Privacy Policy
Last updated: June 2026
colevo ("we", "us") provides an AI assistant for small businesses. This policy explains what we collect, how we use it, and your choices. Questions? Email brian@colevo.io.
What we collect
- Account: your email and a password (handled by our authentication provider — we never see your password).
- Your business info: the details you give the assistant during setup (business name, services, prices, hours, FAQs, etc.).
- Connected accounts: if you connect Google, we access your Gmail and Google Calendar to provide the features you ask for — reading recent emails and events, drafting replies, and sending email only when you approve it.
- Usage: basic logs needed to run and secure the service.
How we use it
- To run the assistant — answering your questions, drafting and (with your approval) sending messages, and organizing your day.
- Your messages and relevant business data are processed by our AI provider (Anthropic) to generate responses. We do not sell your data, and it is never used for advertising.
Google user data
colevo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we only use your Google data to provide features you request inside colevo; we do not sell it; we do not use it for advertising; and we do not use it to train generalized AI models. Email is sent only when you explicitly approve it.
Who we share it with
- Anthropic — processes your messages to generate AI responses.
- Supabase — stores your account and business data securely.
- Vercel — hosts the application.
- Google — your connected email/calendar data, accessed on your behalf.
- Stripe — processes payments (when billing is enabled). We never store your card details.
We do not sell your personal information to anyone.
Your choices
- Disconnect Google anytime from your dashboard — we delete the stored access tokens.
- Ask us to delete your account and data by emailing brian@colevo.io.
Security
Connection tokens are stored server-side and never exposed to your browser. We rely on industry-standard providers with encryption in transit and at rest.
Changes
We'll update this page as the product grows and post the new date above.