Operator OSSign in

Legal

Privacy Policy

This policy explains how Erviq handles information when businesses and their authorized users use Operator OS.

Who we are and when this policy applies

Effective date:

This Privacy Policy applies when a business or its authorized users access or use Operator OS, a service provided by Erviq. The service is designed for businesses and the people they authorize to use it.

A customer must have the authority and provide any notices needed to connect its accounts and allow us to process information about its clients, prospects, contacts, and employees. Depending on the context, Erviq may act as a controller of personal information or as a processor acting on a customer's instructions.

Information we collect

We collect and retain the following categories of information:

  • Account and organization information. Authentication email, user ID, organization name, organization membership and role, and lead-response and invoice-reminder policy settings.
  • Google Workspace information.Connected mailbox, OAuth permission details, encrypted OAuth tokens, Gmail thread ID, subject, participants, senders, timestamps, delivery and automation indicators, a limited excerpt from the latest message, approved draft content, and the identifier of a draft created in Gmail. We also derive and retain a writing-style profile for the connected mailbox: a distilled description of greeting and sign-off habits, formality, brevity, punctuation habits, characteristic short phrases, and stylistic notes. The profile is designed to contain only stylistic description, not email content, customer names, or amounts. When an owner separately enables Calendar, we also receive optional read-only access to the connected owner's primary calendar. We retain only event ID and iCalendar UID, event status, created, updated, start, and end timestamps, organizer and attendee email addresses, attendee response status, and a safe Google Calendar source link.
  • QuickBooks Online information. Connected company ID and name, encrypted OAuth tokens, customer ID, name, and email, and invoice ID, number, dates, currency, totals, balances, and update time.
  • Operational information. Cases, evidence, recommendations, uncertainty, approved or dismissed decisions, draft attempts and status, synchronization status, and audit events.
  • Access-request information. Full name, work email, company name, team-size range, and any optional message submitted through the public access-request form.
  • Technical and support information. Session and security information, limited operational metadata needed to operate and protect the service, and information you send to hello@erviq.com. To limit automated abuse of the public access-request form, we process the connection address into a rotating, keyed pseudonymous security identifier. We store the identifier and request count, not the raw connection address, for this control.

During Gmail synchronization, we request Gmail threads in full format, transiently process their content, and decode message bodies to derive the limited latest message excerpt and normalized fields described above. We discard those full responses after processing and do not retain complete message bodies or raw Gmail API payloads in Operator OS. We also request recent messages from the connected mailbox's Sent mail in full format and transiently process their bodies to derive the writing-style profile described above. We discard those bodies after processing; they are never retained. We also do not intentionally retain complete raw QuickBooks API payloads.

We do not retain Calendar event titles, descriptions, locations, conferencing details, attachments, organizer display names, or raw Calendar API payloads. We do not read secondary or shared calendars in this release.

How we use information

We use information to:

  • authenticate users and isolate each organization's information;
  • connect authorized Google Workspace and QuickBooks Online accounts;
  • synchronize authorized records;
  • when separately enabled, read limited primary-calendar metadata to confirm an unambiguous accepted meeting;
  • detect potential unanswered sales leads and overdue invoices using deterministic rules;
  • produce evidence-backed decision briefs;
  • learn the connected mailbox owner's writing style from recent sent messages so proposed drafts read as the owner's own writing;
  • create a Gmail draft after an authorized owner approves its exact content;
  • audit decisions, attempted actions, results, and synchronization activity;
  • operate, secure, maintain, and support the service; and
  • comply with applicable law and enforce our agreements.

We use access-request information to evaluate and respond to an access request or demo request. It is not used to make automated eligibility decisions.

Operator OS does not automatically send email and does not write to QuickBooks or Google Calendar.

AI-assisted features

We send limited stored evidence to OpenAI to generate a structured decision brief and, where appropriate, proposed draft text. We also send OpenAI the transient bodies of recent sent messages from the connected mailbox to derive the writing-style profile described above; those bodies are held only for that request and are never stored by Operator OS. The model may summarize the evidence we supply, recommend an action, draft text, and identify uncertainty. Deterministic rules, not the model, decide whether a case exists.

These OpenAI API requests use store: false.

OpenAI states that it does not use API inputs and outputs to train its models by default. OpenAI may temporarily retain API data in abuse-monitoring logs unless separate retention controls apply, and may retain it longer when legally required or reasonably necessary to protect its services or others from harm.

Erviq does not use Google Workspace or QuickBooks Online data to train or improve a general-purpose AI model.

How we disclose information

Except for Google Workspace API data, which is subject to the narrower rules described below, we may disclose the other categories described above as follows:

  • to Intuit to connect an authorized QuickBooks Online company and synchronize permitted customer and invoice records;
  • to OpenAI to process limited stored evidence, and, transiently, recent sent-message bodies, for the AI-assisted features described above;
  • to service providers that support hosting, database, authentication, background-job, infrastructure, and security functions, only as needed to provide and protect the service;
  • to professional advisers, auditors, insurers, and authorities when reasonably necessary for advice, legal compliance, security, or the establishment or defense of legal claims; and
  • to counterparties and advisers in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to applicable notice and consent requirements.

Erviq does not sell personal information, use connected data for targeted advertising, or provide connected data to data brokers.

Google Workspace API data

Operator OS's use and transfer of information received from Google Workspace APIs complies with the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.

We transfer Google Workspace API data only to provide or improve the consented user-facing features described in this policy, for security purposes, to comply with applicable laws and regulations, or as part of a merger, acquisition, or sale of assets after obtaining the user's explicit prior consent.

This includes transferring limited stored Google Workspace evidence, together with the transient bodies of recent sent messages used to derive the writing-style profile, to OpenAI only to provide the consented user-facing AI-assisted features described above.

After an owner approves a Gmail draft, we transfer its recipient, subject, and body to Google to create the draft in the owner's connected Gmail mailbox. Operator OS does not send the email automatically.

Operator OS sends an email automatically only under a playbook the owner has explicitly enabled to send on its own. Each automatic send stays within that playbook's configured limits and is delayed by a cancellable window before it leaves the owner's Gmail account, so the owner can cancel any pending send before it goes out. Turning on automatic sending requires a separate, explicitly granted Google permission to send email that an ordinary connection does not include.

Optional Calendar access is limited to read-only metadata from the connected owner's primary calendar. Operator OS does not create, update, or delete Calendar events and does not claim access to secondary or shared calendars.

We do not allow humans to read Google Workspace API data except when we have obtained and documented a user's explicit consent to access specific data for support, when access is necessary for a security investigation or legal compliance, or when the data has been properly aggregated and anonymized for internal operations in accordance with applicable law.

Data retention and deletion

We retain information only for as long as reasonably necessary to provide and secure the service, preserve audit integrity, comply with law, resolve disputes, and enforce agreements. Retention periods vary by data type and context.

Disconnecting Google Workspace or QuickBooks Online stops future access, but disconnecting does not automatically delete information that Operator OS already retained.

The retention rules above also apply to stored Calendar event metadata. We do not assign Calendar metadata a longer fixed retention period, and disconnecting Calendar stops future Calendar access without automatically deleting metadata already retained.

To request deletion, email us at hello@erviq.com. Limited records may remain when necessary for law, security, fraud prevention, dispute resolution, or the integrity of approval and action audit records.

Your privacy rights

Depending on applicable law, you may ask us to access, correct, delete, or obtain a portable copy of personal information about you. You may also have the right to object to or restrict certain processing and to appeal a denied privacy request.

Submit a request or appeal to hello@erviq.com. We may verify your identity and, when you make a request for another person or an organization, your authority to act for them. We will respond within the period required by applicable law.

Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. These include organization isolation, access controls, encrypted OAuth tokens, and HTTPS in production. No system or transmission method is completely secure.

Children's privacy

Operator OS is a business service and is not directed to children under 13. We do not knowingly collect personal information from children under 13 through Operator OS.

Where information is processed

Information may be processed in the United States and in other locations where our service providers operate, subject to protections required by applicable law.

Changes to this policy

We may update this policy from time to time and will update its effective date when we do. We will notify affected users of material changes as required by applicable law. We will request consent before materially expanding our use of Google user data when Google policy requires consent.

Contact us

The contact below accepts privacy requests and appeals.

Erviq
133 33rd St, Union City, New Jersey 07087
hello@erviq.com