Korvo Technologies LLC

Privacy Policy

Effective July 5, 2026 · Last updated September 14, 2026

Information we collect

Korvo may collect business contact information, account information, workspace records, customer intake details, appointment and job details, communications metadata, and files that authorized users add to their private workspaces.

How we use information

We use information to operate Korvo workspaces, route customer requests, coordinate appointments and jobs, support business communications, maintain audit records, improve reliability, and respond to support or vendor verification requests.

Communications

Korvo may process email, SMS, phone, and web-form data when a business uses Korvo to communicate with customers or internal team members. These workflows are intended for legitimate operational messages such as quote follow-up, scheduling, reminders, service updates, support, and account verification.

Google user data: access and use

When an authorized user connects a Google account, Korvo uses the approved Google access only to provide the workspace features the user turns on. Depending on the connected workflow, Korvo may access Google account profile information, Gmail messages and attachments, Gmail send capability, Google Forms structure and responses, Google Sheets rows, and Google Drive file metadata. Korvo uses this data to sync business mailbox threads, display communication history, send authorized email, route intake forms, read connected reporting sheets, and let users select or identify files for workspace workflows.

Google user data: sharing, transfer, and disclosure

Korvo shares, transfers, or discloses information received from Google APIs with the following recipients for the connected workspace features:

  • The connected business and its authorized users: workspace owners, administrators, and team members with the required permissions can view synced messages, attachments, form responses, sheet-derived records, and file metadata relevant to their workspace access. Korvo staff access is limited as described under Sensitive data protection mechanisms below.
  • Google and intended message recipients: Korvo sends account authorization information and API requests to Google to maintain the connection and read or send data. When an authorized email is sent, its content and recipient addresses are transferred to the selected email delivery provider, such as Gmail or Resend, and delivered to the intended recipients.
  • Infrastructure providers: Korvo's application hosting provider, Vercel, and the database and storage providers used by Korvo process Google account connection information and synced workspace records to run and store the connected features.
  • AI processing providers: where AI email summaries are configured, OpenAI or Anthropic receives the mailbox address, sender information, subject, and message preview needed to generate the summary. This processing supports the user-facing email summary feature; it is not used to develop, improve, or train generalized AI or machine learning models.
  • Notification delivery providers: where enabled, browser or device push services and business messaging providers process notification content, such as an email subject or preview, to alert authorized workspace users about incoming messages or related work.

Google API limited use

Korvo's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements. Korvo does not sell Google user data, does not use Google user data for advertising, and does not use Google Workspace API data to develop, improve, or train generalized artificial intelligence or machine learning models. Google user data is used only to provide or improve the user-facing Korvo features that the authorized user requested.

Sensitive data protection mechanisms

Korvo protects sensitive Google user data and other sensitive account, mailbox, customer, payment, and workspace data with HTTPS/TLS transport, encrypted OAuth tokens and provider secrets at rest, authenticated access, role-based permissions, tenant-scoped workspace access, least-privilege provider scopes where available, audit records for operational actions, production access controls, limited staff access, and infrastructure vendors used only to operate, secure, monitor, and support Korvo. Google OAuth tokens are not exposed to customers or public pages, and staff access to connected Google data is limited to support, security, and operational troubleshooting for the authorized workspace.

Google user data retention and deletion

Korvo retains Google OAuth tokens only while a Google integration remains connected or while a limited operational retry window is needed to safely disconnect the integration. Synced Google user data, such as mailbox records, message history, form responses, sheet-derived records, and Drive metadata, is retained only as long as needed to provide the connected workspace feature, preserve business communication history requested by the business owner, troubleshoot delivery, meet legal or security obligations, or honor the business owner's configured retention settings. Users may disconnect Google integrations, request export, correction, or deletion review from the app, or contact admin@korvohq.com. When a deletion request is approved, Korvo revokes or removes applicable Google tokens where available and deletes or de-identifies applicable synced Google user data from active systems unless retention is required for legal, security, billing, fraud-prevention, or active customer-service obligations. Backup copies age out under Korvo's standard backup retention cycles.

SMS consent and opt-out

When a visitor provides a phone number and agrees to receive calls or texts, Korvo or the operating business may use that number for the requested business purpose. Message and data rates may apply. Reply STOP to opt out or HELP for help. Mobile opt-in data and consent are not sold or shared with third parties for their marketing.

Access controls

Private Korvo workspaces require authentication. Role-based access limits what each user can view or manage. Public website pages do not expose private customer records, internal assistant controls, or operational data.

Service providers

Korvo may use trusted vendors for hosting, email delivery, messaging, payments, maps, analytics, storage, or other infrastructure needed to provide the service.

Contact

Questions about privacy or business verification can be sent to admin@korvohq.com.