Privacy Policy

Effective date: July 18, 2026

Operiva AI (“Operiva,” “we,” “us”) provides AI-powered workflow automation and agent services to businesses. This policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to our website at operiva.ai and to the Operiva service.

1.Information we collect

Account information. When you create an account we collect your name, email address, and authentication details. Sign-in is handled by our identity provider, Clerk; we do not see or store your password.

Connected-service data. The core of our service is acting inside tools you connect — for example Microsoft 365 / Outlook, QuickBooks Online, and Slack. When you connect a service through its official authorization (OAuth) flow, we receive access tokens and, depending on the workflow you configure, process content from that service, such as:

  • Email messages relevant to your workflow (for example, incoming order emails), including sender, subject, body, and thread context
  • Accounting records your workflow creates or reads (for example, customers, items, and invoices in QuickBooks Online)
  • Messages our service posts to your messaging channels

Workflow and usage data. We keep records of each automation run — what was read, what was created, timestamps, and outcomes — so that you can audit and review everything the service did on your behalf. We also collect standard technical logs (IP address, browser type, pages visited) to operate and secure the website.

2.How we use information

  • To run the workflows you configure, end to end
  • To show you a complete, reviewable record of every automated action
  • To provide support and respond to your requests
  • To secure, maintain, and improve the service
  • To comply with legal obligations

We do not sell your personal information, and we do not use your business content for advertising.

3.AI processing

Operiva uses large language models provided by Anthropic to read and interpret content your workflows process (for example, extracting order details from an email). This content is sent to Anthropic under commercial API terms. Your content is not used to train AI models. AI outputs are constrained by your configured business rules, and every AI-initiated action is logged for your review.

4.How we protect information

  • Access to your connected services uses OAuth only — we never ask for or store your passwords for those services
  • OAuth tokens are encrypted at rest using AES-256-GCM before storage
  • All data in transit is encrypted using TLS
  • Access is scoped to the minimum permissions each workflow requires

No method of transmission or storage is 100% secure, but we design the service so that a minimum of data is held, for a minimum of time, with a minimum of access.

5.Service providers (subprocessors)

We rely on a small set of infrastructure providers to run Operiva. Each processes data only as needed to provide their service to us:

  • Clerk — authentication and account management
  • Neon — database hosting (PostgreSQL)
  • Anthropic — AI model processing
  • Vercel — application hosting and file storage
  • Upstash — rate limiting and caching

We may also disclose information if required by law, or as part of a merger, acquisition, or sale of assets, in which case this policy will continue to apply to previously collected data.

6.Data retention and deletion

We retain workflow records for as long as your account is active so your audit history stays complete. Email content is processed to run your workflow and is not retained beyond what the workflow record requires. When you disconnect a service, we stop accessing it immediately and delete its stored tokens. When your account is closed, we delete associated data within a commercially reasonable period, except where retention is required by law.

7.Your choices and rights

  • Disconnect at any time.You can disconnect any connected service from within Operiva, and additionally revoke Operiva's access from the provider's own security settings (Microsoft, Intuit, or Slack)
  • Access and correction. You may request a copy of the personal information we hold about you, or ask us to correct it
  • Deletion. You may request deletion of your account and associated data

To exercise any of these rights, email support@operiva.ai.

8.Children

Operiva is a business service and is not directed to children under 13. We do not knowingly collect personal information from children.

9.Changes to this policy

We may update this policy as the service evolves. If we make material changes, we will notify account holders by email or an in-product notice before the changes take effect. The effective date above always reflects the current version.

10.Contact us

Questions about this policy or our data practices: support@operiva.ai. See also our Terms of Service.