1. Launch waitlist and emails
The HighLevel waitlist form collects your name if supplied, email address, contact number, optional community or business group, your reason for interest in Maven AI, email consent, submission time and technical submission information such as timezone. Mavens HQ stores these records in HighLevel to manage the waitlist, send confirmation, helpful preparation emails and the launch update you requested, and track signups through the launch pipeline. Your interest and community answers help us understand what you want from Maven AI and prepare relevant onboarding. Supplying a contact number does not subscribe you to SMS marketing.
Use the unsubscribe link in an email to stop marketing and launch messages, or contact sarah@mavenshq.com to request removal. Unsubscribing stops future messages but does not automatically erase historical consent or CRM records. Joining does not connect your Gmail or business CRM, require payment or reserve a beta spot. The hosted form is subject to HighLevel's provider processing and functional storage.
2. Operator and scope
Mavens HQ operates Maven OS. This policy describes the current public website and owner-restricted AI business workspace, and the planned beta payment flow where expressly identified. Contact sarah@mavenshq.com for privacy questions. Each beta customer receives assisted onboarding of a separate workspace connected only to their own authorized accounts.
The public homepage and legal pages contain informational and sample content, not private workspace records. Reservations and live checkout are not yet open. This policy distinguishes implemented data handling from provider settings that have not been verified; it does not promise a particular provider recording or retention configuration.
3. Information processed
- Account and session information: Google sign-in profile information, including your email, name and profile image where supplied, account identifiers, verified identity information and authentication/session tokens. The server uses a configured owner email to authorize the current workspace.
- Tasks and preferences: task text, priority and completion state, automation-panel preferences and the selected microphone device identifier. Task text can contain personal or business information you choose to enter.
- Gmail information: connected mailbox identity, message and thread identifiers, senders and recipients, subjects, snippets, timestamps and labels; email body text and thread content when requested and content-sharing is enabled. Proposed drafts, replies, sends, label changes or trash actions include the details needed to review and execute them. Existing mailbox content remains with Google.
- HighLevel information: contacts and their available contact details, opportunities and pipeline stages, calendars and appointments, conversation metadata and message text requested through the integration, and the relevant details of proposed record changes or messages.
- Voice and conversation information: microphone audio while a voice session is active, typed messages, conversation text/transcripts, AI responses, requested tool inputs/results and relevant task, email or CRM information used to answer your request.
- Integration credentials: connection/API credentials, configured integration identifiers and short-lived voice connection credentials needed for authorized provider access. Private integration/API credentials are handled server-side or by the connection service, not displayed as workspace data.
- Security, diagnostics and support: server errors, stack traces and cause details, provider operation/status errors, and information you send by email for help. Hosting or provider systems may also process request, device, network and access information necessary to deliver and protect the service.
- Beta and payment records: the implemented reservation structure contains name, email, optional business, reservation status and timestamps, hold expiry, checkout/order identifiers, amount and currency, paid timestamp, and payment-event identifier/receipt timestamp. These records support the future checkout flow; the waitlist separately collects signup information as described above and does not take payment. Creem handles payment information in its checkout when enabled. Maven OS has no implemented storage field for full card details or card security codes.
4. Why information is used
We process information to authenticate and authorize access, connect authorized business accounts, display requested workspace information, answer voice or typed requests, manage local tasks, prepare actions for review and execute confirmed actions. We also use necessary information for security, troubleshooting, support and, when enabled, beta reservations, payment reconciliation, capacity handling and refunds. Lovable Visitor analytics is enabled to understand website visits, and AI app context is enabled to use context from AI calls to debug and improve the app.
Connected-account access is limited to the permissions granted and the features requested. Gmail functionality requires permission to read mailbox information and, for confirmed drafts, sends, labels or trash operations, the corresponding modification permissions. HighLevel access uses the configured location and permissions for contacts, opportunities, calendars/events and conversations/messages. Revoking or limiting permissions can prevent those features from working.
Google API data is used only for requested user-facing features, not for advertising or general-purpose model training. The application does not implement an advertising use or a general-model training pipeline for that data. This statement is not a blanket guarantee about every provider's independent data policies or unverified account settings.
5. Providers and information sharing
- Lovable and Lovable Cloud: application hosting, authentication, database, private server functions, stored secrets and connector infrastructure. Gmail requests pass through Lovable's connection gateway. Authentication and proposal/reservation records are processed by the hosted backend. Editor previews also use Lovable's session-sharing and diagnostic facilities. Lovable Visitor analytics and AI app context are enabled; the latter allows context from AI calls to be used for debugging and improving the app. These hosting-level settings are separate from the application's own storage and from ElevenLabs processing.
- Google / Gmail: Google sign-in and access to the authorized mailbox. Google processes sign-in and mailbox requests under its own terms and privacy notices.
- HighLevel: access to the authorized CRM location and requested contact, pipeline, appointment and conversation operations.
- ElevenLabs: real-time voice-agent processing. The browser connects to ElevenLabs using a server-issued signed connection URL. Audio, typed messages, transcripts and relevant tool results—including requested Gmail bodies or CRM conversation text when content sharing is enabled—can be sent to the agent so it can respond. Summary text is limited where implemented, but requested full-content tools can supply more detailed text. Email and CRM content is marked as untrusted input, not instructions.
- Creem: selected payment provider for the future beta checkout. The adapter sends a buyer's email and reservation identifier to create a checkout and processes signed payment notices containing payment/order information. Checkout is currently disabled. Creem's handling of payment details is governed by its own notices and obligations.
- Support and required disclosures: information sent to our support address is processed through the email services involved. Relevant records may also be provided where necessary to address a payment dispute, comply with applicable legal obligations or protect accounts and the service.
6. Visitor analytics and AI app context
Lovable settings currently have Visitor analytics ON and AI app context ON. Visitor analytics processes information about visits to this website. AI app context allows context from AI calls to be used to debug and improve the app. Context may contain information supplied in requests or responses; the exact captured fields, redaction, coverage of external voice calls, access controls, retention and any further provider uses have not been independently verified.
These enabled settings mean we cannot promise that all AI-call context stays only in transient workspace memory or is used solely to generate the immediate response. Debugging and app improvement are distinct from general-purpose model training; enabling app context does not by itself establish a training practice or a no-training guarantee. We have not verified whether or how Google API-derived content is captured by this setting. Our restriction of Google API data to requested user-facing features remains applicable; sensitive content should not be shared where a specific provider processing arrangement is required until that arrangement is verified. Contact us with questions about analytics or AI context processing.
7. Voice recording and AI settings
The application keeps the displayed conversation transcript in React memory for the mounted workspace; it does not implement a separate local recording file or database transcript archive. This does not mean ElevenLabs does not record or retain conversations.
The ElevenLabs account's recording, transcript retention, data-use settings and any model provider configured inside the hosted agent have not been verified from this application's source. We therefore do not claim that recordings are disabled, that provider copies are immediately deleted, or that a particular additional model provider is used. Contact us before sharing information that requires a specific recording or processing arrangement.
Microphone access is requested when starting a session or checking a microphone. A preliminary permission-check stream is stopped before the voice session stream is opened. You can mute or end the session, and the application requests that the session end when the workspace closes. Muting or ending a call does not delete information already processed by a provider.
8. Transient data and stored records
Live Gmail and HighLevel reads are fetched through private server functions and held in browser memory for the workspace; the application does not write those live read snapshots to browser storage or its own database. Connected providers retain their own underlying records, and information returned to the voice agent is subject to that provider's processing.
There is an important exception to memory-only reading: action proposals are stored in the backend. A proposal may include email recipients, subject/body, CRM details or other proposed content, together with the owner's identifier, action type, summary, payload hash, status, expiry and result information. This enables the on-screen review and single-use confirmation process. A proposal's 10-minute confirmation expiry prevents late execution; it is not an automatic deletion deadline. No scheduled proposal deletion period is implemented.
Tasks and preferences persist in local browser storage. Authentication records and proposal records are held in Lovable Cloud. Reservation and payment-event structures are also implemented for the disabled payment flow. Diagnostic logs can retain error messages, stack traces and technical operation details; we do not guarantee that every logged error is free of personal information.
10. Retention and deletion
We retain information as necessary to operate and secure the service, provide support, address disputes and meet applicable legal or payment-record obligations. The current implementation does not establish a fixed deletion schedule for authentication records, proposals, reservation/payment records or hosting logs. Local tasks/preferences remain until changed, deleted through the relevant controls or cleared from browser storage. Transient workspace data and displayed transcripts are lost when the mounted workspace is discarded, but that does not erase provider records or logs.
Deletion requests are reviewed according to the information involved and applicable obligations. Some records may need to be retained for legal, payment, fraud-prevention or dispute purposes. Backup copies may persist under the hosting provider's recovery lifecycle, and provider-held copies are subject to that provider's controls. Revoking an integration stops future authorized use through that permission; it does not itself delete prior proposals, provider records or payment records.
11. Your permissions and privacy requests
You can revoke Maven OS-related Google account permissions through Google's account permission controls, and revoke or restrict the HighLevel integration through your authorized HighLevel account. Contact support for help disconnecting a service or understanding the effect of a permission change. You can also deny browser microphone permission or end voice sessions.
To request access, correction or deletion of information associated with you, or raise a privacy concern, email sarah@mavenshq.com. Identify your account and the request without sending passwords, API keys, full card details or excessive private content. We may need to verify your identity and authority before releasing or changing records. Requests concerning another person's business data may need to be handled with the account owner or relevant provider.
We will consider requests and the rights that apply under relevant law. Contact the provider directly where you need changes to a record it controls. Local browser data can be removed using task controls or browser storage controls.
12. Security and international processing
Implemented safeguards include server-side verification of the current owner's verified Google identity for private data and voice-credential functions, server-side handling of integration secrets, restricted database access, and owner-bound action proposals with payload integrity checks, confirmation expiry and atomic single-use execution. External sends and record writes require on-screen review. These safeguards reduce risk but do not guarantee absolute security or prevent every AI error.
Our hosting, integration, voice and payment providers can process information internationally, potentially outside your country. Exact processing locations and provider contractual arrangements have not been verified in the application source. Contact us if location or cross-border requirements affect whether you can use the service.
13. Adult business service and policy updates
Maven OS is intended for adults using authorized business accounts, not for children. Do not use it to submit children's information without appropriate authority and safeguards. Contact us if you believe information was submitted inappropriately.
We may update this policy as the product, integrations or verified provider settings change. The effective date will be updated, and material changes will be communicated through the service or available account contact information where appropriate. For privacy questions, contact sarah@mavenshq.com. Our Terms of Service describe the beta and refund policy.