Conversaya

Privacy policy

Last updated 16 August 2026

This covers the Conversaya installation at conversaya.com. Anyone running their own copy of Conversaya on their own servers holds their own data and answers for it themselves, and this policy doesn't speak for them.

What we ask Google for

These are the permissions the app requests, exactly as Google names them on the consent screen. The list below is read out of the same file the sign-in code reads, so it can't say one thing here and ask for another there.

openid
When you sign inProves to us that the Google account signing in is yours. It carries no mail and no calendar.
email
When you sign inYour address becomes your account here, and it is how a colleague finds you in the workspace.
profile
When you sign inYour name and profile picture, shown beside anything you write or approve.
https://www.googleapis.com/auth/gmail.readonly
When you sign inReads the mail in your mailbox so each message is filed against the person and company it belongs to, and so a reply stops the sequence that person is in. A bounce notice from Google is read the same way, and the address it names is blocked from then on.
https://www.googleapis.com/auth/calendar.readonly
When you sign inReads your calendar so a meeting booked with a tracked contact shows up on their record, along with whether they accepted. Nothing is ever written to your calendar.
https://www.googleapis.com/auth/gmail.send
Only if you turn sending on, from SettingsSends a message from your own address, either one you wrote or one you approved. We show you the exact mailbox before you grant it, and it is never asked for at sign-in.

We ask for nothing wider. The app can't delete a message, move one, change a label or touch a draft, and it can't write to your calendar. If you connect Outlook instead, the Microsoft equivalents are the only two we use: read your mail, and send mail once you turn sending on.

What we store from your mailbox

For a message involving somebody your workspace tracks, we keep the subject, the full text of the message, a short preview cut from that text, who it came from, everyone it was addressed to, when it was sent, and the id the provider gave it. Threads are grouped by the message id in the mail headers. We don't download or store attachments, and there is no column to put one in.

We store the full text on purpose rather than by accident. A rep reading half a conversation is the problem this replaces, and two of the safety behaviours read the text too: a reply stops the sequence the recipient is in, and a bounce notice from the mail server permanently blocks the address it names.

An email your team sends through Conversaya is stored the same way, with its subject, its text, the address it went to and the address it went from.

What we store from your calendar

The title, the description, the location, the video call link, the start and end times, whether it was cancelled, the organiser's address, and for each person invited their address, their name and whether they accepted. That last part is the whole point: it's how a booked meeting shows on a contact's record and how the team knows the person turned up.

Who else sees it

The assistant reads the messages filed against a contact. To do that it sends their text to a language model, reached through the Vercel AI Gateway. The model this installation uses by default is zai/glm-5.2, and an administrator can pick a different one for their workspace. The text goes there to answer that one request. No part of this application sends your mail anywhere to train or fine-tune a model, and there is no dataset being built out of it.

Nothing else receives mail or calendar text. A few optional services can be switched on by whoever runs the installation, and each of them gets only what it needs to do its one job: a name and a company domain to find or verify a business email address, a LinkedIn handle to read a public profile, and a logo or profile picture to store. With their keys unset they are absent, and the features that use them are gone with them.

We don't sell or rent any of it, and nothing here is used for advertising.

Google's Limited Use rules

Conversaya's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

How long we keep it

There is no timer on mail or calendar data. We keep it until you delete it or until the workspace is deleted, and we'd rather say that plainly than publish a retention period the software doesn't enforce.

One thing does expire on a schedule: if your team installs the Conversaya tracking script on its own website, the page views and form submissions it records are swept after 90 days.

How to get rid of it

Both controls are in Settings, under Connections, and both are yours to press without asking us.

  • Disconnect the mailboxWe send your token to Google's revocation endpoint and refuse to finish if Google doesn't confirm, so the access is gone on Google's side and not only on ours. Syncing stops, sending stops, and any campaign pinned to that mailbox is paused rather than thrown away. Messages we already synced stay until you delete them. Microsoft publishes no revocation endpoint, so for Outlook we clear our copy of the token and the screen tells you to remove the consent in your Microsoft account.
  • Delete the data we syncedThis removes every message your account brought in and every calendar event it brought in. A thread nobody else synced goes with them. A thread a colleague also synced keeps their messages and is rebuilt around what's left, because their copy is not yours to delete. It doesn't remove emails your team sent through Conversaya, which are records of what your team did rather than a copy of your inbox.

Deleting a whole workspace is not a button in the app, on purpose, because one wrong click would take everyone's work with it. Write to privacy@conversaya.com from the address on the account and we'll do it, along with a copy of what we hold if you want one first.

How the connection is protected

The token that lets us read your mailbox is encrypted where it sits, and no page in the app will hand one to a browser. It is used only inside the server process that talks to Google, it is never written to a log, and the assistant never receives one. When it expires we refresh it in the same place.

What we measure about the product

Product analytics ship switched off, and this installation has not turned them on. If we do, what goes out is counts and statuses: how many contacts, how many messages arrived, which version is running, what class of error occurred. The list of properties allowed to leave is written in the code and anything not on it is dropped before an event is built. No subject, no message text, no address and no name is on that list, and the install is identified by a random id with no person attached to it.

Cookies

One cookie, for your session, so you stay signed in. No advertising cookies and no third-party trackers on this site.

Getting in touch

Questions about any of this, a request for a copy of your data, or a deletion: privacy@conversaya.com. If we change this policy we'll change the date at the top, and anything that widens what we read from your mailbox needs your consent again through Google before it can happen.