Privacy Policy

Effective Date: 5 November 2025
Last Updated: 7 August 2026

Kenvo (“we,” “us,” or “our”) is operated by YOX64 HIVE SRL, a company registered in the European Union. This Privacy Policy explains how we collect, use, and protect your personal information when you use Kenvo, including when you connect your Gmail or Google Contacts account.


1. Information We Collect

a. Google User Data

Kenvo offers two separate, independently optional Google integrations. Neither is required to use Kenvo, and connecting one does not connect the other:

  • Gmail — reads message metadata only (email headers) to discover who you actually correspond with and how often. You may connect more than one Gmail account.
  • Google Contacts — imports contacts saved in your Google account.

Google OAuth Scopes Used

Kenvo requests the following permissions from your Google account. Every permission we request is read-only:

1. Read-Only Access to Your Gmail Messages

https://www.googleapis.com/auth/gmail.readonly

  • What it does: Grants read access to your Gmail mailbox. Google does not offer a narrower permission that supports the filtered searches Kenvo relies on, so this is the minimum scope that makes the feature possible.
  • Why we need it: To identify the people you genuinely correspond with, and to measure how frequently, so Kenvo can rank your real relationships instead of treating every contact as equal.
  • How we use it: We list message IDs matching filtered queries (for example, sent mail, and received mail excluding spam, trash, and promotional categories), then request each message with format=metadata and a fixed allowlist of headers.
  • What data we access: Only these message headers — sender, recipients (To, Cc), date, reply-to, and a set of technical headers used to identify bulk mail, newsletters, and automated notifications.
  • What we never access: We do not read, request, or store message bodies, subject lines, or attachments. Our requests are technically incapable of returning them.
  • When we access it: When you first connect a Gmail account, and on subsequent syncs you trigger from Settings → Integrations.

2. Your Basic Google Account Identity

openid.../auth/userinfo.email.../auth/userinfo.profile

  • What it does: Identifies which Google account you just connected.
  • Why we need it: Kenvo supports connecting several Gmail accounts. We need a stable account identifier to tell them apart, avoid connecting the same account twice, and label each one in Settings so you know what you have connected.
  • What data we access: Your Google account ID and email address.

What We Store From Your Gmail Account

Kenvo does not keep a copy of your mailbox. From the headers described above we derive and store only:

  • Contact identities: Email addresses, and display names where present, of people you have exchanged mail with.
  • Interaction counts: The number of one-to-one messages sent and received per contact, and the dates of your first and most recent exchange.
  • LinkedIn notification records: Where a received message is a LinkedIn messaging notification, we store the Gmail message identifier and the matched contact, so the interaction counts toward that relationship’s strength. We store the identifier only — never the notification’s contents.
  • Connection credentials: The OAuth tokens for each connected account, and that account’s email address.

Addresses recognised as newsletters, mailing lists, no-reply senders, and other bulk mail are filtered out and are not added to your contacts.

Kenvo also requests the following permissions to import your Google Contacts:

3. Read-Only Access to Your Google Contacts

https://www.googleapis.com/auth/contacts.readonly

  • What it does: Provides read-only access to contacts you have manually saved in your Google Contacts.
  • Why we need it: To import your personal contacts into Kenvo’s private contacts database.
  • How we use it: Calls the Google People API endpoint /v1/people/me/connections to retrieve contact information.
  • What data we access: Names, email addresses, phone numbers, organizations, profile photos, and physical addresses.
  • When we access it: Only when you click the “Import Contacts” button in Settings → Integrations.

4. Read-Only Access to Your “Other Contacts”

https://www.googleapis.com/auth/contacts.other.readonly

  • What it does: Provides read-only access to contacts that Google automatically saved from your email interactions.
  • Why we need it: To import people you’ve communicated with via email, providing broader contact coverage beyond manually saved contacts.
  • How we use it: Calls the Google People API endpoint /v1/otherContacts to retrieve contact information.
  • What data we access: Basic contact information (names and email addresses) from your email interactions.
  • When we access it: Only when you click the “Import Contacts” button in Settings → Integrations.

How Google Data Is Used

Google data is stored in your private contacts database and used only to power features you can see and use in Kenvo:

  • Personal Contact Management: Contacts discovered from your Gmail correspondence, and contacts imported from Google Contacts, are added to your private contacts list, where you can view, search, edit, and delete them.
  • Connection Strength: Your one-to-one email counts and LinkedIn messaging interactions are scored to estimate how strong each relationship is, so Kenvo can tell a close colleague apart from someone you emailed once.
  • Search and Explore: Your contacts, including the relationship signals above, are searchable and can be queried in conversational form through Kenvo’s Explore feature.

Your Gmail data is used only for your own account. It is never pooled with other users’ data, exposed to other Kenvo users, or used to build any shared or general-purpose dataset.

Data Storage, Control, and Deletion

You maintain full control over your Google data:

  • Secure Storage: All contact data and OAuth tokens are encrypted and securely stored in Kenvo’s database within the European Union.
  • Disconnect at Any Time: You can disconnect any connected Google or Gmail account from Settings → Integrations. Each Gmail account is disconnected independently. Disconnecting revokes Kenvo’s access to that account, deletes the stored tokens, and stops all future syncing.
  • Manual Contact Deletion: You can delete individual contacts from your private contacts list at any time.
  • Token Revocation: You can revoke Kenvo’s access to your Google account directly from your Google Account Permissions page.
  • Account Deletion: If you delete your Kenvo account, all Google-derived data — imported contacts, Gmail-discovered contacts, email interaction counts, LinkedIn notification records, and OAuth tokens — is permanently deleted within 30 days.

Important: Kenvo only reads from your Google account. We never modify, delete, or write any data back to it, and we never send email on your behalf. Every permission we request is read-only, so your mailbox and contacts remain unchanged.

b. Other Data You Provide

We also collect:

  • Contacts you import manually or via LinkedIn
  • Basic account information (such as name and email)
  • Usage data through Mixpanel for analytics purposes

2. How We Use Your Information

We use your information to:

  • Provide and improve the Kenvo platform
  • Display and manage your network and contacts
  • Help you find relevant connections
  • Analyze anonymized usage data to enhance the product experience

We do not:

  • Sell your data
  • Use your Google user data for advertising or marketing
  • Transfer your Google user data to advertising platforms or data brokers
  • Use your Google user data to create, train, or improve any generalized or shared artificial intelligence or machine learning model
  • Use your Google user data for creditworthiness or lending-eligibility assessments

Artificial Intelligence Features

Kenvo uses AI to power features such as conversational search over your contacts. Where a feature requires it, contact information — which may include data derived from your Gmail metadata, such as a contact’s email address or how often you correspond — is sent to our AI and search providers to generate a response for you, in that moment.

We contractually require that these providers do not use your data to train their models, and we do not use it to train ours. Your Google user data is never used to build a model, index, or dataset that serves anyone other than you.


3. Data Sharing

We never sell your personal or contact data, and we never share it with advertisers or data brokers. We share it only in these cases:

  • Service providers who operate Kenvo on our behalf, under contractual data protection obligations, and only to deliver features you use. These are our cloud hosting and database provider, our search infrastructure provider, and the AI providers behind Kenvo’s conversational and enrichment features.
  • As required by law or to comply with valid legal process.
  • To detect, prevent, or address fraud, abuse, security, or technical issues.
  • In a merger or acquisition, in which case we will obtain your explicit consent before your Google user data is transferred.

Data derived from Google APIs is shared with these providers only to the extent needed to deliver a Kenvo feature you are using. It is never shared for their own purposes, and never for advertising.


4. Data Storage and Retention

Your Google data is securely stored in our database for as long as your account remains active and the integration remains connected.

Disconnecting a Gmail account revokes our access and deletes that account’s stored OAuth tokens immediately. If you revoke Google access or delete your Kenvo account, all associated Google-derived data — contacts, email interaction counts, LinkedIn notification records, and tokens — is permanently deleted within 30 days.

Because we never retrieve message bodies, subjects, or attachments, no Gmail message content exists in our systems to retain or delete.


5. Data Security

We implement appropriate technical and organizational measures to protect your information from unauthorized access, loss, misuse, or disclosure. Access to Google user data is limited to the minimal functionality necessary to provide the service. OAuth tokens and contact data are encrypted, and access to production systems is restricted and logged.

Human Access to Your Data

Kenvo staff do not read your Google user data. Your data is processed automatically. A human will only ever access it if:

  • You have given us your explicit, affirmative permission — for example, to investigate a support issue you have reported
  • It is necessary for security purposes, such as investigating abuse or a suspected breach
  • We are required to do so to comply with applicable law
  • The data has been aggregated and anonymized, and is used for internal operations such as capacity planning

6. User Control and Deletion

You can:

  • Disconnect any individual Gmail or Google account at any time from Settings → Integrations inside Kenvo
  • Revoke Google access at any time from your Google Account Permissions page
  • Request deletion of your Kenvo account and data by contacting werner@kenvo.ai
  • Request access, correction, or export of your data under GDPR

7. Cookies and Analytics

We use Mixpanel to collect anonymized usage data to help us understand how users interact with Kenvo. Mixpanel may use cookies or similar technologies. You can opt out of Mixpanel tracking by following the instructions on Mixpanel’s opt-out page.


8. International Data Transfers

Your information may be processed and stored within the European Union. If data is transferred outside the EU, we ensure it is protected by appropriate safeguards consistent with GDPR requirements.


9. Legal Basis for Processing (GDPR)

We process your personal data under the following legal bases:

  • Consent: When you connect your Google account or import LinkedIn data
  • Contractual necessity: To deliver the Kenvo service you requested
  • Legitimate interest: To analyze usage data and improve our platform

10. Children's Privacy

Kenvo is not directed to individuals under 16 years old. We do not knowingly collect data from minors. If you believe a minor has provided us data, please contact us for deletion.


11. Changes to This Policy

We may update this Privacy Policy periodically. Updates will be posted on this page with the revised “Effective Date.” If material changes occur, we will notify users by email or through the app.


12. Contact Us

If you have any questions or concerns about this Privacy Policy or your data, please contact:

YOX64 HIVE SRL
Email: werner@kenvo.ai
Website: https://kenvo.ai

13. Google API Services Disclosure

Kenvo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Because Kenvo requests a restricted scope (gmail.readonly), we specifically affirm that:

  • We limit our use of Google user data to providing and improving user-facing features that are prominent in Kenvo’s interface
  • We transfer Google user data only as necessary to provide or improve those features, to comply with applicable law, or as part of a merger or acquisition following your explicit consent
  • We do not use or transfer Google user data for serving advertisements, and we do not sell it or transfer it to data brokers or information resellers
  • We do not allow humans to read Google user data, except with your affirmative agreement for specific messages, for security purposes, to comply with applicable law, or where the data is aggregated and anonymized for internal operations
  • We do not use Google user data to create, train, or improve any generalized artificial intelligence or machine learning model

For more details, see: https://developers.google.com/terms/api-services-user-data-policy

← Back to Kenvo