How Navon collects, uses, stores, and protects information — including exactly what we do with Google user data.
Effective date: August 24, 2026
Navon is a product of CONCEPTZERO LLC ("Navon," "we," "us"). This Privacy Policy describes how we collect, use, store, and share information when you visit navon.vc, use the Navon application, or otherwise interact with us. Navon is a fund operating platform used by venture capital firms and their authorized team members.
Note on roles. For personal data our customers put into the platform (deal contacts, founders, LP records, emails), the customer firm is the data controller and Navon acts as a processor/service provider on the firm's instructions, under our Data Processing Addendum. This policy covers what we collect and how we handle it in both roles.
Account information. Name, work email address, firm affiliation, role, and authentication identifiers when you or your firm creates an account. Sign-in is via Google OAuth; we do not store passwords.
Customer Data. Content your firm submits to or connects with the platform: deals, portfolio positions, LP and fund records, documents, notes, meeting data from connected integrations, and emails processed through the Gmail integration described below.
Usage and device data. Log data, IP address, browser type, pages viewed, and actions taken in the product, used for security, debugging, and improving the service.
Website data. The navon.vc marketing site does not use advertising trackers. It loads fonts and serves pages through infrastructure providers that may log IP addresses for security and delivery.
If you connect a Google account, Navon accesses Gmail data solely to provide user-facing features of the platform:
Navon's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Use of Google user data is limited to providing and improving user-facing features that are prominent in Navon's interface; it is never used to develop generalized AI/ML models, transferred except as necessary to provide those features, and never used for serving ads.
You can disconnect Gmail at any time in Settings, which stops further access. OAuth tokens are stored encrypted and are revoked on disconnection.
Navon AI answers questions, drafts reports, and extracts data from documents using large language model providers acting as our subprocessors. Content sent to these providers is used only to generate the requested output; our providers are contractually restricted from using your data to train their models. AI outputs are informational only and are not investment, legal, tax, or accounting advice.
To provide, secure, and improve the service; to enrich records you ask us to enrich (e.g., company and founder profiles from public sources); to communicate with you about the service; to comply with legal obligations; and to enforce our agreements. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Only with: (a) subprocessors that host and power the service (see our current Subprocessor List) under written data-protection obligations; (b) your firm — data in a firm workspace is visible to that firm's authorized members per its own permission settings; (c) professional advisers and authorities where required by law; and (d) a successor entity in a merger, acquisition, or asset sale, subject to this policy.
Data is encrypted in transit (TLS) and at rest. Access is scoped per firm with strict tenant isolation; every request is authorized against the caller's firm. OAuth tokens and credentials are stored encrypted. We maintain least-privilege access, audit logging, and daily encrypted backups stored independently of our primary hosting provider. No method of transmission or storage is 100% secure, but we treat fund data with the level of care it demands.
Customer Data is retained while the firm's subscription is active. Upon termination, firms may export all data (Excel, CSV, PDF), and we delete Customer Data within 60 days of the end of the agreed export window, except where retention is required by law or for backup cycles that expire on schedule.
Depending on where you live, you may have rights to access, correct, delete, or port your personal data, and to object to or restrict certain processing (GDPR, CCPA/CPRA, and similar laws). Where Navon processes data on behalf of a customer firm, we will direct your request to that firm and assist them in honoring it. To exercise rights with respect to data Navon controls, contact privacy@navon.vc.
We are U.S.-based and process data in the United States. Where personal data from other jurisdictions is transferred to us, we rely on appropriate safeguards, including standard contractual clauses incorporated in our DPA.
Navon is a business product and is not directed to anyone under 18.
We will post any changes to this policy on this page and update the effective date. Material changes affecting customer firms are notified per the customer agreement.
privacy@navon.vc · CONCEPTZERO LLC, d/b/a Navon, United States.