Privacy Policy

Last updated 7 September 2026

This policy explains what Qonvo (“Qonvo”, “we”) collects, why, how long we keep it, and who else sees it. It covers both the business owners who sign up for Qonvo (“you”) and the customers who message their WhatsApp number (“end customers”).

Who we are

Qonvo is operated by Aliasghar Ezzy, trading as Qonvo, based in Pakistan. For any privacy question or request, contact hello@qonvo.org.

What we collect

Account data. Your name, email address, business name, and password (stored only as an Argon2 hash, so we never see it). If you sign in with Google, we receive your email address and display name instead of a password.

Business knowledge. Whatever you add to Qonvo so it can answer questions: hours, prices, policies, documents, and settings.

Conversations. Messages exchanged between your WhatsApp number and your end customers, including their phone number, message text, and any voice notes. Voice notes are transcribed to text so the assistant can respond.

Operational data. Logs, timestamps, error reports, and usage counts we need to run and debug the service.

We do not intentionally collect special-category data (health, financial account credentials, government identifiers). Please do not put such data into Qonvo's knowledge base.

Google user data we access

Google access is entirely optional. Nothing below happens unless you explicitly connect your Google account, and you can disconnect at any time.

Sign in with Google: openid, email, profile. We read your email address and name solely to create and identify your Qonvo account.

Google Calendar: calendar.app.created lets Qonvo create a single calendar named “Qonvo Bookings” in your account and read or write events only on that calendar. It cannot see or change your other calendars. calendar.freebusy lets it read your busy/free time blocks: start and end times only, never event titles, attendees or descriptions, so it does not book a customer over an existing commitment.

Google Sheets and Drive: drive.file grants per-file access. Qonvo can only open a spreadsheet you personally select in the Google file chooser, or one it created for you. It cannot list, read, or search anything else in your Drive. We use this to append leads and orders to the sheet you chose and to read rows back when a customer asks about stock, pricing, or order status.

We request the narrowest scopes that make these features work, and we ask for Calendar and Sheets access separately, only when you turn that feature on.

How we use it

To operate the service: generating replies to your end customers, booking appointments, recording leads and orders, sending you alerts, and providing your dashboard and analytics. We also use operational data to keep the service secure and reliable.

We do not use your data, your end customers' messages, or any Google user data to train machine-learning models, and we do not sell data or use it for advertising.

Google API Services Limited Use

Qonvo's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Concretely: we use Google user data only to provide the features you enabled, we never transfer it to others except as described below, we never use it for advertising, and no human at Qonvo reads it except with your explicit permission, to resolve a support issue you raised, for security purposes, or where required by law.

Who else sees it

We do not sell your data. We share it only with the providers needed to deliver the service:

  • AI providers. To generate a reply, the relevant conversation messages and your business knowledge are sent to the AI provider configured for your account (such as Google Gemini, OpenAI, or Groq). If voice replies are on, audio is sent to a speech provider for transcription and synthesis.
  • WhatsApp / Meta. Message delivery happens over WhatsApp and is subject to its own terms and privacy policy.
  • Google. Only when you connect it, and only for the calendar and spreadsheet described above.
  • Hosting and email. Our server host and, if configured, the email provider used to send you alerts.
  • Legal. Where we are legally required to disclose, or to protect our rights or someone's safety.

How we protect it

Google refresh tokens and other third-party credentials are encrypted at rest with Fernet (AES-128-CBC with HMAC authentication) before being written to the database. All traffic is served over HTTPS.

Every tenant's data is isolated at the database level with PostgreSQL row-level security, enforced by a dedicated application role that cannot bypass it, so one business's conversations, knowledge, and credentials are not reachable from another's session, even in the event of an application bug.

No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your data, we will notify you without undue delay.

How long we keep it

Account and business data are kept while your account is active. Conversations and operational logs are retained while they are useful for running the service and supporting you.

When you disconnect Google, we delete the stored refresh token and clear the cached access token immediately. Where that grant is not shared with another connected Qonvo feature, we also revoke it with Google. Content already written to your calendar or spreadsheet stays in your Google account. It is yours, and we do not delete it.

When you delete your account, we delete your data within 30 days, except where we must retain something to meet a legal obligation.

Your choices and rights

You can view and edit your business data in the dashboard at any time. You may request a copy of your data, correction, or deletion by emailing hello@qonvo.org. Depending on where you live, you may also have rights to object to or restrict processing, or to complain to a data-protection authority.

You can revoke Qonvo's access to your Google account at any time, either from the Integrations page in Qonvo, or directly at myaccount.google.com/permissions. Revoking stops all Google features immediately; the rest of Qonvo keeps working.

Your end customers

When people message your WhatsApp number, you are the controller of that conversation and Qonvo processes it on your behalf. You are responsible for telling your customers that an AI assistant may respond and for having a lawful basis to process their messages. We will help you honour any access or deletion request they make to you.

International transfers and children

Our providers may process data in countries other than yours, including the United States. Qonvo is a business tool and is not directed at children under 16; we do not knowingly collect their data.

Changes

We may update this policy as the product changes. We will update the date at the top and, for material changes, notify you by email or in the dashboard.

Contact

Questions, requests, or complaints: hello@qonvo.org.