Skip to content
ProductHow it works
ENESPTDE
Log inMeet Renvora
ProductHow it worksEarly access
Log inMeet Renvora
ENESPTDE
Back to Renvora

Privacy

App privacy policy

This policy covers the Renvora application at app.renvora.lat and its API — the sales CRM your workspace signs up to use — separately from the website privacy policy, which covers only the public marketing site. Renvora is in a private beta: today only workspaces Kunz Global invites can sign up, and outbound e-mail runs in a sealed test mode that can send only to a founder-controlled allow-list, never to a real customer, lead or supplier. This policy describes how the application is built to handle data once a workspace uses it, so it is accurate both for the private beta and for the wider release it prepares for.

Last updated: 25 September 2026

Contents

  1. Data controller
  2. What Renvora is
  3. Account and workspace data
  4. CRM data your workspace enters
  5. Google user data
  6. AI processing
  7. Purposes and legal basis
  8. Sub-processors
  9. International transfers
  10. Retention
  11. Security
  12. Managing and deleting your data
  13. Your rights
  14. Changes to this policy
  15. Contact

Data controller

Owner
Kunz Pazer Stanley
Business name
Kunz Global
RUT
220451740014
Registered tax address
Ruta 1 km 51, Departamento de San José, República Oriental del Uruguay
Product
Renvora
Country
Oriental Republic of Uruguay
Email
stan@kunzglobal.com

What Renvora is

Renvora is a business-to-business sales CRM — an "AI Sales Employee" — for companies that manage contacts, leads and outreach. A workspace can connect its own Gmail or Google Workspace mailbox to send e-mails its members wrote or approved to contacts in its own CRM, see replies in an in-app inbox, and let sequences stop automatically the moment a contact replies. Renvora never owns a mailbox, never sends through a Renvora domain, and every e-mail Renvora's connectors deliver was written or approved by a person at the sending workspace — a model can draft a message, but it can never make Renvora send one on its own.

Account and workspace data

  • Account: name, work email address and password (handled by Supabase Auth; Renvora never sees or stores the plain password), and your language and time zone preference.
  • Workspace and membership: the workspaces and brands you belong to, your role (owner, admin or member) and the actions your role allows.
  • Usage and audit records: which features you use, records of sensitive actions (for example connecting a mailbox, sending a campaign or approving a message) kept for accountability, and technical logs kept to operate and secure the service. Audit and log entries reference records by id and never copy an e-mail body, an address or a token into them.

CRM data your workspace enters

Your workspace controls what it stores in its own CRM: companies, contacts, leads, notes and the outcome of its outreach. A contact record carries where it came from, its country and language, and — before it can receive outreach — a consent basis and, where required, the evidence for it. Renvora acts as the processor of this data on your workspace's behalf; your workspace decides what it enters, imports or removes.

Google user data

Renvora's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. The use of information received from Google Workspace scopes (the Gmail API) will adhere to the Google User Data Policy, including the Limited Use requirements. In particular:

  • Renvora uses Google user data only to provide and improve the features you can see and use in Renvora: connecting your mailbox, sending the messages you wrote or approved, detecting and showing replies, and the other features described in this section.
  • Renvora does not transfer Google user data to others, except to the sub-processors listed below as needed to provide these features, to protect the security of the service, to comply with the law, or as part of a merger or acquisition with notice to you.
  • Renvora does not use Google user data for advertising, and does not sell it.
  • No person at Renvora reads your Google user data unless you give permission for specific messages (for example in a support request), it is needed for security (for example investigating abuse), it is needed to comply with the law, or the data has been aggregated and anonymised for internal operations.
  • Renvora does not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models.

When you connect a Gmail or Google Workspace mailbox, Renvora requests exactly two Google scopes and nothing else: gmail.send and gmail.readonly. No narrower scope returns a message body or lets Renvora find one of its own messages again after an unclear send, which the inbox, reply detection, bounce handling and reply drafting all need. Renvora does not request the broader gmail.modify, gmail.compose or full-mailbox scopes; it never changes, labels, archives or deletes anything in your mailbox, and never reads your drafts.

Renvora's customer-facing Google connection is the OAuth app of its Google Cloud project for the public product. A second, separate Google app can be used only by accounts of the operator's own Google Workspace organisation, for the operator's own testing. Each app has its own credentials, and a connected mailbox always stays with the app it was connected through.

gmail.sendgmail.readonly
Why Renvora asks for itTo send messages a person at your workspace wrote or explicitly approved, from your own mailbox.To detect replies and bounces in conversations Renvora started, show reply text in your inbox, and let the assistant draft a reply for you to review.
What Renvora readsOnly the send confirmation (message and thread id) — never your mailbox contents.The headers (sender, recipients, subject, date, message and thread ids, reply and auto-reply markers) of new messages in your Inbox, Sent and Spam folders, to decide whether a message belongs to a conversation Renvora started. The body only once a message is matched to such a conversation: a reply, or a delivery-failure notice, of which only the delivery status is kept. After a send whose outcome is unclear, Renvora looks up that one message by its message id, so it never sends it twice. Headers of messages it cannot match are not stored, except a pointer record (ids, a one-way hash of the sender's address and the reason) when a contact of your workspace writes to you, or someone else writes in a conversation Renvora started; your workspace's owner or admin can assign or dismiss it.
Where it is storedThe sent text, as plain text, in Renvora's database (Supabase, hosted in São Paulo, Brazil).Matched reply text, as plain text, in the same database. Inbound HTML is converted to plain text before storage and is never rendered or executed; a bounce is recorded as a delivery status, not as message content.
How longSubject and text are kept for your workspace's retention period, 180 days by default (your workspace can set 7–180 days), then cleared automatically; message ids, status and timestamps stay while the conversation exists, for threading.Same retention as sent text. A pointer record is deleted after 90 days, or 30 days after your workspace assigned or dismissed it.
DeletionDisconnecting the mailbox revokes Renvora's access at Google and deletes the encrypted token. Erasing a contact clears the subject and text of the messages exchanged with them and every value derived from their address on those messages (see below).Same as sent data; pointer records of an erased contact are deleted with the erasure.

The refresh token that lets Renvora act on your behalf is encrypted (AES-256-GCM) before it is stored, is never sent to your browser, and is readable only by Renvora's server-side workers. Renvora does not sell Gmail data, does not use it for advertising, and does not share it with any third party except the sub-processors listed below and, only where your workspace turns on e-mail AI for itself, the configured AI provider described in the next section.

Renvora sends no e-mail on its own initiative through a connected mailbox: every send is either a click by a signed-in person, or a message a signed-in person approved in advance (a single message, or the template of an approved sequence). No automated process, model or rule can create a send by itself.

AI processing

Renvora can use an AI model to classify a reply (for example: interested, not interested, out of office) and to draft a suggested reply for you to review, edit or discard. This is off unless your workspace turns on e-mail AI for itself, is used only for that purpose, and a person always decides whether a drafted reply is ever sent. Before a reply reaches the model, e-mail addresses, phone numbers and links in its subject and text are replaced with placeholders; names and the rest of the text are not removed. The model never receives your Gmail credentials, and nothing it returns can send a message.

Renvora's current model provider is Google Gemini. During this development and private-beta phase, Renvora sends the model only the operator's own test data — never a real customer's, lead's or contact's information; the application enforces this by allowing e-mail AI only on conversations with the operator's own test addresses while the free tier is in use — because Google's free tier for this API may be used to improve Google's products and may be read by human reviewers. Before any customer's Gmail or CRM data reaches a model, Renvora will move to a paid tier under terms where the content is not used to train Google's models, and will keep this policy's description of that switch up to date.

Purposes and legal basis

  • Providing the CRM, the connected-mailbox features and the in-app inbox — performance of the contract with your workspace.
  • Keeping the service secure, preventing abuse, and meeting audit and accounting obligations — our legitimate interest, or a legal obligation.
  • Sending, detecting and classifying e-mail through a connected mailbox, and using AI on reply text — your workspace's consent, given when it connects the mailbox and again when it turns on e-mail AI; consent can be withdrawn at any time by disconnecting the mailbox or the AI switch.

Sub-processors

ProviderPurposeDataLocation
SupabaseDatabase, authentication and file storage for the applicationEvery category above, including Gmail message text and the encrypted refresh tokenProject hosted in the São Paulo region (Brazil)
VercelHosting, delivery and the background jobs that poll Gmail and send mailTechnical access data; message content passes through in memory, never stored by VercelCompany based in the United States; the application's functions run in the São Paulo region (`gru1`)
ResendDelivering Renvora's own account e-mails (sign-in links, password reset, e-mail change) — not your outreach, which is sent from your own connected mailboxYour account e-mail address and the content of the account e-mailDomain configured in the São Paulo region
GoogleGmail API access for a connected mailboxGoogle user data as described aboveCompany based in the United States; infrastructure in several regions
AI model provider (currently Google Gemini)Classifying and drafting a reply, only when your workspace turns e-mail AI onMasked reply text (see AI processing above); never your Gmail credentialsCompany based in the United States

International transfers

Our sub-processors may process data outside Uruguay, in particular in the United States. International transfers are governed by Article 23 of Law No. 18,331 and the rules of the Unidad Reguladora y de Control de Datos Personales (URCDP); where the destination does not offer an adequate level of protection, a transfer takes place only in the cases the law allows, such as performing the contract with your workspace or your consent.

Retention

Account and workspace data are kept while your account or workspace exists. Gmail message text follows the schedule in the Google user data section. Audit records are kept for a set number of days (365 by default) for accountability, delivery-attempt records (codes only, no content) for one year, and technical logs for shorter periods, after which they are deleted or, where an id is still needed for threading, stripped of their content. A do-not-contact entry (see below) is kept while the workspace exists, because it is what keeps a person who objected from being contacted again.

Security

Every workspace's data is isolated from every other workspace at the database level (row-level security), so one workspace's rows are never visible to another. Tokens are encrypted before storage and readable only by server-side code, never by your browser or by a workspace member directly. Traffic to the application runs over HTTPS only. Message content, e-mail addresses and tokens are never written into logs or job records; log entries reference records by id.

Managing and deleting your data

Erasing a contact. A workspace owner or admin can erase a contact from its page ("Erase personal data"). This clears the contact's personal details, the notes about them, the subject and text of the messages exchanged with them, and every value derived from their e-mail address that is stored with those messages or their unsubscribe links; it stops any pending message to them. The unsubscribe link in an e-mail already sent keeps working but no longer refers to the address.

Do-not-contact entries. A one-way hash of the address is kept only as a do-not-contact entry, never the address itself, and only where a block has to be honoured: when the workspace chooses "Never contact this address again" during the erasure, when the person unsubscribed or objected, or when someone at the workspace blocked the address on purpose. A block kept only for technical reasons (a permanent delivery failure) is removed with an erasure that does not choose "Never contact again". A hash is still personal data: it lets the application recognise the same address if it is entered again, and it is used for nothing else.

Disconnecting Gmail. You can disconnect a mailbox at any time from the workspace's Integrations page: Renvora revokes its access at Google and deletes the stored token. Messages already stored follow the retention and erasure rules above. You can also remove Renvora's access in your Google Account (Security → Third-party connections); Renvora then can no longer reach the mailbox, and disconnecting it in Renvora also deletes the stored token.

Deleting your account or workspace. Deleting an account or a whole workspace is not yet a button in the application. The workspace owner writes to stan@kunzglobal.com from the account's e-mail address; we disconnect every mailbox of the workspace, delete its accounts, CRM data, stored messages and tokens within 30 days, except records the law requires us to keep, and confirm when it is done.

Your rights

Under Uruguay's Law No. 18,331 you can ask for access to, rectification, updating, inclusion or erasure of your data. Write to stan@kunzglobal.com. We will ask for what is needed to verify your identity and reply within the legal time limits. You can also turn to the URCDP or bring a habeas data action. Where the GDPR applies, you additionally have the rights to restriction, portability, objection, withdrawal of consent at any time and to lodge a complaint with a supervisory authority.

Changes to this policy

We update this policy when the application, its providers or the rules change, and publish the new version on this page with its date. Before a material change to how Google user data is handled takes effect, we tell the owners of the affected workspaces.

Contact

For privacy questions about the application, write to stan@kunzglobal.com. The operator’s details are in the legal notice, and the website (not the application) is covered by a separate policy.

Your AI Sales Employee.

A product of Kunz Global, Uruguay.

ENESPTDE

Product

  • How it works
  • Control
  • Channels
  • Early access

Company

  • About
  • Product status
  • Contact

Legal

  • Legal notice
  • Privacy
  • Cookies
  • App privacy
  • Terms of service
© 2026 Kunz Global. All rights reserved.Legal noticePrivacyApp privacyTerms of service