Navaa← All legal documents
Navaa legal

Privacy Policy

Last updated: October 7, 2026

Navaa is a product operated from India. In this policy, “Navaa”, “we” and “us” mean the business that operates Navaa, and “you” means the person using it.

We are the data fiduciary under India's Digital Personal Data Protection Act, 2023, and the data controller under the EU and UK GDPR or any other applicable law in a relevant jurisdiction, for the account information described below. Where you use Navaa to manage your team's work, you control the content in your workspace and we process it on your instructions.

This policy is available in English. If you would like it in another language listed in the Eighth Schedule to the Constitution of India, write to hello@navaa.app and we will provide one.

In short

  • We don't sell your data or use it for advertising.
  • There are no analytics, advertising or tracking scripts in Navaa.
  • There are no passwords. You sign in with a 6-digit code sent to your email, a one-time link, or Google.
  • The WhatsApp bot is automated software, not a person, and it uses AI to understand your messages.
  • Navaa is free during the private beta, so we collect no payment or billing information yet.
  • Google sign-in only asks for your basic profile. We never get access to your Gmail, Drive, Calendar or Contacts.
  • We don't ask for access to your camera, microphone, contacts, GPS location or push notifications.
  • We don't keep backups during the beta. Export anything you can't afford to lose.

1. What information we collect

1.1 Early access and sign-in

  • Email address you enter when you request early access. We use it to review your request and send you an approval link.
  • Access request status and the dates our team reviewed it.
  • Temporary sign-in codes and links:
    • 6-digit sign-in code: expires after 10 minutes and is cancelled after 5 wrong attempts.
    • Approval link: single use, expires after 24 hours.
    • Sign-in handoff code: single use, expires after 10 minutes.

1.2 Sign in with Google

If you choose to sign in with Google, Google shares the following with us, with your permission:

  • Your Google account email address and whether it is verified
  • Your name and profile picture link
  • Your Google user ID

We only request Google's basic sign-in permissions (openid, email and profile). We do not get access to your Gmail, Google Drive, Google Calendar, Google Contacts or any other Google data.

We use the sign-in tokens Google gives us only to confirm who you are, and we don't store them long-term. We keep only your Google user ID so we can match you to your Navaa account. If you sign in with Google using an email address that already has a Navaa account, we connect it to that account instead of creating a new one.

1.3 Your account and profile

  • Full name, shown to your teammates, in Navaa emails and WhatsApp messages, and in activity history
  • Email address, used for sign-in and service emails, and shown to your teammates
  • Job title
  • Role in your workspace (Owner or Member)
  • Account status, setup completion date and join date

1.4 Your workspace

  • Company or workspace name
  • Team size and use case, used to create your starter boards
  • Timezone and daily check-in schedule (time, days, on or off)
  • Subscription and paid access status

1.5 People you invite

Workspace owners can invite colleagues by entering their email addresses. We store the invited person's email address, who sent the invite and when it was sent, accepted or cancelled, and membership status (invited, active or removed).

The invited person receives an invite email. The invite link expires after 24 hours. If you invite someone, please make sure they would expect to hear from Navaa.

1.6 Your work content

  • Boards and statuses: names, icons, descriptions and order
  • Tasks: title, description, priority, labels, due date, status, creator, assignees, whether it was created on the web or WhatsApp, and completion date
  • Checklist items and comments
  • Activity history: a record of each task being created, edited, moved, deleted or commented on, and who did it
  • In-app notifications: what happened, which task, who caused it, and when you read it
  • Task search data: an AI-generated representation (an “embedding”) of each task's title and description, so the WhatsApp bot can find tasks by meaning

1.7 WhatsApp

If you connect your WhatsApp number, we collect:

  • Your phone number, confirmed by a 6-digit code we send you on WhatsApp (expires after 10 minutes, cancelled after 5 wrong attempts)
  • Message log: every message you send to the Navaa bot and every message it sends you, including phone numbers, message text, time, message ID, and the linked task
  • Processing records: what our AI understood from your message, for example the intent, task title, assignee and dates, and any errors
  • Open bot questions: when the bot is waiting for your reply. These are cleared after 10 minutes, or 24 hours for daily check-in replies
  • Daily check-in log: the date and whether the check-in was delivered, blocked or failed

If someone messages the Navaa bot from a number that isn't linked to a Navaa account, we still log that message.

1.8 Payments and billing

Navaa is free during the private beta, so we do not collect payment or billing information yet. When we introduce paid plans, payments will be processed by Razorpay and we will collect:

  • Billing contact: name, email address and phone number
  • Company details: company name, billing address, GSTIN, and VAT number for EU and UK customers
  • Payment references from Razorpay: order ID, payment ID and payment signature
  • Payment history: amount, currency, date, whether the payment succeeded or failed, and refunds
  • Subscription details: plan, start date, renewal date and cancellation
  • Payment method summary as Razorpay provides it: method type (card, UPI, netbanking or wallet) and, for cards, the card brand, last 4 digits and expiry date
  • Invoices and receipts

You will enter your payment details directly into Razorpay Checkout. Your full card number, CVV, UPI PIN and bank login details will never reach Navaa's servers.

1.9 Help and support

When you use Contact support or Report a problem, we collect your message and what you expected to happen, your name, email address and workspace name, and an optional screenshot (PNG, JPEG or WebP, up to 5 MB). Only the image you choose in your browser's file picker is uploaded.

1.10 Information collected automatically

  • Signed-in sessions: browser and device type, IP address, approximate city and country, and when the session was last active. Sessions end 7 days after they were last used, or when you sign out.
  • Approximate location: we work out your city and country from your IP address on our own server using an offline database, so your IP address isn't sent anywhere for this. It's shown only on your Active sessions page. We never use GPS.
  • Server logs: IP address, the page or API address requested, response status, referring page, browser details and time. Kept for 30 days.
  • Delivery logs: email recipient addresses and some WhatsApp delivery errors.

1.11 Cookies

We only use cookies that are strictly necessary for signing in. We don't use analytics or advertising cookies, and we don't use your browser's localStorage or sessionStorage.

CookiePurposeLasts
navaa_access_tokenProves who is signed in (cannot be read by page scripts)15 minutes
navaa_refresh_tokenRenews your session (cannot be read by page scripts)7 days
navaa_sessionTells the app a session exists; contains only “1”Your session
navaa_admin_tokenNavaa team admin console sign-in only8 hours
navaa_admin_sessionNavaa team admin console only; contains only “1”Admin session

Every cookie we set is strictly necessary to sign you in and keep your session secure, which is why Navaa does not show a cookie consent banner. Under EU and UK rules, consent is not required for cookies essential to deliver a service you have asked for. If that ever changes, we will ask for your consent before setting anything non-essential.

2. How we use your information

We use your information to create your account, sign you in and keep your session secure; run your workspace, including boards, tasks, comments, invitations and notifications; run the WhatsApp bot, including understanding your messages with AI and sending task notifications and daily check-ins; send service emails such as sign-in codes, access approvals, invites, support confirmations and workspace deletion notices; process payments, manage subscriptions and issue invoices; meet our legal, tax and accounting obligations; prevent abuse and keep Navaa secure; and answer your support requests.

We don't send marketing emails. We don't process your information for advertising or profiling, and no decision that affects you is made solely by automated means.

Where we rely on consent, you can withdraw it at any time. Withdrawing consent for processing that is essential to the service means we can no longer provide it, and your account will be closed.

3. AI features

The Navaa WhatsApp bot is automated software, not a person. It uses artificial intelligence to understand what you write. It tells you this when you first message it.

Navaa uses OpenAI's API to interpret your messages and to power task search.

What we send to OpenAI:

  • The text of the messages you send to the Navaa bot
  • Your recent conversation with the bot, so it understands follow-up replies
  • The names of the members of your workspace, so it can work out who a task should be assigned to
  • The current date and your workspace timezone, so it can understand words like “tomorrow” or “Friday”
  • Task titles and descriptions, so the bot can find tasks by meaning. This includes tasks created in the web app, not only tasks created through WhatsApp.

What we don't send to OpenAI: your email address or phone number; voice notes, images and files, which are never downloaded from WhatsApp; comments, checklists, activity history and support messages; and payment or billing information.

How OpenAI handles it. OpenAI processes this data under its API terms. Data sent through the API is not used to train or improve OpenAI's models unless the developer explicitly opts in, which we have not done. OpenAI keeps it for up to 30 days to run the service and check for misuse, unless legally required to keep it longer. OpenAI processes this data in the United States.

What this means for you. Please don't send the bot anything you wouldn't want a third party to process, such as passwords, bank details, identification numbers or health information. AI can misread a message, so check the tasks the bot creates. Task search is currently part of how Navaa works and can't be switched off. If you'd rather your workspace's task text wasn't processed this way, contact us at hello@navaa.app.

4. Who we share information with

We share personal information only with the providers below, and only to run Navaa. We don't sell your information.

ProviderWhat they receiveWhyLocation
SupabaseAll information stored in NavaaDatabase hostingTokyo, Japan
RailwayAll traffic to the web app, API and admin console, and server logsApp hostingUnited States
Meta (WhatsApp Business Platform)Phone numbers, messages in both directions, verification codes, notification messagesRunning the WhatsApp botIreland and United States
OpenAIAs listed in section 3Understanding messages and finding tasksUnited States
ResendRecipient email addresses and email contentSending service emailsUnited States
ImageKitSupport screenshots, stored as private filesFile storageUnited States
RazorpayPayment details you enter at checkout, order amount and billing contact detailsProcessing payments, once paid plans beginIndia
GoogleSign-in information when you use Sign in with GoogleSign-inUnited States

Razorpay and Google are independent controllers for the information they collect directly, and handle it under their own privacy policies. Razorpay Software Private Limited is PCI DSS compliant and processes payment data in India. See Razorpay's Privacy Policy and Google's Privacy Policy.

We may also share information where the law requires it, or to protect the rights and safety of Navaa, our users or others. If our business is acquired, we will tell you before your information moves.

5. Where your information is stored, and international transfers

Our database is hosted in Singapore. Some providers, including Railway, Meta, OpenAI, Resend and ImageKit, process information in the United States and other countries. Payment data handled by Razorpay is processed in India.

Where we transfer personal information out of the EU, UK or Switzerland, we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914) and, for UK transfers, the UK International Data Transfer Addendum. Our providers are bound by equivalent terms. You can ask for a copy of the safeguards we use by writing to hello@navaa.app.

6. Who can see your information

Teammates in your workspace can see your name, email address, job title, role and membership status, and every board, task, checklist, comment and activity entry in the workspace.

The workspace owner can also see pending invites, remove members, cancel invites, change boards and statuses, and set daily check-ins.

Task permissions. A task can be edited or moved by the workspace owner, the task creator or an assignee. A task can be deleted by the owner or the creator.

The Navaa team. Authorised team members can see, through our admin console, early access emails; each user's email, name, job title, WhatsApp number, workspace name, team size, use case and setup status; support requests and screenshots; and billing records. We use this access only to run Navaa and help you, and access is logged.

Other workspaces can't see anything in your workspace.

7. How we protect your information

Sign-in and sessions. There are no passwords to steal. Sign-in codes expire after 10 minutes and are cancelled after 5 wrong attempts. Sign-in links are single use and expire after 24 hours. Your session is kept in secure cookies that page scripts can't read: access lasts 15 minutes, and the 7-day refresh token is replaced every time it's used. Google tokens are used only to confirm your identity and aren't stored long-term. You can see every device signed in to your account and sign any of them out. We rate-limit sign-in code requests and checks by IP address to block guessing attacks.

Access control. Your workspace is determined by our server from your signed-in session, never from information sent by your browser, so one workspace can't reach another's data. Permissions are enforced on our server, not just hidden in the app.

WhatsApp. Every message from WhatsApp is checked against Meta's digital signature before we act on it. The bot only trusts a phone number after it has been confirmed with a code, and each number can belong to only one person.

Payments. Payment details are entered in Razorpay Checkout, so full card numbers, CVV and UPI PINs never reach our servers. Payment notifications from Razorpay are verified by signature before we update your subscription.

Files, emails and data handling. Everything sent to our app is validated. Screenshots are checked by their actual file content and size, stored as private files, and opened by our team only through links that expire after 1 hour. Text you type is escaped before it is placed into emails. API keys and database credentials stay on our servers and are never sent to your browser. Security headers are applied to every response, and cross-origin requests are rejected.

Infrastructure and our team. All information is encrypted in transit using HTTPS, and our database provider encrypts stored data at rest. Our admin console has its own separate sign-in, a securely hashed password, and sessions that expire after 8 hours.

If something goes wrong. No system can be completely secure. If a breach affects your personal information, we will tell you without undue delay, report it to the Data Protection Board of India within 72 hours as required, and where GDPR applies notify the relevant supervisory authority within 72 hours. If you believe you've found a security issue, please contact us at hello@navaa.app.

8. Your rights and choices

8.1 What you can do in the app

What you can doWhereWho
Change your name and job titleAvatar menu › ProfileEveryone
Connect or change your WhatsApp numberAvatar menu › ProfileEveryone
See signed-in devices and sign out othersAccount settings › Active sessionsEveryone
Sign outAvatar menuEveryone
Delete your accountAccount settingsEveryone. For owners, this deletes the whole workspace
Edit or move tasks and checklistsBoard, My Tasks, Calendar or task drawerOwner, task creator or assignee
Delete tasksTask drawerOwner or task creator
Remove members and cancel invitesTeamOwner
Delete boards and statusesBoard › ManageOwner
Update billing details or cancel your subscriptioncoming soonOwner

8.2 Disconnect Google

You can remove Navaa's access at any time in your Google Account settings, under Security, third-party apps and services. Your Navaa account stays active, and you can still sign in with a code sent to the same email address.

8.3 Stop WhatsApp messages

Reply STOP to the Navaa bot at any time and we will disconnect your number and stop messaging you. You can also disconnect it in your workspace settings, contact support, or block the Navaa number in WhatsApp. Daily check-ins are turned on or off by the workspace owner for the whole workspace.

8.4 Requests by email

For anything you can't do in the app, email hello@navaa.app. You can ask us to give you a copy of your information, correct it, delete information you can't delete in the app, or withdraw consent you have given us. You can also nominate another person to exercise these rights on your behalf if you die or become unable to do so.

We'll confirm your identity before acting on a request and reply within 30 days. We won't charge you for exercising these rights or treat you differently for doing so.

If you are in the EU, UK or Switzerland, you also have the right to restrict or object to processing and to receive your information in a portable format, and the right to complain to your data protection authority. In the UK that is the Information Commissioner's Office.

If you are in India and you're not satisfied with our response, you can contact our Founder, Gunjan (section 11) and then the Data Protection Board of India.

If you are in the United States, you may ask us what personal information we hold about you, and ask us to delete or correct it, using the same email address above. We do not sell or share personal information, and we do not process it for cross-context behavioural advertising.

8.5 What happens when you delete your account

If you are a member. Removed: your account (sign-in email and name), your Google sign-in link, all your sessions, your WhatsApp number and any pending codes, and open bot questions. Kept: a disabled member row with your email address and job title; tasks you created; your comments and task assignments; activity history showing your name; WhatsApp message logs and processing records; your daily check-in log; your support requests; and your early access email. Each of these is then deleted on the schedule in section 9.

If you are the workspace owner. You'll be asked to type the workspace name to confirm. Every member is signed out and receives an email. Removed: the workspace; every member row and invite; all boards, statuses, tasks, checklists and comments; activity history, notifications and check-in logs; open bot questions and message processing records; your account; and everyone's sessions. Kept: other members' accounts; WhatsApp message logs, no longer linked to the workspace; support requests; and early access emails, each deleted on the schedule in section 9.

Billing records, once paid plans begin, are kept for as long as Indian tax and accounting law requires, currently 8 years, even after your account or workspace is deleted.

To have information that is kept after deletion removed sooner, email hello@navaa.app.

9. How long we keep information

InformationHow long
Sign-in codes and WhatsApp verification codes10 minutes, or until used
Approval links and invite links24 hours, or until used
Open bot questions10 minutes; 24 hours for check-in replies
Signed-in sessions7 days after last use, or until you sign out
Account and profileUntil you change it or delete your account
Work content, activity history and notificationsWhile the workspace exists
Daily check-in logWhile your membership exists, then 12 months
WhatsApp message logs and AI processing records12 months from the date of the message
Support requests and screenshots24 months from the date the request is closed
Early access emails not converted to an account12 months from the request
Server logs & error reports30 days, per our hosting (Railway) and monitoring (Sentry) providers
Access and security logs12 months, as required under the DPDP Rules
Billing records and invoices, once paid plans begin8 years, as required by law
Data sent to OpenAIUp to 30 days, held by OpenAI

10. Children

Navaa is a work tool for people aged 18 and over. We don't knowingly collect information from anyone under 18. If you believe a child has given us information, contact us and we'll delete it.

11. Contact us

  • Gunjanfounderhello@navaa.app, gunjan@designstencil.com

We acknowledge grievances within 24 hours and resolve them within 15 days, as required under the Digital Personal Data Protection Act, 2023 and the Information Technology Rules.

12. Changes to this policy

We'll update this policy when we change how we handle information, and change the “Last updated” date above. If the changes are significant, we'll tell you by email or in the app at least 14 days before they take effect.

← All legal documentsRefund and Cancellation Policy →
© 2026 Navaa · Stencil Design Private Limitedhello@navaa.app