with no record kept that it existed: anything addressed to more than one person, replies and forwards, no-reply addresses, and mail to any domain you have entered in your inbox settings under "Internal domains" or "Partner domains". Those two lists are the same ones the reply agent sorts senders with, and they are what the check runs against, so fill them in when you connect the mailbox: a list you have not filled in matches nothing. This starts when you connect the mailbox and stops when you disconnect it, whether or not you have the reply agent switched on, and it is deleted with the rest of your analytics data or when you delete your account. There is no open tracking on these sends: a mailbox only sees a message after it has already gone, so nothing can be put in it.
- Third-party content. Email the agent answers may contain personal data about the people who wrote to you. That content is processed only to generate a reply and run the features above. You are responsible for having a lawful basis to process the correspondence in the mailbox you connect.
- AI profile drafting. If you paste a website or a past email to auto-fill your business profile, that text is sent to Anthropic's Claude API to extract the profile.
- Google & Microsoft mailboxes (limited use). If you connect a Google or Microsoft mailbox, Ervona's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and to the equivalent Microsoft Graph terms. We use mailbox data only to provide the features you enable; we do not sell it, use it for advertising, or use it to train AI models.
- Nothing that was already in the mailbox. The agent only answers mail that arrives after you connect the mailbox. Whatever was sitting there when you connected it is left alone: not answered, and not sent to a model to draft a reply. Connecting a mailbox does not hand us its history.
- No human reading of your email. Our personnel do not read the private email in a connected mailbox except where strictly necessary for security, to debug a specific problem, or to handle a support request you initiate — and never for any other purpose.
We do not use your data to train AI models, and our AI provider processes it only to return the output we request.
5. The Ervona Desk (the server-side autopilot)
The Ervona Desk is a paid feature that is off until you set it up and turn it on. Unlike the extension, the Desk is designed to run on our servers, unattended: no browser is open and no one is at the keyboard, so a scheduled worker on our infrastructure does the work. That means the Desk necessarily processes your leads and CRM records on our side. This is the one part of Ervona where lead data is held on our servers rather than staying on your device. Here is exactly what it holds and does:
- The accounts you connect. To run unattended, the Desk uses accounts you connect and we store their credentials (Section 2): a mailbox (a Nylas grant) it sends from and watches for replies, a texting number through the provider you connect (for example Twilio, Telnyx, SignalWire, Plivo, Vonage, Sinch, Infobip, Sendblue, or RingCentral), and your CRM (a HubSpot Private App token, or your Salesforce sign-in and login URL) so it can read and write your records. Credentials are stored write-only, encrypted at rest with a key held outside the database, and read only inside our secured server functions; they are never returned to your browser.
- Prospecting (choosing who). When you build a prospecting filter, our server runs it against your connected CRM (a HubSpot search or a Salesforce SOQL query, with an opt-out guard applied) to select matching people. The matching leads it returns — typically an email address, name, company, and phone number — are stored on your account as the campaign's target list so the Desk can work them. This is CRM lead data held on our servers, and it exists only for the campaigns you run.
- Outreach. The Desk sends email from the connected mailbox and, where you choose, text messages from the connected number, at a pace it controls, and it logs each send. It applies suppression and opt-out flags it can read on the record. "Count opens" is on by default for each Desk campaign and adds a tracking pixel, which makes the email HTML. You can switch it off per campaign; while it is off, that campaign sends plain text with no tracking pixel.
- Finding and verifying leads (optional, your vendor account). If you connect your own data-vendor key and run a search, we send your search filters to that vendor and store the people it returns as targets on your account — that data comes to you under your contract with the vendor, not ours. Before a first send, the Service may check that a recipient address exists at all: a syntax check, a public DNS lookup of the recipient's domain (via Cloudflare's DNS service, which sees only the domain, never the full address), and, where a verification key is configured, the recipient's email address is sent to the verification provider to check deliverability. Verdicts are stored on the target record so an address is never paid for twice.
- Watching for replies. The Desk watches its connected mailbox and texting number for replies. When a prospect replies, our server records that the reply arrived and, to summarize it for the rep, may send the reply text to Anthropic's Claude API. Reply content is treated strictly as data for that summary and is never used as instructions to the model, and is never used to train any model. We keep a snippet of the reply on your account so the rep can see it in the handoff and the activity trail, deleted when you delete your account.
- Referencing and writing back to your CRM. The Desk resolves the matching record in your CRM, and can leave a note, log the reply, set a lead status, flag do-not-contact, or reassign the record's owner. It can also create a record: for people on a list you choose to import into your CRM, and for a warm handoff whose prospect has no record yet. These reads and writes happen on our servers through the credentials you connected, scoped to your own account.
- Handing off to a human. When a lead is worth a person's attention, the Desk assigns or "loops in" a rep on your team and can email that rep the context. It keeps an audit trail of these transitions and handoffs on your account.
- Answering replies to outreach we did not send (off until you turn it on, per persona). A reply can land in a Desk mailbox that answers a message another system sent: a HubSpot or Salesforce sequence, a Pardot drip, or an email a rep typed by hand. When you switch this on for that persona, our server reads that thread in the mailbox so it knows what was pitched, and drafts a reply that always waits for your approval. It only ever looks at a one-to-one thread that the Desk mailbox itself started, with somebody outside your own company and outside the partner domains you listed, that nobody has already answered. Anything else is left alone. Because the thread has to be read to judge it, this is the one place the Desk reads a message that was sent from that mailbox before you connected it: the original outreach it is answering. We keep the reply and, once a thread is taken up, the original outreach message, on your account so you can see what the draft was grounded in; for a thread we decline we keep only the sender's address, the subject line, the time and the machine reason we left it alone, never any message body. The list of what was declined and why is shown to you in the Desk under Leads.
- A connected personal mailbox is the exception. By default the Desk runs on its own dedicated accounts and never touches a rep's personal inbox. Connecting your own personal mailbox to the Desk is optional and something you would only do deliberately (for example, to auto-reply while you are away).
- "How you compare" — the opt-in network benchmark. The Reports view offers a benchmark that is off until you opt in, and it works both ways: you only see the peer numbers if you contribute yours. If you opt in, your account's send and reply statistics are pooled with other opted-in accounts into anonymized aggregates (for example the median reply rate, or reply rate by send hour and subject length). Only percentiles and bucketed rates are ever shown — never a message, an address, a subject line, or any per-account number — and nothing is shown at all until enough accounts contribute that no single account can be picked out of the numbers. You can opt out at any time, which stops your contribution going forward.
You direct and configure the Desk, and you decide draft-only versus automatic-send behavior. Everything the Desk stores about a campaign is protected by row-level security so it is not accessible to other customers, is never sold, is disclosed only to the service providers needed to operate the Service (and to the anonymized, aggregate benchmark above if you opt into it), and is removed when you delete the campaign or your account (see Section 12).
6. Data we do not collect
The browser extension works your CRM in your own browser session. When you use the extension, your lead and customer records and the contents of the CRM are processed on your device and are not transmitted to our servers. By default your run history and reports stay on your device too. The exceptions are the optional features listed below — email analytics is on by default and the rest are off until you turn them on:
- The Ervona Desk (Section 5), which by design processes leads and CRM records on our servers.
- The Inbound Agent (Section 4), which processes the email in a mailbox you connect.
- The record of the email you send from a connected mailbox yourself (Section 4): address, subject, and time, never the body. Connecting the mailbox is what starts it, so it runs even if you leave the Inbound Agent switched off. Disconnecting the mailbox stops it.
- Answering replies to outreach we did not send (Section 5). Off on every Desk persona until you switch it on for that persona, and even then only on a one-to-one thread that mailbox started itself with somebody outside your company.
- Optional cloud sync (Section 3), which keeps a copy of your own run history and reports and never includes lead records.
- Email analytics (Section 3), which logs a limited record of each send plus its reply, and its open wherever an open can be counted at all.
- The extension's access to Gmail and Outlook on the web (Section 3). You grant it per mail service and can revoke it at any time. It reads the recipient and subject of a message you are sending and nothing else: not the body of that message, and nothing else in your mailbox.
Limited diagnostic telemetry (Section 7) reports only that an automated step failed, never the record it was working on. Analytics, cloud sync, the Inbound Agent, and the Desk can all be turned off and their data deleted in Settings.
7. Data collected automatically
Our website and server endpoints log basic technical information (such as IP address, browser type, and timestamps) for security, rate-limiting, and keeping the service running. We keep this to a minimum, do not use it to build advertising profiles, and do not enrich it with third-party data. See our Cookie Policy for the short list of cookies and local storage we use.
Bot protection at sign-in. The sign-in and sign-up forms run Cloudflare Turnstile, a bot-detection check. Turnstile evaluates technical signals from your browser to tell people from automated scripts and returns a pass token; it does not profile you for advertising and cannot follow you across other sites.
Extension diagnostics. Because the outbound agent works inside your live CRM, a CRM update or an unusual org layout can occasionally break one of its automated steps. To detect and fix that, the extension sends us a small, best-effort diagnostic event when a step fails — for example, that the email composer or the Send button could not be found. Each event contains only the structural failure (a short error label and the record type, such as “lead” or “opportunity”), the CRM host it occurred on, and the extension version. It never includes a recipient’s name or email, the contents of any record, or anything you typed. We use it solely to keep the extension working.
8. How we use data
- To create and secure your account and sign you in.
- To sync your settings, templates, and business profile across your devices.
- To process subscriptions and determine which features your plan unlocks.
- To enforce plan seat limits (the device identifier above).
- To run the server-side features you enable — the Inbound Agent and the Ervona Desk — which includes prospecting, sending and watching for replies, and writing back to the CRM you connect, and to provide support and respond to your requests.
- To detect, prevent, and address abuse, fraud, or technical issues.
We do not use your data to train AI models, and we do not sell or rent personal data to anyone.
9. Legal bases (GDPR)
Where the GDPR applies, we process personal data on these bases:
- Contract: account, billing, settings sync, seat enforcement, the Inbound Agent, the Desk, and support. Processing needed to provide the service you signed up for.
- Legitimate interests: security logging and abuse prevention, balanced against your rights.
- Legitimate interests (site analytics): we run Cloudflare Web Analytics on our website to count page views. It is cookieless, stores nothing on your device, does not fingerprint you, and cannot follow you to other sites, so it does not rely on consent. We run no advertising or marketing trackers. If that ever changes, we will ask first via the privacy choices page.
- Legal obligation: tax and accounting records tied to payments.
When you use the Inbound Agent or the Desk, some of the personal data processed is about third parties (the people who write to you, or the leads on your list). For that data you are the controller and Ervona is your processor: you determine the purpose, and you are responsible for the lawful basis to process those records and for giving any notice the law requires. Our Data Processing Addendum governs that relationship.
10. Service providers (subprocessors)
We share the limited data above only with providers that help us run the service:
- Supabase: authentication, account and subscription records, settings and profile storage, the Desk's campaign and worklist data, and serverless functions.
- Stripe: payment processing, subscription management, and fraud prevention.
- Nylas: the email connection for the Inbound Agent and the Desk's mailbox (reading and sending mail in a mailbox you connect), and, when you turn on meeting booking, access to the connected account's calendar: reading your free and busy times to offer real availability, and creating the event itself. Creating it sends a calendar invitation to the person you are meeting. Used only if you enable those features.
- Your texting provider (Twilio, Telnyx, SignalWire, Plivo, Vonage, Sinch, Infobip, Sendblue, or RingCentral — whichever you connect): carries the Desk's SMS outreach and inbound-reply handling, used only if you enable texting. The Desk sends through your own provider account and number, so that provider processes recipient phone numbers and message content under your agreement with it, not as an Ervona subprocessor.
- Email verification providers (e.g., ZeroBounce): checking that a recipient address can receive mail before a first send. Receives recipient email addresses only when verification is configured. Where the check runs through a key you connected, that provider acts under your contract, not as our subprocessor. Domain-level DNS lookups use Cloudflare's public DNS resolver, which receives the domain only.
- Your data vendors (Apollo, People Data Labs, Hunter — only if you connect your key): these act under your agreement with them, at your direction; we transmit your search filters and receive the results on your behalf, and they are not Ervona subprocessors.
- Anthropic (Claude API): AI drafting of inbound replies, summarizing prospect replies for the Desk, and, if you use it, business-profile extraction. Used only for those AI features. Content is never used to train models.
- Cloudflare (Workers AI): a second AI provider, used to classify what a prospect's reply means (interested, not interested, an objection, and so on) and, where enabled, to draft. The text of the reply is sent to Cloudflare's hosted Llama models for that classification. Cloudflare commits that it does not use this content to train any AI model and does not make it available to any other Cloudflare customer, and that it is only stored where a storage service is deliberately used alongside Workers AI, which we do not do. Cloudflare also enables prefix caching by default on some models, which briefly holds the computed form of an input to speed up the next similar request. This is separate from the hosting and analytics use described below.
- Zoho (ZeptoMail) and Resend: delivery of transactional and notification email — such as sign-in verification, password-reset messages, and the Desk's handoff notifications to your reps. They process the recipient email address and the message content of those emails only.
- Cloudflare: website and application hosting, content delivery, and DNS. Processes basic technical request logs (such as IP address) to serve and secure the site. Also provides Cloudflare Web Analytics, a cookieless page-view counter that runs on our website pages and reports the page visited, referrer, and general device type — never your CRM data, and never anything you type.
CRMs you connect (Salesforce, HubSpot). When you connect a CRM to the Desk, we store your credentials and our server reads and writes your records through that CRM's API on your behalf. Salesforce and HubSpot are your own systems and their own controllers; your use of them stays subject to your agreement with them. We name them here so you know where the Desk reads and writes.
These providers process data under contracts and security commitments appropriate to their role. If we add a subprocessor that touches personal data, we will update this list before it goes live and provide any notice required by our Data Processing Addendum.
11. International transfers
Ervona is based in the United States, and our providers may process data in the United States and other countries where privacy laws may differ from those where you live. Where the GDPR or UK GDPR requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses and, for UK transfers, the UK Addendum, together with any supplementary measures appropriate to the transfer. Our Data Processing Addendum explains the applicable modules and how to request a copy of the safeguards.
12. Data retention
- Account, settings, and subscription records: kept while your account is active, then deleted or anonymized within 30 days of a verified deletion request, except records we must keep for legal or accounting reasons.
- Email analytics: only stored if you turn reporting on. The send/open/reply records are kept on your account to power your reports until you delete them ("Delete my analytics data" in Settings) or delete your account, whichever comes first. Turning reporting off stops new records being made; it does not erase the ones already there, so use Delete for that. The records of email you sent yourself from a connected mailbox (Section 4) sit alongside them and the same Delete clears them too, but the reporting switch does not govern them: disconnecting the mailbox is what stops those.
- Inbound Agent connection and history: your mailbox token and connected address are kept until you disconnect the mailbox or delete your account, after which the connection is revoked. The stored incoming excerpt and drafted reply described in Section 4 remain on your account so the approval queue and activity trail work, until you delete the associated data or your account. Status-change records are removed when you apply or dismiss them.
- Ervona Desk: the credentials you connect (mailbox, texting, and CRM) are kept until you disconnect that account or delete your account, after which they are revoked. Your campaigns and their target lists (the lead records the Desk works), the worklist state, and the handoff audit trail are kept on your account until you delete the campaign or your account. Because these hold lead personal data, deleting a campaign or your account removes them.
- Replies to outreach we did not send (Section 5): the record of what was looked at and what was decided is kept on your account so the decision is auditable, and is removed when you delete your account. Where a thread was declined that record holds no message body at all. Where a thread was taken up, the original outreach message and the reply are stored with that lead and go when the campaign or the account does.
- Security and diagnostic logs: ordinarily rotated within 30 days. A limited excerpt may be kept longer when reasonably necessary to investigate an active security incident, prevent abuse, or comply with law, and is removed when that purpose ends.
- Support email: kept while needed to resolve and document the request, then removed under our support-record schedule unless a longer period is required for a legal dispute, fraud prevention, or accounting.
- Everything in your browser (templates, history, reports, settings): under your control, removed when you uninstall the extension or clear its storage. If you turn on optional cloud sync, the copy of your run history and reports on your account is kept until you turn sync off or delete your account.
13. Your rights
Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to:
- Access the personal data we hold about you, and get a copy in a portable format.
- Correct inaccurate data, or delete your data (the "right to be forgotten").
- Object to or restrict certain processing, and withdraw consent where processing is consent-based.
- Not be discriminated against for exercising any of these rights.
- Complain to your data-protection authority (EU/UK) or your state attorney general (US).
You can erase everything yourself at any time: Account → Delete my account & data permanently wipes your profile, settings, CRM maps, all analytics and inbound-agent history, your Desk campaigns and their target lists, and revokes the connected mailbox, texting, and CRM credentials — no request needed. To exercise any other right, email privacy [at] ervona.ai from your account email, which is how we verify it is you. We respond within the time required by law (30 days for GDPR requests, 45 for CCPA). California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA, so there is nothing to opt out of. See Your privacy choices.
Prospects and other people whose data a customer submitted. The Ervona customer who contacted you is ordinarily the controller of that data. Direct your request to that organization first. If you contact us, tell us which Ervona customer contacted you; we will forward the request or assist that customer as required by our Data Processing Addendum.
U.S. state disclosures. In the preceding 12 months we may have collected the identifiers, account and billing information, internet or device activity, professional information, communications, approximate location derived from IP address, and inferences described in Sections 2–7. We collect them from you, your browser or connected accounts, the customer that submitted a lead, and the service providers listed in Section 10; we use and disclose them for the business purposes in Section 8. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or offer financial incentives for personal information.
Business customers (DPA). If you connect a CRM or mailbox on behalf of an organization, our Data Processing Addendum binds Ervona as your processor, lists our subprocessors and security measures, and states our retention and deletion practices. It forms part of our Terms of Service wherever applicable.
14. Security
- All traffic to our services is encrypted in transit (TLS 1.2 or newer).
- Encryption at rest. Everything stored on our servers is encrypted at rest with AES-256. That includes the personal data your reports and metrics contain, such as recipient email addresses, names, and phone numbers, along with campaign lead lists, message records, and settings. Encryption keys are managed by our infrastructure provider, and this disk-level encryption sits underneath the row-level security described below, which is what stops one account reading another's rows.
- Passwords are hashed by our authentication provider. We never handle them in plaintext.
- Database access is protected by row-level security, so your records are readable only by your authenticated session.
- Connected-account credentials (mailbox, texting, and CRM) are stored write-only, encrypted at rest (AES-256-GCM, key held outside the database), and are read only inside our server-side functions, never returned to the browser or the extension.
- Secret keys live only in server-side environments, never in the extension or website code.
- Least-privilege access: the extension requests only the browser permissions it needs to work your CRM tab. Access to Gmail and Outlook on the web is not part of that: it is a separate, optional permission, asked for one mail service at a time only when you switch that feature on, and revocable at any time.
No system is perfectly secure. When you use the extension, keeping your lead and customer records on your device removes a large risk class: we cannot leak what we never had. When you turn on the Desk, you are choosing to have us process those records on our servers so it can run unattended; we protect that data with the controls above and row-level security so it is not accessible to other customers. Authorized systems and personnel may access it only as necessary to operate, secure, or support the Service. If we ever become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
15. Children
Ervona is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, email privacy [at] ervona.ai and we will delete it.
16. Changes to this policy
We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above and, where the change meaningfully affects your rights, communicated to you by email before it takes effect.