Privacy Policy

This policy explains how Navior handles account, workspace, Gmail, Google Calendar, and other service data.

Last updated September 12, 2026

1. Scope

Navior is a workspace automation service operated by Recerc Inc. This Privacy Policy applies to Navior's website, authenticated workspaces, APIs, agents, integrations, and related support services.

2. Data we collect and access

  • Account and workspace data, including name, email address, user and workspace identifiers, authentication state, role, permissions, and security records.
  • Usage and diagnostic data, including activity logs, device and browser metadata, IP address, locale, errors, performance data, and security events.
  • Workspace content that an authorized user submits or connects, such as records, messages, files, prompts, documents, workflow inputs, and generated outputs.
  • Google account profile data needed to identify a connected account, including the Google account identifier, email address, and display name.
  • OAuth grant metadata, including authorized scopes, encrypted access and refresh tokens, token expiry, connection status, and synchronization checkpoints.
  • Gmail message and thread data returned for the connected account's Inbox and Sent mail, including participants, headers, subject, body, labels, timestamps, identifiers, snippets, and related message metadata. The current initial synchronization is limited to the previous year and conversations with an external participant.
  • Google Calendar event data that an authorized user or agent requests Navior to list or create, including calendar identifiers, dates, attendees, descriptions, conferencing details, and delivery preferences supplied for that action.

3. How we use data

  • Authenticate users, enforce workspace permissions, and protect connected accounts.
  • Connect a Google account to the workspace selected by the authorizing user.
  • Synchronize permitted Gmail conversations into a private workspace inbox and preserve message and thread context.
  • Compose and send email only when an authorized user or agent initiates the action. If the user enables open tracking for a sent HTML message, Navior adds a tracking pixel and records the resulting open event.
  • List or create Google Calendar events only when an authorized workspace workflow requests the action.
  • Operate requested automations and agent workflows, troubleshoot provider errors, prevent abuse, and improve service reliability.

4. Sharing and AI processing

Navior shares data only with authorized members of the relevant workspace and service providers needed to operate the requested feature, such as hosting, storage, observability, email, and configured AI providers. Google user data is not sold, used for advertising, transferred to advertising platforms, or used to train generalized AI models. Human access is limited to support, security, legal compliance, or a user's explicit request for assistance.

Our AI processing policy requires Zero Data Retention (ZDR) for prompts and responses sent to eligible models through OpenAI, Anthropic (Claude), Cloudflare AI, or Vercel AI Gateway. Each enabled route must have the applicable ZDR terms and settings verified for both the gateway and the underlying model provider; using a provider or gateway alone does not establish ZDR. These inputs and outputs must not be used to train generalized AI models.

AI processing is limited to the data necessary for the AI feature that an authorized user enables or requests. Enabling a Google integration does not by itself authorize unrelated AI processing. Our policy requires gateway and provider logging to exclude prompt and response content; any separately retained operational metadata must have a documented purpose and retention period. ZDR at an AI provider does not delete workspace records, conversation history, or outputs that Navior stores to provide the requested feature; those records remain subject to the retention and deletion terms below.

5. Security

  • OAuth access and refresh tokens are encrypted at rest and transmitted only over encrypted connections.
  • Workspace and provider-channel permissions limit which authenticated users can access a connected account and its synchronized messages.
  • Access, send, synchronization, and administrative operations are subject to authentication, authorization, validation, and operational logging.

6. Retention, disconnection, and deletion

Navior retains workspace and integration data while the service is active or as needed for security, support, contractual, accounting, and legal obligations. Gmail is synchronized incrementally while the account remains connected. Disconnecting a Gmail account revokes the Google OAuth grant and deletes its locally stored account, label, synchronization, and message records. Calendar events are accessed on demand by the integration and are not copied into the Gmail synchronization store.

7. Your choices and rights

Users may disconnect Google from Navior at any time from workspace integration settings and may also revoke Navior in their Google Account permissions. Requests to access, correct, export, or delete personal data can be sent to legal@recerc.com. We may verify identity and retain records that applicable law requires us to preserve.

8. Google API Services User Data Policy

Navior's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements. Navior requests only the Google scopes used by the connected Gmail and Calendar features described above.

9. Contact

Questions about this policy or Navior's handling of Google user data can be sent to legal@recerc.com.