Privacy Policy

Lavi AI Marketing CRM (operated by Lavi, lavit.io) · Last updated: May 31, 2026

This Privacy Policy explains how Lavi AI Marketing CRM ("we", "us", the "Service"), an AI-assisted outbound CRM available at crm.lavit.io, collects, uses, stores, and protects your information — including data accessed through Google APIs when you choose to connect your Gmail account.

1. Information we collect

2. How we use information

We use the information solely to provide the Service: to authenticate you; to generate and manage outreach drafts; to send messages you approve from your own mailbox; to detect and classify replies for CRM tracking; and to operate, secure, and support the product. We do not use Google user data for advertising, and we do not sell it.

3. Google API Limited Use disclosure

Lavi AI Marketing CRM's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We access your Gmail data only to (a) detect and classify replies to outreach you sent through the Service and (b) send outreach emails that you have explicitly approved, on your behalf, from your own account. We do not transfer or sell this data, do not use it for advertising or to train generalized AI/ML models, and do not allow humans to read it except where required for security, to comply with applicable law, or with your explicit consent.

4. AI processing & subprocessors

To provide its features, the Service uses AI models (currently Anthropic's Claude) to draft outreach copy and to classify the content of replies. Where reply text is processed for classification, it is sent to this AI provider acting as our processor, only to deliver the user-facing feature. This data is not used to train generalized models. We use a limited set of infrastructure subprocessors (hosting, the AI provider, and Google) and require them to protect your data.

5. Storage & security

Data is stored on servers we control. Google OAuth refresh tokens are encrypted at rest; access to production systems is restricted. Each business's data is logically isolated from other businesses ("tenants") in the Service.

6. Data sharing

We do not sell your data and do not share Google user data except: with the subprocessors named above to operate the Service; when required by law; or with your explicit consent.

7. Retention & deletion

You can disconnect your mailbox at any time from the Settings page; this revokes the stored refresh token at Google and stops further mailbox access. You may request deletion of your account and associated data by contacting us. You can also review and revoke the Service's access at any time at myaccount.google.com/permissions.

8. Your rights

Subject to applicable law, you may request access to, correction of, or deletion of your personal data. Contact us using the details below.

9. Changes

We may update this policy; material changes will be reflected by the "Last updated" date above.

10. Contact

Lavi · shay@lavit.io · lavit.io