Privacy Policy

Effective date: August 2, 2026

Handov is provided by Naro AI, Inc., a Delaware corporation ("Handov", "we", "us", or "our").

This Privacy Policy explains how we collect, use, disclose, and protect information when you use Handov and related services.

This Privacy Policy does not apply to third-party websites, products, or services that we do not control, even if you access or connect to them through Handov.

1. Information we collect

We may collect:

  • Account and contact information, such as your email address and authentication information.
  • Recordings and derived content. Audio you choose to record with Handov, and the transcripts, summaries, notes, commitments (previously called action items), and other content derived from it. Recordings made in the real world may capture the voices of people around you. You can also attach photos to a recording.
  • Voice identification data. Numeric voice embeddings used to label who said what in your sessions. See "Voice identification" below.
  • Google Calendar data, if you connect Google Calendar. See "Google Calendar" below.
  • Location information, if you enable session location: the approximate place where a recording happened, attached to that session.
  • Content you provide or process, including materials you choose to create, import, capture, upload, or otherwise make available through the service.
  • Usage, device, and log information, such as app activity, device and browser information, diagnostics, and security events.
  • Connection information when you choose to link Handov with another service or authorize another service to interact with Handov.
  • Communications you send to us, including support requests and feedback.

We may collect information directly from you, automatically when you use the service, and from services you connect to or authorize.

2. Audio recording and people around you

Handov records only when you start a recording, and the app shows a visible indicator while a recording is active. Because Handov records the world around you, your recordings may capture other people. You are responsible for providing any notice and obtaining any consent required by the recording and privacy laws that apply to you and to the people being recorded.

We process audio of other people only on your behalf, to provide your transcripts, summaries, and speaker labels. We do not use it for advertising and we do not sell it.

3. Voice identification

To label who said what, Handov creates voice embeddings, which are numeric representations of voice characteristics and are sometimes called voiceprints. Embeddings are created for you and, automatically, for distinct speakers detected in your recordings, including people you have not named. This lets the same person keep a consistent label across your sessions. Before you name a speaker, make sure you have that person's permission.

Voice embeddings are used only to recognize and label speakers within your own account. They are never used for advertising, never sold, and never shared across accounts. Embeddings for speakers you have not named are deleted automatically after a period of inactivity. All voice embeddings are retained only as long as they are needed for speaker labeling in your account, and they are permanently destroyed when you erase your Handov data or delete your account.

4. Google Calendar

If you choose to connect Google Calendar, Handov uses read-only access to identify calendars you selected and can read, and to retrieve upcoming event metadata. This can include calendar and event identifiers, event title, start and end time, status, your response status, event type, recurrence information, and conferencing or meeting-link information. Handov never creates, edits, or deletes events or other data in your Google Calendar.

Handov uses this data only to show your upcoming meetings, send pre-meeting reminders, and support actions you request, such as joining a meeting or starting Handov for it. We store encrypted Google access and refresh credentials and the minimum event metadata needed for these features. We discard descriptions, attendee lists, attachments, raw Google Calendar payloads, and location text; when a supported meeting URL is found in an event, only the sanitized URL is retained and its surrounding text is discarded.

We do not sell Google Calendar data, use it for advertising, or use it to train general-purpose AI models. We disclose it only to service providers as needed to operate and secure these Calendar features, or as otherwise described in this policy. If you disconnect Google Calendar, Handov removes the stored Google credentials and synchronized event data and stops future access. Erasing your Handov data or deleting your account also removes this information from our production systems.

Handov's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

5. ChatGPT, Codex, and MCP connections

If you connect Handov to ChatGPT, Codex, or another Model Context Protocol (MCP) client, the client uses an authorization flow to access only the Handov account you approve. Depending on your request, Handov may return private transcripts, summaries, notes, commitments, threads, images, and related session details. An interactive session card may receive additional private session data needed to render the card inside that client.

Raw microphone-recording audio is not returned by Handov tools. Write access follows the grant you approve: the tier submitted to chat surfaces can only create or update private commitments in your Handov account, while the full write scope can also create, edit, or delete sessions, notes, and threads. No tier sends messages, publishes content, or changes external systems.

Every submitted tool also returns the account/request timezone and current ISO/local-date context used to interpret relative dates.

Information returned to a third-party client is also governed by that third-party client's privacy and retention practices. Revoking a Handov grant or credential stops future access through that credential. A client-only disconnect can vary by client, so confirm the connection is revoked in Handov controls; neither action automatically deletes copies the client already received. Use the client's controls to manage those copies, and contact us if you need help.

6. How we use information

We may use information to:

  • provide, operate, maintain, and improve Handov;
  • process content and provide AI-assisted features you request;
  • authenticate users and protect accounts, users, and the service;
  • diagnose errors, respond to support requests, and communicate with you;
  • understand service usage and develop new or improved features;
  • create and use deidentified or aggregated information for lawful business purposes, including analytics, security, and improving the service; and
  • comply with law and enforce our agreements.

7. How we disclose information

We may disclose information:

  • to service providers that help us host, operate, secure, support, and improve Handov;
  • to services or people you choose to connect with or authorize;
  • when reasonably necessary to comply with law, protect rights or safety, investigate abuse, or enforce our agreements;
  • in connection with a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets; or
  • with your direction or consent.

We do not sell personal information.

8. AI-assisted processing and service providers

Handov uses third-party service providers to operate the service and provide requested features. Audio is transcribed by third-party speech-to-text providers, and transcripts and other content are processed by third-party AI providers, to generate summaries, commitments, and other features. We also use providers for hosting, storage, authentication, error monitoring, payment processing, and, when you enable session location, turning a location into a place label. These providers process information only on our behalf to provide the service, and are contractually restricted from selling it or using it for their own advertising. Automated results may be incomplete or inaccurate, and you should review them before relying on them.

The current list of our subprocessors is available on request at support@handov.ai.

9. Retention

Raw audio from ambient session recordings is retained temporarily: after a session is processed into transcripts and summaries, the raw audio is automatically deleted. Audio you attach to a note is kept with that note until you delete the note, the session, or your account. Audio samples you record to set up voice identification are kept while your voice profile exists; erasing your Handov data or deleting your account removes them. Transcripts, summaries, notes, and other derived content remain in your account until you delete them or delete your account. Items you delete are kept for 7 days so you can restore them, then removed. Voice embeddings follow the retention rule in "Voice identification" above. Google Calendar credentials and synchronized event data are deleted when you disconnect Google Calendar, erase your Handov data, or delete your account.

For other information, we retain it for as long as reasonably necessary to provide the service, fulfill the purposes described here, comply with legal obligations, resolve disputes, and protect Handov and its users. Some information may remain for a limited period in backups, security records, fraud-prevention systems, or as deidentified or aggregated data.

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Your choices and rights

You can erase your Handov data or permanently delete your account at any time from Settings in the app. Account deletion removes your recordings-derived content, voice embeddings, connected-service credentials, synchronized Calendar event data, and account information from our production systems. You can disconnect Google Calendar at any time to remove its stored credentials and synchronized events. You can disconnect a ChatGPT, Codex, or MCP connection in its client, then confirm or revoke the corresponding Handov grant or credential in Handov controls to stop future access through that credential. You can turn optional collection, such as session location, on or off in Settings.

You may be able to access, correct, export, or request deletion of certain information through the service or by contacting us. Depending on where you live, applicable law may provide additional privacy rights. We may need to verify your identity before completing a request, and legal exceptions may apply.

We may limit or decline a request where permitted by law, including if we cannot verify your identity, the request would adversely affect the rights of others, or we are not legally required to comply.

12. International processing

We and our service providers may process information in the United States and other countries where privacy laws may differ from those where you live.

13. Children

Handov is intended for people who are at least 13 years old. We do not knowingly collect personal information from children under 13. If you are 13 or older but under the age of legal majority where you live, use Handov only with consent from a parent or legal guardian where applicable law requires it. If you believe a child under 13 has provided information to us, contact us.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy and revise the effective date, and we may provide additional notice when required by law.

15. Contact

Questions or privacy requests: support@handov.ai.