Encryption
All data encrypted in transit (TLS 1.3) and at rest (AES-256).
Your data security is foundational to our service. We implement industry-standard security measures to protect your information.
All data encrypted in transit (TLS 1.3) and at rest (AES-256).
Role-based access with audit logging. No unauthorized data access.
GDPR and CCPA compliant with Google API Limited Use adherence.
All connections to Nuvflo use TLS 1.3 encryption. We enforce HTTPS for all traffic and use HSTS to prevent downgrade attacks.
Sensitive data, including OAuth tokens and extracted billing information, is encrypted using AES-256 encryption before storage. Encryption keys are managed separately from encrypted data.
OAuth tokens for connected email accounts are:
We do not allow employees to read your email content unless you explicitly request support assistance. Our access policy:
Nuvflo is hosted on enterprise-grade infrastructure:
When you connect your Gmail account, we follow Google's strict security requirements:
We request only the minimum permissions necessary:
| Scope | Purpose | When Requested |
|---|---|---|
| gmail.readonly | Read billing emails to extract refund details | When you enable inbox scanning |
| gmail.send | Send approved refund requests from your account | When you enable send feature |
| gmail.compose | Create drafts for your review | When you enable draft creation |
We comply with Google's Limited Use requirements:
You can revoke Nuvflo's access at any time:
Upon revocation, we immediately delete stored OAuth tokens.
When generating refund request drafts, we use OpenAI's API:
| Data Type | Retention Period |
|---|---|
| Account data | Active account + 30 days after deletion |
| OAuth tokens | Until disconnection (then immediate deletion) |
| Extracted email facts | 90 days (then auto-deleted) |
| Generated drafts | 30 days (then auto-deleted) |
| Payment records | 7 years (legal requirement) |
You can delete your data at any time:
We process deletion requests within 30 days, except where retention is legally required.
In the event of a security incident:
To report security vulnerabilities or concerns:
We take all security reports seriously and will respond within 48 hours.
We are committed to continuous security improvement:
Enterprise customers requiring specific compliance certifications or security assessments can contact enterprise@nuvflo.io.
For security-related questions or to request additional information: