Privacy Policy
Last updated 2026-06-23 · Version 2
1. Introduction
IAVA Productions (“we”, “us”, “IAVA”) operates the IAVA one platform at iava.one. This Privacy Policy explains what personal information we collect when you use IAVA one, how we use it, who we share it with, and the choices you have.
By creating an account, you accept this Privacy Policy and our Terms of Service. If you do not agree, do not use the service.
2. Information we collect
We collect three categories of personal information:
- Account information: name, email, password (hashed), optional phone / contact handles (e.g. WhatsApp number or Telegram username you choose to add), an optional company address for your invoices, and other profile details you provide.
- Customer content: data you upload or generate inside IAVA one — your clients, leads, projects, invoices, emails (when you connect Gmail), calendar events (when you connect Google Calendar), files, deliverables, notes, AI-extracted facts about your clients.
- Usage data: feature interactions and error reports (via Sentry), plus AI-token usage. No cross-site tracking; no advertising; no advertising identifiers.
We do not knowingly collect data from children under 13. We do not use your customer content to train external AI models, and we do not sell your data.
3. How we use your information
- Service operation: render dashboards, send emails on your behalf, sync calendars, process invoices, run AI-assisted features (drafts, summaries, scope extraction).
- AI features: untrusted external content (email bodies, public form input) is wrapped in delimiters and passed to our AI provider (OpenRouter) on a per-request basis, solely to generate the result you asked for. We do not use your data — including Google user data — to train or improve AI/ML models.
- Support: when you contact us, we use your email and any details you share to respond.
- Security: detect abuse, rate-limit, audit access. OAuth refresh tokens are encrypted at rest with AES-256-GCM.
- Legal compliance: respond to lawful requests, comply with tax / accounting / GDPR obligations.
4. Sharing & sub-processors
We share data with these sub-processors only to operate the service. We do not sell your data, and we never share it with advertisers, ad networks, or marketing partners.
- Supabase (database hosting, auth) — Postgres, encrypted at rest with row-level security.
- Vercel (web hosting) — application server.
- Stripe (payment processing) — for your subscription to IAVA one and for invoicing your clients. We never store card numbers.
- Wise (payment matching) — when you connect Wise, to reconcile incoming client payments against your invoices.
- OpenRouter (AI API gateway) — per-request AI calls; no retention or training on your data.
- Resend (transactional email) — sending account and notification emails.
- Google (Gmail / Calendar OAuth) — when you connect your account; we only use the scopes you grant (see section 5).
- Sentry (error monitoring, production only) — anonymized error reports, no customer content.
- Telegram (optional notifications + assistant bot) — only when you connect Telegram, to deliver notifications and let you interact with your account.
- Twilio (optional WhatsApp messaging) — only when you enable WhatsApp, to send summaries and assistant replies.
5. Google user data & Limited Use
When you connect your Google account, IAVA one accesses Google data only to provide features you see in the app:
- Gmail — read (
gmail.readonly): to show your incoming client emails in your Inbox, match them to the right project or lead, draft AI-assisted replies from the conversation, and reflect their read/unread status. We can only read your mail — we cannot label, move, delete, or otherwise modify it. - Gmail — send (
gmail.send): to send the client emails you compose and confirm in IAVA one, from your own Gmail. - Google Calendar — events (
calendar.events): to read your calendar events for availability, and to create, update, or delete the filming and studio-session events you schedule. - Google Calendar — calendar list (
calendar.calendarlist.readonly): to see the list of your calendars (names only) so availability can span all of them. We do not read your free/busy, settings, or other people's calendars.
We store this data only in your own team-scoped account, encrypt OAuth tokens at rest, and never use Google user data to train or improve generalized AI/ML models, nor share it with advertisers. You can disconnect at any time in Settings → Integrations, and export or delete all your data from Settings → Account.
IAVA one's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Retention
We retain your data for as long as your account is active, plus a short window after deletion for backups and legal obligations. When you delete your account or request erasure, we delete your customer content within 30 days from active systems and within 90 days from backups. Audit logs are retained for up to one year.
7. Your rights
You have the following rights regarding your personal data:
- Access: request a copy of the data we hold about you.
- Erasure: request deletion of your account and customer content.
- Portability: export your data in a machine-readable format.
- Rectification: correct inaccurate data.
- Object / restrict: object to certain processing or restrict it.
- Withdraw consent: where processing is based on consent, withdraw at any time.
You can export or delete your data directly from Settings → Account. To exercise any other right, email hello@iava.productions. We respond within 30 days. EU residents may also lodge a complaint with their local data protection authority.
8. International data transfers
IAVA one is operated from Canada with sub-processors located in the United States, European Union, and other regions. When data is transferred outside your jurisdiction, we rely on Standard Contractual Clauses (SCCs) and the safeguards required under GDPR / UK GDPR / Swiss FADP. EU business customers can countersign our Data Processing Addendum.
9. Cookies
We use only essential cookies required to keep you signed in (Supabase auth session), plus local storage for small preferences (such as dismissed tips and your dashboard layout). We do not use advertising, analytics, or third-party tracking cookies.
10. Security
We protect your data with industry-standard measures: TLS in transit, AES-256-GCM encryption for OAuth refresh tokens at rest, row-level security (RLS) on all customer-scoped tables, HMAC-signed OAuth state parameters, rate limits on public endpoints, and HTTPS-only cookies. No system is perfectly secure; please report vulnerabilities to hello@iava.productions.
11. Children
IAVA one is not directed at children under 13 (or 16 in the EU). We do not knowingly collect data from minors. If you believe a child has provided us with personal data, contact us and we will delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via email or an in-app prompt before the changes take effect. The version number and last-updated date at the top of this page reflect the current version.
13. Contact
IAVA Productions, Ontario, Canada
Email: hello@iava.productions