← Back to site
Legal

Privacy Policy

Last updated: August 21, 2026

Ervona has two ways of working, and they handle data differently. The short version: the browser extension runs the outreach agent in your own browser, so your CRM and lead data stay on your device. The Ervona Desk is the opposite by design: it is an optional, paid autopilot that runs on our servers with no browser open, so when you turn it on it necessarily processes your CRM records, leads, and outreach on our side. To run any account we also hold your email, your subscription status, a device identifier, and the settings and business profile you save. This page explains all of it in plain language.

At a glance

1. Who we are

Ervona LLC ("Ervona", "we", "us") is the data controller for the personal information described in this policy. Our mailing address is 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA. Ervona provides: the Ervona SDR browser extension, which automates outbound outreach inside your CRM in your browser; the Ervona Desk, an optional server-side autopilot that works a list of leads unattended; the optional Inbound Agent, which answers email in a mailbox you connect; the ervona.ai website; and the Ervona mobile app, which is another window onto the same account — it reads and controls the same Desk and settings through the same authenticated APIs and creates no separate data. This policy covers all of them. For anything privacy-related, or general help, email privacy [at] ervona.ai.

2. Data you give us

3. Data the extension creates and syncs

This section is about the browser extension. Its outreach agent works your CRM in your own browser session, so most of what follows is about configuration and history rather than your leads. Two items are different and are spelled out below: email analytics, and the optional access to Gmail and Outlook on the web that the extension needs before it can track email you type there.

Where the open pixel goes, and where it cannot. Counting an open means putting an invisible 1x1 image in the message before it is sent, so it can only happen where something of ours is in the compose window at that moment:

Wherever opens are counted, they over-count, because some email apps and security scanners load images automatically. Replies are the reliable signal.

4. The optional Inbound Agent (a connected mailbox)

The Inbound Agent is a paid feature that is off until you connect a mailbox and enable it. Because it answers email for you, it necessarily processes that email on our servers. Here is exactly what happens. One item below is different and is marked as such: the record of the email you send from that mailbox begins as soon as the mailbox is connected, not when the agent is enabled.

We do not use your data to train AI models, and our AI provider processes it only to return the output we request.

5. The Ervona Desk (the server-side autopilot)

The Ervona Desk is a paid feature that is off until you set it up and turn it on. Unlike the extension, the Desk is designed to run on our servers, unattended: no browser is open and no one is at the keyboard, so a scheduled worker on our infrastructure does the work. That means the Desk necessarily processes your leads and CRM records on our side. This is the one part of Ervona where lead data is held on our servers rather than staying on your device. Here is exactly what it holds and does:

You direct and configure the Desk, and you decide draft-only versus automatic-send behavior. Everything the Desk stores about a campaign is protected by row-level security so it is not accessible to other customers, is never sold, is disclosed only to the service providers needed to operate the Service (and to the anonymized, aggregate benchmark above if you opt into it), and is removed when you delete the campaign or your account (see Section 12).

6. Data we do not collect

The browser extension works your CRM in your own browser session. When you use the extension, your lead and customer records and the contents of the CRM are processed on your device and are not transmitted to our servers. By default your run history and reports stay on your device too. The exceptions are the optional features listed below — email analytics is on by default and the rest are off until you turn them on:

Limited diagnostic telemetry (Section 7) reports only that an automated step failed, never the record it was working on. Analytics, cloud sync, the Inbound Agent, and the Desk can all be turned off and their data deleted in Settings.

7. Data collected automatically

Our website and server endpoints log basic technical information (such as IP address, browser type, and timestamps) for security, rate-limiting, and keeping the service running. We keep this to a minimum, do not use it to build advertising profiles, and do not enrich it with third-party data. See our Cookie Policy for the short list of cookies and local storage we use.

Bot protection at sign-in. The sign-in and sign-up forms run Cloudflare Turnstile, a bot-detection check. Turnstile evaluates technical signals from your browser to tell people from automated scripts and returns a pass token; it does not profile you for advertising and cannot follow you across other sites.

Extension diagnostics. Because the outbound agent works inside your live CRM, a CRM update or an unusual org layout can occasionally break one of its automated steps. To detect and fix that, the extension sends us a small, best-effort diagnostic event when a step fails — for example, that the email composer or the Send button could not be found. Each event contains only the structural failure (a short error label and the record type, such as “lead” or “opportunity”), the CRM host it occurred on, and the extension version. It never includes a recipient’s name or email, the contents of any record, or anything you typed. We use it solely to keep the extension working.

8. How we use data

We do not use your data to train AI models, and we do not sell or rent personal data to anyone.

9. Legal bases (GDPR)

Where the GDPR applies, we process personal data on these bases:

When you use the Inbound Agent or the Desk, some of the personal data processed is about third parties (the people who write to you, or the leads on your list). For that data you are the controller and Ervona is your processor: you determine the purpose, and you are responsible for the lawful basis to process those records and for giving any notice the law requires. Our Data Processing Addendum governs that relationship.

10. Service providers (subprocessors)

We share the limited data above only with providers that help us run the service:

CRMs you connect (Salesforce, HubSpot). When you connect a CRM to the Desk, we store your credentials and our server reads and writes your records through that CRM's API on your behalf. Salesforce and HubSpot are your own systems and their own controllers; your use of them stays subject to your agreement with them. We name them here so you know where the Desk reads and writes.

These providers process data under contracts and security commitments appropriate to their role. If we add a subprocessor that touches personal data, we will update this list before it goes live and provide any notice required by our Data Processing Addendum.

11. International transfers

Ervona is based in the United States, and our providers may process data in the United States and other countries where privacy laws may differ from those where you live. Where the GDPR or UK GDPR requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses and, for UK transfers, the UK Addendum, together with any supplementary measures appropriate to the transfer. Our Data Processing Addendum explains the applicable modules and how to request a copy of the safeguards.

12. Data retention

13. Your rights

Depending on where you live (including under the GDPR and the CCPA/CPRA), you may have the right to:

You can erase everything yourself at any time: Account → Delete my account & data permanently wipes your profile, settings, CRM maps, all analytics and inbound-agent history, your Desk campaigns and their target lists, and revokes the connected mailbox, texting, and CRM credentials — no request needed. To exercise any other right, email privacy [at] ervona.ai from your account email, which is how we verify it is you. We respond within the time required by law (30 days for GDPR requests, 45 for CCPA). California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA, so there is nothing to opt out of. See Your privacy choices.

Prospects and other people whose data a customer submitted. The Ervona customer who contacted you is ordinarily the controller of that data. Direct your request to that organization first. If you contact us, tell us which Ervona customer contacted you; we will forward the request or assist that customer as required by our Data Processing Addendum.

U.S. state disclosures. In the preceding 12 months we may have collected the identifiers, account and billing information, internet or device activity, professional information, communications, approximate location derived from IP address, and inferences described in Sections 2–7. We collect them from you, your browser or connected accounts, the customer that submitted a lead, and the service providers listed in Section 10; we use and disclose them for the business purposes in Section 8. We do not sell personal information, share it for cross-context behavioral advertising, use it for targeted advertising, or offer financial incentives for personal information.

Business customers (DPA). If you connect a CRM or mailbox on behalf of an organization, our Data Processing Addendum binds Ervona as your processor, lists our subprocessors and security measures, and states our retention and deletion practices. It forms part of our Terms of Service wherever applicable.

14. Security

No system is perfectly secure. When you use the extension, keeping your lead and customer records on your device removes a large risk class: we cannot leak what we never had. When you turn on the Desk, you are choosing to have us process those records on our servers so it can run unattended; we protect that data with the controls above and row-level security so it is not accessible to other customers. Authorized systems and personnel may access it only as necessary to operate, secure, or support the Service. If we ever become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.

15. Children

Ervona is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children. If you believe a child has provided us data, email privacy [at] ervona.ai and we will delete it.

16. Changes to this policy

We may update this policy as the product evolves. Material changes will be reflected by the "Last updated" date above and, where the change meaningfully affects your rights, communicated to you by email before it takes effect.

17. Contact

✉ privacy [at] ervona.ai