Legal

Privacy Policy

Last updated August 18, 2026.

1. Introduction

Barvol is an early-stage company intelligence workspace for founders. This Privacy Policy explains what information Barvol collects, why it is collected, how it is used, how long it is retained, and how you can control or request deletion of it.

By creating an account or connecting an integration, you agree to the practices described in this policy. If you disagree, do not use the service.

2. Information We Collect

2.1 Account information

When you sign up, we collect your name, email address, and password (stored as a secure hash — never in plain text). If you sign in with Google, we receive your name, email address, and profile picture from Google’s authentication service.

2.2 Workspace content

Anything you create inside Barvol — decisions, goals, journal entries, CRM contacts, tasks, and notes — is stored in our database associated with your workspace.

2.3 Google API data

When you choose to connect a Google service, we access data through Google’s OAuth 2.0 authorization flow using only the permissions you grant. Each Google integration is described in full in Section 4. You can disconnect any integration at any time from Settings → Integrations.

2.4 Other integration data

When you connect other services (GitHub, Notion, Slack, Linear, Jira, Stripe) through their OAuth flows, we access only the data required to operate the feature you enabled and only for as long as the integration is active.

2.5 Usage data

We collect standard server logs — IP address, browser type, pages visited, and feature interactions — to operate, debug, and improve the product.

3. How We Use Your Information

  • Delivering the product: powering your workspace — decisions, goals, CRM, AI summaries, integrations, and all other features.
  • AI-assisted features: we transmit selected data to our AI provider (Groq) to generate summaries, classify content, and surface insights within your workspace. The specific data sent is described per feature in Section 4. Groq’s terms of service prohibit training their models on API inputs.
  • Communications: account notices, billing information, and optional product updates.
  • Security: detecting fraudulent activity and unauthorized access attempts.
  • Legal compliance: fulfilling obligations under applicable law where required.

We do not sell your data. We do not use your data for advertising targeting. We do not share your data with third parties for their own marketing purposes.

4. Google API Services — Data Access Details

The following describes exactly what data each Google integration accesses, why, and how it is stored. These descriptions correspond to the OAuth scopes our Google Cloud application requests.

4.1 Gmail — gmail.readonly

What we receive:

Email metadata only — the subject line and sender name and email address of emails received today (up to 50 per day). We use the Gmail API’s metadata format and request only the Subject and From headers.

We do not access email body text, attachments, recipients, CC/BCC fields, read/unread state, labels, or threads.

Why:

The list of today’s email subjects and senders is sent to Groq AI, which classifies whether any represents an urgent founder-level communication (such as an investor message, customer escalation, or billing issue). At most one flagged item is surfaced in your workspace daily.

What is stored:

A daily summary record containing: total email count for the day, and — where the AI identifies an important item — the subject line, sender name/address, and a short AI-generated reason phrase. Summaries are stored per user in our database and are not used for any other purpose.

What we never do:

  • Read email body content or attachments.
  • Send, reply to, draft, modify, or delete any email.
  • Share email metadata with any party other than the Groq AI API described above, which does not train on API inputs.

4.2 Google Calendar — calendar.readonly

What we receive:

Events from your primary Google Calendar for the next 14 days (up to 50 events): event title, start and end time, whether the event is all-day, location, event description, and the email addresses of attendees.

Why:

We display upcoming meetings inside your workspace. Attendee email addresses are matched against your Barvol CRM contacts so that meeting interactions are automatically logged against the relevant contact record — this is a core feature of the CRM integration.

What is stored:

Full event records (title, times, location, description, attendee email addresses) are written to your workspace database. Where an attendee email matches a CRM contact, a meeting interaction is logged on that contact.

What we never do:

  • Create, update, or delete calendar events.
  • Access calendars other than your primary calendar.
  • Share calendar data with third parties other than our database provider (Google Firestore) and Groq AI where you trigger AI features.

4.3 Google Analytics — analytics.readonly

What we receive:

Aggregated metrics for the Analytics 4 property you specify: weekly active users and weekly page views for the past 7 days. No individual visitor data or personally identifiable information is accessed.

Why and what is stored:

These two headline numbers are displayed in your workspace as a growth indicator. They are stored in your workspace’s company state record and overwritten on each sync.

4.4 Google Search Console — webmasters.readonly

What we receive:

Aggregated totals for the verified Search Console property you specify: total search clicks and total search impressions for the past 7 days. No individual query, page, or user data is accessed.

Why and what is stored:

These two headline numbers are displayed in your workspace as an SEO indicator. They are stored in your workspace’s company state record and overwritten on each sync.

5. Google API Services — Limited Use Policy

Barvol’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

In particular, Barvol confirms that Google user data is:

  • Used only to provide or improve the specific Barvol features you have enabled — for no other purpose.
  • Not sold to any third party, under any circumstances.
  • Not used for advertising, interest-based targeting, or the construction of advertising profiles of any kind.
  • Not transferred to data brokers or to any third party for purposes unrelated to operating Barvol.
  • Not used to train generalized AI or machine learning models. When AI processing occurs (Groq classifying Gmail headers to surface important communications), it is used solely to provide the feature you enabled and operates under Groq’s API terms, which prohibit training on customer inputs.
  • Not accessible to Barvol employees or contractors for manual review, except where you have explicitly granted permission, where a security investigation requires it, or where required by applicable law — and only as permitted by Google’s policies.

Revoking Google access: disconnect any Google integration from Settings → Integrations in your workspace, or visit myaccount.google.com/permissions to revoke Barvol’s access directly from Google. See Section 7 for what happens to stored data after disconnection.

6. Data Storage and Infrastructure

Barvol uses the following infrastructure to store and process data:

  • Google Firestore (Google Cloud): all workspace data, OAuth tokens, calendar events, and Gmail summaries are stored in Firestore. Google Cloud encrypts Firestore data at rest and in transit using Google’s platform security controls.
  • Vercel: Barvol’s application runs on Vercel’s global edge network. All traffic is served over HTTPS. Vercel applies its own platform security controls.
  • Groq: email header metadata (subject and sender only) is transmitted to Groq for the Gmail classification feature. Groq does not retain or train on API inputs under their terms of service.

OAuth tokens are stored in restricted Firestore subcollections that are inaccessible from the browser — only server-side application code can read them.

7. Data Retention and Deletion

7.1 While your account is active

Workspace content, integration connection records, and synced data are retained for as long as your account exists.

7.2 When you disconnect an integration

Disconnecting an integration stops future data syncing. However, OAuth tokens and previously synced data (such as Gmail summaries and calendar events) are not automatically deleted at the point of disconnection. They remain in our database until you request deletion or until your account is deleted.

If you want previously synced Google data deleted immediately upon disconnection, contact us at privacy@barvol.online and we will process the deletion within 30 days of your request.

7.3 Account deletion

Barvol does not currently have an in-product account deletion flow. To request full account and data deletion, email privacy@barvol.online with the subject line “Delete my account.” We will process the request within 30 days.

After deletion, personal data is removed from our active Firestore database. Google Cloud backup snapshots may temporarily retain data for a short additional period under Google’s backup policies, after which it is also removed.

8. Cookies and Analytics

Barvol uses the following cookies and tracking technologies:

  • Authentication session cookie: a secure, HTTP-only cookie used to maintain your signed-in session. Strictly necessary for the product to function; cannot be declined while using the service.
  • Google Analytics 4 (G-TLGYJM6QMT): we use GA4 to understand how visitors engage with our marketing website. GA4 sets cookies such as _ga to distinguish sessions. Data is aggregated and not used to identify individuals. You can decline GA4 via the cookie consent banner on your first visit.
  • Microsoft Clarity (xxwipf9ogk): we use Clarity on our marketing website to record anonymised session replays that help us identify usability problems. No personally identifiable information is captured in replays. You can decline Clarity via the cookie consent banner.

A browser localStorage entry (barvol-theme) stores your display preference locally in your browser. It is not a cookie and is not sent to our servers.

We do not use advertising cookies. We do not share cookie or analytics data with ad networks or data brokers.

9. Third-Party Services

The following service providers may process personal data as part of operating Barvol:

  • Google (Firebase Auth, Firestore, Cloud): authentication and database infrastructure.
  • Vercel: application hosting and edge delivery.
  • Groq: AI inference for product features (Gmail classification). Groq does not train on API inputs.
  • Paddle: payment processing. We do not store card or banking details — all payment data is handled by Paddle.
  • Google Analytics 4 / Microsoft Clarity: anonymised marketing website analytics. Disabled if you decline the cookie banner.

We do not share personal data with any third party for their own marketing or advertising purposes.

10. Your Privacy Rights

Barvol is designed to support privacy rights for all users. Depending on your location, you may have the right to:

  • Access the data we hold about you.
  • Correct inaccurate data.
  • Delete your data and account.
  • Export your data in a machine-readable format.
  • Restrict certain types of processing.
  • Withdraw consent for consent-based processing (such as a Google integration) at any time, without affecting past processing.

To exercise any right, or to request deletion of specific Google API data, contact privacy@barvol.online. We respond within 30 days.

We do not claim formal GDPR certification. We do not have an appointed Data Protection Officer. Privacy requests are handled directly by the Barvol team.

11. Legal Basis for Processing (EU / UK)

Where EU or UK data protection law applies, we process personal data on the following bases:

  • Contract performance: providing the Barvol service you signed up for.
  • Consent: for optional integrations you connect via OAuth; you can withdraw at any time.
  • Legitimate interests: security, fraud prevention, and aggregate product analytics.
  • Legal obligation: where required by applicable law.

12. Children

Barvol is a professional tool for founders and is not directed at anyone under 16 years of age. We do not knowingly collect personal data from anyone under 16. If you believe we have done so inadvertently, contact us and we will delete it promptly.

13. Changes to This Policy

We may update this policy as the product evolves or legal requirements change. The “last updated” date at the top reflects the most recent revision. For material changes, we will notify you by email or in-app notice at least 14 days in advance.

14. Contact

For privacy questions, data requests, or concerns about Google API data handling: