Outrevio
Legal & privacy centerPrivacy Policy
Effective: August 17, 2026 · Last updated: September 25, 2026
This Privacy Policy describes the personal information Outrevio currently handles, where it comes from, why it is used, the service providers or user-authorized third parties that may receive it, and the controls available to users.
1. Scope and who this policy covers
This policy covers personal information processed through the Outrevio website, authenticated CRM, integrations, internal AI features, and user-authorized external AI/MCP connections. It covers information about Outrevio account holders and information an account holder chooses to store about professional contacts who may not have an Outrevio account.
The legal entity that will operate Outrevio for public U.S. launch has not yet been finalized.
2. Categories of information, sources, purposes, disclosures, and retention
The inventory below is tied to data flows that currently exist in the application. It is intentionally more specific than a generic list of "information you provide."
Account, authentication, and legal records
Examples
- Name, email address, avatar URL, role, time zone, and account status
- Password hash when configured, email-confirmation and password-reset state, login/security state, optional email sign-in verification state, and connected Google or Microsoft sign-in identity metadata
- Hashed refresh-token records and server session timestamps
- Terms version, Privacy Policy version acknowledged, acceptance time, and acceptance source
Sources
- You
- Outrevio authentication and security systems
- Google when you choose Google sign-in
- Microsoft when you choose Microsoft sign-in
Why Outrevio uses it
- Create and secure your account
- Authenticate sessions and recover access
- Prevent abuse and investigate security events
- Keep evidence of versioned legal acceptance
Who may receive it
- Render for API and PostgreSQL database hosting
- Vercel for the frontend session boundary
- Google only when you choose Google sign-in; Outrevio requests openid, email, and profile identity scopes and keeps this separate from Google Calendar and Gmail permissions
- Microsoft only when you choose Microsoft sign-in; Outrevio requests openid, email, and profile identity scopes and keeps this separate from Outlook Calendar, Outlook Email, and Teams permissions
- Have I Been Pwned Pwned Passwords receives only a five-character SHA-1 hash prefix when compromised-password screening is enabled; Outrevio does not send the password or email address
Current retention approach
Email-confirmation and password-reset token hashes are cleared after expiry or successful use. Optional email sign-in verification codes and account-deletion verification codes are protected at rest and cleared when consumed, verified, invalidated, or expired. A queued authentication email may temporarily contain the corresponding one-time delivery credential protected with Outrevio server-side Data Protection; that protected payload is cleared after successful delivery or abandonment, and terminal outbox metadata is removed after about 7 days. Expired/revoked first-party refresh-token hashes are retained for up to 30 days after invalidation, then removed. Legal acceptance records remain with the account during the seven-day deletion recovery window and are removed by the final permanent purge.
Current controls
- Update account information
- Connect or disconnect Google or Microsoft sign-in when another sign-in method remains available
- Log out/revoke sessions
- Create a password-verified privacy export
- Request permanent account deletion through password and six-digit email-code verification in Settings → Privacy & Data; access is locked immediately and final purge follows the seven-day recovery window
Profile, onboarding, goals, and preferences
Examples
- School, program, organization, role, industry, graduation month, and career direction
- Networking goals, target companies, target industries, wanted positions, relationship intentions, and networking challenges
- Dashboard/settings preferences, notification preferences, and experience settings
Sources
- You
Why Outrevio uses it
- Store the onboarding/profile choices you submit
- Personalize other profile, goals, and preference fields where the product currently uses them
- Support onboarding, goals, analytics, and user-selected AI features for fields included in those features
Who may receive it
- Render for API and PostgreSQL database hosting
- A selected AI provider only when the relevant permission is enabled and you explicitly request an AI action
- An external MCP app only when an authorized scope permits the requested data
Current retention approach
Kept with your account until you change it or permanently delete the account. Outrevio does not currently collect or use a visa-sponsorship preference; any previously stored affirmative value is cleared because there is no current product purpose for retaining that immigration-context preference.
Current controls
- Edit profile/settings
- Change AI data permissions
- Create a password-verified privacy export
- Request permanent account deletion through Settings → Privacy & Data; final purge follows the seven-day recovery window
CRM contacts and relationship information
Examples
- Names, employers, roles, industries, city/state, email addresses, phone numbers, LinkedIn URLs, and other contact methods
- How you know a person, relationship type/intent, warm-introduction paths, notes, tags, pipeline stage, archive state, and inferred relationship signals
- Information about people who may not themselves have an Outrevio account
Sources
- You
- Files you import
- Information you choose to enter from your professional relationships
Why Outrevio uses it
- Provide contact and pipeline management
- Search, filtering, reminders, analytics, relationship intelligence, and recommendations
- Supply bounded context to AI/MCP only under the permissions and user actions described in this policy
Who may receive it
- Render for API and PostgreSQL database hosting
- A selected AI provider only for an explicit AI request and permitted data categories
- An external MCP application only within the scopes you authorize
Current retention approach
Kept with the CRM account until the user edits, archives, deletes individual records, or permanently deletes the account through the self-service privacy control.
Current controls
- Edit/archive contacts
- Create a password-verified privacy export
- Change AI/MCP access
- Request permanent account deletion through Settings → Privacy & Data; final purge follows the seven-day recovery window
Activities, reminders, notes, and attachments
Examples
- Contact timeline entries, dates, notes, quality indicators, life-event/context fields, and goal outcomes
- Reminder titles, notes, due dates, completion state, and suggested tasks
- Files attached to contacts, including file name, content type, size, and file contents
Sources
- You
- Imported CRM data
- Reviewed Google Calendar relationship updates after the user saves them
- Confirmed AI/WhatsApp actions
Why Outrevio uses it
- Maintain relationship history and reminders
- Produce analytics, deterministic recommendations, and user-requested summaries
- Support file storage for the contact record
Who may receive it
- Render for API and PostgreSQL database hosting
- A selected AI provider only when the matching data permission is enabled and the user requests AI assistance
- An external MCP app only when the applicable scope is authorized
Current retention approach
Kept as part of the relevant CRM record until removed or account data is deleted. AI proposal payloads are handled separately below.
Current controls
- Edit CRM records
- Complete/delete supported records
- Change AI/MCP permissions
- Create a password-verified privacy export
- Request permanent account deletion through Settings → Privacy & Data; final purge follows the seven-day recovery window
Imports, exports, and data-management metadata
Examples
- CSV content submitted for preview/commit, column mappings, import file name, import batch identifiers, validation results, and rollback markers
- User-requested CRM exports and password-verified privacy ZIP exports
Sources
- Files and actions you provide
Why Outrevio uses it
- Import CRM records safely
- Detect duplicates/invalid values
- Provide user-requested export and rollback tools
Who may receive it
- Render for request processing and PostgreSQL storage of committed CRM records
Current retention approach
Committed import data becomes part of the CRM. Import markers can remain in CRM timeline/notes. The application does not intentionally create a permanent server-side copy of an uploaded CSV merely to preview it.
Current controls
- Exclude rows before import
- Rollback supported imports
- Export account data
- Edit/delete resulting CRM records
Google Calendar connection and calendar context
Examples
- Google account identifier/email, OAuth access and refresh tokens, granted scope, connection and sync timestamps
- Calendar events requested from Google for display and CRM-aware matching
- Invitee names and email addresses for displayed events, temporarily used to let you review whether to create CRM contacts
- Minimal derived CRM evidence for qualifying events, including an event marker/date, matched contact, classification/confidence, and event summary
Sources
- Google, after you authorize the integration
Why Outrevio uses it
- Display calendar events
- Let you explicitly review event invitees before creating CRM contacts
- Create calendar events you request
- Sync qualifying professional events into relationship context
Who may receive it
- Render for application processing, connection metadata, and qualifying derived CRM evidence
Current retention approach
Outrevio does not maintain a persistent cache of the full Google event list. On disconnect, stored Google access/refresh tokens are cleared and the connection is marked inactive; minimal CRM evidence already created remains part of the CRM until changed or deleted.
Current controls
- Connect/disconnect Google Calendar
- Choose which displayed invitees, if any, become CRM contacts
- Control the events you create or sync through the integration
Outlook Calendar connection and calendar context
Examples
- Microsoft account identifier/email, protected OAuth access and refresh tokens, granted scope, and connection timestamps
- Calendar events requested from Microsoft Graph for display in the signed-in user's calendar view
- Invitee names and email addresses for displayed events, temporarily used to let you review whether to create CRM contacts
- Minimal CRM timeline evidence when the user explicitly creates an Outlook event from a CRM contact or reminder
Sources
- Microsoft / Microsoft Graph, after you authorize the integration
- Event details you explicitly choose to create in Outlook Calendar
Why Outrevio uses it
- Display Outlook calendar events
- Let you explicitly review event invitees before creating CRM contacts
- Create Outlook calendar events you request
- Keep calendar sources visibly distinct inside Outrevio
Who may receive it
- Microsoft / Microsoft Graph
- Render for application processing and connection metadata
Current retention approach
Outrevio does not maintain a persistent general cache of Outlook event lists. On disconnect, stored Microsoft access/refresh tokens are cleared and the connection is marked inactive; minimal CRM evidence already created remains part of the CRM until changed or deleted.
Current controls
- Connect/disconnect Outlook Calendar
- Choose which displayed invitees, if any, become CRM contacts
- Choose Outlook explicitly when creating an external calendar event
Outlook Email basic metadata connection
Examples
- Microsoft account identifier/email, protected OAuth access and refresh tokens, granted scope, and connection timestamps
- Bounded Inbox/Sent metadata pages requested on demand: sender/recipient, subject, and date
- No message body, body preview, attachment, extended property, send, delete, or mailbox-write access in the current integration
Sources
- Microsoft / Microsoft Graph, after you separately authorize Outlook Email
Why Outrevio uses it
- Let you choose email metadata inside Capture from email, including older pages only when you select Load more
- Match or create a CRM contact only after review
- Optionally log the reviewed email or create a follow-up
Who may receive it
- Microsoft / Microsoft Graph
- Render for OAuth processing and transient application processing
Current retention approach
Outrevio does not maintain a persistent general cache of Outlook messages. Protected OAuth credentials remain until disconnect or permanent account deletion; CRM records you explicitly create remain under normal CRM retention.
Current controls
- Connect/disconnect Outlook Email independently
- Choose which message metadata enters the CRM
- Keep using local paste/.eml capture without connecting a mailbox
Gmail header-metadata connection
Examples
- Connected Gmail address, protected OAuth access and refresh tokens, granted scope, and connection timestamps
- Bounded Inbox/Sent header-metadata pages requested on demand: sender/recipient, subject, and date
- No message body, snippet, attachment, send, delete, label-modification, or mailbox-write access in the current integration
Sources
- Google Gmail API, after you separately authorize Gmail
Why Outrevio uses it
- Let you choose Gmail header metadata inside Capture from email, including older pages only when you select Load more
- Match or create a CRM contact only after review
- Optionally log the reviewed email or create a follow-up
Who may receive it
- Google Gmail API
- Render for OAuth processing and transient application processing
Current retention approach
Outrevio does not maintain a persistent general cache of Gmail messages. Protected OAuth credentials remain until disconnect or permanent account deletion; CRM records you explicitly create remain under normal CRM retention.
Current controls
- Connect/disconnect Gmail independently
- Choose which Gmail metadata enters the CRM
- Keep using local paste/.eml capture or Outlook Email without connecting Gmail
WhatsApp CRM Assistant data
Examples
- Linked WhatsApp phone number, display name, connection/last-seen timestamps
- Message ID, a minimized incoming-message excerpt, parsed intent, action/status/safety decision, and errors
- Short-lived pending confirmation payloads for supported actions
Sources
- Meta/WhatsApp when you message the configured Outrevio assistant number
Why Outrevio uses it
- Authenticate/link the assistant
- Execute supported user commands
- Reply inside a user-initiated assistant conversation when replies are enabled
- Prevent duplicate/replayed commands
- Safety, troubleshooting, and auditing
Who may receive it
- Meta/WhatsApp
- Render for application processing and PostgreSQL storage
Current retention approach
Message-log excerpts are limited and email/phone patterns inside the excerpt are masked where possible. Command logs are automatically removed after 30 days. Pending confirmations expire after 10 minutes; their payload is cleared at completion/expiry and terminal metadata is removed after 7 days.
Current controls
- Disconnect WhatsApp
- Clear WhatsApp action logs
- Do not use the integration
- No proactive CRM-contact or campaign sending in the current product
Connected meeting metadata and provider-generated transcripts
Examples
- Zoom or Microsoft Teams account/tenant identifiers, connected account email/display name, granted scopes, subscription/sync state, and connection timestamps
- Meeting title, date/time, organizer information, participant names/emails where the provider supplies them, and conservative user-confirmed links to CRM contacts
- Provider-generated transcript text in VTT/normalized text form, transcript identifiers, byte length, content hash, import time, and retention deadline
Sources
- Zoom or Microsoft Teams after you explicitly connect the provider
- Provider-generated meeting/transcription data available to the connected account
- Your manual contact-link confirmations
Why Outrevio uses it
- Import and display provider-generated meeting transcripts without Outrevio recording or transcribing the meeting
- Search imported meeting text and show meeting/participant context
- Support user-initiated AI analysis only when the separate Meeting transcripts AI permission is enabled
- Maintain webhook/subscription synchronization and security diagnostics
Who may receive it
- Zoom when you connect or revoke the Zoom integration
- Microsoft when you connect Microsoft Teams and Outrevio calls Microsoft Graph
- Render for Outrevio application/database processing
- A selected AI provider only when you explicitly choose Analyze transcript and have enabled the separate Meeting transcripts permission
Current retention approach
Imported transcript text is retained until its per-transcript RetainUntilUtc deadline; the current production baseline is 90 days from import. Expired transcript rows are automatically deleted and are excluded from search, reading, and AI even before the cleanup worker removes the row. Meeting/participant metadata and connection metadata can remain while the provider stays connected so the meeting history and synchronization state continue to work. Disconnecting Zoom or Teams deletes that provider's imported meeting/transcript data and stored provider credentials from Outrevio. Final account purge after the seven-day recovery window removes all local meeting-provider data.
Current controls
- Connect/disconnect Zoom or Microsoft Teams
- Do not enable the integration
- Create a password-verified privacy export containing current meeting metadata and unexpired transcript text
- Control whether internal AI may use Meeting transcripts
- Request permanent account deletion through Settings → Privacy & Data; final purge follows the seven-day recovery window
Internal AI requests, permissions, proposals, and usage metadata
Examples
- AI provider preference and permission flags for contacts, notes/activity, goals/targets, reminders, and meeting transcripts
- Bounded CRM context assembled for an explicit AI request
- Provider/model, action, request status, token counts, quota/credit metadata, and failure codes
- Temporary action proposals for creating a reminder, logging an activity, or applying a user-reviewed meeting CRM batch when Ask before changes is enabled
- A resized business-card/contact-card image only when you explicitly choose the image-capture AI action; Outrevio does not persist that image
Sources
- You
- Your current Outrevio CRM data
- A business-card/contact-card image you explicitly choose for one extraction request
- Unexpired provider-generated meeting transcript text when you explicitly permit and request analysis
- The AI provider response/usage report
Why Outrevio uses it
- Provide AI assistance you explicitly request
- Extract review-only contact fields from a business-card image you explicitly submit
- Enforce permissions and spend/usage limits
- Prepare confirm-before-write actions
Who may receive it
- OpenAI, Anthropic, or Google Gemini only when selected/available and an explicit user AI request is made
- Render for application processing and PostgreSQL storage
Current retention approach
Server-side AI usage records contain usage metadata rather than prompts/CRM evidence/generated answers. Chat history is not stored server-side in this phase. Business-card image bytes are processed transiently for the explicit extraction request and are not stored by Outrevio. Pending action proposals expire after 10 minutes; their payload/confirmation text is cleared on execution, cancellation, or expiry, and terminal proposal metadata is removed after about 7 days.
Current controls
- Turn AI off
- Choose provider
- Change each data permission
- Use Read only
- Edit/include/exclude reviewed meeting changes
- Confirm or cancel each prepared write proposal
External AI/MCP authorization data
Examples
- Registered external client identity, granted scopes, authorization reference, policy fingerprint, timestamps, and revocation state
- Temporary OAuth authorization-request state needed to complete a connection
- CRM data returned to a connected app only when a request is allowed by the current user, client, connection, and scope
Sources
- You
- The external application you choose to connect
- Outrevio OAuth/MCP authorization systems
Why Outrevio uses it
- Authorize and revoke external AI-app access
- Enforce current scopes and ownership
- Detect stale/revoked policy chains
Who may receive it
- The external MCP application you authorize, such as ChatGPT during developer validation
- Render for application processing and PostgreSQL storage
Current retention approach
Connection metadata remains so authorization/revocation can be enforced. Revoked connections are marked revoked. Temporary OAuth authorization-request details expire after about 10 minutes and are removed as terminal/expired attempts are cleaned up. External MCP reads do not call Outrevio's internal AI providers.
Current controls
- Review requested scopes
- Approve only selected permissions
- Disconnect/revoke the external application
Operational, security, and diagnostic information
Examples
- Correlation IDs, authenticated user ID where applicable, HTTP method/route/status/duration, resource/action identifiers, outcome, and bounded security metadata
- Hashed client-source information for abuse/security controls when used
- Diagnostic, audit, and security events
Sources
- Your use of the service
- Outrevio servers and security controls
- Hosting infrastructure
Why Outrevio uses it
- Operate and troubleshoot the service
- Detect abuse and security incidents
- Audit important actions
- Maintain availability and performance
Who may receive it
- Render for API processing and persistent PostgreSQL system events
- Vercel for frontend/platform request handling
Current retention approach
Outrevio's current retention baseline keeps diagnostic system events for 30 days, audit events for 365 days, and security events for 730 days. The persistent system-event writer allow-lists metadata rather than storing request bodies or CRM note contents.
Current controls
- Security/audit records generally cannot be edited by users
- Permanent account deletion detaches retained system events from the deleted account rather than preserving an active user profile
Cookies and browser storage
Examples
- HttpOnly access-token cookie (up to about 1 hour) and refresh-token cookie (up to about 14 days)
- Local/session storage used for theme/interface preferences, dismissed setup prompts, loading/navigation state, data-freshness flags, and a short-lived pending sign-in-verification challenge reference
Sources
- Your browser and Outrevio frontend
Why Outrevio uses it
- Keep you signed in
- Protect authenticated routes
- Remember interface state
- Coordinate navigation/loading behavior
Who may receive it
- Vercel and Render as necessary to serve/authenticate requests
Current retention approach
Authentication cookies use configured expiration periods and are cleared on logout. UI/session-storage values are browser-local and may persist until cleared, expire by application logic, or are removed by the user/browser.
Current controls
- Log out
- Clear site data in your browser
- Use browser privacy controls, subject to essential authentication requirements
Outrevio does not currently collect or use a visa-sponsorship preference. Any previously stored affirmative value is ignored and cleared by the application retention cleanup, and this preference is not provided to AI or external MCP applications while collection is disabled.
3. Information about people who are not Outrevio users
Outrevio is a personal/professional relationship CRM. An account holder may therefore store business or relationship information about another person who has never opened an Outrevio account. That information is provided by the account holder or through an import they choose to make; Outrevio does not treat the contact as having agreed to Outrevio merely because another user saved their information.
Account holders are responsible for having an appropriate and lawful reason to collect and use information they place in their CRM. Outrevio uses that data to provide the account holder's CRM features and does not currently sell it or use it for cross-context behavioral advertising.
4. Cookies, local storage, and tracking
Outrevio uses essential HttpOnly authentication cookies for access and refresh sessions. The current frontend also uses limited browser local/session storage for interface preferences, dismissed setup prompts, short-lived loading/navigation state, and freshness flags. These mechanisms are used for service functionality rather than advertising profiles.
The current frontend does not intentionally embed Google Analytics, Meta Pixel, PostHog, Mixpanel, Hotjar, Microsoft Clarity, Segment, Vercel Analytics, or another third-party advertising/behavioral analytics SDK. Outrevio does not currently authorize third-party advertising or behavioral-analytics companies to collect personally identifiable information through the product over time and across unrelated websites for behavioral advertising. If Outrevio later introduces analytics, advertising, or other tracking that changes this statement, the privacy disclosures and any legally required consent/opt-out controls must be updated before that tracking is enabled.
5. Google and Microsoft sign-in
Google sign-in is optional and separate from Google Calendar. If you choose it, Outrevio uses Google's OpenID Connect identity response to authenticate you and stores the Google account's stable provider identifier plus the verified email snapshot needed to maintain that sign-in method. Outrevio does not store Google access or refresh tokens for this sign-in-only flow.
The Google sign-in authorization requests only openid, email, and profile. It does not grant Google Calendar access. Calendar access, if you choose it later, uses the separate Google Calendar integration and a separate authorization. You can disconnect Google sign-in from Profile → Account when another sign-in method remains available.
Microsoft sign-in is also optional and separate from Outlook Calendar and Teams. Outrevio validates Microsoft's OpenID Connect identity response and stores the stable Microsoft provider identifier plus an email snapshot for the connected sign-in method. Microsoft email claims are not treated as proof that an existing Outrevio account should be merged automatically; existing accounts must explicitly connect Microsoft from Profile → Account.
Microsoft sign-in requests only openid, email, and profile. New Microsoft-created Outrevio accounts must still verify the email address with Outrevio's six-digit email code before sign-in is completed. Outlook Calendar and Teams continue to require their own separate authorizations and provider permissions.
6. Google and Microsoft calendar and email integrations
Google Calendar and Outlook Calendar are optional and use separate provider authorizations. Outrevio stores the connected account information and protected connection details needed to provide the calendar features you authorize. Each calendar connection is separate, and disconnecting one provider removes Outrevio's saved access for that provider without disconnecting another integration.
Outrevio can display Google and Outlook events to the signed-in user, but it does not maintain a persistent general cache of those external event lists. Calendar events do not become relationship evidence automatically. A completed meeting affects relationship intelligence only after you explicitly review and save the CRM relationship update. Personal, private, busy-only, holiday, gym, medical, travel, family, and unknown events remain calendar-only. Calendar descriptions are not sent to Outrevio's AI provider context by the current calendar flow. When you explicitly create an external calendar event from a CRM contact or reminder, Outrevio sends the event details you entered to the provider you selected and may record a minimal scheduling note; that scheduling note does not refresh relationship intelligence or count as a completed interaction.
Gmail is optional and is authorized separately from Google sign-in and Google Calendar. The current Gmail connection requests only https://www.googleapis.com/auth/gmail.metadata. Outrevio uses that permission to fetch a bounded page of Inbox and Sent message metadata for the Capture from email feature. If you explicitly choose Load more, Outrevio requests the next bounded metadata page; it does not search or crawl your entire mailbox in the background. For a selected message, Outrevio requests only the message identifier and the From, To, Subject, and Date headers needed to identify the correspondence and its counterpart. The current integration does not request Gmail message bodies, snippets, attachments, sending, deletion, label modification, or general mailbox-write access.
Gmail metadata is fetched on demand when you open the email-capture experience or explicitly choose Load more, and is not maintained as a persistent general mailbox cache. Protected OAuth access/refresh credentials and connection metadata are kept while you keep Gmail connected. Message metadata becomes durable Outrevio CRM data only when you explicitly review and choose to create or update a contact, log an email interaction, or create a follow-up. The Gmail metadata connection itself does not send Gmail data to an AI provider.
Outlook Email is also optional and separately authorized from Microsoft sign-in, Outlook Calendar, and Teams. The current Outlook Email connection uses Microsoft Graph's delegated Mail.ReadBasic permission to display bounded basic message metadata for Capture from email. It does not request message bodies, body previews, attachments, sending, deletion, or mailbox-write access. As with Gmail, metadata fetched for review is not maintained as a persistent general mailbox cache and enters the CRM only after your explicit action.
Outrevio's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google API data is used only to provide or improve the user-facing features you choose, subject to the controls and disclosures in this policy.
7. WhatsApp CRM Assistant
WhatsApp is optional. Outrevio processes messages sent to the configured CRM assistant number; it does not import unrelated WhatsApp chat history, scrape a user's WhatsApp contacts, or automatically contact CRM contacts merely because WhatsApp is connected. If assistant replies are enabled, the current implementation replies only inside the conversation initiated by the linked user; the WhatsApp assistant is not a proactive CRM-contact campaign channel.
Outrevio stores linking information and bounded command logs for security, duplicate/replay prevention, troubleshooting, and user-requested actions. Logged message text is reduced to a short excerpt and recognizable email/phone patterns inside that excerpt are masked where possible. Users can disconnect WhatsApp and clear WhatsApp command logs. Command logs are automatically removed after 30 days. Short-lived confirmation records expire after 10 minutes; their payload is cleared after completion/expiry and terminal metadata is removed after 7 days.
8. Zoom and Microsoft Teams meeting transcripts
Meeting transcript integrations are optional. Outrevio does not join meetings as a bot, record audio/video, capture microphone or system audio, or run its own speech-to-text service. When you connect Zoom or Microsoft Teams, Outrevio imports only transcript text that the provider generated and that the connected account is permitted to access, together with limited meeting/participant metadata needed to display, search, secure, and synchronize that data.
Meeting transcripts can contain personal communications about people who do not have an Outrevio account. Zoom and Microsoft Teams provide their own participant recording/transcription notices and, depending on provider/account policy, consent controls. Those provider controls do not let Outrevio determine whether every downstream use is permitted in a particular jurisdiction, workplace, school, confidential relationship, or meeting. Account holders should connect/import/use meeting transcripts only when they have appropriate authority and should avoid using Outrevio to retain material they are not permitted to handle.
Outrevio keeps imported transcript text for 90 days from import. After that deadline, transcript text is no longer available for reading, search, or meeting AI and is removed automatically. Limited meeting, participant, connection, and synchronization information may remain while the provider stays connected. Disconnecting Zoom or Teams removes that provider's imported meetings and transcripts from Outrevio. Final account purge after the deletion recovery window removes all local meeting-provider data.
Meeting transcript text is sent to OpenAI, Anthropic, or Google Gemini only when the user separately enables the Meeting transcripts AI data permission and explicitly chooses Analyze transcript. Importing, viewing, searching, retention cleanup, and provider synchronization do not automatically invoke an AI provider.
8. Communications and outreach
Outrevio currently prepares drafts and records CRM activity, but it does not operate a general automated email, SMS, WhatsApp, or campaign sender to CRM contacts. Contact information stored in the CRM is therefore not automatically transmitted to an email/SMS provider merely because a user imports or saves it.
If Outrevio later enables outbound communication, the Privacy Policy and product controls must be updated before launch to describe the channel, recipient data, provider(s), purposes, consent or preference records where applicable, suppression/opt-out data, communication metadata, and retention. See the Communications & Outreach disclosure for the current launch gate.
9. Internal AI assistance
Outrevio uses an external AI provider only when you choose an AI action, such as sending an AI chat prompt or selecting Generate, and only with the data permissions you enabled. Ordinary page loads, imports, contact updates, and non-AI recommendations do not trigger an AI request.
For an AI request, Outrevio sends only the permitted data needed for that action rather than the entire CRM. Depending on your provider choice, the request may be sent to OpenAI, Anthropic, or Google Gemini. Outrevio records limited usage information such as provider, model, action, status, and usage totals, but the AI usage record does not store the prompt, CRM evidence, note content, generated answer, or provider credentials.
Outrevio does not train its own AI models on CRM content. Third-party AI providers process the requests they receive under their own applicable terms and privacy commitments, and providers may handle data differently. Outrevio limits what it sends according to the data permissions you choose.
Generated assistance and inferred relationship signals can be incomplete or inaccurate. Outrevio instructs external AI providers not to infer protected/highly sensitive traits from CRM evidence and not to make or rank regulated eligibility or consequential decisions about another person. Relationship intelligence remains a networking-context feature, not an employment, credit, housing, insurance, or admissions assessment.
Outrevio does not currently keep AI chat history after the active experience requires it. If Ask before changes is enabled, Outrevio can prepare supported CRM actions for your confirmation. Prepared action details are cleared when completed, cancelled, or expired, and remaining status metadata is removed after approximately seven days.
10. External AI applications
Outrevio may allow separately operated applications such as ChatGPT to connect to your account. These connections are separate from the provider that powers AI inside Outrevio. Each external app receives only the permissions you approve.
Outrevio stores limited connection information needed to manage and revoke connected apps. Temporary connection-request details expire after about 10 minutes. Reading Outrevio data through a connected external app does not use the AI provider selected inside Outrevio. Connected third-party applications have their own privacy practices, which you should review before authorizing them.
Outrevio treats CRM content shared with a connected app as data, not as instructions that can change your Outrevio permissions. A separately operated app may have its own behavior after it receives information you authorized, so connect only apps you trust and disconnect access you no longer want. See the AI & External Connections disclosure for more detail.
11. Service providers and other disclosures
Outrevio uses service providers or user-selected integrations to operate the features described in this policy. The current categories are:
| Category | Current provider(s) | Purpose |
|---|---|---|
| Frontend hosting and request delivery | Vercel | Serve the Next.js application and related platform requests. |
| Backend hosting | Render | Run the Outrevio API, integrations, OAuth/MCP endpoints, and server-side processing. |
| Database hosting | Render PostgreSQL | Store Outrevio account, CRM, integration, audit, and related application records. |
| Password compromise screening | Have I Been Pwned — Pwned Passwords | Screen new or changed passwords against known compromised-password data using the privacy-preserving range API; Outrevio sends only the first five hexadecimal characters of a locally computed SHA-1 digest, not the password or account email. |
| User-selected authentication provider | Google; Microsoft | Authenticate with Google or Microsoft only when the user explicitly chooses that sign-in method. These identity authorizations request only openid, email, and profile scopes and stay separate from Google Calendar, Gmail, Outlook Calendar, Outlook Email, and Teams permissions. |
| User-selected calendar integration | Google; Microsoft / Microsoft Graph | OAuth identity and calendar functionality when a user connects Google Calendar or Outlook Calendar. |
| User-selected email metadata integration | Google Gmail API; Microsoft Graph | Fetch bounded message-header/basic metadata only after the user separately connects Gmail or Outlook Email and explicitly opens email capture; mailbox bodies and attachments are outside the current integration. |
| User-selected messaging integration | Meta / WhatsApp Business Platform | Receive and optionally reply to messages sent to the configured CRM assistant. |
| User-selected meeting transcript integrations | Zoom; Microsoft / Microsoft Graph | Authorize the connected meeting provider, receive provider transcript-availability notifications, and retrieve provider-generated transcript text that the connected account is permitted to access. |
| User-selected AI processing | OpenAI, Anthropic, Google Gemini | Process bounded context only for explicit AI requests when the matching Outrevio permissions are enabled. |
| User-authorized external AI application | For example ChatGPT during MCP developer validation; future clients only after separate enablement | Receive only data permitted by the OAuth/MCP scopes the user authorizes. |
Outrevio may also disclose information when reasonably necessary to comply with law, respond to valid legal process, protect users or the service, investigate fraud/security abuse, or complete a legitimate corporate transaction subject to appropriate safeguards and updated notices where required.
No Stripe or PayPal payment processing is active in this policy version. Payment-provider and subscription disclosures must be added before Outrevio begins charging users.
12. Sale, targeted advertising, Do Not Track, and Global Privacy Control
Outrevio does not currently sell personal information and does not currently disclose personal information for cross-context behavioral advertising or operate third-party advertising trackers in the authenticated product.
Because those practices are not currently part of Outrevio, there is no sale/share or targeted-advertising opt-out to apply to the current service. Browser Do Not Track or Global Privacy Control signals therefore do not change essential authentication, security, or user-requested integration behavior today. If Outrevio later introduces a practice for which applicable law requires recognition of an opt-out preference signal, the product and this policy must be updated before that practice is enabled.
13. Retention and deletion
Outrevio keeps information only for as long as it is reasonably needed for the feature, security, audit, dispute, or operational purpose described below. The schedule below establishes the current application-controlled retention baseline and automated cleanup for short-lived credentials and integration records.
| Data | Retention | Why |
|---|---|---|
| Active account and CRM records | Until the user edits/deletes the record or permanently deletes the account | Needed to provide the CRM feature the user requested. |
| Legal acceptance records | While the account exists; removed with permanent account deletion in the current product | Documents the policy versions affirmatively accepted by the account holder without creating an indefinite post-deletion identity record. |
| Email-confirmation and password-reset tokens | Cleared after expiry; successful use clears them immediately | The token has no account-recovery purpose after it expires or is used. |
| Email sign-in verification challenges | Code is protected at rest and cleared on successful use or invalidation; terminal/expired challenge metadata is removed after about 24 hours | Needed only to finish an explicitly enabled, short-lived sign-in verification step and enforce replay/attempt limits. |
| Authentication email outbox delivery payloads | One-time delivery payload is protected at rest and cleared immediately after successful delivery or abandonment; terminal outbox metadata is removed after about 7 days | Allows reliable retry of user-requested account-security email without retaining a usable reset/confirmation credential after delivery is complete. |
| Expired or revoked first-party refresh-token hashes | Up to 30 days after expiry/revocation | Short security-investigation grace period, after which the invalid credential hash is removed. |
| Temporary MCP OAuth authorization requests | About 10 minutes or until consumed, then removed by cleanup | Only needed to complete the active OAuth consent bridge and prevent replay. |
| Provider-generated meeting transcript text | 90 days from Outrevio import under the current production baseline, using each transcript's RetainUntilUtc deadline | Meeting transcripts can contain sensitive communications. Expired transcript rows are deleted automatically and excluded from reading, search, and AI as soon as the deadline passes. |
| Meeting, participant, and provider-connection metadata | While the meeting provider remains connected or until permanent account deletion; provider disconnect deletes that provider's local meeting data | Minimal metadata supports the meeting history, provider synchronization, ownership checks, and connection diagnostics without retaining transcript text indefinitely. |
| AI action proposal content | Pending for about 10 minutes; terminal payload content is cleared and terminal proposal metadata is removed after about 7 days | Supports user confirmation and short troubleshooting without retaining proposal content indefinitely. |
| WhatsApp pending-confirmation payloads | Payload cleared when completed/expired; terminal metadata removed after 7 days | Confirmation content is only needed while the user is deciding whether to approve the action. |
| WhatsApp command logs | 30 days | Short troubleshooting, duplicate-detection, abuse/safety, and user-visible integration history window. |
| Persistent diagnostic system events | 30 days | Short operational troubleshooting window. |
| Persistent audit system events | 365 days | Security/accountability history for important actions without indefinite retention. |
| Persistent security system events | 730 days | Longer abuse, incident-response, and security-investigation history; persistent event metadata is deliberately bounded. |
| Google Calendar credentials and connection metadata | Until disconnect or permanent account deletion | Required only while the user keeps the integration connected. |
| Outlook Calendar credentials and connection metadata | Until disconnect or permanent account deletion | Required only while the user keeps the Microsoft calendar integration connected. |
| Outlook Email credentials and connection metadata | Until disconnect or permanent account deletion | Required only while the user keeps the separate Outlook Email metadata integration connected. Recent message metadata is fetched on demand and is not kept as a general mailbox cache. |
| Gmail credentials and connection metadata | Until disconnect or permanent account deletion | Required only while the user keeps the separate Gmail metadata integration connected. Recent message headers are fetched on demand and are not kept as a general mailbox cache. |
| MCP external-connection metadata | Active/revoked connection metadata remains with the account and is removed on permanent account deletion | Supports authorization/revocation safety and connection auditability while the account exists. |
Provider-managed infrastructure logs and backups can have separate retention controlled by Vercel, Render, Google, Meta, or another provider. Outrevio will verify and reconcile those provider-side periods during the final production legal launch gate rather than promising deletion timing the application cannot directly enforce.
Authenticated account holders can create a privacy export and request permanent account deletion from Settings → Privacy & Data after re-entering their current password and completing a short-lived six-digit email-code verification. A verified request locks the account immediately and starts a seven-day recovery window before final purge. The deletion process and retained-record limitations are described in the Data Deletion Instructions.
14. Security and operational logs
Outrevio uses authentication, ownership checks, CSRF/same-origin controls, rate limits, request-size limits, structured logging, revocation controls, and other safeguards intended to protect user data. No system can guarantee absolute security.
Outrevio's persistent system-event store is designed around bounded metadata such as route, status, duration, action/resource identifiers, outcomes, and security source hashes. The persistent event writer allow-lists metadata keys instead of persisting request bodies or CRM note contents. Hosting and infrastructure providers may maintain their own operational logs under their own service terms and retention practices.
15. Security incidents and breach-notification review
Outrevio maintains an incident-response process for investigating suspected unauthorized access, misuse, credential exposure, or other security events. An automated alert is treated as an investigation signal, not automatic proof that a legally reportable breach occurred.
When an incident may involve personal information, Outrevio is designed to contain active risk, preserve relevant evidence, identify affected systems/accounts/data and integrations, revoke or rotate affected credentials and OAuth/MCP grants where appropriate, and escalate the facts for human security and legal review. Whether notice is legally required can depend on the people and jurisdictions affected, the data involved, contractual obligations, and the then-current law; Outrevio does not automate that legal decision.
The current response approach is described in the Security & Incident Response disclosure.
16. Your choices and U.S. privacy rights
Current product controls include editing profile and CRM data, exporting supported account data, connecting or disconnecting Google or Microsoft sign-in when another sign-in method remains, disconnecting Google Calendar or Outlook Calendar, disconnecting WhatsApp, clearing WhatsApp command logs, disabling/changing internal AI permissions, switching AI actions to Read only, and disconnecting external MCP applications.
Depending on where a person lives, the type of information involved, and whether a particular state privacy law applies to Outrevio, additional rights may include access, correction, deletion, portability, limits on certain sensitive-data processing, opt-out rights for sale/sharing or targeted advertising, and an appeal process for denied requests. Outrevio is being designed around a common U.S. privacy-rights baseline rather than assuming only one state matters.
Users can review or correct much of their own account and CRM information directly in the product. Authenticated account holders can download a portable privacy export or request permanent account deletion through Settings → Privacy & Data; verified deletion requests enter a seven-day recovery window before final purge. Additional instructions are maintained on the Data Deletion page. A request involving a person who is not an Outrevio account holder must be handled without revealing whether that person appears in another user's private CRM.
17. Children and minimum age
Outrevio is not designed as a service directed to children under 13. The final public-launch minimum age has not yet been set. Outrevio will not represent the service as available to a particular age group until that eligibility decision and the corresponding product/legal controls are finalized.
18. Changes to this Privacy Policy
Outrevio versions this Privacy Policy and shows its last-updated date. The policy must be updated when product behavior materially changes—for example, if Outrevio introduces payment processing, new tracking/analytics, new external providers, materially broader AI/MCP permissions, automated outreach, or new categories of personal information. Where applicable, a material change may require additional notice or renewed acknowledgement rather than silently relying on an old acknowledgement.
19. Contact
Privacy questions and requests can be sent to support@outrevio.com.
Current legal-document versions and contact details are maintained in the Legal & Privacy Center.
