Skip to content

A note from the founder

You can hand Nova the keys.

Nova reads your email, your calendar, your notes. That's the deal. In return we owe you a straight answer to every honest question you have about what happens to that data — and a product that behaves like we mean it.

This page is that answer. No compliance-brochure language, no invented certifications. Just what Nova does today and what it will never do.

The awkward question

What happens if Nova sees something it shouldn't?

Nova will see private things. A doctor's appointment. A legal thread. A quiet conversation with a lawyer, an accountant, a therapist. This is unavoidable — it's in the inbox you asked us to watch.

Here's what happens when it does:

  • ·It stays yours. Sensitive content is never surfaced to us as humans. No support agent, no engineer, no founder — nobody at Nova reads your mail. Access to your data by any Nova staff member requires an explicit support request from you, is logged, and is time-boxed.
  • ·It's never used to train a model. Not ours (we don't operate one), and not the providers we call — we run those calls under paid API terms with training disabled where the provider offers that switch. If you want the current provider configuration in writing for compliance, email us and we'll send it.
  • ·Nova won't act on it without your tap. Nothing sends, books, or pays without an approval event tied to that specific draft. This is enforced by the database itself, not by our good intentions.
  • ·You can rip it out. One tap disconnects a source (Nova forgets it immediately). One tap in your account exports every row Nova holds about you as a JSON file. One tap, with a typed confirmation, wipes your account for good.
  • ·If we ever get compelled by law to disclose your data, we'll narrow the scope as far as the request allows and notify you unless legally prohibited.

The nine rules we won't bend

Approval-first by design

Every outbound action lands in your inbox as a draft. Nothing sends, books, or pays without you tapping approve. This is a database-level invariant — not a setting we can flip off.

Row-level isolation

Every table in the database enforces row-level security scoped to your user id. Your data is unreachable from any other account, even by mistake.

Secrets stay server-side

API keys, OAuth tokens, and webhook secrets live only in encrypted server storage. The browser bundle never sees them.

Your data, exportable

One tap inside your Trust centre exports everything Nova knows about you as a JSON file. Another tap erases your memory and starts you fresh.

No silent training

Nova learns from how you approve and edit drafts. We don't ship your data to third-party training pipelines.

Verified webhooks only

Payment and integration callbacks reject any payload without a valid HMAC signature. Replays and forged events do nothing.

Audited status changes

Card lifecycle (drafted → approved → sent) is append-only logged. A client cannot mark something sent without a prior approval event.

Guardrails you set

Quiet hours, spend limits, and allowed action types are yours to configure on the Profile page. Nova won't cross them.

WhatsApp: approvals, not a chatbot

Nova uses WhatsApp only to send you approval prompts on your own opted-in number — never as a public AI chatbot. One message when something needs your tap; you approve in Nova. You can turn it off in one tap.

Timezone-safe scheduling

Every card that carries a time — briefings, renewals, watchers, reminders — is computed in your timezone using explicit UTC-anchored dates, not the server's local clock. Daylight-savings changes don't double-book or drop reminders.

About certifications

Nova is early. We follow the access, correction and deletion rights defined by GDPR, POPIA and CCPA today. We are not yet SOC 2 or ISO 27001 certified — SOC 2 Type I is on the roadmap as we grow. We will not claim any certification until it's formally issued to us. If someone tells you otherwise, they're wrong, and we'd like to hear about it.

Where to take action

  • Privacy notice — what we collect and why, in plain English.
  • Terms — the legal frame.
  • Status — live system health.
  • Signed in? Open your account to export or wipe your data.
  • Security concern or vulnerability? Email security@heynova.tech and you'll get a human — usually within a working day.

— The Nova team

Next step

Approval-first isn't a setting — it's the design.

See it on your own inbox. Nova drafts, you approve every send.

No card. Nova drafts — you approve every send.