Privacy Policy
NuvoMail is committed to protecting your privacy. This policy outlines how we collect, use, and protect your data — including email content, contacts, and account information — in compliance with applicable privacy laws.
1. Scope and Our Role
Who Operates NuvoMail
NuvoMail is operated by Nuvo Innovations. This Privacy Policy explains how Nuvo Innovations collects, uses, discloses, retains, and protects personal information when you visit, register for, administer, or use NuvoMail.
Organization and Service-Provider Roles
For email, contact, employee, customer, and other workspace data submitted by an organization, that organization generally decides why and how the information is used, and Nuvo Innovations processes it to provide the Service. Nuvo Innovations separately determines how account, billing, security, support, and service-usage information is used for its own legitimate business purposes and legal obligations.
Organization Responsibilities
Organizations using NuvoMail are responsible for providing any notices, obtaining any consents, responding to recipient or employee requests, and establishing a lawful basis for the personal information they upload or transmit through the Service.
2. Information We Collect
Account Data
We collect information such as your name, email address, authentication information, organization membership, roles, preferences, and account activity. Authentication providers may process passwords or other login credentials on our behalf.
Organization, Domain, and Integration Data
We collect organization and group information, group timezones, connected domains, approved sender identities, mailbox assignments, provider connection details, API credentials, webhook configuration, DNS or domain-readiness information, and related administrative and audit records.
Email Content and Metadata
When email is composed, sent, received, synchronized, or managed through NuvoMail, we may process subjects, bodies, sender and recipient addresses, Reply-To information, headers, attachments, delivery events, timestamps, thread relationships, read or workflow state, and provider identifiers.
Contacts and Business Context
We process contact names, email addresses, company information, job titles, phone numbers, notes, and any customer, project, invoice, location, or other business context your organization chooses to associate with communications.
Usage, Device, and Support Data
We may collect IP address, browser and device information, timestamps, diagnostic logs, feature usage, security events, support communications, and information submitted through feedback, abuse, or help requests.
Billing Data
We and our payment processors may collect subscription, transaction, billing-contact, payment-status, and tax information. Nuvo Innovations generally does not receive complete payment-card numbers from the payment processor.
3. How We Use Information
Providing the Service
We use information to authenticate users; create and administer organizations, domains, identities, mailboxes, contacts, drafts, messages, and attachments; transmit and receive email; display delivery information; operate collaboration features; process billing; and provide requested support.
Security and Reliability
We use account, provider, usage, and diagnostic information to prevent fraud and abuse, authenticate webhooks, investigate complaints, enforce rate and storage limits, protect accounts and infrastructure, troubleshoot failures, maintain backups, and improve availability.
Communication and Administration
We use contact information to send account, security, billing, service, support, and legal notices. Where required, we obtain consent before sending optional marketing communications, and you may opt out of those communications.
Service Improvement and Analytics
We may analyze service usage and operational metrics to understand performance and improve features. Where practical, we use aggregated or de-identified information. We do not use customer email content to create advertising profiles or sell it to data brokers.
Legal and Business Purposes
We may use information to comply with law, respond to valid legal process, protect rights and safety, establish or defend legal claims, enforce agreements, and evaluate or complete a financing, reorganization, merger, acquisition, or sale of assets subject to appropriate confidentiality protections.
4. Workspace Access and Customer Instructions
Team Visibility
Workspace owners and administrators determine who may join an organization and configure access to addresses and communications. Information may be visible to authorized coworkers, administrators, mailbox members, assignees, or group members according to the organization's configuration and the Service's permission model.
Customer Instructions
We process workspace data according to the organization's instructions, these Terms, and applicable law. If you are an employee, contact, customer, or recipient seeking access, correction, or deletion of information held by an organization, you should normally contact that organization first.
Administrative Oversight
Organization administrators may manage membership, provider connections, domains, sender identities, shared addresses, retention, and audit information. Administrators must use that access lawfully and only for legitimate organizational purposes.
6. Retention and Deletion
Retention Periods
We retain information for as long as reasonably necessary to provide the Service, maintain security and continuity, comply with customer instructions and contractual commitments, resolve disputes, enforce agreements, and satisfy legal, accounting, or reporting obligations. Retention may vary by data type, workspace settings, plan, and legal requirements.
Deletion Requests and Account Closure
Authorized users may delete certain information through the Service or request account or workspace deletion. Deletion may be delayed where needed for backup rotation, security investigations, legal holds, fraud prevention, billing records, or other lawful obligations. We may retain de-identified information that can no longer reasonably identify an individual.
Provider Copies
Deleting information from NuvoMail does not necessarily delete copies already transmitted to recipients, email providers, recipient servers, customer-controlled systems, or other independent third parties. Their retention is governed by their own systems and policies.
7. Security
Safeguards
We use administrative, technical, and organizational safeguards designed to protect information, including authentication, tenant scoping, access restrictions, private storage, logging, and secure transport where supported. Provider credentials are restricted to server-side processing and are not intended to be displayed back to ordinary users after configuration.
No Absolute Security
No internet service, transmission, or storage system is completely secure. You are responsible for account security, appropriate permissions, endpoint security, credential rotation, domain configuration, and promptly reporting suspected compromise.
Security Incidents
If we become aware of a security incident affecting personal information, we will investigate and provide notices to affected organizations, individuals, regulators, or others when required by applicable law.
8. Privacy Choices and Rights
Access, Correction, Export, and Deletion
Depending on your location and relationship with NuvoMail, you may have rights to request access, correction, export, deletion, restriction, objection, or withdrawal of consent. These rights may be subject to identity verification, organizational authority, legal exceptions, and the rights of others.
How to Make a Request
Account holders may use available product controls or contact support@nuvomail.app. For workspace data controlled by an organization, we may direct your request to that organization or assist it in responding. You may also have the right to complain to an applicable privacy regulator.
Marketing Choices
You may opt out of optional NuvoMail marketing messages using the unsubscribe method provided. You may still receive transactional, security, billing, support, and legal communications necessary for the Service.
9. Policy Changes and Contact
Updates
We may update this Policy to reflect changes to NuvoMail, providers, law, or our practices. We will post the updated version with a new effective date and provide additional notice of material changes when required by law.
Contact
Questions, privacy requests, and complaints may be sent to support@nuvomail.app. Please do not include passwords, provider API keys, or unnecessary sensitive message content in your request.
This document was last updated on September 1, 2026. Questions? Contact us at support@nuvomail.app