Terms of Service
Last updated: August 21, 2026
These Terms of Service ("Terms") are a binding agreement between you (or the organization you represent) ("Client", "you") and Ervona LLC, a limited liability company with a mailing address at 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA ("Ervona", "we", "us") governing your access to and use of the Ervona software, browser extension, the Ervona Desk, website, dashboards, reports, and related services (together, the "Service"). By creating an account, installing the extension, or using the Service, you agree to these Terms. If you are agreeing on behalf of a company, you represent that you have authority to bind it.
1. The service & how it operates
Ervona has two ways of working, and they operate differently.
- The browser extension (client-side). Ervona SDR is a Chrome extension that automates outbound sales work inside your own CRM session in your browser — composing and sending email through your CRM's composer, sending SMS through your connected provider, logging notes, and updating record status. This core outreach runs client-side: your CRM records are read and written on screen, in your session, and are not copied to our servers to perform outreach. The extension can additionally track email you write in Gmail or Outlook on the web. That is a separate, optional browser permission which is not requested at install, is asked for one mail service at a time only when you switch the feature on, and can be withdrawn at any time; while it is on, the extension reads the recipient and subject of a message you are sending in order to record the send, and never the body of your mail or anything else in your mailbox.
- The Ervona Desk (server-side). The Desk is an optional, paid autopilot that runs on our servers, unattended, with no browser open. When you enable it, you connect the accounts it needs (a mailbox, a texting number, and your CRM), and the Desk selects leads by prospecting your CRM, sends outreach, watches for replies, references and writes back to your CRM records, and hands leads to a human rep. Because the Desk runs without a browser, it necessarily processes your CRM records, leads, and outreach on our servers. Section 8 describes it and the credential handling in detail.
The Ervona mobile app is another window onto the same account: it reads and controls the same Desk and the same settings through the same authenticated APIs, and creates no separate data or separate obligations — everything in these Terms applies equally when you act through the app.
Certain other optional features also process limited data on our servers: (a) the AI "analyze & fill" that drafts your business profile; (b) email open/reply reporting, which is on by default and stores the recipient's email address and subject line to build your reports, until you turn it off; (c) the optional Inbound Agent, part of Ervona Desk, which, if and when you connect a mailbox and enable it, processes the email it answers; and (d) the record of the email you send yourself from a mailbox you connect, described in Section 7. The agents are tools you direct and configure; you, not Ervona, are the sender of record for your messages.
Open tracking. An open can only be counted by placing an invisible image in a message before it is sent, so the Service does that only where it is in the compose step: email the extension sends, email you write in the Salesforce console, and, if you grant the separate optional permission for it, email you write in Gmail or Outlook on the web. "Count opens" is on by default for each Ervona Desk campaign and can be switched off per campaign; while it is off, that campaign sends plain text with no tracking pixel. Email you send from your own mail application is never given one, because nothing can add to a message after it has left. Open counts run high wherever they are collected, since some mail clients and security systems load images automatically, and Ervona does not warrant their accuracy.
2. Definitions & platform role
- "Client Data" means any information you input into, connect to, or make available through the Service, and any information the Service reads from your CRM or connected accounts on your behalf — including personal information such as names, business email addresses, telephone numbers, company names, and message content ("PII") — together with the inputs you provide and the report outputs the Service generates for you.
- Roles. As between the parties, the Client is the Data Controller (or "business" under U.S. state privacy laws) and determines the purposes and means of processing Client Data. To the extent Ervona processes Client Data containing personal information on its servers on your behalf — including when you enable the Ervona Desk or the Inbound Agent — Ervona acts as your Data Processor (or "service provider"/"sub-processor") and processes it only on your documented instructions to provide the Service. Where you use only the extension, much of your CRM data is never received by Ervona at all; where you enable the Desk, your leads and CRM records are processed on our servers as described in Section 8.
- Data Processing Addendum. To the extent Ervona processes Client Data as your processor or service provider, our Data Processing Addendum (DPA) is incorporated into and forms part of these Terms automatically. It is particularly relevant if you enable the Desk, which processes your leads on our servers. Where it conflicts with these Terms on data protection, the DPA controls.
3. Client data, ownership, privacy & intellectual property
- Your data stays yours. You retain 100% ownership of all Client Data, including CRM data, your inputs, and the report outputs the Service generates for you. We claim no ownership of them. We grant you the right to use the report outputs for your business purposes.
- Zero-training guarantee. We will not use, store, sell, or share your Client Data or PII to train, fine-tune, or otherwise improve our own models or any third-party models (including Anthropic's Claude). Client Data is processed only to provide the Service to you.
- Security. Data we process on your behalf is transmitted over secure, authenticated APIs, encrypted in transit (TLS 1.2 or newer), and encrypted at rest with AES-256, including the personal data in reports and metrics such as email addresses, names, and phone numbers. Credentials you connect for server-side features are stored write-only and read only inside our server-side functions. No method of transmission or storage is perfectly secure, and we do not guarantee absolute security.
- Reporting is on by default, opt-out. Email open/reply reporting stores the recipient's email address and subject line in our database to build your reports; a plain toggle turns it off (with a warning shown if you turn it back on), and you can permanently delete that data at any time from Settings.
- Our IP. Ervona and its software, models, branding, and content are owned by us and protected by law. We grant you a limited, non-exclusive, non-transferable, revocable right to use the Service while your account is in good standing. You may not copy, reverse-engineer, resell, or create derivative works from the Service except as permitted by law.
4. Acceptable use & AI use restrictions
You are responsible for the messages you send, the lists you send them to, and the actions you direct the agents to take. You agree to use the Service lawfully and, in particular, to:
- Comply with all applicable laws, including anti-spam and marketing laws (e.g., the U.S. CAN-SPAM Act and Canada's CASL) and telemarketing/text-messaging laws (e.g., the TCPA), and obtain any required consent before sending email or SMS.
- Honor opt-outs, unsubscribe requests, and do-not-contact flags promptly, and comply with the terms of your CRM, email, and SMS providers.
- Have all rights and permissions necessary to process the Client Data and to contact the recipients you load into the Service or that the Desk selects by prospecting your CRM.
- Where the law requires disclosure that a message is automated or AI-generated (e.g., bot-disclosure and consumer-protection rules), configure the agents so that you meet that obligation. The Service lets you control disclosure settings; choosing them lawfully is your responsibility.
AI-provider (Anthropic) flow-down. Because the Service uses Anthropic's Claude API, you also agree that you will not use the Service, and will not direct the AI, to: (i) generate deceptive content, including misinformation, fake news, phishing, impersonation, or deceptive business materials; (ii) make or automate high-risk decisions without qualified human review, including legal judgments, medical diagnosis or triage, or credit, lending, employment, or insurance eligibility determinations; or (iii) engage in any use prohibited by the usage policies of Anthropic and Cloudflare. You acknowledge that Anthropic may throttle, rate-limit, or restrict our access, that this may delay or interrupt reporting, the Desk, and the Inbound Agent, and that Ervona is not liable for such slowdowns. Violations may cause our upstream provider to suspend our access; we may suspend your account to prevent or stop a violation.
Text messaging (SMS) & the TCPA. If you use SMS — whether the extension texting through your connected provider, or the Desk texting from a number you connect — you are responsible for compliance with the Telephone Consumer Protection Act (TCPA), the CAN-SPAM and CASL frameworks as applicable, carrier and provider rules, and any stricter state laws, including obtaining any legally required prior consent before texting and honoring opt-outs. As a safeguard, the Service includes a quiet-hours guard that infers the recipient's time zone from the phone number's US area code and, by default, skips a text when local time is outside 8:00 AM–9:00 PM or when the time zone cannot be verified. This guard is a best-effort aid, not a guarantee: area-code inference is imprecise (e.g., because of number portability), it applies to US numbers only, and some laws are stricter than the 8–9 window. You remain solely responsible for TCPA quiet-hours compliance and consent. Opt-outs / "STOP": the extension sends SMS through your connected texting provider and does not read inbound replies, so for that path you are responsible for honoring "STOP" and other opt-out requests. The Desk sends from a texting number you connect and does receive inbound replies on that number in order to detect responses; even so, carrier-level "STOP" handling is enforced by your texting provider, and you remain responsible for suppressing opted-out and do-not-contact recipients and for honoring opt-outs promptly. The Service honors do-not-contact/opt-out flags it can read on the record, but that is not a substitute for your own monitoring.
As between you and Ervona, you direct the messages and are responsible for their content, recipients, and lawful configuration. Whether either party is treated as a statutory sender, initiator, controller, processor, or other regulated party is determined by applicable law and cannot be changed solely by these Terms.
5. AI reporting & data-export liability
The Service presents analytics in dashboard views and lets you download reports (e.g., CSV, PDF, Excel). Although reports are generated with the assistance of AI and automated processing, you are solely responsible for reviewing and verifying the accuracy, completeness, and suitability of any report before relying on it for business, financial, legal, or operational decisions. AI output can be incomplete or incorrect.
Exported copies. Once you export, download, print, or forward a report or data set, you are responsible for securing and lawfully using the copy under your control. Ervona remains responsible for its own acts and omissions and for the Service while the data remains in Ervona's systems; this provision does not waive responsibility that cannot lawfully be limited.
6. Third-party integrations & dependencies
The Service integrates with, and depends on, third parties, including external CRM platforms (for example, Salesforce and HubSpot; additional CRMs may be supported over time), third-party AI models (Anthropic's Claude and Cloudflare Workers AI), email infrastructure (Nylas for connected mailboxes; Zoho/ZeptoMail and Resend for transactional and notification email), the texting provider you connect for the Desk's SMS (for example Twilio, Telnyx, SignalWire, Plivo, Vonage, Sinch, Infobip, Sendblue, or RingCentral), and payment (Stripe) and infrastructure (Supabase, Cloudflare) providers. You are responsible for maintaining all accounts, licenses, API permissions, and rights required with your CRM and other providers, and for complying with their terms. Ervona does not control these third parties and is not liable for service interruptions, downtime, latency, API throttling or rate-limit blocks, deprecations, or breaking changes caused by them, or for any resulting loss. If a provider changes or restricts its platform, features that depend on it may be delayed, degraded, or discontinued.
7. Mailbox integration & automated communications (Inbound Agent)
This Section applies if and when you connect a commercial mailbox to the Service (through your mail provider's own sign-in, i.e. OAuth), including for the Inbound Agent, part of Ervona Desk. Mailbox connections are carried by our email-infrastructure provider, Nylas, acting as our service provider. The application you grant access to depends on your mail provider: connecting Google grants access to Nylas's application, and connecting Microsoft grants access to Ervona's own registered application. You may revoke that access at any time from your mail provider or by disconnecting the mailbox in the Service.
- License you grant. By connecting a mailbox, you grant Ervona a limited, revocable license to access, read, and analyze the messages in that mailbox, to read the connected account's calendar availability and create calendar events on it (which sends an invitation to the person you are meeting), and to draft and, where you configure it to do so, send replies on your behalf, solely to provide the feature. You may disconnect at any time, which revokes the license going forward.
- Your own outbound mail is recorded, in outline only. While a mailbox is connected, the Service records the one-to-one email you send from it yourself so that those sends have a reply rate, and it does so whether or not the Inbound Agent is enabled. What is recorded is the recipient's email address, the subject line, and the time sent. The message body is not recorded. Mail to more than one recipient, replies, forwards, no-reply addresses, and mail to any domain you have entered in your inbox settings under "Internal domains" or "Partner domains" are excluded and leave no record. The domain exclusions are matched against those configured lists, so a list you have not filled in excludes nothing; configuring them is your responsibility. Recording stops when you disconnect the mailbox, and the records are deleted with your other reporting data or on account deletion.
- You control what is sent. You are solely responsible for all email transmissions from your connected mailbox, for compliance with all applicable anti-spam and communications laws (including CAN-SPAM and CASL), for honoring opt-outs, and for ensuring the agent does not send unauthorized, unlawful, or unintended communications. You are responsible for choosing draft-only versus automatic-send modes and for any message the agent sends under a mode you enabled.
- Provider policies. Your use of connected Google and Microsoft mailboxes is also subject to those providers' API terms and limited-use requirements, as described in our Privacy Policy. Our internal personnel do not read your private email except as strictly necessary for security, debugging, or a support request you initiate.
8. The Ervona Desk & connected credentials (server-side processing)
This Section applies if and when you enable the Ervona Desk. The Desk is a paid, optional autopilot that runs on our servers, unattended. By enabling it you acknowledge and agree to the following:
- Server-side processing of your leads and CRM. To run without a browser open, the Desk processes your Client Data — including the leads it selects, the replies it receives, and the CRM records it references and updates — on our servers. This is a deliberate difference from the extension, and you instruct us to perform this processing when you turn the Desk on.
- Personas (sending identities). Ervona Desk includes two (2) personas — each an autonomous identity with its own sending mailbox and, where you enable texting, its own texting number. Personas beyond the two included require an extra-persona add-on (billed per persona) or an Enterprise plan. We enforce this on our servers, and the allowance covers email and SMS alike: creating a persona past your allowance is declined, and a persona or mailbox connected outside the normal flow does not send. Routing warm leads across a roster of different people is an Enterprise feature.
- Credentials you connect. To operate the Desk you connect accounts and we store the credentials for them: a mailbox connection (a Nylas grant), a texting-provider credential and number, and your CRM credentials — a HubSpot Private App token, or your Salesforce sign-in (username, password, and login URL) or a linked Connected App. You represent that you are authorized to connect these accounts and to grant Ervona access to act through them on your behalf. Credentials are stored write-only and read only inside our secured server-side functions; you may disconnect any of them at any time, which revokes access going forward.
- Prospecting. When you build a prospecting filter, the Desk queries your connected CRM to select matching people and stores the resulting target list on your account. You are responsible for having the rights and permissions to contact the people the filter selects and to process their records.
- Writeback and record changes. The Desk can leave notes, log activity, set a lead status, flag do-not-contact, reassign record ownership, and create records in your CRM — for people on a list you import, and for a warm handoff whose prospect has no record yet. You direct these actions by your configuration, and you are responsible for reviewing and, where needed, correcting them. See Section 9 on backups.
- Your own data-vendor accounts (optional). You may connect your own account with a third-party data vendor — for example Apollo, People Data Labs, or Hunter for finding and enriching leads, or ZeroBounce, NeverBounce, or Bouncer for verifying email addresses — by saving that vendor's API key with us. The key is stored write-only and read only inside our server-side functions, and is used solely to run the searches, enrichments, and verifications you request. Data obtained this way is supplied to you under your own contract with that vendor, at your own rates: Ervona does not resell contact data, takes no margin on it, and is not a party to your vendor agreement. You are responsible for complying with your vendor's terms and for having the right to process and contact the people whose records you import. Separately, before a first send the Service may check that a recipient address can receive mail at all, using public DNS lookups and, where a verification key is configured, a verification provider.
- Answering replies to outreach the Desk did not send (optional, off by default). A reply can arrive in a Desk mailbox that answers a message a different system sent — a marketing-automation sequence, another vendor's AI agent, or an email one of your people typed by hand. Switching this on for a persona instructs us to read that thread in the connected mailbox in order to draft an answer to it, including the original outreach message, which may have been sent from that mailbox before you connected it to us. The Service confines itself to a one-to-one thread the Desk mailbox itself started, with a counterparty outside your own company domains and outside the partner domains you configure, that nobody has already answered; those domain lists are yours to maintain and a list you have not filled in excludes nothing. Every reply on such a thread is held for your approval before it is sent. You represent that you are entitled to have us process the correspondence in that mailbox for this purpose, and you remain the sender of record for anything sent as a result.
- You remain the sender and controller. You, not Ervona, are the sender of record for the Desk's messages and the controller of the leads it processes, and you are responsible for their content and for your compliance, including choosing draft-only versus automatic-send behavior.
9. Human oversight & data backup (your responsibilities)
- Human-in-the-loop. The Service is an assistant, not a replacement for human judgment or oversight. You are responsible for supervising the agents and for reviewing their actions, data updates, and drafted messages before you rely on or finalize them. You decide which actions the agents may take and remain responsible for those actions.
- Backups. You are responsible for maintaining independent, current backups of your CRM and other data. Ervona is not responsible for backing up your data or for restoring CRM records that are corrupted, altered, or deleted, whether by the Service, by the Desk, by your configuration, by the AI, by your CRM, or by a third party.
10. Eligibility & accounts
- You must be at least 16 and able to enter into a contract, and you are responsible for your credentials and for all activity under your account.
- Seats. Unless your order or plan page states otherwise, each subscription includes one active device for the browser extension. Running the extension on additional devices may require Enterprise or additional seats. We enforce seat limits with a device identifier, and concurrent use beyond your plan's allowance may be blocked or require an upgrade. Seat limits apply to the browser extension only; the Desk runs on our servers and does not consume a device seat.
- One CRM organization per account. Every plan (including Free and Ervona Desk) connects a single CRM organization at a time. You may switch your account to a different organization; switching permanently deletes the saved CRM mapping for the previous organization.
- You must have the right to use the CRM, email, and messaging accounts you connect, and to process the messages in any mailbox you connect.
11. Plans, billing & cancellation
- Free plan. Available at no cost, subject to usage limits (currently 50 emails/day). We may adjust free-plan limits over time.
- Ervona Desk trial. New Desk subscriptions may start with a 7-day free trial through Stripe checkout. A valid payment method is required to start the trial, and the plan you selected (monthly or annual) begins automatically, and your card is charged, when the trial ends unless you cancel before then. You can cancel at any time during the trial from Account → Manage plan (the Stripe billing portal) and you will not be charged. During the trial, the Desk is the full product with one guard: sending is capped (currently 50 emails/day) and texting begins when the paid subscription starts; subscribing lifts the cap. One trial per customer; we may decline a trial where one has already been used for the same person or organization.
- Paid plans. Solo, Growth and Ervona Desk are billed in advance through Stripe (monthly or annually as selected), as are existing Growth subscriptions. Prices are shown at checkout and exclude applicable taxes. The Desk and texting are paid features gated to the applicable plan tiers.
- Add-ons. Extra personas beyond the two included with Ervona Desk are billed per persona, on the same billing period as your subscription, and can be added or removed from the billing portal. Adding a persona is prorated for the current period and charged immediately; removing one is prorated as a credit toward your next invoice, and that persona stops sending once you are back within your included allowance.
- Renewal, management & cancellation. Subscriptions renew automatically until canceled. You can manage your plan, update your card, download invoices, and cancel at any time from Account → Manage plan (the Stripe billing portal); on cancellation you keep paid features until the end of the current period, then revert to free.
- Refunds. Except where required by law and except as provided by the 30-day warm-handoff guarantee below, payments are non-refundable.
- 30-day warm-handoff guarantee (Ervona Desk). If, during the thirty (30) days after your first campaign begins sending (the "guarantee window"), the Desk records zero warm handoffs, we will refund your first month's subscription fee — we check for this ourselves when the window closes, and you can always also request it at support@ervona.ai. "First month's subscription fee" means your first monthly payment for the Desk plan, or one-twelfth (1/12) of the plan portion of your first annual payment if you are billed annually; the refund goes to your original payment method. The window is measured from the start time the Desk records server-side for your earliest campaign; time you spend on setup before your first campaign does not count against it, and the window does not open until a campaign begins, so the guarantee does not apply to an account that never starts one. A "warm handoff" is a handoff event the Desk records with a traction signal — a real prospect reply the Desk routed to a human — as shown live in your portal's Handoffs tab. Verification is performed against those same server-side records, which are written by the Desk and cannot be created, edited, or backdated by any user; we verify using aggregate counts and dates only and do not access the content of your conversations or records to assess a claim. The guarantee applies once per customer, requires that the Desk sent at least one hundred (100) emails during the window and that each mailbox the Desk sent from remained connected for the rest of the window (so the Desk could see the replies those sends produced), and does not apply where sending was suspended for a violation of these Terms. It covers the subscription fee only (not add-ons such as extra personas, which share the invoice but are excluded line by line) and does not apply to comped or free accounts.
- Changes. We may change plan features or pricing with reasonable notice; changes take effect on your next billing cycle.
12. Disclaimers
The Service is provided "as is" and "as available," without warranties of any kind, express or implied, including merchantability, fitness for a particular purpose, non-infringement, and any warranty as to accuracy, availability, deliverability, responses, or results. Because the Service operates within your CRM and depends on third-party providers, its behavior can be affected by changes to your CRM, your configuration, or those providers. AI-generated content may be inaccurate; you are responsible for verifying it.
13. Limitation of liability
To the fullest extent permitted by law, Ervona and its suppliers will not be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, or for any lost profits or revenue, lost or corrupted data or CRM records, lost or missed sales opportunities, deletion or alteration of records by the Service or the AI, or loss of goodwill, whether in contract, tort, or otherwise, even if advised of the possibility. Except for liability that cannot lawfully be limited, Ervona's total aggregate liability for all claims relating to the Service will not exceed the total amounts you paid Ervona for the Service in the twelve (12) months immediately before the event giving rise to the claim. Nothing in these Terms excludes liability for fraud, willful misconduct, or gross negligence, or limits either party's obligations under the DPA to the extent such a limitation is prohibited by applicable law. Some jurisdictions do not allow certain limitations, so parts of this Section may not apply to you.
14. Indemnification
You agree to defend, indemnify, and hold harmless Ervona and its officers, employees, and agents from third-party claims, damages, losses, and reasonable legal fees to the extent arising from: (a) Client Data, recipients, or lists you supplied without the necessary rights; (b) messages or automated actions you unlawfully configured or directed; or (c) your material violation of these Terms, applicable communications or privacy law, or a third party's rights. This indemnity does not apply to the extent a claim was caused by Ervona's breach of these Terms or the DPA, negligence, willful misconduct, or unlawful processing.
15. Suspension & termination
You may stop using the Service at any time. We may suspend or terminate access if you violate these Terms, create legal or security risk, or if required by a provider we depend on. On termination, your license ends; you may export or delete your data as described in our Privacy Policy, and the sections that by their nature should survive (including data ownership, disclaimers, limitation of liability, and indemnification) survive.
16. Governing law & disputes
These Terms are governed by the laws of the State of Florida, without regard to conflict-of-laws rules, and the state and federal courts located in Florida have exclusive venue, except where mandatory local law provides otherwise.
17. Changes to these terms
We may update these Terms as the Service or law changes. The "Last updated" date reflects any change. We will give account holders advance email or in-product notice of material changes, unless a change must take effect sooner for security or legal reasons. Changes do not retroactively reduce rights or increase charges for a billing period already paid. Continuing to use the Service after the stated effective date means you accept the revised Terms.
18. Contact
Ervona LLC
7901 4th St N, STE 300
St. Petersburg, FL 33702, USA
19. General
Neither party is liable for delay caused by events beyond its reasonable control, except for payment obligations. You may not assign these Terms without our written consent, except as part of a merger, reorganization, or sale of substantially all relevant assets; Ervona may assign them as part of such a transaction. If any provision is unenforceable, it will be limited to the minimum extent necessary and the remainder will stay in effect. A failure to enforce a provision is not a waiver. Notices to Ervona must be sent to the legal contact above; we may send notices to the email address on your account. These Terms, the Privacy Policy, the DPA where applicable, and any order form are the entire agreement concerning the Service. An order form controls on commercial terms, the DPA controls on data processing, and these Terms control otherwise.