LookSavi

Privacy Policy

Last updated September 2026

LookSavi is a small, single-operator business platform. This policy describes what it collects and why, in plain terms. It is not legal advice, and it describes the software as it is actually built.

Who this covers

Two groups of people use LookSavi, and they are treated differently:

What we collect about clients

Signing in with Google

The client portal offers “Continue with Google” as an alternative to an emailed sign-in link. It requests only your name, email address and profile picture (the standard openid, email and profile scopes).

Your email address is used for one purpose: to match you to an existing client record so we know which account to show you. If it does not match a client on file, you are not signed in and nothing is stored. We do not read your Gmail, your contacts, your calendar or your files, and the permission requested does not allow it.

The operator’s own Google data

LookSavi includes an internal tool that the operator may connect to their own Google account to see which emails still need a reply. It is separate from the client portal, applies only to the operator’s own mailbox, and never touches a client’s Google account.

Where it is used, these limits apply and are enforced in code:

LookSavi’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Contracts and AI review

Agreements created or reviewed in LookSavi can be checked by an AI model at the operator’s request. When that happens, the full text of the agreement is sent to the AI provider — which includes whatever the document itself contains: party names, notice addresses, fees and rates, payment terms, and any commercially confidential terms written into it.

This only ever runs when the operator presses a review or revision control on that specific document. It is not run on a schedule, not run when a page is opened, and not run on a document a client is viewing in the portal. An uploaded agreement that was signed elsewhere is stored as a file and is not sent to any AI model.

The model is used to read and suggest wording. It cannot send, sign, publish or alter a document: every change it proposes is shown as a marked-up comparison and is written only after a person approves it.

The operator’s page assistant

The operator’s own administrative screens carry an assistant that can answer questions about the page in front of them and take requests to change it. When it is used, an image of that page is captured and sent to an AI model along with the question. An administrative page can show customer names, email addresses, invoice amounts and connected-account figures, so those may be in the image.

It is only ever triggered deliberately, by the operator, on the operator’s own screens — never on this site, never on the client portal, and never on a page a customer is viewing. The image is stored only while the request is open and is deleted when it is answered or closed. Nothing is used to train a model.

How information is used

To operate the service: producing invoices and reports, taking payment, sending you the emails you would expect from us, and supporting you when something goes wrong. We do not sell personal information, and we do not share it for advertising.

Who else handles it

We use a small number of service providers, each for a specific job: Google Cloud (hosting and database, in the United States), Stripe (payments), Resend (email delivery), and the sales or advertising platforms you connect yourself. They may process your information only to provide those services to us.

How long it is kept

Invoices, payments and the records behind them are kept for as long as the business relationship lasts and afterwards for as long as tax and accounting rules require. Operational data — sign-in links, email delivery logs, connection credentials — is kept only while it is useful, and credentials are deleted when a connection is removed.

Security

Traffic is encrypted in transit. Credentials for connected services and for the operator’s mailbox are encrypted before being written to the database. Access to the administrative side is restricted to a single allow-listed account. No system is perfectly secure, and we make no claim to any formal certification.

Your choices

You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it — write to hello@looksavi.com. You can disconnect a connected sales or advertising account at any time, and you can unsubscribe from marketing email using the link in any such message. Invoice and account emails are not marketing and are not affected.

Children

LookSavi is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16.

Changes

If this policy changes in a way that materially affects you, we will say so before it takes effect. The date at the top always reflects the current version.

Contact

Questions about this document, or a request about your information: hello@looksavi.com.