Privacy Policy
What Nevlar reads, what it keeps, who helps us run it, and how to download or delete all of it.
01What Nevlar is
Nevlar is an AI assistant that works inside your Google Workspace and, if you connect it, your Microsoft 365 account. You ask in plain language and it drafts emails, creates and edits documents, spreadsheets and slides, manages your calendar, finds files and emails, and runs automations you set up. Pulse, an optional feature, looks over your recent mail and calendar once each morning and suggests what needs you, with drafts ready for your approval.
This policy covers nevlar.com and the Nevlar app. By signing in, you agree to it.
02What we can access
Nevlar only gets what you approve on Google's or Microsoft's sign-in screen, and you can take it back at any time.
Your Google profile
Name, email address and profile picture, to sign you in.
Gmail
Read messages and attachments, and create drafts. Nevlar does not send mail by itself; you send each draft.
Drive, Docs, Sheets, Slides
Find, read, create and edit files when you ask. Files Nevlar makes are saved in your own Drive.
Calendar and Tasks
Read your schedule and tasks, and add or change events you ask for. Nobody is invited without you.
Contacts
Read-only, to match a name you type ("email Priya") to the right address.
Microsoft 365, if you connect it
Outlook mail, OneDrive files and Outlook calendar, under the same rules as Google.
Apps you connect, if any
Tools like Notion, Linear, GitHub or Zapier, only after you add them. Actions that change something there ask you first.
03What we keep
Nevlar reads your mail and files when a task needs them. It does not keep a copy of your mailbox or your Drive. This is what it does keep, and why.
| What | Why | How long |
|---|---|---|
| Account details | Name, email, Google ID, picture, plan, usage credits, timezone and preferences, to run your account. | While your account exists |
| Sign-in tokens | So Nevlar can act for you without asking you to sign in each time. Encrypted at rest. | Until you disconnect or delete your account |
| Chat history | Your conversations are saved to your account so you can come back to them. | Until you delete the chat or your account |
| Files you attach in chat | Kept with that chat so later messages in it can use them. | As long as the chat |
| Pulse cards | Short summaries, snippets and suggested drafts about the emails and events that need you. | Short-lived; cleared as you act on them |
| Memory notes | Facts that personalise Nevlar's answers, such as your role and preferences. You can see and delete them in your account panel. | Until you delete them |
| Automations and connected apps | The rules you set up, and the encrypted access tokens for apps you add. | Until you remove them |
| Security logs | Sign-ins, account deletions and similar events, to protect accounts and investigate abuse. | A limited period |
04How we use it
- To do what you ask: write the draft, build the deck, move the meeting.
- To run Pulse, if you use it: one scan each morning in your timezone, reading recent mail, calendar and files to suggest what needs you.
- To write emails that sound like you: when you ask for an email, Nevlar looks at a few of your own recent sent emails for tone and sign-off.
- To keep your account secure, apply plan limits, and fix problems.
05Services that help run Nevlar
To answer a request, Nevlar sends the relevant text (your message, plus the parts of emails or files the task needs) to an AI model provider. Which provider answers can vary for speed and reliability.
| Provider | What for |
|---|---|
| Google (Gemini), Groq, DeepSeek, Mistral AI, Cerebras, OpenRouter | AI models that read your request and write the answer |
| Google APIs, Microsoft Graph | Acting in your Google and Microsoft accounts |
| Tavily | Web search, when a task needs the web |
| Unsplash | Stock photos for slides and documents (only search words are sent) |
| Stripe | Payments. Your card details go to Stripe, never to us. |
| Oracle Cloud | The servers and database that run Nevlar |
These providers handle data under their own terms. Some AI providers' free tiers may use submitted content to improve their services; we are moving to tiers that don't. Please don't put passwords, card numbers or government ID numbers in chat.
06Google API Limited Use
Nevlar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data from Google APIs is used only to provide features you use in Nevlar. It is not used for advertising, not sold, and not used to train generalised AI models.
07Security
- All traffic is encrypted in transit (HTTPS with HSTS).
- Google, Microsoft and connected-app tokens are encrypted at rest with AES-256-GCM.
- Nothing goes out without you: emails are drafts, and actions in other apps ask first.
- Nevlar warns you about likely scam and phishing emails, and treats text inside emails and web pages as information, never as instructions.
No system is perfectly secure. If we learn of a breach that affects your data, we will tell you without undue delay. More detail is on the Security page.
08Download, delete, disconnect
- Download your data: in the app, open your account panel, go to Your data and press Download. You get everything Nevlar holds on you as a JSON file.
- Delete your account: account panel, Danger zone, Delete my account. This erases your profile, chats, memory, Pulse data and stored tokens.
- Disconnect Google: remove Nevlar at myaccount.google.com/permissions.
- Disconnect Microsoft: from your account panel, or at account.microsoft.com/privacy/app-access.
You can also email us to ask for a copy, a correction or the deletion of your data.
09Children
Nevlar is not directed to children under 13, and we do not knowingly collect their data. If you believe a child under 13 has signed up, contact us and we will delete the account.
10Changes to this policy
When this policy changes, we update the date at the top. If a change materially affects how your data is used, we will tell you in the app before it takes effect.
11Contact
Questions, requests or concerns about your data: