Nava Labs
  • Platform
  • Integrations
  • Pricing
  • Docs
  • Blog
  • About
Log In Get Early Access
  • Platform
  • Integrations
  • Pricing
  • Docs
  • Blog
  • About
  • Log In
  • Get Early Access
Legal

Privacy Policy

Last updated: February 7, 2026

1. Introduction

Nava Labs, Inc. ("the Company," "we," "us," or "our") operates navalabshq.com and the Nava Labs data and analytics infrastructure platform (together, the "Service"). The Service is an AI-powered developer tool that lets engineering teams connect multiple data sources, run SQL queries across those sources without moving data, and monitor schema drift and ingestion health in real time. This Privacy Policy explains what information we collect in the course of providing the Service, how we use it, and the rights you have over it.

We are based at 301 Brannan Street, Suite 220, San Francisco, CA 94107, and can be reached at [email protected].

2. Information We Collect

2.1 Information You Provide Directly

When you register for early access, create an account, or contact us, we collect:

  • Account details: work email address, full name, job title, and company or team name;
  • Contact and inquiry data: the content of messages you send through our contact form, integration request form, or support email;
  • Billing contact information: name and email for the person responsible for subscription payments on paid plans (Developer, Team, or Scale).

2.2 Data Source Connection Configuration

A central function of the Nava Labs platform is connecting to your existing data sources (for example, PostgreSQL, BigQuery, Snowflake, Amazon S3, MySQL, Kafka, and others from our connector library). To enable those connections, you supply credentials such as host addresses, port numbers, database names, access tokens, or service account keys. We treat this configuration data as follows:

  • Credentials are encrypted at rest using AES-256 and in transit using TLS 1.2 or higher;
  • We use credentials only to execute the queries and ingestion tasks you configure. We do not query your source databases on our own initiative;
  • We do not ingest, copy, or retain the contents of your data rows. The platform reads schema metadata (table names, column names, data types) to power features like cross-source joins and schema drift alerts. Row-level data passes through the query engine in memory during query execution and is not persisted on our systems;
  • Credentials are deleted promptly when you disconnect a source or close your account.

2.3 Platform Usage and Pipeline Data

When you use the Service, we collect operational records tied to your account:

  • SQL queries you write and save, connector configuration settings, pipeline schedules, and schema mapping rules;
  • Query execution history: query text, execution timestamp, latency, and row count. The Team and Scale plans retain query history for 30 days as an in-product feature. Aggregated telemetry (timing, error rates, ingestion volume by source) is retained for up to 13 months for performance analysis;
  • Schema metadata: table and column structures discovered from your connected sources. We retain this metadata while the source connection is active and for 14 days after disconnection;
  • Connector sync events: timestamps, row counts, and error codes from scheduled ingestion runs.

2.4 No Model Training on Your Query or Schema Content

We do not use the text of your SQL queries, your connector configurations, or the schema metadata from your data sources to train machine learning models. Aggregated, anonymized performance signals (such as median query latency or connector error rates across all customers) may inform product roadmap decisions, but no query text or schema content exits our secure processing environment for model training purposes.

2.5 Information Collected Automatically

When you visit navalabshq.com, we automatically collect limited technical information:

  • IP address and approximate location (city or region level, not precise geolocation);
  • Browser type, operating system, and device class;
  • Pages visited, referring URLs, and time on page;
  • Cookie and similar identifiers (see Section 5 and our Cookie Policy).

2.6 Children's Data

navalabshq.com is a developer tool directed at professional engineering teams, not at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact [email protected] and we will delete it promptly.

3. How We Use Information

We use the information we collect to:

  • Provision and operate the Nava Labs platform: authenticate your account, maintain source connections, execute your SQL queries, and deliver query results and ingestion reports;
  • Send service communications: connector sync summaries, schema drift alerts, query execution notifications, and critical product or security updates;
  • Maintain and improve the Service: analyze usage patterns to optimize query engine performance, connector reliability, and ingestion throughput across our supported source types;
  • Manage your subscription: process plan upgrades or downgrades, apply usage limits for your tier, and communicate billing-related information;
  • Respond to inquiries, integration requests, and early-access applications;
  • Send marketing communications about new connectors, product features, or engineering-relevant content, where you have opted in or where applicable law permits;
  • Detect, investigate, and prevent abuse, fraud, or security incidents;
  • Comply with legal obligations and enforce our Terms of Service.

We do not sell personal information for monetary value. Where applicable state law treats certain advertising arrangements as a "sale" or "share," see the California section below.

4. Sharing of Information

We share personal information only with:

  • Service providers acting on our behalf, including cloud infrastructure providers (data storage and compute), transactional email services, product analytics tools, and payment processors. Each provider operates under contractual terms that limit their use of data to services performed for us;
  • Legal authorities or courts, when required by law, legal process, or to protect the rights, safety, or property of the Company, our users, or the public;
  • A successor entity in the event of a merger, acquisition, financing round, or asset sale, provided the successor is bound by obligations consistent with this Policy.

We do not sell personal information to third parties. We do not share schema metadata or query data with parties outside our service-provider relationships described above.

5. Cookies and Tracking

We use cookies and similar technologies to operate the site, manage developer sessions, and measure usage. Our analytics instrumentation is configured to anonymize IP addresses before storage. For details and opt-out options, see our Cookie Policy.

6. Data Retention

We retain personal information only as long as needed for the purposes described in this Policy, to comply with legal or accounting obligations, and to resolve disputes:

  • Account information: retained for the duration of your account, plus 30 days after deletion for backup recovery purposes;
  • Data source credentials: deleted immediately when you disconnect a source or close your account;
  • Schema metadata: retained while the source connection is active and for 14 days after disconnection;
  • Query text: retained 30 days after execution (supports the query history feature on paid tiers);
  • Aggregated usage telemetry: retained up to 13 months;
  • Billing records: retained 7 years to satisfy accounting obligations;
  • Marketing list contacts: purged after 24 months of inactivity;
  • Server access logs: retained 90 days, then aggregated and anonymized.

7. Security

We apply administrative, technical, and physical safeguards appropriate to the sensitivity of the data we handle. These include TLS 1.2 or higher for all data in transit, AES-256 encryption for credentials stored at rest, role-based access controls with least-privilege principles for internal systems, and regular security reviews. No system is perfectly secure, and we cannot guarantee absolute security of your information.

8. Your General Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, or limit certain processing of your personal information. To submit a request, email [email protected]. We will respond within the timeframe required by applicable law. California residents have additional rights described in Section 9 below.

9. California Residents (CCPA / CPRA)

Under the California Consumer Privacy Act ("CCPA") and the California Privacy Rights Act ("CPRA"), California residents have specific rights regarding personal information collected about them. This section supplements the rest of the Policy.

9.1 Categories We Collect

In the past 12 months, we have collected the following categories of personal information defined under Cal. Civ. Code §1798.140: identifiers (name, work email address, IP address, developer account token); professional or employment information (job title, employer name); commercial information (subscription plan tier, billing contact); internet or other electronic network activity (browsing on navalabshq.com, query execution events); and inferences drawn from the above for service-improvement purposes.

9.2 Sources, Purposes, Disclosure

We obtain this information from you directly and through automatic site and platform instrumentation. We use it to operate and improve the Service, communicate with you, manage your subscription, and meet legal obligations. We disclose it only to service providers under written contract and to legal authorities where required.

9.3 Your CCPA / CPRA Rights

  • Right to Know: request the categories and specific pieces of personal information we have collected about you in the past 12 months.
  • Right to Delete: request deletion of personal information we collected from you, subject to legal exceptions.
  • Right to Correct: request correction of inaccurate personal information.
  • Right to Opt Out of Sale or Sharing: we do not sell personal information; we do not "share" it for cross-context behavioral advertising as defined under CPRA.
  • Right to Limit Use of Sensitive PI: we do not collect or use sensitive personal information as defined under Cal. Civ. Code §1798.140(ae) for purposes beyond those permitted without authorization. Data source credentials are encrypted service configuration, not sensitive PI subject to the use-limitation right.
  • Right to Non-Discrimination: we will not deny services, charge different prices, or provide a different level of service because you exercised a right.

9.4 How to Exercise

Submit a verifiable request by emailing [email protected] with the subject line "California Privacy Request." Include enough detail for us to verify you are the person whose information is the subject of the request. We respond within 45 days, with a possible 45-day extension for which we will notify you.

9.5 Authorized Agents

You may designate an authorized agent to make a request on your behalf. The agent must provide proof of authorization; we may also require you to verify your identity directly.

9.6 "Shine the Light"

California Civil Code §1798.83 entitles California residents to request information regarding our disclosure of personal information to third parties for direct marketing. We do not disclose personal information for third-party direct marketing.

9.7 Do Not Track and Global Privacy Control

Under the California Online Privacy Protection Act (Cal. Bus. & Prof. Code §22575), we disclose how we respond to "Do Not Track" (DNT) browser signals. Because there is no common industry standard for interpreting DNT signals, we do not currently respond differently to them. We do not authorize third parties to collect personally identifiable information about your activity across different websites when you use the Service. We honor an opt-out preference signal sent by a platform or browser that complies with the CPRA, such as the Global Privacy Control (GPC); when we detect a GPC signal, we treat it as a valid request to opt out of the sale or sharing of personal information for that browser or device.

10. Changes to This Policy

We may update this Policy from time to time. Material changes will be reflected by a new "Last updated" date and, where appropriate, a notice on the Service.

11. Contact

Questions, requests, or complaints about this Policy can be sent to:

Nava Labs, Inc.
301 Brannan Street, Suite 220
San Francisco, CA 94107
Email: [email protected]
Phone: +1 (415) 553-7390
Nava Labs

Run analytics across any data source. No pipeline-wiring required.

301 Brannan Street, Suite 220
San Francisco, CA 94107
+1 (415) 553-7390
[email protected]

Product

  • Platform
  • Integrations
  • Pricing
  • Docs

Company

  • About
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Cookie preferences
© 2026 Nava Labs, Inc.