Last updated: September 27, 2026
Enconvo is an AI assistant for your computer and iPhone. Enconvo is developed by THE GREAT LIONHEART PTE. LTD. ("Enconvo", "we", "us"). This policy explains what data the Enconvo desktop app, the Enconvo iPhone app, the website enconvo.com, and the Enconvo cloud services collect, how we use it, where it is stored, who we share it with, and how you can delete it.
It does not cover third-party plugins, MCP servers, or AI providers you add yourself. Those are governed by their own privacy policies.
Your conversation history, chat sessions, plugin settings, knowledge base, and the API keys you enter for AI providers are stored locally on your device. We do not upload them to our servers. When you use your own API key, Enconvo sends your request directly from your device to that provider.
Enconvo asks for system permissions only for the features that need them, and only when you use those features:
You need an Enconvo account for Enconvo's cloud features, subscriptions, and the iPhone app. When you sign up with an email and password, or with Google Sign-In, we store:
Payments are processed by Stripe. We receive and store the plan you bought, the amount, the currency, the purchase and refund dates, and Stripe's reference identifiers. We never receive or store your full card number.
When you choose one of Enconvo's built-in cloud models, or a cloud feature such as web search, image or video generation, speech recognition, or text-to-speech, your request passes through our servers to the provider that performs it (for example OpenAI, Anthropic, Google, or the other providers listed in the model picker). The request can include your prompt, the files or context you attach, and any data an agent has gathered for the task.
We use this content only to return the result you asked for. We do not store prompts or responses in our databases. Our servers keep short-lived operational logs, which can include parts of a request, to diagnose failures and prevent abuse. These logs are deleted automatically after at most 7 days. Providers process your request under their own terms for API customers.
Enconvo accesses Google user data only when you choose to connect a Google account.
How we use it. We use Google user data only to provide the features you use in Enconvo. For example, we show your emails to you, summarize them, draft replies, or send a message you asked an agent to send, or add an event you asked for. We do not use it for advertising, and we do not use it to create, train, or improve any AI or machine learning model.
Where it goes and where it is stored. Gmail and Google Calendar connections currently run through Composio, a service provider that holds the Google authorization for your Enconvo account. Composio knows your account only by an anonymous account id, not by your email address. Each request goes from your device through our servers to Composio and on to Google, and the result comes back the same way. Our servers pass it through without storing its content. Composio does not store the content either; it keeps a record of which action ran, when, and whether it worked. We do not copy your email or events to our servers. If you set up the older Gmail plugin in an earlier version of Enconvo, its requests go directly from your device to Google, and its authorization token is kept encrypted on your device. Messages and events an agent reads may be saved in your local chat history on your device, and you can delete that history at any time.
Who we share it with. When a task needs email or calendar content, Enconvo includes only the content that task needs in the request to the AI model you selected. If you use one of Enconvo's built-in cloud models, that request passes through our servers as described above. We do not sell Google user data or share it with advertising platforms, data brokers, or information resellers. Apart from Composio, which runs your Gmail and Google Calendar requests as described above, we share it with others only when you ask us to, when it is needed for security, or when the law requires it.
Human access. No person at Enconvo reads your Google user data unless you give us explicit permission for a specific message (for example, in a support request), it is needed to investigate abuse or a security incident, or the law requires it.
Removing access. You can disconnect Gmail or Google Calendar in Enconvo at any time, which revokes the authorization and deletes it from Composio; for the older Gmail plugin, it deletes the token from your device. You can also revoke access at myaccount.google.com/permissions, where a Gmail or Google Calendar connection is listed under Composio and the older Gmail plugin under Enconvo.
Enconvo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
The desktop app sends product analytics to PostHog to help us understand which features work and where they fail. This is on by default, and you can turn it off in Settings > General. Events include the app version, system version, device identifier, plugin and command identifiers, status, and duration. If you are signed in, we link these events to your Enconvo account. Analytics never include your prompts, selected text, clipboard contents, files, emails, API keys, or model responses.
The website enconvo.com uses Google Analytics to measure visits. The iPhone app does not include an analytics SDK.
We rely on these providers to operate Enconvo. Each processes data only on our behalf:
We keep account, plan, and usage records while your account is active. Operational logs are deleted after at most 7 days. To delete your account and the data tied to it, including synced Phone chats, email us at support@enconvo.com from the address on your account. We complete deletion within 30 days, except for payment records that we must keep by law.
Data stored only on your device, such as local chat history, is removed when you delete it in Enconvo or uninstall the app and remove its data folder.
Connections to our servers use TLS. Stored data is encrypted at rest by our infrastructure providers. Tokens for connected accounts are encrypted on your device, and access to production systems is limited to the people who operate Enconvo.
Enconvo is not directed to children under 13, and we do not knowingly collect personal data from them.
We may update this policy as Enconvo changes. We will post the new version on this page and update the date at the top. If a change materially affects how we handle Google user data or other personal data, we will also notify you in the app or by email before it takes effect.
If you have questions about this policy or want to exercise your privacy rights, contact us at support@enconvo.com.