Legal
Privacy Policy
Last updated: September 7, 2026
Ovillo is a work tool: almost everything we store is data your organization puts
in to run its work (tasks, documents, comments, time logs).
We do not sell your data, we do not use it for advertising, and we do not
train AI models on your workspace content.
1. Who we are
The controller is Ovillo, operator of the service available at
ovillo.lat and app.ovillo.lat. For any privacy matter,
write to hello@ovillo.lat.
When you use Ovillo inside a company, your organization decides what data
goes in and who can see it. In that setting Ovillo acts as a processor
handling that data on the organization's behalf and under its instructions.
2. What data we process
Account data
- Name, email address and, if you sign in with Google or Microsoft, the profile
picture that provider returns to us.
- The organization you belong to, your role and permissions, weekly capacity and
language.
- If you use a password, we store only a bcrypt hash — never the
password itself. If you use a passkey, we store the credential's public key
(the private key never leaves your device).
Your workspace content
- Spaces, tasks, incidents, goals, sprints, documents, comments, tags, time logs
and file attachments that users create.
- Conversations with the AI agent and the runs of assignable agents, which are
recorded so it can be audited what the agent did and with what data.
- If your organization enables the meeting assistant: the meeting's audio or
video, its transcript and the generated notes.
Technical and usage data
- Daily presence per client: we record that a user used a given
client (web app, Chrome extension, VS Code extension, MCP client) on a given
day, to know what actually gets adopted.
We deliberately do not store IP address or user agent in that
table.
- AI consumption: tokens and credits spent per user, for billing
and limit enforcement.
- Server logs: method, path (with sensitive query parameters
redacted), response code and source IP. They are used to operate the service
and for security (for example, throttling login attempts) and live in the
server logs, not in the application database.
- Sessions and tokens: sessions, personal access tokens and
OAuth tokens are stored only as SHA-256 hashes.
Marketing site
On ovillo.lat we use Google Analytics to measure
visits. If you fill in the contact form, we process what you send us in order to
reply. The application (app.ovillo.lat) carries no third-party
analytics and no advertising trackers.
3. Why we use it
- To provide the service: authenticate you, show you what your
permissions allow, store your work and notify you.
- AI features: answering in chat, running tools over your
spaces, triaging tickets, transcribing meetings.
- Billing: active seats, plans and credit consumption.
- Security and abuse prevention: detecting improper access,
throttling login attempts, revoking sessions.
- Support and product improvement: aggregate adoption metrics
and answering the requests you send us.
Where the GDPR or an equivalent law applies, our legal bases are
performance of the contract (providing the service),
legitimate interest (security, abuse prevention, aggregate
metrics), consent (marketing-site analytics, meeting recording)
and legal obligation (accounting and tax duties).
4. Artificial intelligence
Ovillo's agent runs on a third-party large language model. When you use an AI
feature, the text of your request and the data the agent needs to answer it (for
example, the tasks in the space you asked it to look at) are sent to the model
provider to generate the response.
- By default the provider is OpenAI, through its business API,
where data submitted via the API is not used to train their
models.
- On the plans that allow it, your organization can use its own API
key: traffic then goes to whichever provider you configure, under
your agreement with them.
- Ovillo does not train or fine-tune models on your workspace
content.
- The agent never reaches the database directly: it operates through a bounded
set of tools that run with your own permissions, and an
administrator can turn chat tools off for the whole organization.
5. Connectors and external clients
You can connect Ovillo to external assistants through our MCP
server (app.ovillo.lat/api/mcp/web with OAuth 2.1, or
/api/mcp with a personal access token). When you connect one:
- The client you connect (Claude or ChatGPT, for instance) can read and act on
only what you yourself can see and do; authorization is
re-checked on every call and there is no privilege escalation.
- Whatever that assistant retrieves from Ovillo also ends up in the hands of that
assistant's provider, subject to their privacy policy.
- You can cut access at any time: Settings → Connections → Connected AI
apps (revokes that client's tokens), or by deleting the personal
access token.
- We record which client connected and on which day, under the daily-presence
rule described above.
6. Who we share it with
We do not sell or rent personal data. We share it only with providers that run
services we need to operate, and only the data each one needs:
| Provider | Purpose | What it receives |
| Amazon Web Services | Hosting, database and attachment storage (us-east-1, United States) | All service data, encrypted in transit |
| OpenAI | AI features (unless you use your own key) | The text of the request and the data the agent needs to answer it |
| Stripe | Payments and subscriptions | Billing email and subscription identifiers. Card details are handled by Stripe: Ovillo never sees them. |
| Google / Microsoft | Sign-in, if you choose that option | What your identity provider already manages: name, email, picture |
| Brevo | Transactional email (invitations, password reset, alerts) | The recipient's name and email and the content of the notice |
| Recall.ai | The bot that joins the call, only if you enable the meeting assistant | The meeting link and its audio/video |
| Telegram / Slack | Incident notifications, only on the channels your organization enables | The content of the notice sent to that channel |
| Google Analytics | Marketing-site metrics only | Browsing data on ovillo.lat |
We may also disclose data when a competent authority requires it through a valid
legal channel, or to defend our rights against misuse of the service.
7. Where data lives, and international transfers
Ovillo's infrastructure is in the United States (AWS, us-east-1).
If you access it from another country, your data is transferred there. For users in
the EEA or the UK that transfer relies on our providers'
standard contractual clauses.
If your organization needs data to stay inside its own perimeter, Ovillo can be
installed on your own infrastructure; in that mode this policy does
not cover hosting, which is on you.
8. How long we keep it
- Workspace content: for as long as the account is active. What
you delete in the app (a task, a document, an attachment) is deleted from the
database.
- User account: until an administrator in your organization
deletes it, or until the organization is closed, at which point its associated
data is deleted.
- Sessions and tokens: sessions expire after 7 days of
inactivity with a 30-day ceiling; a connector's access token expires in 1 hour
and is refreshed while the connection stays authorized. Revoking cuts access
immediately.
- Server logs: short retention, on the order of days, for
diagnostics and security.
- Billing records: as long as applicable accounting and tax law
requires, including after the account is closed.
- Meeting recordings and transcripts: for as long as your
organization keeps them; they can be deleted from the app.
9. Security
- All traffic goes over HTTPS, with certificates renewed
automatically.
- Passwords with bcrypt; sessions, personal access tokens, codes
and OAuth tokens only as SHA-256 hashes.
- Per-organization and per-space access, enforced on every server request and not
just in the interface.
- Support for passkeys (WebAuthn) and session revocation.
- No system is infallible: if you find a security problem, write to
hello@ovillo.lat and we treat it as a
priority.
10. Your rights
You can request access, correction, deletion, restriction, objection and
portability of your personal data, and withdraw consent where the
processing relies on it.
- Much of it you can do yourself in the app: edit your profile, export tasks to
CSV or JSON, revoke tokens and connected apps, delete the content you
created.
- For anything else, write to
hello@ovillo.lat and we answer within the
deadline the applicable law sets (30 days as a reference).
- If you use Ovillo through your employer, we may have to route the request to
that organization, which is the one deciding over that data.
11. Children
Ovillo is a professional tool and is not directed at children under 16. We do not
knowingly collect data from minors; if you spot a case, tell us and we delete it.
12. Changes to this policy
If we update it, we change the date in the header and, when the change is material,
we announce it in the app or by email before it takes effect.
13. Contact
hello@ovillo.lat — privacy questions, requests
about your data and security reports.