Effective date: September 13, 2026 (version 1.0).
Bervo LLC ("Bervo", "we") is a Florida limited liability company. Bervo provides a private, AI-based executive assistant that reads the email, calendar, contacts, and, where you choose, text messages you connect to it, and produces briefings, reminders, drafts, and a searchable record of your commitments and relationships, with an AI layer that summarizes and organizes it and an assistant you direct in chat. This policy explains what we collect, why, where it lives, who can see it, how you control what the assistant sees, and how you delete it.
Account information. Your name, email address, the sign-in identity you use with Bervo, and your settings (including what you choose to exclude — see §5).
Connected-account data. With your authorization, the service reads from the accounts you connect:
| Source | What we read | What we do not read |
|---|---|---|
| Email (Gmail, Microsoft 365, Outlook.com) | Message headers, bodies, and folder placement for the mailbox you connect; the calendar and contacts of that account if you grant those permissions | Attachments are not downloaded or stored; no other mailbox |
| Email on your Mac (any account set up in Apple Mail — for example iCloud, Yahoo, or a work account that does not allow Microsoft's connector) | Read from your Mac's local mail data by the Bervo Mac app, if you install it: the same headers, bodies, and folder placement as above | Attachments; any account you do not select |
| Calendar | Event titles, times, attendees, locations, and responses for the calendars you connect | Calendars you exclude by name |
| Contacts | Names, email addresses, phone numbers, and birthdays | Other fields in your address book — postal addresses, notes, job titles, relationships, photos — are not read |
| Text messages (optional) | Messages you send and receive, read from your own Mac, from a Mac we operate for you, or from an Android app you install, subject to the exclusions in §5 | Attachments; messages from contacts you exclude; messages the relevance filter removes (§5) |
Data we generate. Summaries, extracted tasks, initiatives, and deadlines, relationship and attention scores, drafts, briefings, notes you write in Bervo, and your conversations with the assistant. All of it is generated from your data after your sanitization choices (§5) have been applied.
Technical data. Server logs, error reports, and pipeline health records needed to operate your instance. These are not analytics products; they exist so your instance keeps working.
Sanitization is our word for the masking you choose to apply before any of your data (email, calendar, contacts, or messages) reaches the AI model or is stored in summaries: last names and email addresses. You set the level; each level costs the assistant some precision.
You set these during onboarding and can change them at any time. Each choice is explained with a concrete example of what the assistant sees with and without it, and with its cost, because every exclusion makes the assistant less useful in a specific way.
You may invite people to work in your instance with you, such as an assistant or a colleague. For each person we collect their name, email address, and login, and we record which of them did what, so actions in your instance are attributed to the person who took them. People you add can see the data in your instance; they are users of your instance, not sources of data, and Bervo never reads their own email, calendar, or messages. You are responsible for adding only people who are permitted to see the data you have connected, including under any obligation you have to your employer or clients, and for removing them when that permission ends. You can remove a person at any time from Settings, and their access ends immediately.
Bervo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Specifically: we use Gmail, Calendar, and Contacts data only to provide the assistant features you see in Bervo; we do not transfer it except to provide those features, to comply with law, or as part of a merger or acquisition with notice to you; we do not use it for advertising; and humans do not read it except with your explicit consent, for security purposes, to comply with law, or in aggregated, anonymized form for internal operations.
When you sign in with Microsoft, we request delegated permissions to read mail, calendars, and contacts, and, for the drafting feature, to write draft messages to your mailbox. We never request permission to send mail unless you or your organization's administrator explicitly enable a send feature. Your organization's administrator may need to approve Bervo for your tenant; that approval covers only the permissions listed on the consent screen.
Summaries, drafts, and answers are produced by sending the relevant text to a large-language-model provider (Anthropic) over an API. Where you supply your own API key, those requests are made under your account with that provider and are governed by its terms. Where Bervo supplies the key during a trial, requests are made under Bervo's account and the provider's API terms, which do not permit training on API inputs. We apply your privacy choices (§5) before anything is sent to the provider: exclusions on your device, the text-message relevance filter and search indexing with models that run on your own server, and name and address masking on your server. Nothing a filter removes is sent to the provider.
What learns, and what doesn't. Your Bervo instance learns from your data and your corrections: how you write, who matters to you, what you want to be told about, and what you've committed to. That learning stays on your server, is never used for another customer, and is destroyed when you delete your instance. The AI model provider does not learn from you: requests are sent under API terms that do not permit training on them, and no data of yours is used to train any model, by us or by anyone.
Your server has no open ports to the internet. Traffic reaches it only through an encrypted tunnel after you sign in with your existing Google or Microsoft account, and your Bervo login sits on top of that. Credentials to your connected accounts are stored as revocable OAuth tokens on your instance only, never in a shared store. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay and within any period required by law.
Bervo is for business use by adults. We do not verify anyone's age. You are responsible for who you allow to use your instance.
Bervo is a small US company. We honor access, export, and deletion requests from anyone, regardless of where you live, because your data sits on a dedicated server we can hand you or destroy. Depending on where you live you may also have rights to correct or restrict your personal information, and to object to certain processing; we honor those too. Contact privacy@bervo.ai.
We will post changes here with a new effective date and, for material changes, notify you by email or in the app before they take effect.
Bervo LLC · 460 Hickorynut Ave, Oldsmar, FL 34677 · privacy@bervo.ai