NuvoBack

Privacy Policy

Last updated September 9, 2026

Who we are

Nuvo (“we”, “us”) is a single-user life management application. This policy explains what we collect, why, and how Google user data is handled when you Sign in with Google or connect Google Calendar. Questions: hello@nuvo.day.

Data we collect (summary)

Nuvo collects only what it needs to run your private planner:

  • Account: email and authentication credentials (Supabase Auth), including when you use Sign in with Google or Sign in with Apple.
  • Planning data you create: domains, initiatives, projects, tasks, time blocks, labels, settings, and notes.
  • Optional calendar connections you choose (Google Calendar, Microsoft 365, Apple/iCloud, ICS) — detailed below.
  • When you use Ask Nuvo: prompts and the planning context needed to answer, sent to our language-model provider for that request only.

We do not sell personal data. We do not use Google user data for advertising.

Google Sign-In

You can create or open a Nuvo account with Sign in with Google. When you do, we receive your Google account email (and basic profile identifiers needed for sign-in) so we can authenticate you. That is separate from connecting Google Calendar.

Sign-in data is used only to create and secure your Nuvo account. Delete anytime: Settings → Account → Delete account (type DELETE), including from the expired-trial lock screen.

Google user data & Limited Use

Nuvo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data. We do not use Google user data for advertising. We do not use Google user data to train generalized AI/ML models. Human access to Google user data is limited to cases with your consent, for security, to comply with law, or to provide support you request.

Connecting Google Calendar is optional and separate from Google Sign-In.

Account & planning data

When you create an account we store your email and authentication credentials via our provider (Supabase Auth). Inside the app we store the planning data you create: domains, initiatives, projects, tasks, time blocks, labels, week commitments, settings, and related notes. That data is yours. It is stored in a private database with row-level security so only your signed-in account can read or write it.

Google Calendar

Connecting Google Calendar is optional and separate from Google Sign-In. If you choose to connect, Nuvo requests these OAuth scopes:

  • https://www.googleapis.com/auth/calendar — read and write calendar events so Nuvo can sync your calendars, show them on the planning surface, and write scheduled tasks back (including a dedicated “Nuvo” mirror calendar).
  • https://www.googleapis.com/auth/userinfo.email — identify which Google account you connected.

We store OAuth refresh tokens in a secured vault (not in plain application tables), plus calendar list metadata and mirrored event data needed to keep your schedule in sync. Google Calendar data is used solely to provide Nuvo’s calendar sync and scheduling features to you.

Microsoft 365, Apple Calendar & ICS

Optional connections work the same spirit: credentials are stored in a secured vault; event data is synced only to power your planning surface.

  • Microsoft 365 — calendar read access (events appear in Nuvo; Nuvo does not write back to M365).
  • Apple / iCloud Calendar — you connect with Apple ID + an app-specific password for two-way CalDAV sync.
  • ICS subscriptions — read-only feeds; the feed URL is stored so we can refresh events.

Assistant & AI features

When you use Nuvo’s assistant, prompts and the planning context needed to answer (tasks, calendar snippets, project structure) may be sent to our language-model provider to generate proposals. That processing is in service of features you invoke. We do not use your Google Calendar content to train generalized AI models.

Device-local preferences

Appearance (skins / themes), some timezone preferences, and similar UI settings may be stored on your device (e.g. localStorage). They are not required for core sync.

Retention & deletion

We retain your account and planning data while your account is active. You can disconnect Google (or other calendars) in Settings at any time — that revokes further API access and we stop syncing that account.

To delete your Nuvo account and the planning data we store, open the app and go to Settings → Account → Delete account. If your trial or subscription has ended and you are on the locked screen, Delete account is there too. Type DELETE to confirm. That wipe is immediate: the account cannot sign back in. If you subscribed through Apple, cancel in Apple Account settings first (Settings → your name → Subscriptions) — we cannot cancel an App Store subscription for you. If you pay through the web or Mac, we cancel that Stripe subscription when you delete. If you cannot open the app, email hello@nuvo.day from the address on the account. We retain billing records where the law requires it.

Sharing

We do not sell personal data. We use infrastructure processors (hosting, auth, database, email delivery if applicable, AI inference for assistant features) solely to run Nuvo. They process data under our instructions.

Security

Access tokens and calendar credentials are stored in a vault. Application data is protected with authentication and row-level security. No method of transmission or storage is perfectly secure; we work to protect your data with industry-standard practices.

Children

Nuvo is not directed at children under 13. We do not knowingly collect personal information from children.

Changes

We may update this policy as Nuvo evolves. The “Last updated” date above will change when we do. Material changes that affect Google user data use will be called out clearly.

Contact

Privacy requests and questions: hello@nuvo.day.