Navaa is a product operated from India. In this policy, “Navaa”, “we” and “us” mean the business that operates Navaa, and “you” means the person using it.
We are the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the data controller under the EU and UK GDPR or any other applicable law in a relevant jurisdiction, for the account information described below. Where you use Navaa to manage your team's work, you control the content in your workspace and we process it on your instructions.
This policy is available in English. If you would like it in another language listed in the Eighth Schedule to the Constitution of India, write to hello@navaa.app and we will provide one.
In short
- We don't sell your data or use it for advertising.
- There are no analytics, advertising or tracking scripts in Navaa.
- There are no passwords. You sign in with a 6-digit code sent to your email, a one-time link, or Google.
- The WhatsApp bot is automated software, not a person, and it uses AI to understand your messages.
- Navaa is free during the private beta, so we collect no payment or billing information yet.
- Google sign-in only asks for your basic profile. We never get access to your Gmail, Drive, Calendar or Contacts.
- We don't ask for access to your camera, microphone, contacts, GPS location or push notifications.
- We don't keep backups during the beta. Export anything you can't afford to lose.
1. What information we collect
1.1 Early access and sign-in
- Email address you enter when you request early access. We use it to review your request and send you an approval link.
- Access request status and the dates our team reviewed it.
- Temporary sign-in codes and links:
- 6-digit sign-in code: expires after 10 minutes and is cancelled after 5 wrong attempts.
- Approval link: single use, expires after 24 hours.
- Sign-in handoff code: single use, expires after 10 minutes.
1.2 Sign in with Google
If you choose to sign in with Google, Google shares the following with us, with your permission:
- Your Google account email address and whether it is verified
- Your name and profile picture link
- Your Google user ID
We only request Google's basic sign-in permissions (openid, email and profile). We do not get access to your Gmail, Google Drive, Google Calendar, Google Contacts or any other Google data.
We use the sign-in tokens Google gives us only to confirm who you are, and we don't store them long-term. We keep only your Google user ID so we can match you to your Navaa account. If you sign in with Google using an email address that already has a Navaa account, we connect it to that account instead of creating a new one.
1.3 Your account and profile
- Full name, shown to your teammates, in Navaa emails and WhatsApp messages, and in activity history
- Email address, used for sign-in and service emails, and shown to your teammates
- Job title
- Role in your workspace (Owner or Member)
- Account status, setup completion date and join date
1.4 Your workspace
- Company or workspace name
- Team size and use case, used to create your starter boards
- Timezone and daily check-in schedule (time, days, on or off)
- Subscription and paid access status
1.5 People you invite
Workspace owners can invite colleagues by entering their email addresses. We store the invited person's email address, who sent the invite and when it was sent, accepted or cancelled, and membership status (invited, active or removed).
The invited person receives an invite email. The invite link expires after 24 hours. If you invite someone, please make sure they would expect to hear from Navaa.
1.6 Your work content
- Boards and statuses: names, icons, descriptions and order
- Tasks: title, description, priority, labels, due date, status, creator, assignees, whether it was created on the web or WhatsApp, and completion date
- Checklist items and comments
- Activity history: a record of each task being created, edited, moved, deleted or commented on, and who did it
- In-app notifications: what happened, which task, who caused it, and when you read it
- Task search data: an AI-generated representation (an “embedding”) of each task's title and description, so the WhatsApp bot can find tasks by meaning
1.7 WhatsApp
If you connect your WhatsApp number, we collect:
- Your phone number, confirmed by a 6-digit code we send you on WhatsApp (expires after 10 minutes, cancelled after 5 wrong attempts)
- Message log: every message you send to the Navaa bot and every message it sends you, including phone numbers, message text, time, message ID, and the linked task
- Processing records: what our AI understood from your message, for example the intent, task title, assignee and dates, and any errors
- Open bot questions: when the bot is waiting for your reply. These are cleared after 10 minutes, or 24 hours for daily check-in replies
- Daily check-in log: the date and whether the check-in was delivered, blocked or failed
If someone messages the Navaa bot from a number that isn't linked to a Navaa account, we still log that message.
1.8 Payments and billing
Navaa is free during the private beta, so we do not collect payment or billing information yet. When we introduce paid plans, payments will be processed by Razorpay and we will collect:
- Billing contact: name, email address and phone number
- Company details: company name, billing address, GSTIN, and VAT number for EU and UK customers
- Payment references from Razorpay: order ID, payment ID and payment signature
- Payment history: amount, currency, date, whether the payment succeeded or failed, and refunds
- Subscription details: plan, start date, renewal date and cancellation
- Payment method summary as Razorpay provides it: method type (card, UPI, netbanking or wallet) and, for cards, the card brand, last 4 digits and expiry date
- Invoices and receipts
You will enter your payment details directly into Razorpay Checkout. Your full card number, CVV, UPI PIN and bank login details will never reach Navaa's servers.
1.9 Help and support
When you use Contact support or Report a problem, we collect your message and what you expected to happen, your name, email address and workspace name, and an optional screenshot (PNG, JPEG or WebP, up to 5 MB). Only the image you choose in your browser's file picker is uploaded.
1.10 Information collected automatically
- Signed-in sessions: browser and device type, IP address, approximate city and country, and when the session was last active. Sessions end 7 days after they were last used, or when you sign out.
- Approximate location: we work out your city and country from your IP address on our own server using an offline database, so your IP address isn't sent anywhere for this. It's shown only on your Active sessions page. We never use GPS.
- Server logs: IP address, the page or API address requested, response status, referring page, browser details and time. Kept for 30 days.
- Delivery logs: email recipient addresses and some WhatsApp delivery errors.
1.11 Cookies
We only use cookies that are strictly necessary for signing in. We don't use analytics or advertising cookies, and we don't use your browser's localStorage or sessionStorage.
| Cookie | Purpose | Lasts |
|---|---|---|
| navaa_access_token | Proves who is signed in (cannot be read by page scripts) | 15 minutes |
| navaa_refresh_token | Renews your session (cannot be read by page scripts) | 7 days |
| navaa_session | Tells the app a session exists; contains only “1” | Your session |
| navaa_admin_token | Navaa team admin console sign-in only | 8 hours |
| navaa_admin_session | Navaa team admin console only; contains only “1” | Admin session |
Every cookie we set is strictly necessary to sign you in and keep your session secure, which is why Navaa does not show a cookie consent banner. Under EU and UK rules, consent is not required for cookies essential to deliver a service you have asked for. If that ever changes, we will ask for your consent before setting anything non-essential.
2. How we use your information
We use your information to create your account, sign you in and keep your session secure; run your workspace, including boards, tasks, comments, invitations and notifications; run the WhatsApp bot, including understanding your messages with AI and sending task notifications and daily check-ins; send service emails such as sign-in codes, access approvals, invites, support confirmations and workspace deletion notices; process payments, manage subscriptions and issue invoices; meet our legal, tax and accounting obligations; prevent abuse and keep Navaa secure; and answer your support requests.
We don't send marketing emails. We don't process your information for advertising or profiling, and no decision that affects you is made solely by automated means.
Where we rely on consent, you can withdraw it at any time. Withdrawing consent for processing that is essential to the service means we can no longer provide it, and your account will be closed.
3. AI features
The Navaa WhatsApp bot is automated software, not a person. It uses artificial intelligence to understand what you write. It tells you this when you first message it.
Navaa uses OpenAI's API to interpret your messages and to power task search.
What we send to OpenAI:
- The text of the messages you send to the Navaa bot
- Your recent conversation with the bot, so it understands follow-up replies
- The names of the members of your workspace, so it can work out who a task should be assigned to
- The current date and your workspace timezone, so it can understand words like “tomorrow” or “Friday”
- Task titles and descriptions, so the bot can find tasks by meaning. This includes tasks created in the web app, not only tasks created through WhatsApp.
What we don't send to OpenAI: your email address or phone number; voice notes, images and files, which are never downloaded from WhatsApp; comments, checklists, activity history and support messages; and payment or billing information.
How OpenAI handles it. OpenAI processes this data under its API terms. Data sent through the API is not used to train or improve OpenAI's models unless the developer explicitly opts in, which we have not done. OpenAI keeps it for up to 30 days to run the service and check for misuse, unless legally required to keep it longer. OpenAI processes this data in the United States.
What this means for you. Please don't send the bot anything you wouldn't want a third party to process, such as passwords, bank details, identification numbers or health information. AI can misread a message, so check the tasks the bot creates. Task search is currently part of how Navaa works and can't be switched off. If you'd rather your workspace's task text wasn't processed this way, contact us at hello@navaa.app.
4. Who we share information with
We share personal information only with the providers below, and only to run Navaa. We don't sell your information.
| Provider | What they receive | Why | Location |
|---|---|---|---|
| Supabase | All information stored in Navaa | Database hosting | Tokyo, Japan |
| Railway | All traffic to the web app, API and admin console, and server logs | App hosting | United States |
| Meta (WhatsApp Business Platform) | Phone numbers, messages in both directions, verification codes, notification messages | Running the WhatsApp bot | Ireland and United States |
| OpenAI | As listed in section 3 | Understanding messages and finding tasks | United States |
| Resend | Recipient email addresses and email content | Sending service emails | United States |
| ImageKit | Support screenshots, stored as private files | File storage | United States |
| Razorpay | Payment details you enter at checkout, order amount and billing contact details | Processing payments, once paid plans begin | India |
| Sign-in information when you use Sign in with Google | Sign-in | United States |
Razorpay and Google are independent controllers for the information they collect directly, and handle it under their own privacy policies. Razorpay Software Private Limited is PCI DSS compliant and processes payment data in India. See Razorpay's Privacy Policy and Google's Privacy Policy.
We may also share information where the law requires it, or to protect the rights and safety of Navaa, our users or others. If our business is acquired, we will tell you before your information moves.
5. Where your information is stored, and international transfers
Our database is hosted in Singapore. Some providers, including Railway, Meta, OpenAI, Resend and ImageKit, process information in the United States and other countries. Payment data handled by Razorpay is processed in India.
Where we transfer personal information out of the EU, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum. Our providers are bound by equivalent terms. You can ask for a copy of the safeguards we use by writing to hello@navaa.app.
6. Who can see your information
Teammates in your workspace can see your name, email address, job title, role and membership status, and every board, task, checklist, comment and activity entry in the workspace.
The workspace owner can also see pending invites, remove members, cancel invites, change boards and statuses, and set daily check-ins.
Task permissions. A task can be edited or moved by the workspace owner, the task creator or an assignee. A task can be deleted by the owner or the creator.
The Navaa team. Authorised team members can see, through our admin console, early access emails; each user's email, name, job title, WhatsApp number, workspace name, team size, use case and setup status; support requests and screenshots; and billing records. We use this access only to run Navaa and help you, and access is logged.
Other workspaces can't see anything in your workspace.
7. How we protect your information
Sign-in and sessions. There are no passwords to steal. Sign-in codes expire after 10 minutes and are cancelled after 5 wrong attempts. Sign-in links are single use and expire after 24 hours. Your session is kept in secure cookies that page scripts can't read: access lasts 15 minutes, and the 7-day refresh token is replaced every time it's used. Google tokens are used only to confirm your identity and aren't stored long-term. You can see every device signed in to your account and sign any of them out. We rate-limit sign-in code requests and checks by IP address to block guessing attacks.
Access control. Your workspace is determined by our server from your signed-in session, never from information sent by your browser, so one workspace can't reach another's data. Permissions are enforced on our server, not just hidden in the app.
WhatsApp. Every message from WhatsApp is checked against Meta's digital signature before we act on it. The bot only trusts a phone number after it has been confirmed with a code, and each number can belong to only one person.
Payments. Payment details are entered in Razorpay Checkout, so full card numbers, CVV and UPI PINs never reach our servers. Payment notifications from Razorpay are verified by signature before we update your subscription.
Files, emails and data handling. Everything sent to our app is validated. Screenshots are checked by their actual file content and size, stored as private files, and opened by our team only through links that expire after 1 hour. Text you type is escaped before it is placed into emails. API keys and database credentials stay on our servers and are never sent to your browser. Security headers are applied to every response, and cross-origin requests are rejected.
Infrastructure and our team. All information is encrypted in transit using HTTPS, and our database provider encrypts stored data at rest. Our admin console has its own separate sign-in, a securely hashed password, and sessions that expire after 8 hours.
If something goes wrong. No system can be completely secure. If a breach affects your personal information, we will tell you without undue delay, report it to the Data Protection Board of India within 72 hours as required, and where GDPR applies notify the relevant supervisory authority within 72 hours. If you believe you've found a security issue, please contact us at hello@navaa.app.
8. Your rights and choices
8.1 What you can do in the app
| What you can do | Where | Who |
|---|---|---|
| Change your name and job title | Avatar menu › Profile | Everyone |
| Connect or change your WhatsApp number | Avatar menu › Profile | Everyone |
| See signed-in devices and sign out others | Account settings › Active sessions | Everyone |
| Sign out | Avatar menu | Everyone |
| Delete your account | Account settings | Everyone. For owners, this deletes the whole workspace |
| Edit or move tasks and checklists | Board, My Tasks, Calendar or task drawer | Owner, task creator or assignee |
| Delete tasks | Task drawer | Owner or task creator |
| Remove members and cancel invites | Team | Owner |
| Delete boards and statuses | Board › Manage | Owner |
| Update billing details or cancel your subscription | coming soon | Owner |
8.2 Disconnect Google
You can remove Navaa's access at any time in your Google Account settings, under Security, third-party apps and services. Your Navaa account stays active, and you can still sign in with a code sent to the same email address.
8.3 Stop WhatsApp messages
Reply STOP to the Navaa bot at any time and we will disconnect your number and stop messaging you. You can also disconnect it in your workspace settings, contact support, or block the Navaa number in WhatsApp. Daily check-ins are turned on or off by the workspace owner for the whole workspace.
8.4 Requests by email
For anything you can't do in the app, email hello@navaa.app. You can ask us to give you a copy of your information, correct it, delete information you can't delete in the app, or withdraw consent you have given us. You can also nominate another person to exercise these rights on your behalf if you die or become unable to do so.
We'll confirm your identity before acting on a request and reply within 30 days. We won't charge you for exercising these rights or treat you differently for doing so.
If you are in the EU, UK or Switzerland, you also have the right to restrict or object to processing and to receive your information in a portable format, and the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office.
If you are in India and you're not satisfied with our response, you can contact our Founder, Gunjan (section 11) and then the Data Protection Board of India.
If you are in the United States, you may ask us what personal information we hold about you, and ask us to delete or correct it, using the same email address above. We do not sell or share personal information, and we do not process it for cross-context behavioural advertising.
8.5 What happens when you delete your account
If you are a member. Removed: your account (sign-in email and name), your Google sign-in link, all your sessions, your WhatsApp number and any pending codes, and open bot questions. Kept: a disabled member row with your email address and job title; tasks you created; your comments and task assignments; activity history showing your name; WhatsApp message logs and processing records; your daily check-in log; your support requests; and your early access email. Each of these is then deleted on the schedule in section 9.
If you are the workspace owner. You'll be asked to type the workspace name to confirm. Every member is signed out and receives an email. Removed: the workspace; every member row and invite; all boards, statuses, tasks, checklists and comments; activity history, notifications and check-in logs; open bot questions and message processing records; your account; and everyone's sessions. Kept: other members' accounts; WhatsApp message logs, no longer linked to the workspace; support requests; and early access emails, each deleted on the schedule in section 9.
Billing records, once paid plans begin, are kept for as long as Indian tax and accounting law requires, currently 8 years, even after your account or workspace is deleted.
To have information that is kept after deletion removed sooner, email hello@navaa.app.
9. How long we keep information
| Information | How long |
|---|---|
| Sign-in codes and WhatsApp verification codes | 10 minutes, or until used |
| Approval links and invite links | 24 hours, or until used |
| Open bot questions | 10 minutes; 24 hours for check-in replies |
| Signed-in sessions | 7 days after last use, or until you sign out |
| Account and profile | Until you change it or delete your account |
| Work content, activity history and notifications | While the workspace exists |
| Daily check-in log | While your membership exists, then 12 months |
| WhatsApp message logs and AI processing records | 12 months from the date of the message |
| Support requests and screenshots | 24 months from the date the request is closed |
| Early access emails not converted to an account | 12 months from the request |
| Server logs & error reports | 30 days, per our hosting (Railway) and monitoring (Sentry) providers |
| Access and security logs | 12 months, as required under the DPDP Rules |
| Billing records and invoices, once paid plans begin | 8 years, as required by law |
| Data sent to OpenAI | Up to 30 days, held by OpenAI |
10. Children
Navaa is a work tool for people aged 18 and over. We don't knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we'll delete it.
11. Contact us
- Gunjanfounderhello@navaa.app, gunjan@designstencil.com
We acknowledge grievances within 24 hours and resolve them within 15 days, as required under the Digital Personal Data Protection Act, 2023 and the Information Technology Rules.
12. Changes to this policy
We'll update this policy when we change how we handle information, and change the “Last updated” date above. If the changes are significant, we'll tell you by email or in the app at least 14 days before they take effect.