NAVI Privacy and Data Controls
This page describes how NAVI collects, uses, retains, and deletes data across our web platform and mobile applications.
Last updated: July 11, 2026
What We Collect (Web Platform)
Lead contact information, attribution metadata, submitted messages, and portal activity required to operate websites for clients.
Mobile Applications
NAVI provides Android applications NAVI Client and NAVI Admin (collectively, the Mobile Apps). This section describes data practices for the Mobile Apps in addition to our web services.
Data we collect through the Mobile Apps
- Account information — email address, name, and user identifier when you sign in.
- App activity — interactions with dashboards, CRM features, and administrative views needed to provide the service.
- Device identifiers — push notification tokens and installation identifiers used to deliver notifications and maintain sessions.
- Diagnostics — crash logs and performance data to improve stability.
How we use mobile data
We use mobile data to authenticate you, provide NAVI features, send operational notifications you enable, and diagnose crashes.
Third-party services in the Mobile Apps
- Supabase — authentication, database, and realtime sync
- Google Firebase — push notifications and crash reporting
Permissions
NAVI Client may request permission to send notifications. We request this permission only to deliver notifications you expect from the service. You can disable notifications in device settings.
AI-Assisted Features
AI chat features are not currently enabled in the production platform. If AI-assisted features are introduced in the future, this section will be updated to describe the specific provider(s), data handled, retention period, and opt-out mechanism before the feature is activated.
If you have questions about AI data practices, contact support@naviinc.io.
Retention and Third-Party Services
Operational data is retained according to platform policy:
- Lead and inquiry records — up to 180 days in the platform database, then scheduled for deletion.
- Account and app data — retained while your account is active and as needed to provide the service, comply with law, and resolve disputes.
- Security and audit logs — up to 1 year for routine logs; up to 3 years for confirmed security incidents.
Third-party services used in delivering the platform:
- Vercel — website hosting and edge delivery (server logs ~30 days)
- Supabase — database, authentication, storage
- Stripe — payment processing (billing data)
- Resend — transactional email delivery (delivery logs ~30 days)
- Google Firebase — push notifications, crash reporting
- Cloudflare — bot protection and challenge (request metadata)
- GitHub — source code management (code only; no end-user PII)
Admin-controlled retention jobs can purge lead and automation records on a shorter schedule. To request early deletion of your data, use the form below.
Your Rights and Choices
- Request disclosure of personal data categories held by this service.
- Request deletion of personal data, subject to legal and operational exceptions.
- Request corrections for inaccurate contact information.
- Access or update account information in the app or by contacting support@naviinc.io.
- Request deletion of your account and associated data via this page (form below) and in the Mobile Apps under Settings → Request data deletion.
- Opt out of notifications via device settings.
Security and Children
We use encryption in transit (TLS) and industry-standard safeguards for data at rest managed by our infrastructure providers. The Mobile Apps are not directed to children under 13 (or applicable age in your jurisdiction). We do not knowingly collect personal information from children.
Contact
Questions about this policy: support@naviinc.io