LookSavi is a small, single-operator business platform. This policy describes what it collects and why, in plain terms. It is not legal advice, and it describes the software as it is actually built.
Who this covers
Two groups of people use LookSavi, and they are treated differently:
- Clients who sign in to the client portal to see their invoices, reports and payment methods.
- The operator — the LookSavi account holder — who runs the business side of the platform.
What we collect about clients
- Contact and business details you give us, or that we record to bill you: name, email address, business name, and the terms of our arrangement.
- Invoices and payments. Card details are handled by Stripe and are never stored on our servers — we keep only the reference Stripe gives us and the status of a payment.
- Sales and advertising figures from services you choose to connect, such as Shopify, Amazon or Meta. These are read to produce your reports and to calculate commission. Access credentials for those services are encrypted before being stored.
- Email activity for messages we send you — whether an invoice or campaign was delivered, opened, or bounced.
Signing in with Google
The client portal offers “Continue with Google” as an alternative to an emailed sign-in link. It requests only your name, email address and profile picture (the standard openid, email and profile scopes).
Your email address is used for one purpose: to match you to an existing client record so we know which account to show you. If it does not match a client on file, you are not signed in and nothing is stored. We do not read your Gmail, your contacts, your calendar or your files, and the permission requested does not allow it.
The operator’s own Google data
LookSavi includes an internal tool that the operator may connect to their own Google account to see which emails still need a reply. It is separate from the client portal, applies only to the operator’s own mailbox, and never touches a client’s Google account.
Where it is used, these limits apply and are enforced in code:
- The permission requested is read-only. It cannot send, delete or alter mail.
- Message bodies are never retrieved. Only the sender, subject, date and Google’s own one-line preview are read.
- Sender, subject and that one-line preview may be sent to an AI model — and nothing else — solely to sort mail into “needs a reply”, “worth knowing” and “filtered”. Message bodies cannot be sent, because they are never fetched from Google in the first place. Nothing is used to train a model.
- Access can be revoked at any time from the app or from Google account settings, and revoking it deletes the stored credential.
LookSavi’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Contracts and AI review
Agreements created or reviewed in LookSavi can be checked by an AI model at the operator’s request. When that happens, the full text of the agreement is sent to the AI provider — which includes whatever the document itself contains: party names, notice addresses, fees and rates, payment terms, and any commercially confidential terms written into it.
This only ever runs when the operator presses a review or revision control on that specific document. It is not run on a schedule, not run when a page is opened, and not run on a document a client is viewing in the portal. An uploaded agreement that was signed elsewhere is stored as a file and is not sent to any AI model.
The model is used to read and suggest wording. It cannot send, sign, publish or alter a document: every change it proposes is shown as a marked-up comparison and is written only after a person approves it.
The operator’s page assistant
The operator’s own administrative screens carry an assistant that can answer questions about the page in front of them and take requests to change it. When it is used, an image of that page is captured and sent to an AI model along with the question. An administrative page can show customer names, email addresses, invoice amounts and connected-account figures, so those may be in the image.
It is only ever triggered deliberately, by the operator, on the operator’s own screens — never on this site, never on the client portal, and never on a page a customer is viewing. The image is stored only while the request is open and is deleted when it is answered or closed. Nothing is used to train a model.
How information is used
To operate the service: producing invoices and reports, taking payment, sending you the emails you would expect from us, and supporting you when something goes wrong. We do not sell personal information, and we do not share it for advertising.
Who else handles it
We use a small number of service providers, each for a specific job: Google Cloud (hosting and database, in the United States), Stripe (payments), Resend (email delivery), and the sales or advertising platforms you connect yourself. They may process your information only to provide those services to us.
How long it is kept
Invoices, payments and the records behind them are kept for as long as the business relationship lasts and afterwards for as long as tax and accounting rules require. Operational data — sign-in links, email delivery logs, connection credentials — is kept only while it is useful, and credentials are deleted when a connection is removed.
Security
Traffic is encrypted in transit. Credentials for connected services and for the operator’s mailbox are encrypted before being written to the database. Access to the administrative side is restricted to a single allow-listed account. No system is perfectly secure, and we make no claim to any formal certification.
Your choices
You can ask us what we hold about you, ask for it to be corrected, or ask for it to be deleted where we are not required to keep it — write to hello@looksavi.com. You can disconnect a connected sales or advertising account at any time, and you can unsubscribe from marketing email using the link in any such message. Invoice and account emails are not marketing and are not affected.
Children
LookSavi is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16.
Changes
If this policy changes in a way that materially affects you, we will say so before it takes effect. The date at the top always reflects the current version.
Contact
Questions about this document, or a request about your information: hello@looksavi.com.