Privacy Policy

Last updated: 28 September 2026

This policy explains what NetivOS collects, why, and the control you have over it. It is written to be read, not to hide behind.

Who operates NetivOS

NetivOS is operated by Epicenter Consulting ("we", "us"). NetivOS is a team execution and personal focus platform: it helps organisations run their vision, goals, metrics and coaching, and helps individuals plan their day, goals, rhythm and follow-ups.

You can reach us at [email protected].

What we collect

  • Account details — your name, email address and sign-in credentials (or your Google account identity if you sign in with Google).
  • Workspace content — the content you and your organisation enter: vision plans, quarterly goals (Rocks), KPI entries, blockers, role maps, coaching notes and projects.
  • Focus content — your personal goals, daily rhythm, steps, captures, waiting-on items and settings such as your time zone.
  • Routing and people directory — names, email addresses and roles you enter for your clients, projects and people, used to route your follow-ups. These are visible only to you, and to an assistant only where you have shared access.
  • Google Calendar data — when you connect a Google account, we store OAuth tokens that let us read and write calendar events on your behalf, plus the event data needed to show your schedule, detect conflicts and create the events you ask for.
  • Meeting data — when you connect Fathom, Fireflies or Granola, we ingest meeting titles, participants, summaries and action items from your recordings. When more than one service captures the same meeting, we keep it once. We do not store full transcripts; raw content is trimmed to the summary and action items before it is kept.
  • Push subscriptions — the browser push endpoint and keys needed to send you notifications you have switched on.

Connected-service keys

You can save your own API keys for Fathom, Fireflies and Granola. They are encrypted at rest, never shown back in the app after saving and never logged. Our servers use them only to fetch your meeting data. Removing a key or deleting your account deletes its saved key.

AI processing

Meeting summaries and the requests you send to the Focus assistant are processed by AI models through Lovable's AI gateway to extract follow-ups and answer your requests. The meeting extraction uses an OpenAI model and the assistant uses a Google Gemini model through that gateway. We do not use this content to train models.

Why we collect it

Everything above exists to provide the service: showing you your own data, keeping it in sync across your devices, connecting your calendar and meeting tools, sending notifications you asked for, and keeping your organisation's data separate from everyone else's. We do not use your content for advertising, profiling or any purpose unrelated to running NetivOS.

Google API disclosure

NetivOS's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In practice: Google user data is used only to provide the calendar features you switch on (reading your events, creating and updating events you ask for, and detecting scheduling conflicts). It is never used for advertising, never sold, and never shared with third parties for their own purposes.

Where your data is stored

Data is stored in Supabase-hosted databases (in the EU or US region applicable to your workspace) and served through Lovable's hosting infrastructure. Access is enforced per account and per organisation; one workspace's data is not visible to another.

How long we keep it

We keep your data for as long as your account or your organisation's workspace is active. When you delete an item it is removed from the live system. Disconnecting a calendar removes the stored events that came from it.

Who we share it with

We do not sell or share your data with anyone for their own use. The service runs on a small set of sub-processors, each handling only what is needed to operate their part:

  • Supabase — database, authentication and file storage
  • Lovable — application hosting and the AI gateway for meeting follow-ups and Focus assistant requests
  • Google — sign-in and Google Calendar sync when you connect it, and the Gemini AI model accessed through Lovable's gateway
  • OpenAI — the meeting follow-up extraction model accessed through Lovable's gateway
  • Fathom, Fireflies and Granola — meeting summaries and action items, when you connect them
  • Resend — transactional email delivery

Revoking access and deleting your data

You can revoke NetivOS's access to your Google account at any time from your Google account permissions page, or by disconnecting the calendar inside NetivOS (Settings → Calendars). Revoking access stops all further reading and writing immediately.

To delete your account or any of your data, email [email protected] from the address on the account and we will remove it.

Contact

Questions about this policy or your data: [email protected].