Privacy Policy
Last updated: July 27, 2026
colevo is one chat screen. You connect the apps your business already runs on, you ask a question, and colevo reads those apps at that moment to answer you with real names and real figures. It writes replies in your voice, and it sends one only after you type send it. This Privacy Policy explains what information we collect, why we collect it, who we share it with, how long we keep it, and the choices you have. It applies to colevo.io and the colevo app (together, the “Service”). If you have any questions or want to make a request about your data, email brian@colevo.io.
What we collect
- Account & identity: your email address and a password, handled by our authentication provider (Supabase). We never see or store your password. If you sign in with Google, we receive your name, email, and profile basics.
- What colevo learns about your business: a short memory file in plain words: your business name, how you work, what you charge, who your regulars are. It is written from your own answers and from what colevo read while answering you, and you can read the whole of it in Settings.
- Connected accounts (only what you choose to connect): connections are made and held by Composio, our connection provider, so the access token for your Gmail or your books is stored on their side and never in your browser. We keep only the id of the grant, so we can use it and so disconnecting can revoke it. Every one of these is read-only, with a single exception named at the end.
- Your email, Gmail, Outlook: we read recent conversations at the moment you ask, so colevo can tell you who is waiting on you and write a reply in your voice. For Gmail we request read (gmail.readonly), write-a-draft (gmail.compose) and send (gmail.send). We never ask for gmail.modify, which would let us relabel or archive your mailbox, and we never delete your mail.
- Your books, QuickBooks, Xero, FreshBooks: we read invoices, payments and customers to answer money questions with real figures. We never create, edit or delete anything in your books.
- Money coming in, Stripe, PayPal, Square: we read payments and invoices so colevo can say what has landed and what has not. Each is reported on its own and never merged with another, because the same job in two systems is not two payments. Read-only.
- Your calendar, Google Calendar, Outlook Calendar, Calendly: we read the day’s events to answer questions about your time. Read-only.
- Your files, Google Drive, Docs, Sheets, OneDrive: we read documents you point us to, such as a price list or a job log, so colevo can answer from them. Read-only; we never edit or delete a file.
- Your customer records, HubSpot, Salesforce: we read contacts and deals so colevo can answer about a customer by name. Read-only.
- The one exception: colevo sends an email reply from your connected Gmail, and only after you have read the exact reply on screen and typed send it. One reply, the one you were shown, nothing else.
- Payment information: if you subscribe on the website, your card is collected and processed by Stripe and we never receive or store your full card number. If you subscribe inside the iPhone app, Apple takes the payment and tells us only that the subscription started, renewed or ended. We never see your card, and Apple never tells us who paid beyond your own account id.
- Usage & technical data: basic logs, security and rate-limit records, and AI-usage counts (how much processing your account uses) needed to run, secure, and meter the Service.
- Cookies: we use only the cookies needed to keep you signed in and secure. We do not use advertising or cross-site tracking cookies.
How we use it
- To answer the question you just asked, reading your connected apps at that moment, naming where every figure came from, and writing a reply in your voice when one is needed.
- To send that reply, once you have typed send it, and never before.
- To operate, secure, and improve the Service, prevent abuse, and provide support.
- To process payments and send you essential account email (sign-in, receipts, important notices).
Nothing runs in the background. colevo reads your apps when you ask a question and at the moment you connect an app, to check the connection works. It does not watch your inbox, and there is no schedule on which it reads you. The one exception holds no content: a daily check of which trial accounts have gone unused, which looks at dates and nothing else.
We do not sell your personal information, and we never use your data, including your connected-account data, for advertising or to train AI models.
Google user data
colevo’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The rest of this section describes exactly how we access, use, store, share, and delete Google user data.
What we access
We request only the Google scopes needed for the apps you choose to connect: read Gmail (gmail.readonly), write a draft (gmail.compose), send that draft once you have typed send it (gmail.send), read Calendar (calendar.readonly), and read Drive, Docs and Sheets (drive.readonly). We do not request gmail.modify, and we do not request write access to your documents or spreadsheets.
How we use it
We use Google user data only to provide and improve the user-facing features you ask for inside colevo, reading your email to answer the question you asked, drafting a reply, answering from your calendar and your documents, and sending one reply after you type send it. We use it for nothing else.
How we store & protect it
Your Google connection is held by Composio, our connection provider; we store only the id of that grant, and it is never exposed to your browser and never shared between accounts. Where colevo holds a token of its own it is encrypted at rest (AES-256-GCM) and stored server-side. We keep no copies of your emails, files, or calendar events: they are read at the moment you ask and used to write that one answer. What is kept afterwards is the conversation you can see on your own screen.
How we share it
To generate a response, relevant content may be sent to our AI provider (Anthropic) solely to produce the output you asked for. We do not sell Google user data, do not use it for advertising, and do not transfer it to anyone except: to provide the features you requested (with your consent); for security purposes, such as investigating abuse; to comply with applicable law; or as part of a merger or acquisition, after obtaining your prior consent.
AI / machine learning
We do not use Google user data, and we do not allow our AI provider to use it, to train, develop, or improve any generalized or standalone AI or machine-learning model. It is used only at the moment you ask, to generate the specific output you requested, and is not retained by our AI provider for training.
Human access
We do not allow humans to read your Google data, except: (a) with your explicit consent (for example, to troubleshoot an issue you report); (b) where necessary for security or to comply with applicable law; or (c) where the data has been aggregated and anonymized for internal operations. Email is sent only after you type send it, and only the exact reply you were shown.
Retention & deletion
You can disconnect Google at any time in Settings, which revokes the grant at the source and deletes what we hold for it. You can delete your whole account and everything in it with one button in Settings, and it is done the same day. You can also review and revoke colevo’s access in your Google Account permissions.
QuickBooks (Intuit) data
If you connect QuickBooks Online, colevo accesses your accounting data through Intuit’s official API, on your behalf and only to power the features you ask for. This section describes exactly how we access, use, store, share, and delete your QuickBooks data.
What we access
We request a single scope, com.intuit.quickbooks.accounting, and we use it to read: your invoices (amounts, due dates, who has paid and who is overdue), your customers (names, emails, balances), and your company name. colevo never writes to your books. It creates nothing, edits nothing, and deletes nothing there.
How we use it
We use your QuickBooks data only to answer the questions you ask inside colevo, such as “who owes me money” or “how did we do this month”. We use it for nothing else.
How we store & protect it
We do not store your QuickBooks financial records. They are read at the moment you ask, used to generate your answer, and then discarded, nothing is saved, cached, logged, or copied into our database. The only thing we keep is the id of your QuickBooks connection, which is stored server-side, never exposed to your browser, and isolated to your account; the grant itself is held by Composio, our connection provider. One customer’s QuickBooks data is never visible to, or combined with, another customer’s.
How we share it
To generate your answer, the relevant QuickBooks figures are sent to our AI provider (Anthropic) solely to produce the output you asked for. We do not sell your QuickBooks data, do not use it for advertising, do not use it, or allow Anthropic to use it, to train any AI or machine-learning model, and do not give any other third party access to it.
Retention & deletion
You can disconnect QuickBooks at any time in Settings, which revokes colevo’s access with Intuit at the source and deletes what we hold for it. You can delete your whole account with one button in Settings, done the same day.
Square data
If you connect Square, colevo accesses your Square data through Square’s official API, on your behalf and only to power the features you ask for. This section describes exactly how we access, use, store, share, and delete your Square data.
What we access
We request read access only: your invoices (amounts, due dates, who has paid and who is overdue), your payments (money that has landed), your customers (names and emails), and your merchant profile and locations (your business name, used as your connection label). colevo never writes to your Square account. It creates nothing, edits nothing, and deletes nothing there.
How we use it
We use your Square data only to answer the questions you ask inside colevo, such as “who owes me money” or “what landed this week”. We use it for nothing else.
How we store & protect it
We do not store your Square financial records. They are read at the moment you ask, used to generate your answer, and then discarded, nothing is saved, cached, logged, or copied into our database. The only thing we keep is the id of your Square connection, stored server-side, never exposed to your browser, and isolated to your account; the grant itself is held by Composio, our connection provider. One customer’s Square data is never visible to, or combined with, another customer’s.
How we share it
To generate your answer, the relevant Square figures are sent to our AI provider (Anthropic) solely to produce the output you asked for. We do not sell your Square data, do not use it for advertising, do not use it, or allow Anthropic to use it, to train any AI or machine-learning model, and do not give any other third party access to it.
Retention & deletion
You can disconnect Square at any time in Settings, which revokes colevo’s access with Square at the source and deletes what we hold for it. You can delete your whole account with one button in Settings, done the same day.
How the AI works
To generate answers and drafts, your messages and the relevant business or connected-account content are sent to our AI provider, Anthropic, for processing. Under our agreement with Anthropic, this content is used only to produce your response and is not used to train Anthropic’s models.
Nothing sends until you say so, in words. colevo shows you the whole reply, and it goes only after you type send it. That yes is judged by ordinary code, not by the AI, and only the exact text you were shown can be released.
Who we share it with
We share data only with the service providers that help us run colevo (“subprocessors”), each under contract and only as needed to operate the Service:
- Anthropic, the AI that reads what was fetched and writes your answer. Privacy
- Composio, makes and holds the connections to the apps you connect, and carries each read at the moment you ask. Your access tokens live here, not in your browser. Privacy
- Supabase, stores your account, your conversation, and the ids of your connections. Privacy
- Vercel, hosts and serves the application. Privacy
- Stripe, takes your subscription payment on the website. We never store your card details. If you also connect your own Stripe account, we read it to answer your money questions. Privacy
- Apple and RevenueCat, if you subscribe inside the iPhone app, Apple takes the payment and RevenueCat tells our server that it started, renewed or ended. Neither passes us your card. Apple privacy · RevenueCat privacy
- Sentry, error monitoring, so a failure can be found and fixed. Reports carry the name and shape of the failure; personal details are turned off and scrubbed, and our own rule is that no email content is ever written into an error in the first place. Privacy
- Resend, delivers essential account email (sign-in and notices). Privacy
- Google, your connected email, calendar, and Drive, Docs and Sheets, read on your behalf. Privacy
- Intuit (QuickBooks), your connected books, read on your behalf to answer your questions. Privacy
- Square, your connected Square invoices, payments, and customers, read on your behalf. Privacy
- The other apps you choose to connect, Microsoft (Outlook, OneDrive), Xero, FreshBooks, PayPal, Calendly, HubSpot and Salesforce, each read on your behalf under their own privacy terms.
We may also disclose information if required by law, to protect the rights, safety, and security of colevo or others, or in connection with a merger or acquisition (in which case we’ll notify you). We do not sell your personal information to anyone.
Files you upload
colevo reads documents where they already live, in your Drive or your OneDrive, rather than asking you to upload them. If you have uploaded files to colevo in the past, we store them privately, use them only to answer you, and never sell or share them. When you disconnect an app, any files you had uploaded are deleted right away, the raw files and the text indexed from them, and the delete button removes them along with everything else.
How long we keep it
We keep your information for as long as your account is active. When you disconnect an app, the grant is revoked at the source and what we held for it is deleted, along with any files you had uploaded. One button in Settings deletes everything, your account, your conversation, what colevo learned about you, your uploads, and every connection, and it happens the same day, not on a queue. We keep only the limited records we must for legal, tax, or security obligations. Routine backups are purged on a rolling cycle.
Security
We use industry-standard providers with encryption in transit and at rest. The grants for your connected apps are held by Composio; where colevo stores a token of its own it is encrypted at rest with AES-256-GCM. Nothing of either kind is ever exposed to your browser. Each account’s data is isolated by row-level access controls so one customer can never see another’s, and every read is made under your own account’s connection. No system is perfectly secure, but we work to protect your information and will notify you of a breach as required by law.
Your rights & choices
- Access & export: ask us for a copy of the data we hold about you.
- Read and correct: everything colevo has learned about you is in Settings, in plain words, and you can tell it what is wrong.
- Disconnect: remove any connected app in Settings at any time, the grant is revoked at the source, not just hidden.
- Delete: one button in Settings deletes your account and everything in it, the same day. You can also email brian@colevo.io and we will do it for you.
Depending on where you live, you may have additional rights under laws such as the GDPR or California’s CCPA (including the right to access, delete, correct, or port your data, and to not be discriminated against for exercising them). We honor these requests, just email us. We do not sell or “share” personal information as those laws define it.
Your customers’ data
Some information you bring into colevo is about your customers (names, emails, job details). For that data, you are the controller and colevo is your processor, we handle it only to provide the Service to you and on your instructions. You’re responsible for having the right to use that information and to contact those customers. If you’re an EU/UK business that needs a Data Processing Agreement, contact us.
International users
colevo is operated from the United States, and our providers may process data in the U.S. and other countries. By using the Service you understand your information may be transferred to and processed in the United States, which may have different data-protection laws than your country.
Children
colevo is a business tool not intended for anyone under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us information, contact us and we’ll delete it.
Changes
We’ll update this page as the product grows and revise the “Last updated” date above. For material changes we’ll provide additional notice (such as an email or an in-app notice) where appropriate.
Questions or requests about your privacy? Email brian@colevo.io.