Privacy
Privacy policy
What Navlio collects, where it goes, and what we will not do with it. Written to be checked against the product rather than to sound reassuring.
Last updated 1 September 2026
Who this covers
Navlio is a brand health product operated by a small team in Brazil. It reads a website, reports where the brand stands in search and in AI answers, and proposes fixes a person approves before anything ships. This policy covers navlio.io and the application behind it.
Questions, requests, complaints: hello@navlio.io. A person reads that address.
What we collect
Only what the product needs to do the thing you asked for. There is no data collection here that exists to be sold or resold later.
- Account: your email address and a bcrypt hash of your password. We cannot read your password and neither can anyone who steals the database.
- Sites you add: the domain, and the content of its public pages, which we fetch the way a search crawler does.
- Connections you authorize: an encrypted refresh token per connected account, the scopes it was granted, and the property or repository you pointed it at.
- Conversations: what you type to the agent and what it replied, so the thread survives a page reload.
- Reports: the scores, findings and measurements produced for the sites you scanned.
- Our own marketing pages: pseudonymous visit counts through Google Analytics for Firebase.
Google user data
This section is the specific one, because Google account data deserves specific answers rather than a policy that covers it by implication.
Navlio requests two Google scopes, both read only. Analytics uses analytics.readonly. Search Console uses webmasters.readonly, which Google classifies as sensitive. Nothing we hold can write to, change, or delete anything in your Google account, because a read only grant makes that impossible rather than merely forbidden.
From Search Console we run one kind of request: a search analytics query returning rows of page, query, clicks, impressions and average position. That is the data behind the keyword and reach parts of a report. From Analytics we read traffic metrics for the property you selected. We do not read your Google profile, contacts, mail, files, or anything outside the property you connected.
Your refresh token is encrypted with AES-256-GCM before it is stored, under a key held only in the server environment. It is decrypted in memory for the length of one request and never logged, never sent to a third party, and never shown back to you.
Navlio's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide and improve the features you connected it for. It is never sold, never used for advertising, and never used to train a machine learning model. No human at Navlio reads your Google data except where you have asked us to look at something specific, where the law requires it, or where it is necessary to investigate a security incident or abuse.
You can disconnect at any time from the module page in the product, which deletes the stored token. You can also revoke Navlio independently at myaccount.google.com/permissions, which we cannot prevent or undo. Either route ends our access immediately.
Language models see your content
Worth saying plainly, because it is the part most policies bury. Navlio's reports and replies are written by large language models it does not host. Page content we fetched, report data, and what you type to the agent are sent to a model provider to be turned into an answer.
Today that provider is OpenRouter, which routes each request to the model named in our configuration. Anthropic is the alternative, selectable per deployment. Both are named in the list below with what they receive.
What is not sent: your Google refresh tokens, your password hash, your Stripe details, or the raw Search Console rows of anyone who is not the customer asking. We do not send your data to a model provider for the purpose of training, and we do not train models of our own on it. We cannot make a promise on behalf of a provider's own retention window, so if that matters to your risk assessment, read their terms rather than take ours as covering it.
Where it lives
The application runs on Google Cloud Run in europe-west6, which is Zurich. The database is Neon, hosted on AWS in us-east-1, which is Virginia in the United States. So data you give us is stored in the United States and processed in Switzerland, and if you are in the European Union or Brazil that transfer is a fact you should know before you connect anything rather than after.
Traffic to and from the application is TLS encrypted. Connection tokens are additionally encrypted at rest as described above. Passwords are hashed, not encrypted, which means they are not recoverable by us at all.
Who else gets it
The services below, each for one purpose, and nobody else. We do not sell personal data, we do not share it with advertisers or data brokers, and we do not run advertising on navlio.io.
We will hand over data if a law or a valid legal order requires it. If that ever happens and we are permitted to tell you, we will.
| Service | Why | What it receives |
|---|---|---|
| Google Cloud Run (europe-west6, Zurich) | Runs the application | Everything the application processes, in transit |
| Neon (AWS us-east-1) | Postgres database | Accounts, sites, connections, reports, conversations |
| OpenRouter | Routes requests to the language models that write reports and replies | Page content we fetched, report data, and what you type to the agent |
| Anthropic | Alternative model provider, selectable per deployment | The same content, when the deployment is configured for it |
| Stripe | Subscriptions and payment | Billing email, subscription state. Card details go to Stripe directly and never reach us |
| Resend | Transactional email | Your email address and the message body |
| Google Analytics for Firebase | Counts visits to our own marketing pages | Pseudonymous usage events and identifiers |
| Google PageSpeed Insights | Measures how fast a page loads | The public url being measured |
| Brave Search | Looks up where a site ranks and finds mentions of a brand | Search queries built from the domain and brand name |
| Microsoft Bing (IndexNow) | Tells search engines a page of ours changed | Urls on navlio.io only |
| ElevenLabs | Voice mode, when you start it | Audio of what you say and the reply |
Public brand pages
Navlio publishes report pages at navlio.io/brand for some domains, including domains whose owners never asked us to. Those reports are built entirely from publicly available information: pages a search crawler can already read, public search results, and what public language models answer when asked about the brand. They contain no personal data, no private analytics, and nothing behind a login.
If you own a domain with a page there and want it gone, write to hello@navlio.io and we will delete it. We do not require you to explain why, and we do not ask for anything in exchange.
Keeping and deleting
Account data lives as long as the account does. Reports and conversations stay until you delete them or the account. Disconnecting an integration deletes its token then, not later.
To delete your account and everything attached to it, write to hello@navlio.io from the address on the account. We will confirm when it is done. Backups roll off on their own within thirty days, so a deletion is complete rather than partial after that window.
Regardless of the account, you may ask what we hold about you, ask for a copy, ask for a correction, or object to a use. Those are your rights under the GDPR and under Brazil's LGPD and we honour them for everyone, not only people the law happens to cover.
Cookies
Two kinds, and no advertising cookies of any kind.
- navlio_session keeps you signed in. Without it the product cannot tell one request from another, so it is not optional and there is no consent banner pretending otherwise.
- Google Analytics for Firebase sets analytics identifiers on our marketing pages. Blocking them costs you nothing in the product and we will not nag you about it.
Children
Navlio is a business product and is not directed at anyone under 16. We do not knowingly collect their data, and if we learn we have, we delete it.
Changes
Last updated 1 September 2026. If a change actually affects what happens to your data, we will email account holders rather than quietly reposting the page with a new date.
Contact
Write to hello@navlio.io for anything on this page, including a deletion request or a question about a connected account.