Last updated: August 29, 2026

Privacy Policy

Controller and contact

The data controller is Théo Soubra-Belay. For privacy questions or to exercise your rights, contact: theo.soubrabelay@nevermiss-ai.online.

Scope

This policy describes the processing carried out by NeverMiss when you use the website, application, collaboration features and Gmail, Outlook or WhatsApp connectors. Third-party services that you choose to connect also apply their own terms and policies.

Data collected directly

NeverMiss may process information you provide when creating and using an account: name, email address, phone number when provided, authentication provider, avatar, organization, role, team size, preferences, language, time zone, subscription, billing, support requests and actions performed in the product. Passwords are managed by Supabase Auth and are not stored in plain text by NeverMiss.

Data from connectors

Gmail. With your authorization, NeverMiss uses the openid, email and gmail.readonly scopes. Access is read-only and may cover account identity, email address, technical identifiers, threads, senders, recipients, dates, subjects, labels, snippets and message bodies necessary for analysis. Offline access enables the continuous processing you authorize. OAuth tokens are protected server-side. NeverMiss cannot send, modify or delete your emails. Outlook. With your authorization, NeverMiss processes in read-only mode the Microsoft profile, email address, tokens, identifiers, senders, recipients, dates, subjects, previews, bodies and context required for analysis. NeverMiss does not write, modify or delete Outlook emails. Email content needed for analysis is retrieved when the analysis runs. NeverMiss does not retain exact source snippets in its scan records after processing. Technical identifiers and structured results needed to operate the service may be retained for the periods described below. WhatsApp. You may associate your number with the NeverMiss flow and send messages to the NeverMiss number to create tasks. Necessary content is protected during processing. It is erased after successful processing or, only for a failed event that cannot otherwise be replayed, no later than 72 hours.

Use of artificial intelligence

The flow can be summarized as: connected source → NeverMiss processing → Mistral AI analysis → structured result → task or follow-up. NeverMiss sends Mistral AI the content necessary for the requested analysis. Zero Data Retention is enabled for the NeverMiss organization on compatible stateless APIs used by the service, including Chat Completions. Under this mechanism, transmitted content and generated responses are not retained beyond the processing required for the request. Certain technical, security or billing data may nevertheless be processed under the applicable terms. API training is disabled and Labs models are disabled. AI is probabilistic: NeverMiss does not guarantee exhaustive detection or error-free results.

Tasks, analyses and derived data

From connected sources, NeverMiss may produce derived data such as a task, summary, deadline, priority, status, follow-up, signals, labels or an excerpt useful for understanding the result. A task is considered used after an explicit action: editing, completing, archiving, adding a note, changing membership or sharing. Simply generating or viewing a task is not enough. A used task may remain useful after its private source is deleted; it can then no longer open the deleted source message.

Collaboration and sharing

When you share a task, authorized members can see the information actually shared, including its summary, deadline, priority, status, collaborative notes and activity required for collaboration. Private source content, tokens and connections are not shared. A private task is deleted with the account. A shared task or note that remains useful to other members may remain with its author dissociated and shown as “Deleted user”. Private source data is deleted. An item with no surviving member is deleted, and no owner is invented automatically.

Purposes of processing

NeverMiss processes data to create and secure accounts, connect authorized sources, detect and organize important actions, provide tasks and reminders, enable collaboration, manage subscriptions and service communications, answer support requests, prevent abuse, resolve incidents and improve the strictly necessary operation of the product. NeverMiss does not sell personal data or use it for targeted advertising.

Legal bases

Depending on the purpose and context, processing may rely on performance of the requested service or contract, NeverMiss's legitimate interests in security, operation and strictly necessary service improvement, compliance with legal obligations, or your consent where required. You may withdraw consent at any time without affecting the lawfulness of earlier processing. Some features can no longer operate after the corresponding authorization is withdrawn.

Providers and processors

NeverMiss uses the following active providers, depending on the features used: Supabase for authentication, database, storage and server processing; Vercel for hosting and delivery; Google for authentication and Gmail; Microsoft for Outlook; Meta for WhatsApp; Mistral AI for AI analysis; Stripe for billing; and Resend for service emails. These providers process data required for their function under the applicable terms. NeverMiss does not describe their downstream processors, provider retention periods or processing locations as more limited than is actually guaranteed.

International transfers

Some providers or their processors may process data outside your country or the European Economic Area. Where required, these transfers must be covered by an appropriate mechanism, such as an adequacy decision, standard contractual clauses or another recognized safeguard. The precise location may depend on the provider, service and applicable terms.

Retention periods

NeverMiss applies the following periods: • automatically generated task with no explicit user action: 30 days after creation; simply viewing it does not suspend this period; • task with an explicit user action: while useful and until the applicable deletion; • detailed collaborative activity: 12 months; • invitation: valid for 14 days; expired or revoked invitation: deleted 30 days after expiry or revocation; • unread notification: up to 90 days; read or archived notification: 30 days; • temporary WhatsApp content for a non-replayable retry: up to 72 hours; • completed Gmail/Outlook technical scans and jobs: 30 days; • technical account-deletion details: 90 days; • pseudonymized technical proof of deletion: 12 months after completion; • attributable AI metrics: up to 12 months; • NeverMiss operational logs: 30 days; specific security events: up to 12 months where necessary. Account data and other active data are retained while the service is used and then deleted according to the processing, your actions and applicable obligations. Provider logs and backups follow their applicable terms; NeverMiss does not publish an unverified provider period here.

Connector disconnection and revocation

Disconnecting stops new reads and removes the connection, tokens and associated private source references from NeverMiss. NeverMiss also attempts revocation with the provider where technically possible. You can manually revoke Gmail in your Google Account security settings and Outlook in your Microsoft account. For WhatsApp, disconnection removes the link and associated private data. A task with an explicit user action may survive without its source email or message. Reconnecting is a new start and does not restore deleted private history.

Account deletion

Deletion starts immediately after confirmation. Some technical operations may require processing time and continue until completion. NeverMiss normally aims to complete deletion within 24 hours, but this is not an absolute guarantee. Any request still open after 24 hours is flagged for priority follow-up until resolved; after 30 days it becomes critical and requires human intervention. The action is irreversible. New writes are blocked, private data and private tasks are deleted, and connector access is removed or revoked where technically possible. Collaborative items still useful to other members may survive with the author dissociated. A new registration creates an empty account, and individual restoration is not available. NeverMiss retains a pseudonymized technical deletion fingerprint for 12 months after completion. It is used to prevent accidental recreation and secure the deletion process.

Backups

Residual copies may temporarily remain in technical backups subject to rotation cycles and access controls. They are not used to restore an individual deleted account and are processed under the applicable infrastructure terms.

Technical and security logs

NeverMiss retains limited operational logs for 30 days to operate the service, diagnose errors and ensure reliability. Specific security events may be retained for up to 12 months where necessary to investigate an incident, prevent abuse or protect users. NeverMiss seeks to prevent logs from containing unnecessary private content, tokens or secrets.

Audience measurement, performance and fonts

NeverMiss no longer loads Vercel Web Analytics or Vercel Speed Insights in its frontend and does not replace them with another browser-tracking tool. The fonts used by the interface are hosted and served directly by NeverMiss. Loading them does not cause a browser request to Google Fonts.

Google User Data and Limited Use

NeverMiss uses gmail.readonly because the feature needs to read the necessary messages to detect tasks, follow-ups, deadlines and commitments requested by the user. Categories accessed may include account identity, email address, technical identifiers, threads, senders, recipients, dates, subjects, labels, snippets and necessary bodies. NeverMiss may derive tasks, summaries, deadlines, priorities and signals from them. Necessary content is sent to Mistral AI solely to provide this analysis. NeverMiss does not sell Google User Data, use it for advertising, or use it to train or improve a general-purpose model. Mistral is configured with Training disabled, Labs disabled and ZDR active for compatible stateless APIs used by NeverMiss, including Chat Completions. Disconnection removes local tokens and private references, stops new reads and triggers an attempted Google revocation. You can also revoke access manually in your Google Account. Reconnecting begins new collection and does not restore private history that was previously deleted. NeverMiss's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Individual rights

Depending on applicable law, you may request access, rectification, erasure or restriction of your data, object to certain processing, request portability where applicable, and withdraw consent where processing is based on consent. You may also complain to the competent data protection authority. To exercise your rights, write to theo.soubrabelay@nevermiss-ai.online. Reasonable identity verification may be requested.

Security

NeverMiss applies technical and organizational measures intended to protect data, including access controls, environment separation, encryption in transit, server-side token protection, access restrictions and deletion procedures. No system is completely risk-free. NeverMiss does not claim certifications it has not obtained and encourages users to protect their own accounts and devices.

Changes to this policy

This policy may change to reflect the product, providers or applicable requirements. For a material change, NeverMiss will provide appropriate notice and request renewed consent where required by law or by the nature of the change.

Contact

Data controller: Théo Soubra-Belay. Privacy contact and rights requests: theo.soubrabelay@nevermiss-ai.online.