Privacy Policy
Version 1.2 · Effective August 16, 2026 · Last updated August 16, 2026
NAVO is operated by NAVO Technologies LLC (Ashland, Ohio, USA). We do not publish a street address; please contact us by email.
Our privacy commitment
NAVO is your home's memory. The information you put into NAVO — your home, your belongings, your documents — is yours. We build privacy in by default: optional analytics are off until you turn them on, we do not sell personal data, we do not run advertising or cross-site tracking, and we collect the minimum we need to run the service well.
This policy describes what NAVO does today. If our practices materially change, we will update this policy and notify you as appropriate before the change takes effect.
Information we collect
Account and authentication data. Your email address, password (stored only as a salted hash by our authentication provider), first and last name, optional avatar image, and timestamps such as sign up and last activity. We also keep basic session and security records so we can keep accounts safe.
Legal acceptance records. We record which versions of our Terms of Service and this Privacy Policy you accepted and when, so we can show you a notice if they change. We do not collect your date of birth, IP address or a device fingerprint for this purpose.
Household and home data. Household name, timezone and preferences, properties, rooms, household membership and roles, and invitations you create.
Assets, documents and media. Asset records (name, brand, model and serial numbers, category, purchase and warranty details, condition, notes, value), photos you upload, equipment-label photos you scan, receipts, manuals, insurance and other documents you upload, and web links you save.
Derived data. Text extracted from your documents and label photos, document text segments and their vector embeddings used for search, classification and warranty/recall/manual suggestions, maintenance schedules and reminders, notifications, home-timeline events, health and ownership scores, in-app search history, and AI conversation records tied to your household.
Operational and security data. Application and server logs (timestamps, normalized route, status code, latency, an opaque request identifier, and error details), security audit records, and abuse / rate-limit records. These are necessary to operate and secure the service and are not optional analytics — see the sections below.
Optional analytics data. Only if you affirmatively opt in. See "Optional analytics".
Payment and subscription data. When a household owner purchases a paid plan, Stripe collects and processes payment-method, billing-contact and transaction information. NAVO does not receive or store full payment-card numbers. We receive and store limited billing records needed to provide and administer the subscription, such as Stripe customer and subscription identifiers, plan, billing interval, subscription status, renewal or cancellation timing, and payment-related event records.
How we use information
- Provide the service: store and display your home, assets, documents and reminders.
- Generate features you ask for: document extraction, label scanning, classification suggestions, warranty and recall lookups, manual discovery, health scores and the Ask NAVO assistant.
- Send in-app notifications and digests according to your notification preferences.
- Operate, debug, secure and improve the service, including detecting abuse and enforcing rate limits.
- Meet legal obligations and respond to your privacy requests.
We do not use your household content to serve advertising, and we do not sell it.
AI processing and disclosures
Several NAVO features use AI. When you use them, the relevant content is sent from our servers to the Lovable AI Gateway, which routes the request to the model provider serving that feature. The current provider list appears under "Service providers and sharing" below and is updated when it changes. AI features include:
- Document extraction: text and images from receipts, manuals and other documents you upload.
- Label and receipt scanning: the photo you capture, to read model and serial numbers or purchase details.
- Photo-based asset capture: the asset photo you submit for identification.
- Ask NAVO: your question plus scoped context from the relevant household or asset records, matching passages from your household documents, and NAVO learned knowledge derived from those documents.
- Suggestion and knowledge features: asset identifiers such as brand, model and category.
Ask NAVO checks your household records, uploaded documents and learned knowledge before requesting external guidance. If your information cannot answer the question, the external request is limited to non-sensitive product identifiers such as brand, model and category. It does not include your household name or address, uploaded documents or passages, notes, serial numbers, purchase prices, reminders or maintenance records.
We use a small number of established commercial model providers and do not permit them to use your content to train their models. Where a provider does not use API or business inputs and outputs for training by default unless the customer opts in — as OpenAI states for its API — we rely on that default and have not opted in. We cannot, however, control or guarantee any provider's independent processing or retention beyond the applicable agreements and settings that apply to us.
AI output can be wrong. NAVO's assistant is designed to answer from your own records and to say when it does not have enough evidence, but you should verify anything important — especially warranty, recall, safety or financial information.
Optional analytics, device storage and Global Privacy Control
Off by default, worldwide. Optional product analytics are disabled for every user and every device until you make an explicit affirmative choice. Nothing is pre-checked and there is no implied consent. Before you opt in, no optional analytics are initialized or transmitted and no persistent anonymous analytics identifier is created.
What optional analytics include. Privacy-minimized, anonymous events about reliability and performance — for example page loads, request outcomes, latency buckets and error types — identified only by a random identifier stored locally in your browser. Inside the NAVO application our analytics provider is PostHog, configured with autocapture, session replay and heatmaps disabled, person profiles disabled, and IP/geolocation collection disabled, with aggressive property sanitization and a 30-day vendor retention setting.
HeyCatch on public marketing pages. Optional analytics on NAVO's public marketing pages may use HeyCatch and its analytics infrastructure to collect page views, interactions, device/browser information, and IP-derived technical information after consent. NAVO does not send household records, Ask NAVO content, asset details, documents, warranties, VINs, serial numbers, or email addresses to HeyCatch. HeyCatch runs only on the public pages (home, About, Install, Privacy and Terms) and is never initialized on the sign-in page or on any signed-in page. HeyCatch, Inc. (United States) acts as an optional analytics processor for those pages and uses PostHog US Cloud as part of its analytics infrastructure. HeyCatch documents retention of SDK events through the active subscription and for up to 2 months after subscription end, subject to its deletion and anonymization provisions. International transfers rely on contractual safeguards including the EU Standard Contractual Clauses where applicable. NAVO is the contact point for visitor access or deletion requests relating to this analytics use; such requests are handled manually rather than automatically.
What optional analytics never include. Advertising or cross-site tracking, sale of data, and no household, home, asset, document, search or AI-conversation content. Session replay is disabled everywhere, including in HeyCatch.
Declining and withdrawing. Declining does not limit any NAVO functionality, and you will not be repeatedly prompted. You can opt in or withdraw at any time in Settings → Profile → Privacy & data. Withdrawal stops future optional analytics immediately, clears the local anonymous identifier, and clears HeyCatch's own browser storage on this device. Deleting data already received by HeyCatch is a manual request you can make to us.
Declining and withdrawing. Declining does not limit any NAVO functionality, and you will not be repeatedly prompted. You can opt in or withdraw at any time in Settings → Profile → Privacy & data. Withdrawal stops future optional analytics immediately and clears the local anonymous identifier.
Global Privacy Control. If your browser sends a GPC signal, optional analytics stay off and the toggle is disabled. We do not override GPC with an opt-in.
Device storage. NAVO stores a small amount of data in your browser, all of it functional: your authentication session; your analytics consent decision (status, notice version, timestamp); whether you have already been asked about notification permissions; the time you were last active; and short-lived, tab-session data such as an in-progress onboarding draft and suggestions you dismissed for the current session. Only after you opt in do we also store the random anonymous analytics identifier. We do not use advertising cookies, which is why NAVO has no cookie banner beyond the analytics consent prompt.
Essential operational and security logging
Separate from optional analytics, NAVO keeps the minimum logging required to run and secure the service: structured server logs with an opaque request identifier, application error records, security audit records and abuse/rate-limit records. These are not used for product analytics or marketing, are sanitized to remove personal content where feasible, and cannot be switched off, because without them we cannot operate the service safely.
Shared households: what other members can see
A NAVO household is a shared space. Anyone you add to your household can see that household's content — properties, rooms, assets, photos, documents, reminders, maintenance history, timeline and household-level insights — according to their role. Owners and admins can manage members and household settings; read-only members can view but not change content.
Membership boundaries are enforced in the database with row-level security, so people who are not members of your household cannot read your household's data. Other members do not get access to your private account or security data, such as your credentials, sessions or security records; within a household, other members' identity is limited to what the product already shows — display name, avatar and role.
Only add people you trust. Removing a member ends their access to the household going forward.
Security
We use encryption in transit, private storage buckets with time-limited signed URLs, row-level security policies scoped to household membership, restricted database-function privileges, server-side authorization checks on privileged operations, rate limiting on sensitive actions, and security audit logging.
No service can promise perfect security. We cannot guarantee that unauthorized access will never occur, and you are responsible for keeping your password and devices secure.
Data retention and deletion
Account deletion. You can request deletion from Settings → Profile. Your account then enters a 30-day grace period: you can cancel at any time during that window by signing in. After 30 days, the permanent purge runs — your profile, memberships and personal records are erased, your authentication account is deleted, and your stored files (photos, documents, label scans, avatars) are removed from storage.
Households you own. Deleting your account never silently destroys someone else's household. Households where you are the only member are erased with your account. For a shared household you own, you must explicitly choose, before the request is accepted, either to transfer ownership to a named member or to delete that household. If you are a member but not the owner, only your membership is removed and the household continues.
Deleted assets. Assets you delete are recoverable for 30 days from the "Recently deleted" list. After 30 days a scheduled job permanently removes the record and its associated stored files and derived document data.
Records we retain. Security audit records are kept for 180 days — long enough to investigate abuse or a security incident, short enough to stay minimal — and are pseudonymized when the associated account is purged. Abuse and rate-limit records are kept for 30 days. Backups and logs may persist for a limited additional period until they age out on their normal cycle. We may retain information longer where the law requires it.
Billing records. Stripe retains payment information according to its own legal obligations and privacy policy. NAVO may retain limited subscription, transaction, accounting, tax, fraud-prevention and payment-event records for as long as reasonably necessary to operate the Service, resolve disputes, enforce agreements and meet legal obligations, including after account deletion where required.
Data export
From Settings → Profile → Privacy & data you can download a structured JSON copy of your account data and the household data you are entitled to access: profile, memberships, properties and rooms, assets, document metadata and extracted text, reminders, maintenance history, timeline events, notifications, search history and insights. Other members appear only as display name and role.
The export excludes credentials, tokens, security and audit records, and any data from households you cannot access. Uploaded photos and files are not yet bundled in the export; download those from each asset in the meantime. Exports are generated server-side under your own permissions and are rate limited.
Export remains available during the 30-day account-deletion grace period.
Your privacy controls and rights
- Access and correct your profile and household content directly in the product.
- Download your data as JSON (Settings → Profile → Privacy & data).
- Delete your account with a 30-day grace period, and restore deleted assets within 30 days.
- Opt in to or withdraw from optional analytics at any time; GPC is honored automatically.
- Control in-app notifications in Settings → Notifications.
Depending on where you live, you may have additional rights — access, correction, deletion, portability, objection or restriction, and the right not to be discriminated against for exercising them. Contact us at hello@mynavoapp.com and we will respond within the time the applicable law allows. We do not sell personal data or share it for targeted advertising, so there is nothing to opt out of in that respect.
Minimum age
NAVO is for adults. You must be at least 18 years old to create an independent NAVO account. NAVO is not directed to children, and we do not knowingly collect personal information from children. If we learn that a child has created an account, we will delete it. A household owner is responsible for anyone they choose to add to their household.
International users
NAVO is operated from the United States and our providers may process and store data in the United States and other countries. If you use NAVO from outside the United States, you understand that your information will be transferred to and processed in countries whose data-protection laws may differ from your own. We apply the same conservative privacy standard everywhere, regardless of where you live.
Changes to this policy
We version this policy. The current version and effective date appear at the top of this page. If we make a material change, we will update the version and effective date and give notice in the product before the change takes effect where practical. Continuing to use NAVO after a change means you accept the updated policy.
Contact
Questions, requests or concerns about privacy? Email hello@mynavoapp.com. We read every message.
NAVO · Your home remembers. · Home · Terms of Service