Privacy Policy
Last updated: July 27, 2026
Cavyro is operated by CherryIT, registered in Serbia. This policy explains what we process, why, where it lives and what your rights are. The short version: your workspace data is yours, it lives in the EU, we run no ads, website analytics only with your consent, and deleting your workspace deletes its data immediately.
Two roles
For your account data (name, email, billing state) we are the data controller. For the content of your workspace, including conversations mirrored from Telegram, we act as a processor on behalf of the workspace owner: you decide what the mirror sees and why, we store and process it to provide the service.
What we process
- Account data: name, email, password hash or Google sign-in identity.
- Workspace content: companies, contacts, deals, notes, comments, custom fields, files you upload.
- Telegram mirror data: for the chats you choose to include, we store messages, media and chat metadata, plus the encrypted session that keeps the mirror connected. Chats you exclude are not stored. Conversations include messages written by your contacts; you are responsible for having a lawful basis to bring those conversations into your CRM.
- Google Calendar: if you connect it, we store the OAuth token and sync event data both ways. We request only the calendar events scope, use the data solely to provide calendar sync inside your workspace, and never use it for advertising. Cavyro's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can disconnect Google Calendar at any time, which deletes the stored token.
- AI features: when you use the assistant or MCP, the relevant workspace context is sent to our AI model provider to generate the response. It is not used to train models.
- AI tracing: to debug the assistant and measure its quality, each AI request is recorded in Langfuse: your message, the assistant's reply, the tool calls it made and what those returned — which can include workspace content such as contact, company or deal records — together with the model used, token counts and timings. Traces are labelled with the workspace and chat session identifiers rather than your name or email, and any value that looks like a credential is stripped before the trace leaves our servers. Traces are not used to train models.
- Billing: handled by Paddle as merchant of record. Card details never touch our servers.
- Technical data: server logs and error reports needed to keep the service running.
- Website analytics: cavyro.com uses Google Analytics 4, and only after you allow it in the cookie banner; decline and nothing loads. We see aggregate page statistics, not ad profiles. Details and how to change your choice are in the cookie policy.
Why we process it
To provide the service you signed up for (contract), to keep it secure and debug failures (legitimate interest), and to meet legal obligations. We do not sell personal data and we do not use workspace content for advertising.
Where it lives
Production servers and object storage run at Hetzner in Falkenstein, Germany (EU). Some subprocessors below operate outside the EU; where that is the case, transfers rely on standard contractual clauses or an equivalent mechanism.
Subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Hetzner Online | Hosting and object storage | Germany (EU) |
| Paddle | Payments, invoicing, tax (merchant of record) | UK / EU |
| Optional sign-in, Calendar sync, Gmail campaign sending, website analytics (consent-based) | EU / US | |
| OpenAI | AI assistant and MCP responses | US |
| Langfuse | AI request tracing and quality monitoring | EU |
| Bugsnag (SmartBear) | Error monitoring | US |
Google user data
If you connect Google Calendar or Gmail to Cavyro, here is exactly what we touch. From Google Calendar, we read your calendar events to show them inside Cavyro and write back the meetings you create or edit in Cavyro. From Gmail, we send the campaign emails you compose, from your own address — and to detect replies and bounces we read message headers only (sender and thread), never the content of your email.
We do not sell Google user data, we do not use it for advertising, and no humans read it — it is processed only to provide the features above, and it is deleted when you disconnect the integration or delete your account.
Cavyro's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and deletion
Workspace content is kept for as long as the workspace exists. Deleting the workspace deletes its content immediately, including mirrored Telegram data; residual copies in encrypted backups expire on a rolling basis shortly after. We keep the minimum account and billing records the law requires us to keep.
Job applications (CV, contact details, correspondence) are used only for hiring and kept for up to two years after the process ends, so we can contact you about future roles. Email careers@cavyro.com to have your application deleted sooner; we do it within 30 days.
Your rights
You can access, correct, export or delete your personal data, object to processing, and complain to a supervisory authority. For anything you cannot do from the app, email legal@cavyro.com and we will respond within 30 days. If your data appears in someone else's workspace (for example, you messaged a company that uses Cavyro), we will route your request to that workspace owner, as the law expects.
Changes
If this policy changes in a way that matters, we will announce it in the app or by email before it takes effect.
Contact
CherryIT, Serbia · legal@cavyro.com