Privacy Policy

Last updated: May 9, 2026

Operated by UVORA Ltdgrowth.uvora.cloud

Summary: We collect only what is necessary to provide the service. We never sell your data. We comply with GDPR (UK & EU), Meta Platform Terms, Google API Services User Data Policy, and LinkedIn API Terms of Use.

1. Who We Are

UVORA Ltd operates UVORA Growth OS, an AI-powered marketing SaaS platform. Company incorporated in the United Kingdom.

Privacy: privacy@uvora.cloud — Data Protection Officer: dpo@uvora.cloud

2. Data We Collect and Why

2.1 Account Data

Name, email address, password (hashed with bcrypt, never stored in plaintext), workspace name. Legal basis: Contract performance (GDPR Art. 6(1)(b)).

2.2 AI Generation Data

Prompts and outputs you create inside UVORA. Stored per workspace to power the UVORA Brain self-learning system. Never shared with other users or used to train public AI models. Legal basis: Contract performance; Legitimate interests.

2.3 Payment Data

Billing processed exclusively by Stripe. We store only: subscription plan, status, Stripe customer ID. We never see card numbers or bank details.

2.4 Third-Party Integration Data

Meta — Facebook & Instagram

  • OAuth access token for your Facebook account and connected Instagram Business Account
  • List of Facebook Pages you manage (name, Page ID) — used only to post content you initiate
  • We do not read your personal timeline, messages, friends list, or any data beyond what is required to post to your Page
  • Meta user data is not used for advertising, profiling, or sold to third parties
  • Meta user data is not transferred to data brokers or ad networks
  • Revoke access anytime: Facebook Settings → Apps and Websites → UVORA Growth OS → Remove
  • Data deletion: email privacy@uvora.cloud or POST to https://growth.uvora.cloud/meta/delete

Google — Calendar & Ads

  • Google Calendar OAuth token — used only to create/read bookings in your calendar
  • Google Ads API token — used only to create campaigns you explicitly initiate
  • Google API Limited Use Disclosure: UVORA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data to develop, improve, or train generalised AI or ML models.

LinkedIn

  • OAuth token and basic profile (name, LinkedIn ID) required by the API
  • Used solely to post content to your LinkedIn profile or company page when you request it
  • We comply with LinkedIn API Terms of Use

TikTokElevenLabsGoogle Business

  • TikTok for Business OAuth token — used only to publish video content you create in UVORA
  • ElevenLabs API key — stored encrypted, used only when you request voice generation
  • Google Business Profile API — used only to fetch and respond to your business reviews

2.5 CRM and Leads Data

Contact data you import into the Leads CRM (names, emails, phone numbers). This data belongs to you. UVORA processes it as a data processor on your behalf. You are the data controller for imported contacts and must ensure you have a legal basis to hold that data under applicable law.

2.6 Booking Data

Name, email, and appointment details submitted by your clients via your public booking page. Stored in your workspace, visible only to you.

2.7 Analytics

We use Plausible Analytics (no cookies, no personal data, GDPR-compliant by design) and Google Analytics 4 with IP anonymisation enabled. No personal profiles are created for advertising purposes.

3. How We Use Your Data

  • Provide, operate, and improve UVORA Growth OS
  • Authenticate you and maintain your session securely
  • Process payments and manage your subscription
  • Send transactional emails (verification, password reset, invoices) — no marketing without explicit consent
  • Power the UVORA Brain AI memory system within your workspace
  • Publish content on connected social accounts when you explicitly initiate it
  • Respond to support requests
  • Comply with legal obligations

We never: sell your data, use your content to train public AI models, share your workspace data with other customers, or use third-party OAuth data for any purpose beyond the integration you activated.

4. Data Sharing — Sub-Processors

  • DigitalOcean — cloud infrastructure hosting
  • Stripe — payment processing
  • OpenRouter / OpenAI / Anthropic / Google DeepMind / xAI — AI model inference. Your prompts are transmitted to these providers. They retain data for 0–30 days per their respective policies and do not use your data for training without consent.
  • Brevo — transactional email delivery
  • ElevenLabs — voice synthesis (Voice AI module only)
  • Plausible Analytics / Google Analytics — aggregate analytics

No data is shared with any other party except as required by law or court order, in which case we will notify you where legally permitted.

5. International Data Transfers

Some sub-processors operate in the United States. Transfers are covered by Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement (IDTA). By using UVORA Growth OS, you acknowledge these transfers.

6. Data Retention

  • Account data: Duration of subscription + 30 days after deletion (recoverable period)
  • AI generations and workspace content: Active account lifetime; deleted within 90 days of account closure
  • OAuth tokens (Facebook, Google, LinkedIn, TikTok): Deleted immediately upon disconnection or account deletion
  • Payment records: 7 years (UK legal and accounting requirement)
  • Backup copies: Purged within 90 days

7. Your Rights (GDPR / UK GDPR)

  • Access — Request a copy of all personal data we hold about you
  • Rectification — Correct inaccurate or incomplete data
  • Erasure — Request deletion of your data ("Right to be Forgotten")
  • Restriction — Request we limit processing of your data
  • Portability — Receive your data in a structured, machine-readable format
  • Objection — Object to processing based on legitimate interests
  • Withdraw consent — At any time, where processing is consent-based

Email privacy@uvora.cloud to exercise any right. We respond within 30 days. You may also complain to the UK ICO or your local EU supervisory authority.

8. Security

  • All traffic over HTTPS with TLS 1.2/1.3 and HSTS enforced
  • Passwords hashed with bcrypt (cost factor 12)
  • OAuth tokens and API keys stored encrypted in the database
  • Rate limiting, SQL injection protection, XSS filtering on all endpoints
  • Content Security Policy (CSP) headers enforced
  • Regular automated encrypted backups

In the event of a personal data breach, we will notify affected users and the relevant supervisory authority within 72 hours as required by GDPR Article 33.

9. Cookies

  • Essential: JWT authentication token stored in localStorage. Required for the app to function. No consent required.
  • Analytics: Plausible uses no cookies. GA4 uses anonymised cookies. You may opt out via browser settings or a GA opt-out browser extension.
  • No advertising cookies of any kind.

10. Children's Privacy

UVORA Growth OS is not directed to individuals under 18 years of age. We do not knowingly collect personal data from minors. Contact privacy@uvora.cloud immediately if you believe we have done so.

11. Changes to This Policy

Material changes will be communicated by email to active users at least 14 days before taking effect. The "Last updated" date at the top reflects the most recent revision. Continued use after the effective date constitutes acceptance.

12. Contact

UVORA Ltd — United Kingdom

Privacy enquiries: privacy@uvora.cloud

Data Protection Officer: dpo@uvora.cloud