01Introduction
SUVI ("we", "our", or "us") operated by SUVI PTE LIMITED is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform and services at suvi.ai.
02Information We Collect
We may collect the following types of information:
- Account Information: Name, email address, and profile details when you sign up or authenticate via Google OAuth.
- Usage Data: Information about how you interact with our platform, including pages visited, features used, and session duration.
- Device Information: Browser type, operating system, IP address, and device identifiers.
- Communications & Integrations: Data processed through connected services such as Slack, when you choose to integrate them with SUVI.
- Connected Google Data: When you connect your Google Account, we access your Google Calendar events, the files Suvi creates in your Drive or that you explicitly give it, and we send email on your behalf when you ask. Suvi does not read your mailbox and cannot browse the rest of your Drive. See the Google OAuth & API Data section for the exact scopes and their limits.
03How We Use Your Information
- To provide, maintain, and improve our services.
- To authenticate your identity and manage your account.
- To communicate with you about updates, support, and promotional offers.
- To analyze usage patterns and improve user experience.
- To comply with legal obligations.
04Data Sharing & Disclosure
We do not sell your personal information. We may share your data with:
- Service Providers: Third-party services that assist in operating our platform (e.g., hosting, analytics). The specific sub-processors that may receive user-derived content are listed in the Sub-processors section below.
- Legal Requirements: When required by law, regulation, or legal process.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
05Google OAuth & API Data
When you connect your Google Account, Suvi requests only the access listed below, and uses each type of access only as described:
- Sign-in (openid) and email address (userinfo.email): used for sign-in and account identity only.
- Gmail, send only (gmail.send): to send emails and replies that you ask Suvi to send. Every send is user-initiated: Suvi shows you the recipient, subject and body, and sends only after you approve that specific message. This scope grants no ability to read your mailbox.
- Google Calendar events (calendar.events): to read, create, update, and delete calendar events, respond to invitations, and find free time across your calendars.
- Google Drive, per-file access (drive.file): to create files in your Drive, and to read and edit files that Suvi itself created or that you explicitly picked for it. This scope does not give Suvi access to the rest of your Drive.
What Suvi cannot do with your Google Account. These are limits of the access above, not promises about our conduct — the scopes Suvi requests make them impossible:
- It cannot read your email. Reading a message requires a scope Suvi does not request. There are no inbox summaries, no triage, no automatic replies, no draft creation, and no applying labels to your messages.
- It cannot search or browse your Drive. Files you have not given it, and that it did not create, are not visible to it.
- It does not watch your account in the background. Suvi subscribes to no Gmail or Drive change notifications.
Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We do not sell your Google user data, use it for advertising, or use it to train or fine-tune machine-learning models.
- Human access to your Google user data is restricted to what is needed to provide the feature, for security, or to comply with law. Our operational application logs and the assistant’s conversation history may contain your Google data itself, not only metadata — specifically the calendar event details Suvi read on your behalf, the content of messages you asked it to send, and the contents of files it created or you gave it. These are retained as described in the Data Retention and Deletion section below.
What we store. Calendar event data Suvi has read, the emails you asked it to send, and files it created or you shared with it are stored in our database and in the operational queues, logs, and files we use to run the Service, for as long as we need them to provide the features you enabled. Because Suvi cannot read your mailbox, we hold no copies of your incoming email — no message bodies, no attachments, no inbox metadata. Embeddings and other derived data are stored in our own database; we do not use a third-party vector service. Your data is removed when you request deletion, subject to the exceptions described in the Data Retention and Deletion section below. We do not store your Google credentials beyond the OAuth tokens required to keep the features you enabled working, and you can revoke this access at any time from your Google Account permissions.
06Sub-processors
Two different things can happen to your data, and we separate them below: providers we use to run the Service, and services you choose to connect.
Providers we use to operate Suvi. These receive data as part of normal operation:
- Anthropic (Claude): our primary processor. Your conversations with the assistant, your calendar event details, the emails you ask Suvi to compose or send, and the documents you give it are sent here for chat, drafting and OCR. Your incoming email is not, because Suvi cannot read it.
- Amazon Web Services: object storage for the files Suvi processes on your behalf.
- WhatsApp (Meta) and Telegram: where you have connected a messaging channel, Suvi delivers notifications, replies and email briefs through it. Those messages can contain content drawn from your Gmail, Calendar and Drive.
Services you connect yourself. These are third-party accounts you already hold. Nothing is sent to them unless you connect the service and direct Suvi to use it, and you can disconnect any of them at any time:
- Fireflies: when connected, Suvi can call it during a conversation to read or create meeting notes. Because it is available to the assistant while it is working, content from the conversation — which may include Google data — can be sent to it.
- Notion, Zoho and LeadRat: used when you ask Suvi to write something to them, such as saving a note or pushing a lead. Content you direct Suvi to send may include Google-derived data.
- GitHub: optional backup of your assistant memory, which may contain user-derived facts, to a repository that you own and control. The transfer is over HTTPS and the contents are stored under your own account’s access controls; Suvi does not add its own encryption layer to this backup.
Suvi is operated by Metastart. Content you and the assistant generate, which can include summarized email content, is processed and stored on our own first-party infrastructure in order to operate, maintain, and improve the Service for you. This is not a transfer to a third party. We do not use it for advertising, and we do not sell or transfer it to data brokers or advertisers.
07Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS/SSL) and at rest. However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
08Data Retention and Deletion
We retain your data only for as long as necessary to provide the Service and for legitimate operational purposes.
You can revoke access to your Google Account at any time from your Google Account permissions, which stops any further access. To request deletion of your Google data, contact us at contact@suvi.ai, and we will process your request within 30 days.
A Delete my Google data action is available in your account settings, and it deletes your data specifically — not the account’s and not another user’s. It revokes Suvi’s access with Google directly, and removes from our systems the calendar event data Suvi held for you, the record of emails it sent on your behalf, tasks and memory items derived from your calendar, workflow run records, and the files it created or you gave it that are held in our own storage. Message queues used to deliver notifications to you over WhatsApp or Telegram are not cleared by this action, because they also carry non-Google traffic. You are shown a summary of exactly what was removed, and if any part cannot be completed we tell you rather than reporting success — including if a grant could not be revoked with Google, in which case you can remove it yourself from your Google Account permissions. Deleting your Suvi account revokes your Google grants too. You can also request deletion by email at any time.
Three categories of data are not removed by that action, and we want to state this plainly:
- Business records created from files you gave Suvi — such as inventory, product and catalogue data built from a spreadsheet you shared with it. These records remain yours and are maintained independently of Google once imported, so they are kept rather than deleted along with your Google data.
- Operational and diagnostic logs, and assistant conversation history. These may contain content quoted from your calendar, from messages you asked Suvi to send, or from files you gave it, and are retained on our ordinary retention schedule rather than removed by this action. This category also covers extracted document details, stored workflow step values, and memory items that have been merged with non-Google information, which can retain fragments that cannot be attributed back to a single source.
- The optional memory backup in your own repository. If you enabled the GitHub memory backup described above, that copy is under your control and is not removed by this action.
09Your Rights
Under the Hong Kong Personal Data (Privacy) Ordinance (PDPO) and depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you.
- Request correction or deletion of your data.
- Object to or restrict processing of your data.
- Withdraw consent at any time.
- Request data portability.
10Cookies
We use cookies and similar technologies to enhance your experience, analyze traffic, and personalize content. You can control cookie preferences through your browser settings.
11Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the updated policy on this page with a revised "Last updated" date.
12Governing Law
This Privacy Policy shall be governed by and construed in accordance with the laws of the Hong Kong Special Administrative Region. For any questions regarding your personal data rights under the Hong Kong Personal Data (Privacy) Ordinance (PDPO), you may also contact the Office of the Privacy Commissioner for Personal Data, Hong Kong.
13Contact Us
If you have questions about this Privacy Policy, please contact us:
- Company: SUVI PTE LIMITED
- Address: A Block, Hankow Centre, 47 Peking Road, Tsim Sha Tsui, Hong Kong
- Email: contact@suvi.ai