Legal
Privacy Policy
Effective 2 September 2026
Konevo is self-hosted
Konevo does not run a shared customer-data service. The person or organisation operating an instance decides how data in that instance is processed.
1. Who this policy covers
This policy covers the public Konevo website and the Konevo software. It explains the responsibilities of the public website operator and of people who run their own Konevo instance.
2. Public website controller and contact
For the public Konevo website, the data controller is Filip Paučo, an independent developer based in Slovakia.
For privacy questions or to exercise your rights, email filip.pauco08@gmail.com .
3. Self-hosted instances
Every self-hosted Konevo instance is operated independently. Its operator is responsible for its hosting provider, server location, users, retention settings, integrations, security measures, and lawful basis for processing data. Filip Paučo does not receive, access, or control data stored in a self-hosted instance unless the operator separately provides it for support.
4. Data processed by an instance
Depending on the features enabled, an instance may process:
- account, organisation, and sign-in information;
- contacts, companies, tasks, deals, notes, and activity records;
- email addresses, message headers, message bodies, recipients, attachments, and thread metadata synced from connected inboxes;
- Google OAuth tokens needed to maintain a Gmail connection;
- settings, audit records, and files added by the operator or its users.
5. Gmail and Google data
Before a Gmail account is connected, Konevo presents an in-app notice and asks for affirmative acknowledgement. With the account holder's Google authorization, Konevo requests only the permissions needed for its email workspace: reading and changing mailbox state, sending email, importing basic Gmail settings such as a signature, reading calendar events, and identifying the connected Google email address.
Gmail data is used to display and organise conversations, send messages the operator requests or authorises through enabled automation, import a signature, and show connected calendar events. It is stored only in the operator's self-hosted instance. Disconnecting Gmail stops future access, but does not by itself erase data previously stored in the instance.
Konevo does not sell Google user data or use it for advertising. Konevo's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Protecting Google user data
Konevo requires HTTPS for production access, so data sent between a user's browser and the instance is protected in transit with TLS. Gmail data, CRM records, files, and Google OAuth tokens are available only to authenticated users with access to the relevant organisation. Konevo applies organisation-scoped access checks, CSRF protection, secure browser headers, and OAuth state validation. Raw uploaded files are not exposed through a public web-server directory.
A self-hosted instance operator must protect the server, database, uploads, logs, and backups from unauthorised access. This includes restricting database network access, limiting operator and restore access, enabling suitable encryption at rest for its storage and database, and encrypting backups. Konevo stores Google access and refresh tokens in the instance database so that Gmail sync can continue; it does not add a separate application-level encryption layer for those tokens.
7. AI features and third-party providers
When an operator uses an AI feature or enables an AI automation, Konevo sends only the email, thread, or CRM content needed for that feature to the AI provider configured for that instance. The operator chooses the provider and API key. That provider processes the content under its own terms and privacy policy, and may process data outside the European Economic Area.
The public Konevo website operator does not receive the content sent to an operator's configured AI provider.
8. Retention, deletion, and rights
An instance operator controls how long its instance keeps data. People whose data is in an instance should contact that instance operator to request access, correction, deletion, restriction, objection, or portability. The public website operator will respond to privacy requests about the public website at the contact address above.
If you are in the European Economic Area, you may also lodge a complaint with your local data-protection authority.
9. Changes
This policy may change when Konevo's data practices change. A revised effective date will be published on this page.