Privacy Policy
Navōn is built around two non-negotiables: protecting the dignity and Kedushah standards of the communities we serve, and protecting the privacy of every person who trusts us with their data. This Privacy Policy is a binding legal agreement. Please read it carefully, because it explains what we collect, how we use it, how we share it, the choices you have, and the limitations of our liability.
Acceptance & Binding Effect
This Privacy Policy ("Policy") describes how Navōn LLC, a Florida limited liability company ("Navōn," "we," "us," or "our") collects, uses, discloses, retains, transfers, and protects information when you access or use any of our websites, mobile applications, desktop applications, browser extensions, APIs, software development kits, AI generation tools, voice agents, telephony services, messaging bots, embedded widgets, integrations, beta programs, community forums, and any other related products or services we offer from time to time (collectively, the "Services").
By accessing, browsing, registering for, or otherwise using the Services, you acknowledge that you have read, understood, and agreed to this Policy and to our Terms of Use. If you do not agree, you must immediately discontinue use of the Services. If you are using the Services on behalf of an organization, school, congregation, business, family unit, or any other entity ("Organization"), you represent and warrant that you have the legal authority to bind that Organization to this Policy, and "you" refers jointly to you individually and to that Organization.
This Policy is incorporated by reference into our Terms of Use, Data Processing Addendum, Acceptable Use Policy, and Master Content Policy. In the event of any conflict, the document most protective of personal information will control with respect to that conflict, except where a separate written agreement signed by an authorized officer of Navōn expressly states otherwise.
Definitions
For the purposes of this Policy, the following terms shall have the meanings set forth below. Capitalized terms not defined here have the meaning given to them in the Terms of Use or in applicable data-protection law.
- "Personal Information" means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with a particular consumer or household, as defined under applicable law (including GDPR's "personal data" and CCPA/CPRA's "personal information").
- "Sensitive Personal Information" includes government identifiers, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, genetic or biometric data, health information, sex life or sexual orientation, account credentials, and the content of private communications.
- "Processing" means any operation performed on Personal Information, whether automated or not, including collection, recording, organization, storage, adaptation, retrieval, consultation, use, disclosure, alignment, restriction, erasure, or destruction.
- "Controller" and "Processor" have the meanings given to them under GDPR and analogous laws.
- "Generated Content" means any text, image, audio, video, code, document, agent configuration, or other output produced by an AI model within the Services in response to your inputs.
- "Organization Administrator" means an individual designated to manage an Organization's workspace, members, billing, and content controls.
Controller, Roles & Legal Basis
Navōn LLC is the data Controller for Personal Information collected directly from individual users for the purpose of providing the Services. Where the Services are deployed within an Organization workspace (such as a school, congregation, or business), Navōn typically acts as a Processor on behalf of the Organization, which is the Controller of member data within that workspace. The Organization is solely responsible for establishing a lawful basis for its members' Processing and for honoring its members' rights requests, and Navōn will assist the Organization in accordance with our Data Processing Addendum.
2.1 Lawful Bases (GDPR, UK GDPR, and analogous laws)
- Performance of a contract — to provide the Services you have requested, manage your account, and process payments.
- Legitimate interests — to secure the Services, prevent fraud and abuse, improve product quality, enforce our policies, and conduct ordinary business operations, balanced against your rights and freedoms.
- Consent — for non-essential cookies, marketing communications, certain integrations, voice cloning, and any other Processing that requires opt-in. You may withdraw consent at any time without affecting the lawfulness of prior Processing.
- Legal obligation — to comply with tax, accounting, anti-money-laundering, child-safety, content-moderation, and other legal duties.
- Vital interests — in rare cases to protect the life or physical safety of any person.
- Public interest / official authority — only where required by a competent authority and subject to legal review.
Information We Collect
We collect only the information we genuinely need in order to deliver, secure, personalize, and continually improve the Services. The categories below describe the full scope of information that may be collected, depending on which features you use. Not every category applies to every user.
3.1 Information you provide directly
- Account details — full name, email address, password (stored as a salted hash), profile photo, preferred language, time zone, role within an Organization or family, and optional fields such as biography or affiliation.
- Billing details — name on card, billing address, country, tax identifiers, last four digits of payment method, expiry month/year, brand of card, and invoice contact. Full payment card numbers are processed exclusively by our PCI-DSS Level 1 payment partners and never reach Navōn servers.
- Communications — messages you send to support, feedback submissions, survey responses, content of help-desk tickets, live-chat transcripts, and recordings of voluntary user-research sessions.
- Prompts and uploads — text prompts, reference images, documents, audio samples, voice clones, code snippets, knowledge-base materials, and any other inputs you submit to AI tools.
- Connected-account credentials — OAuth tokens, refresh tokens, and scopes for third-party services you choose to connect, stored encrypted at rest.
- Identity-verification information — only where required (for example, age verification for COPPA-restricted features), and only the minimum necessary to satisfy the legal obligation.
3.2 Information generated through use
- Generated Content — text, images, voices, videos, agents, and documents produced by AI models on your behalf, including version history.
- Usage telemetry — feature usage, model selection, token counts, generation duration, error rates, and aggregate performance metrics.
- Moderation events — records of content that was filtered, flagged, blocked, or appealed by our Kedushah and Master Content Policy systems, including timestamps, rule identifiers, and severity scores.
- Collaboration metadata — shared workspaces, comment threads, mentions, role assignments, and audit logs.
3.3 Information collected automatically
- Device and technical data — IP address, browser type and version, operating system, screen resolution, device identifiers, hardware model, language settings, and approximate (city-level) geolocation derived from IP.
- Cookies and similar technologies — session cookies, authentication tokens, analytics identifiers, CSRF tokens, local storage, and IndexedDB entries.
- Log data — request URLs, referrers, timestamps, HTTP status codes, latency measurements, and trace identifiers.
- Security signals — failed-login attempts, anomalous-access alerts, device fingerprints used solely for fraud prevention, and rate-limit events.
3.4 Information from third parties
When you connect a third-party account (such as Google, Microsoft, Apple, Slack, Notion, Dropbox, Twilio, Stripe, WhatsApp Business, or Telegram), we receive limited profile, authorization, and usage information as scoped by your consent. We may also receive information from fraud-prevention vendors, identity-verification providers, business partners, public databases, and Organization Administrators who provision your account.
3.5 Information we do not knowingly collect
We do not knowingly collect government-issued identification numbers (other than tax IDs needed for billing), biometric identifiers for identification purposes, precise GPS-level location, or content from children under 13 outside of a properly provisioned Family Hub or School account. If we learn we have collected such information in violation of this Policy, we will delete it promptly.
How We Use Your Information
We Process Personal Information for the following purposes, each tied to a clear lawful basis:
- Create and authenticate your account, maintain a continuous secure session, and recover access when you forget credentials.
- Deliver every feature you actively request — text, image, video, voice, document, code, and agent generation, plus the storage, retrieval, and sharing of those outputs.
- Enforce our Master Content Policy and Kedushah standards before, during, and after generation, including automated and human review of flagged events.
- Process subscriptions, invoices, refunds, retention offers, chargebacks, dunning, and tax compliance.
- Personalize your dashboard, model recommendations, gallery, notifications, and onboarding without engaging in cross-context behavioral advertising.
- Monitor performance, debug errors, conduct root-cause analysis, and improve reliability and quality of the Services.
- Detect, investigate, prevent, and respond to fraud, abuse, harassment, intellectual-property violations, and security incidents.
- Send transactional emails, service announcements, security alerts, and — only with consent where required — marketing communications.
- Conduct internal analytics, product research, capacity planning, and aggregated reporting in a manner that does not identify individuals.
- Comply with legal obligations, lawful requests, court orders, subpoenas, and regulatory inquiries; establish, exercise, or defend legal claims; and enforce our agreements.
- Effect corporate transactions such as financing, merger, acquisition, reorganization, or sale of assets, subject to continued protection of Personal Information.
What we do not do. We do not use your prompts, uploads, or Generated Content to train models, and we do not sell or license them to anyone for model training. They are processed by the model providers named in Section 6 under those providers’ own terms; we do not control whether a given provider trains on API inputs, so schools that require a contractual no-training or zero-retention commitment should request our current Data Processing Addendum before deploying Navōn. We do not sell Personal Information. We do not share Personal Information for cross-context behavioral advertising. We do not "rent" mailing lists. We do not access your private workspace content except as strictly necessary to provide, secure, or lawfully audit the Services, and only under documented internal access controls.
Kedushah Standards & Content Filtering
Navōn was built for communities that hold themselves to elevated standards of modesty, dignity and the values they have chosen. Our content-moderation pipeline applies a multi-stage audit — at intake, during generation, and post-generation — using a combination of policy-tuned language models, deterministic rule sets, image classifiers, voice classifiers, and (where appropriate) human review.
- Prompts matching a topic your parent or school has blocked are caught on our own servers and are never transmitted to any provider. Every other prompt is sent to our content-screening provider (Google Gemini) to be classified; if it fails that check it is blocked at intake and never reaches a generation model, and no text, image, video, or voice is produced from it.
- Generated outputs are re-scanned before they are returned to you and before they are stored.
- Blocked-attempt metadata is retained for safety auditing but is never used to profile individual users beyond abuse-prevention purposes.
- Organization Administrators may apply stricter filters at the workspace level; those settings are honored above defaults.
- Severe or repeated violations may result in account suspension, termination, and (where required by law) reporting to competent authorities.
- You acknowledge that no automated moderation system is perfect, and you agree not to rely on Navōn moderation as a substitute for your own judgment or supervision, particularly where minors are involved.
How We Share Information
We share Personal Information only in the limited circumstances described below, and only with parties bound by confidentiality and security obligations at least as protective as our own.
- AI model providers — the Lovable AI Gateway, which routes your chat and image prompts to OpenAI and Google models on our behalf; Google (Gemini), which additionally receives prompts and generated output for content-policy screening; Replicate for video generation; and ElevenLabs for voice synthesis. Each Processes the content strictly to return a result.
- Infrastructure providers — Supabase (database, authentication, storage), Cloudflare (CDN and security), and similar vendors that host or transmit Service data.
- Payment processors — Stripe and, where applicable, Paddle, for subscription billing, tax calculation, and fraud screening.
- Telephony and messaging — Twilio for voice agents, and the WhatsApp Business API for messaging bots.
- Email — Resend, for account, invitation, and notification email.
- Analytics, error monitoring, and customer-support tools — used in aggregate or pseudonymized form to operate the Services.
- Organization Administrators — if you join a school, team, congregation, or family workspace, the workspace owner can see your activity, Generated Content, and moderation flags within that workspace, in accordance with the Organization's own policies.
- Professional advisors — lawyers, auditors, accountants, and insurers under duties of confidentiality.
- Legal and safety disclosures — where we believe in good faith that disclosure is necessary to comply with law, lawful process, enforceable governmental request, or to protect the rights, safety, or property of Navōn, our users, or the public.
- Corporate transactions — in connection with a merger, financing, acquisition, reorganization, bankruptcy, or asset sale, with reasonable efforts to ensure continued protection of Personal Information.
A current list of sub-processors is available on request to privacy@navon.org and is maintained in our Data Processing Addendum for enterprise customers.
Security
We protect your information using a defense-in-depth approach modeled on SOC 2, ISO 27001, and NIST 800-53 control families:
- TLS 1.2+ in transit and AES-256 at rest for all Personal Information.
- Database-level Row-Level Security with role-based access enforced via dedicated user-roles tables and security-definer functions.
- Hardware-backed key management, mandatory multi-factor authentication for staff, and principle-of-least-privilege access reviews conducted at least quarterly.
- Continuous vulnerability scanning, dependency auditing, secret scanning, infrastructure-as-code review, and periodic penetration tests by independent third parties.
- Network segmentation, web-application firewalls, rate limiting, and DDoS protection at the edge.
- Logging, monitoring, anomaly detection, and a documented incident-response plan with a 72-hour breach notification commitment to affected users and regulators where required by law.
- Background checks and security training for all employees and contractors with access to production systems.
No system is perfectly secure, and no method of electronic transmission or storage is 100% safe. We cannot guarantee absolute security, but we hold ourselves to current industry practice. If you believe your account has been compromised, contact security@navon.org immediately. Responsible-disclosure reports may be sent to the same address; we will not pursue legal action against good-faith security researchers who comply with our coordinated-disclosure guidelines.
Data Retention
We retain Personal Information only as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Specific retention windows include:
- Account data — for the life of the account plus thirty (30) days after deletion to allow restoration on request.
- Generated Content — until you delete it, or thirty (30) days after account closure, whichever comes first.
- Billing records — seven (7) years to comply with tax and accounting law.
- Moderation and abuse logs — twenty-four (24) months, or longer where required to defend legal claims.
- Security and audit logs — thirteen (13) months by default.
- Support communications — three (3) years from last interaction.
- System backups — encrypted and rotated on a 35-day cycle; deletion requests propagate to backups during the next rotation.
When retention periods expire, we either delete the information or de-identify it irreversibly so that it can no longer be associated with any individual.
Your Rights and Choices
Subject to applicable law (including GDPR, UK GDPR, CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA, the Quebec Law 25, Brazil's LGPD, and similar frameworks), you have the right to:
- Access the Personal Information we hold about you and obtain a copy.
- Correct inaccurate or incomplete information.
- Delete your account and associated Personal Information ("right to be forgotten"), subject to lawful exceptions.
- Port your data in a portable, machine-readable format.
- Object to or restrict certain Processing activities, including Processing based on legitimate interests.
- Withdraw consent at any time, without affecting prior lawful Processing.
- Opt out of "sales" or "sharing" of Personal Information as defined under California law (note: we do not engage in such activity, but the right is preserved).
- Opt out of automated decision-making that produces legal or similarly significant effects; we do not currently engage in such decision-making.
- Designate an authorized agent to exercise rights on your behalf, subject to reasonable verification.
- Appeal a denial of any rights request.
- Lodge a complaint with a supervisory authority, including the data-protection authority of your country of residence, or with your state attorney general.
Most rights can be exercised directly inside your Settings page. For anything else, email privacy@navon.org. We will respond within thirty (30) days, extendable by an additional sixty (60) days for complex requests with notice to you. We may request reasonable information to verify your identity before fulfilling a request, and we will not discriminate against you for exercising any privacy right.
Cookies & Tracking Technologies
Navōn stores what it needs to keep you signed in and to remember interface preferences such as your theme and whether the sidebar is open. It loads no analytics service, no advertising script and no third-party tracker, and it does not track you across other sites.
Because there are no non-essential cookies, there is no cookie banner and nothing to opt out of. Your browser's own controls apply as normal; clearing or blocking what we store will sign you out and reset those preferences. We do not sell or share Personal Information, so a Global Privacy Control signal has nothing to act on — but if that changes, this section changes with it, before the practice does.
International Data Transfers
Navōn primarily Processes data in the United States and the European Union. Where Personal Information is transferred across borders, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, the UK International Data Transfer Addendum, the EU-US Data Privacy Framework (where applicable), the Swiss-US Data Privacy Framework, and the UK Extension to the Data Privacy Framework, supplemented where appropriate by additional technical and organizational measures including encryption, pseudonymization, and access logging.
You may request a copy of the applicable safeguards by writing to privacy@navon.org. By using the Services, you consent to the transfer of your Personal Information to jurisdictions outside your country of residence, including jurisdictions whose data-protection regimes may differ from your own.
Children's Privacy
Standalone Navōn accounts are intended for users 13 and older (16 in the European Economic Area unless local law specifies a lower age). Children below those thresholds may use the Services only through a verified Family Hub or School account managed by a parent, guardian, or institution that has provided verifiable consent under COPPA, GDPR-K, the UK Age Appropriate Design Code, and analogous laws.
Administrators can review, export, or delete a child's information at any time from the Family Hub or Org Hub dashboards. We do not condition a child's participation in any activity on the disclosure of more Personal Information than is reasonably necessary. We do not knowingly use children's Personal Information for advertising, profiling, or any purpose other than providing the educational and family features explicitly requested by their administrator.
If you believe a child has provided Personal Information to us without proper consent, please contact privacy@navon.org and we will promptly delete it.
Region-Specific Disclosures
13.1 California Residents (CCPA / CPRA)
In the preceding twelve (12) months, we have collected the categories of Personal Information described in Section 3 for the business purposes described in Section 4, and we have disclosed those categories to the service providers described in Section 6. We have not sold or shared Personal Information as those terms are defined under California law. California residents have the right to know, delete, correct, opt out of sale/sharing, limit use of Sensitive Personal Information, and not face discrimination for exercising these rights.
13.2 European Economic Area, United Kingdom, and Switzerland
Our EU representative under Article 27 GDPR and our UK representative under the UK GDPR can be reached at privacy@navon.org. You have the right to lodge a complaint with your local supervisory authority.
13.3 Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other US state privacy laws
Residents of these states have the rights described in Section 9, including the right to appeal a denial of any privacy request by emailing privacy@navon.org with the subject line "Privacy Appeal."
13.4 Canada (PIPEDA, Quebec Law 25)
We comply with PIPEDA and, for Quebec residents, with Law 25, including provisions on consent, transparency, and cross-border transfer assessments. Our Privacy Officer can be reached at privacy@navon.org.
13.5 Brazil (LGPD)
Our Encarregado (Data Protection Officer) for LGPD purposes can be reached at privacy@navon.org.
13.6 Israel
We comply with the Israeli Protection of Privacy Law, 5741-1981, and registration requirements where applicable.
13.7 Other jurisdictions
Where additional local requirements apply, we honor them in addition to the protections described in this Policy. Where local law conflicts with this Policy, local law controls to the extent of the conflict.
AI-Specific Disclosures
AI outputs are probabilistic and may contain inaccuracies, hallucinations, biases, or content that does not reflect the views of Navōn or its founders. You are solely responsible for reviewing, validating, and accepting any Generated Content before relying on it for any purpose, including educational, religious, legal, financial, medical, or safety-critical purposes. Navōn does not warrant that Generated Content is accurate, complete, current, fit for any particular purpose, or free from intellectual-property claims.
Voice cloning and image-of-likeness features require lawful consent of the data subject. You represent and warrant that you have obtained all necessary rights and consents before uploading any voice sample, photograph, or likeness, and you agree to indemnify Navōn against any claim arising from your failure to do so. We may, at our discretion, refuse to clone the voice or likeness of any public figure, minor, or deceased person.
We log AI inputs and outputs as described in Section 3 in order to provide the Services, enforce our policies, and defend against misuse. Logs are accessed only by authorized personnel under the controls described in Section 7.
Third-Party Services & Links
The Services may contain links to, or integrations with, third-party websites, applications, models, and services that we do not own or control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices, content, security, or terms. We encourage you to review the privacy policies of every third party before providing them with Personal Information.
If you grant a third-party application access to your Navōn account via OAuth or API key, your interactions with that application are governed by the third party's terms and privacy policy, not by ours.
Organization & Family Accounts
If your account was provisioned by an Organization (such as a school, congregation, or employer) or by a Family Hub administrator, that Organization or administrator may have the ability to access, monitor, restrict, suspend, export, or delete your account and Generated Content in accordance with their own internal policies and applicable law. Navōn acts as a Processor in these cases and is not responsible for the lawfulness of the Organization's Processing. Direct any rights requests relating to that workspace to the Organization or administrator first.
Prohibited Uses & Enforcement
You agree not to use the Services in any manner that violates this Policy, our Terms of Use, our Master Content Policy, applicable law, or the rights of any third party. We reserve the right, without notice or liability to you, to investigate suspected violations, restrict or suspend access, remove content, terminate accounts, cooperate with law-enforcement authorities, and pursue any other remedy available at law or in equity. Nothing in this Policy creates an obligation on Navōn to monitor user content, but we may do so at our discretion.
Disclaimers & Limitation of Liability
The Services are provided on an "as is" and "as available" basis. To the maximum extent permitted by law, Navōn disclaims all warranties, express, implied, statutory, or otherwise, including warranties of merchantability, fitness for a particular purpose, non-infringement, accuracy, security, and uninterrupted availability. No advice or information obtained from the Services creates any warranty not expressly stated in this Policy.
To the maximum extent permitted by law, in no event shall Navōn, its affiliates, officers, directors, employees, agents, suppliers, or licensors be liable for any indirect, incidental, special, consequential, exemplary, or punitive damages, including loss of profits, loss of data, loss of goodwill, business interruption, or any other intangible loss, arising out of or relating to this Policy, the Services, or any Processing of Personal Information, whether based in contract, tort (including negligence), strict liability, or any other legal theory, even if Navōn has been advised of the possibility of such damages.
To the maximum extent permitted by law, Navōn's aggregate liability arising out of or relating to this Policy or the Services shall not exceed the greater of (a) the amount you paid to Navōn for the Services during the twelve (12) months preceding the event giving rise to the claim, or (b) one hundred United States dollars (US$100). Some jurisdictions do not allow the exclusion or limitation of certain damages, so the foregoing limitations may not apply to you to the extent prohibited by law.
Indemnification
You agree to defend, indemnify, and hold harmless Navōn LLC and its affiliates, officers, directors, employees, agents, and licensors from and against any and all claims, damages, obligations, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from: (a) your use of, or inability to use, the Services; (b) your violation of this Policy, the Terms of Use, the Master Content Policy, or applicable law; (c) your violation of any third-party right, including any intellectual-property, publicity, privacy, or contract right; (d) any content you submit to the Services; and (e) any misrepresentation made by you. Navōn reserves the right, at your expense, to assume the exclusive defense and control of any matter otherwise subject to indemnification by you, in which event you agree to cooperate with our defense.
Governing Law, Dispute Resolution & Arbitration
This Policy is governed by the laws of the State of Florida, USA, without regard to conflict-of-laws principles. Subject to the arbitration provision below, the state and federal courts located in Miami-Dade County, Florida shall have exclusive jurisdiction over any dispute, and you consent to personal jurisdiction in those courts.
Binding arbitration & class-action waiver. Except for claims for injunctive relief or claims that may be brought in small-claims court, any dispute, claim, or controversy arising out of or relating to this Policy or the Services shall be resolved exclusively by final and binding individual arbitration administered by the American Arbitration Association (AAA) under its Consumer Arbitration Rules, in Miami, Florida, before a single arbitrator. You and Navōn each waive the right to a trial by jury and the right to participate in a class action, class arbitration, collective action, or representative proceeding. If this class-action waiver is found unenforceable, then the entirety of this arbitration provision shall be null and void, but the remainder of this Policy shall continue in full force.
Opt-out. You may opt out of arbitration by sending written notice to legal@navon.org within thirty (30) days of first accepting this Policy. The notice must include your full name, account email, and an unambiguous statement that you wish to opt out of arbitration.
Time limitation. Any claim arising out of or relating to this Policy or the Services must be filed within one (1) year after the cause of action arose, otherwise the claim is permanently barred, except where prohibited by law.
Changes to this Policy
We may update this Policy from time to time. Material changes will be communicated by email and through an in-app notification at least fourteen (14) days before they take effect, except where a shorter period is required by law or to address an urgent security or legal matter. Continued use of the Services after the effective date constitutes acceptance of the updated Policy. If you do not agree to a material change, your sole remedy is to stop using the Services and delete your account before the effective date. Prior versions are archived and available on request.
Language, Severability & Entire Agreement
This Policy was originally drafted in English. Translations are provided for convenience, and in the event of any conflict between the English version and any translation, the English version shall prevail.
If any provision of this Policy is found to be unenforceable or invalid, that provision shall be limited or eliminated to the minimum extent necessary so that the remainder of this Policy shall continue in full force and effect. No waiver of any provision of this Policy shall be deemed a further or continuing waiver of such provision or any other provision. This Policy, together with the Terms of Use, the Acceptable Use Policy, the Master Content Policy, and any applicable Data Processing Addendum, constitutes the entire agreement between you and Navōn with respect to the subject matter hereof and supersedes all prior or contemporaneous understandings.
You may not assign this Policy or any of your rights or obligations hereunder without our prior written consent. Navōn may assign this Policy, in whole or in part, at any time without notice.
Contact Us
For privacy questions, data-subject requests, or to reach our Data Protection Officer:
Navōn LLC · Privacy Office · Miami, Florida, United States
This Policy is provided for general information and does not constitute legal advice. For advice on how applicable law affects your specific situation, please consult qualified legal counsel.