Privacy Policy
Invena Labs Limited (trading as invena)
167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom
Company number 17237229
Registered in England and Wales
Version: 0.9.6 (beta)
Last updated: 25 August 2026
Effective date: 26 July 2026
This Privacy Policy explains how Invena Labs Limited collects, uses, discloses, and protects personal data when you use our website, app, invitations, and related services.
Beta notice: Invena is in early access. The marketing and legal website is at invena.app / www.invena.app. The product app is at app.invena.app. Retention periods and subprocessors may be refined as we move toward wider launch. We will update this page when we make material changes.
1. Who we are
Data controller: Invena Labs Limited (trading as invena)
| Registered address | 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom |
| Company number | 17237229 |
| Privacy contact | privacy@invena.app · Contact hub — privacy |
| Support | support@invena.app · Contact hub |
| ICO registration | Invena Labs Limited is registered with the UK Information Commissioner’s Office as a data controller (ZC219043). This is a data protection fee listing, not an ICO certification or audit. Verify on the ICO register. |
| Data protection | We are not required to appoint a Data Protection Officer. For privacy matters, contact privacy@invena.app, use Contact hub, or Settings → Privacy in the app. |
This policy applies to:
- our website at invena.app (when live);
- the Invena app at app.invena.app (and any legacy beta UI still in use);
- transactional emails we send (for example Space invitations);
- support and privacy requests you send to us.
It does not cover third-party websites or services you access through links from Invena.
2. What Invena does
Invena helps households organise important information, share selected content with trusted people, and maintain continuity around documents and records.
We aim to:
- collect only the data needed to run the service;
- let you control what you store and who you share it with;
- be clear about what we do and do not do with your data; and
- separate preview steps, such as document extraction, from persistent records until you review and confirm them.
We do not sell your personal data.
3. Personal data we collect
Personal data means information that identifies you or could reasonably be used to identify you.
3.1 Account and profile data
When you create an account or sign in, we process:
- your email address;
- an internal account identifier;
- authentication data, including your password in hashed form only (we do not store plain-text passwords);
- profile information you choose to provide, such as your name or display name;
- your country of residence, when you provide it at signup or when it is updated through support;
- your preferred device timezone (IANA identifier), saved after email confirmation so reminders and time-based features can use your local time — you can change this in Preferences where available; and
- sign-in and session metadata, such as when you last signed in.
We may process country and screening information to comply with legal, sanctions, and access-control obligations.
We collect this data from you when you register or update your profile. Authentication is provided by Supabase (our identity and authentication provider). Supabase may process your email address, account identifiers, and technical data such as IP address and device or browser information when you sign in.
We use sign-in metadata to operate your account, maintain security, and detect abuse. Device timezone is account/technical metadata used for time-based product features; it is retained while your account is active and deleted or anonymised with your account under section 6.
3.2 Spaces, sharing, and invitations
Invena is organised around Spaces: private areas controlled by a Space owner, where you store and share information with people you trust.
We process:
- Space names and descriptions;
- your role in each Space (for example owner, editor, or viewer);
- invitation details, including invitee email address, role, invitation status, delivery state, and related service messages; and
- membership and sharing settings.
Invitation flow
If someone invites you to a Space by email:
- a Space member (usually the owner) enters your email address and chooses your role;
- Invena sends a transactional invitation email on that member's instructions — we do not decide who is invited;
- the invitation does not create an account;
- you must create an account or sign in with that email address and accept the invitation before you can access the Space; and
- until you accept, you cannot view Space content.
Receiving an invitation email alone does not grant access.
Roles for invitation data
For invitation emails, the Space member who sends the invite decides who to invite and what Space context to share. Invena Labs Limited processes the invitee's email address and invitation metadata to send the transactional message, record invitation status, and operate the Service. See section 8 for how we share data with processors such as Resend.
Mistaken or unexpected invitations
If an invitation is sent to the wrong email address, the person who receives that email may see invitation metadata (for example inviter name and Space name) even if they never accept. If you forward an invitation or share login credentials, access may be broader than you intend. We cannot verify that the person who accepts is the person you intended unless you use appropriate care when entering email addresses.
Invitation records
We may keep invitation records and related delivery logs (for example sent, delivered, or bounced) for security, abuse prevention, dispute handling, and legal compliance. See section 6.6.
3.3 Records and documents you add
You may store structured entries (for example insurance, utilities, household records, or membership and loyalty cards) and upload documents (such as PDFs or images).
Your responsibility for content
- You decide what to upload or enter.
- You should only upload material you are entitled to store and share.
- If your content includes information about other people (for example a partner, relative, or household member), you must have authority or another lawful basis to share that information with us and with other Space members you invite.
- Entries may include third-party contact details (for example a family member's phone number or email, a GP or supplier contact, or contacts related to work you manage personally). You are responsible for having authority or another lawful basis to store and share those details. You must only upload information you are lawfully entitled to use and share. Invena is not a CRM or client-management platform.
- Membership and loyalty fields — for example programme names, membership numbers, and barcode values — are personal data. Membership numbers and barcode values may function as access or entitlement identifiers. We therefore protect them as confidential account-related information using our entry-field security controls. They are not special-category data merely because they identify a membership or loyalty account. They are encrypted at rest with our other entry-field controls, included in data exports and deletion flows, and are not intended for analytics, marketing, or error-monitoring payloads.
- Sharing Cards & Passes. If you share a Cards & Passes Entry, the people with access to that Entry may be able to view the card image, membership identifier, barcode value, and any generated barcode, depending on the permissions and content you share.
Sensitive and special category data
We do not require you to provide special category data (such as health information) to use Invena. However, you may choose to upload documents containing sensitive or special category information — for example passports, wills, medical records, insurance documents, bank statements, or estate-related information. You control what you upload, and you should not upload documents unless you are comfortable with that processing.
If you upload such information, you are responsible for ensuring you have a lawful basis to share it with us and with other Space members who can access the relevant Space.
We process this content to provide the service you request, including storage, retrieval, sharing within your Space, reminders, and related product functions.
Documents are treated as evidence attached to your records. We do not use your uploaded documents to train public AI models. Where we use third-party OCR or processing services, we rely on their applicable business or enterprise terms and configured processing settings for the feature in question.
3.4 Intake previews and document extraction
When you upload a document, you may choose to use an extraction feature to generate an assistive preview of text or suggested fields. Extraction is user-directed and optional. The preview does not automatically create a record or change your data. You must review and confirm any extracted information before it is saved.
Important points:
- This is processing of personal data. Extracted text may itself be personal data and may be sensitive depending on the source document.
- Where it runs: Your request is handled by our API. PDF text extract may run on our infrastructure. Photo / image extract (when enabled) uses Google Cloud Vision API configured for the EU for UK/EU beta users. See Subprocessors and our AI Policy.
- Storage: If you run extraction, we may store extracted preview text and related metadata on the intake candidate so you can review it. That stored preview is not an Entry until you confirm and save. If we store extracted preview text or extraction metadata linked to your account, it will be included in your data export where required by law.
- Purpose: Previews support your review only. They do not automatically create or change your records.
- Sensitive content: If you choose extraction, document content (including photos that may contain sensitive information) is processed by our service providers to generate the preview. Do not upload documents unless you are comfortable with that processing.
We will update this policy before changing the processing region or adding new providers for this feature.
3.5 Operational, security, and support data
We process data needed to run the service safely and reliably, including:
- Audit and activity events — who performed an action, what type of action, and when. We do not store the full text of your documents in audit logs;
- In-app notifications — for example invitations, membership changes, or reminders;
- Error and diagnostic data — limited technical information (such as error type, request metadata, and device or browser information) may be sent to our error-monitoring service if something goes wrong; and
- Support and privacy correspondence — if you email us, we keep what you send so we can respond.
We may also send service and security emails, including account verification messages, password-reset messages, invitation messages, and notifications about changes to your email address, password, or other security settings. These are service communications, not marketing.
3.6 Website and beta app technical data
When you visit invena.app (when live) or use the beta app, standard hosting logs may include your IP address, browser type, and pages or requests accessed.
On the marketing website (invena.app / www.invena.app), we may use Plausible Analytics in a cookieless configuration to measure aggregate traffic. Plausible processes limited technical data (such as page URL, referrer, and approximate location derived from IP) on our behalf and does not set analytics cookies in this configuration. The product app (app.invena.app) does not load Plausible. See our Cookie Policy and Subprocessors.
We do not use third-party marketing or advertising analytics on the website or in the beta app.
3.7 What we do not collect today
At present, we do not:
- run a public waitlist that stores your data separately from the app;
- use third-party product analytics (such as PostHog) in production; or
- offer sign-in to Invena via a third-party identity provider (for example “Sign in with Google”). Account access uses email and password (and MFA where enabled).
3.8 Inbox connect (Gmail)
You may optionally connect a Gmail mailbox in Settings → Capture so Invena can help you find Continuity providers and bill-like messages. This is separate from signing in to Invena.
Important points:
- Read-only. We request Google’s
gmail.readonlypermission. Invena cannot send, delete, or modify your email. - You choose the scope. Sync uses labels and/or sender domains you select. We do not ingest or store a full copy of your mailbox.
- Transient processing. When you run Find providers or Sync, selected message metadata and attachments may be read through the Gmail API to create Inbox candidates for your review. Raw mailbox bodies are not retained as a mailbox replica after that processing.
- Nothing is filed until you confirm. Candidates appear in Inbox; you Keep, Dismiss, or Create Space Entries yourself.
- What we keep. Encrypted OAuth refresh tokens and connection settings (email address, selected labels/senders, sync status) until you Disconnect or revoke access in Google. Confirmed Entries and attachments follow ordinary Space retention.
- Provider. Google processes connected-mailbox data under our instructions for this feature. See Subprocessors.
We will update this policy before adding Microsoft or other mailbox providers, or before changing the permissions we request.
3.9 Continuity Place and Entry Location
You may optionally add a Place to a Space (for example, a home or storage location) and a Location to an Entry (for example, an insured address or where a vehicle is kept). These features are optional. You can leave them blank and still use Invena.
When you choose to save a Place or Location, we may process the information you provide, including:
- an address or place label you type, paste, or confirm from suggestions;
- coordinates (latitude and longitude), including when you drop or move a pin on a map, choose a suggestion, or tap Use my location; and
- source metadata, such as whether the value came from typing, a suggestion, a pin, or your device.
Device location. We request browser or device location only when you tap Use my location. We do not continuously track your location, run geofencing, or share your live position with other users as a tracking product.
Maps and geocoding. To help you find and confirm a place, the app may show a map preview or interactive pin and may look up or reverse-look up addresses. In closed beta, map tiles and geocoding may use OpenStreetMap and Nominatim (community endpoints) via our application. Those requests may disclose the search text or map area you are viewing to that provider. We intend to move to a managed tiles and geocoding provider listed on our Subprocessors page before wider launch. Open in Maps opens Apple Maps or Google Maps on your device using a link you choose to follow; those apps process data under their own terms.
Storage and access. Place and Location values are stored with your Space or Entry content, encrypted at rest with our other sensitive-field controls. This is not end-to-end encryption. Space members can see Place according to their role. Entry Location follows Entry permissions. Values are included in data exports and follow Space and Entry retention and deletion rules.
We do not use Continuity Place for advertising, resale of location data, or mobility profiling.
4. Why we use your data (purposes and lawful bases)
Under UK data protection law, we must have a lawful basis for each purpose for which we use personal data. The table below explains our main purposes, the data involved, and the lawful basis we rely on.
| Purpose | Data involved | Lawful basis |
|---|---|---|
| Create and manage your account | Account and profile data | Performance of a contract (to provide the service you sign up for) |
| Provide Spaces, sharing, invitations, and permissions | Space, membership, and invitation data | Performance of a contract; legitimate interests where needed for service administration and secure operation |
| Store and display records, documents, and reminders | Records, documents, metadata, and related content | Performance of a contract |
| Generate document previews and extracted text | Uploaded documents and extracted text | Performance of a contract |
| Optional inbox connect (Gmail) — find providers and sync candidates you choose | Connected mailbox address; encrypted OAuth tokens; selected labels/senders; transient message metadata and attachments | Performance of a contract |
| Optional Continuity Place / Entry Location | Address or place label; coordinates; source metadata; map/geocode queries when you use preview or search | Performance of a contract |
| Maintain security, prevent abuse, and operate logs | Audit, activity, device, and technical data | Legitimate interests (to keep Invena and users safe) |
| Provide support and respond to requests | Correspondence and account details | Legitimate interests; performance of a contract where the request relates to service use |
| Comply with legal obligations | Account, audit, and disclosure records | Legal obligation |
| Send service and transactional emails | Email address and relevant service data | Performance of a contract; legitimate interests |
| Understand aggregate website traffic (cookieless Plausible on the marketing site, when enabled) | Limited technical traffic data | Legitimate interests (to operate and improve the public website) |
| Optional features that require consent (if introduced) | Limited technical data or identifiers | Consent, where required |
Legitimate interests: Where we rely on legitimate interests, we balance our interests against your rights and freedoms and only use data where necessary and proportionate.
Consent: We use consent only for optional processing (for example optional analytics if we introduce them). You may withdraw consent at any time. Withdrawal does not affect processing that happened before withdrawal, and it does not affect processing we carry out on another lawful basis (such as contract) for core service features.
We do not rely on consent for core product processing such as account creation, document storage, access control, invitations, or security logging.
5. Who can see your data
5.1 Within Invena
A Space is a private area controlled by the Space owner. Members can access only the content and actions permitted by their role.
- You can access the Spaces and records your permissions allow.
- Space owners can manage members, invitations, and governance-sensitive actions.
- Editors can create and update records and upload documents within a Space, subject to role limits.
- Viewers can see content they are invited to but cannot make destructive changes.
Permissions are enforced on our servers — not only in the app interface.
5.2 Our access to your content
We do not routinely access the contents of your Spaces or documents to browse user data.
We may access limited account or technical information when you contact support so we can help you. Any broader access to your content would only occur with your direction, to resolve a specific support request you raise, or where required by law. Access for operational support is limited and proportionate.
5.3 Service providers and subprocessors
We use trusted providers to run Invena. They process data only on our instructions and for the purposes of providing services to us.
| Provider | Role | Typical data | Location |
|---|---|---|---|
| Supabase | Authentication, database, and file storage | Account data, app content, metadata | West Europe (London) |
| Resend | Transactional email (invitations from invites@invena.app) | Email address, inviter name, Space name | United States |
| Sentry | Error monitoring | Technical diagnostics, limited identifiers | European Union |
| Railway | API hosting | Request metadata | United States |
| Vercel | Website and product app hosting (www + app.invena.app) | IP address, request logs, session cookies on the product app | United States / global edge |
| Cloudflare | Bot protection on product auth (Turnstile) | Challenge tokens; limited client/browser signals for bot detection | Global edge |
| Chatwoot (self-hosted on UpCloud) | Support and privacy messaging | Conversation content; contact emails; helpdesk metadata | United Kingdom |
| Google Cloud Vision | Optional document extraction (Photo Extract) | Document image/PDF bytes for OCR preview when you choose Extract | European Union (EU Vision endpoint for UK/EU beta) |
| Google (Gmail API) | Optional inbox connect | Connected Gmail address; OAuth tokens; selected labels/senders; transient scoped message metadata and attachments | United States / Google global infrastructure |
Where account and household data are stored. Primary customer content — including Spaces, entries, and documents — is stored with Supabase in West Europe (London) (UK). Other service components (for example API hosting, email delivery, website/app hosting, and edge security) may process data in the UK, the EEA, or other countries as listed above and in our Subprocessors register. Sign-up and auth forms may use Cloudflare Turnstile for abuse prevention.
Closed-beta map preview: when you use Continuity Place, map tiles and geocoding may use OpenStreetMap / Nominatim community endpoints (not commercial subprocessors with a customer DPA). Those requests may disclose search text or the map area you view. See Subprocessors. A managed map provider will be listed before wider launch.
We may also use categories of provider such as cloud hosting, identity infrastructure, email delivery, error monitoring, and customer communications tools as the service matures.
For document extraction, we use Google Cloud Vision API in the EU for UK/EU beta users. For inbox connect, we use the Gmail API with read-only access as described in §3.8. We will update this policy before changing regions, permissions, or providers for these features.
A detailed subprocessor register is published at invena.app/subprocessors.
Some providers are located outside the UK. Where we transfer personal data internationally, we use appropriate safeguards as required by UK data protection law.
5.4 Legal requirements
We may disclose information if required by law, regulation, court order, or to protect the rights, safety, and security of users and Invena.
6. How long we keep data
We keep personal data only for as long as necessary for the purposes described in this policy, including to provide the Service, maintain security, meet legal obligations, resolve disputes, and enforce our terms. Retention depends on the type of data. Some categories are kept for a fixed recovery window; others are kept while your account is active or for a purpose-limited period after deletion.
6.1 Active account data and Space content
While your account remains active, we keep your account data and the content you store in Spaces until you delete it, purge it, or close your account, subject to the recovery windows below.
Place and Location fields are part of Space or Entry content and follow the same active, soft-delete, and purge rules as that content.
6.2 Soft-deleted Entries and Spaces
Invena uses soft delete before permanent removal. During the recovery window, deleted content is retained for restore only — not for ordinary use — before it becomes eligible for permanent purge from active systems.
| Item | Recovery period before permanent purge |
|---|---|
| Entry (record) | 30 days after deletion |
| Space | 90 days after deletion |
During the recovery period, authorised owners may be able to restore items. After that window, purge permanently removes stored content from active systems.
6.3 Account deletion
You may request deletion of your account and associated personal data in the app (Settings → Privacy) or via our Privacy rights contact page.
Where you request deletion, we may apply a 72-hour cooling-off period before permanent purge begins. You may cancel the request during that period. After the cooling-off period ends, we delete or anonymise data we no longer need, subject to legal, security, audit, and dispute-resolution obligations.
We will explain what can be deleted immediately and what must be retained for legal, security, or operational reasons.
Deleting your account does not delete content you have already shared into a Space, unless that Space is also deleted or purged.
6.4 Audit and security events
When content is purged, we may retain limited audit records (for example that a Space existed and who performed a deletion) in append-only logs for security, abuse prevention, dispute handling, accountability, and legal purposes. Audit records do not include the full text of your documents.
Audit and security events are typically retained for up to 24 months, unless a longer period is needed for security investigations, legal claims, or regulatory requirements.
6.5 Customer request records
When you submit a privacy or account request (for example access, export, or deletion), we retain a compliance record of that request for dispute, legal, security, and accountability purposes. This is separate from the user content the request relates to. We aim to respond within 30 days where UK GDPR applies; retaining the request record does not mean we keep all related personal data indefinitely.
6.6 Invite and delivery logs
We keep limited records of invitations and message delivery events, such as whether an invitation was sent, delivered, bounced, expired, or revoked. These records may include recipient email addresses, timestamps, and related invitation metadata.
We keep invite and delivery logs only as long as reasonably necessary for service integrity, security, abuse prevention, and dispute handling. We do not use open or click tracking for transactional invitations.
We may also retain account-change logs and related security events for the same purposes. Where data is no longer needed for those purposes, we will delete or anonymise it.
Pending invitations and support emails are kept for as long as needed to provide the service or resolve your request, then deleted or archived in line with our retention practices.
Future contact import: If we later allow importing address books or contact lists, we will publish an updated notice explaining what is collected and how it is used before that feature is enabled.
6.7 Inbox connect tokens
If you connect Gmail, we retain an encrypted refresh token and connection settings only while the connection remains active. When you Disconnect in Invena, or revoke Invena in your Google Account, we remove the stored token and stop sync. Confirmed Inbox candidates and Space Entries you already created are not deleted by disconnect alone.
6.8 Backups
Database backups support recovery from incidents and are retained only for the rotation period used by our infrastructure providers.
| Backup type | Intended retention (beta → production) |
|---|---|
| Automated daily backups (Supabase Pro, when enabled) | Up to 7 days |
| Operator-managed backups (during beta) | Up to 30 days |
Purged content is removed from active use. Some deleted data may remain in encrypted backups or other residual systems until those systems rotate or are overwritten.
7. Security
We take security seriously. Measures include:
- Encryption in transit using HTTPS/TLS;
- Encryption at rest through our cloud providers (provider-managed encryption — we do not currently offer end-to-end or client-side encryption);
- Role-based access within Spaces, enforced on our API;
- Re-authentication — requiring your current password before changing to a new one; and
- Out-of-band confirmation — we may require re-authentication or out-of-band confirmation for sensitive actions, such as changing your email address, password, or other security settings;
- Soft delete and staged purge rather than immediate silent removal; and
- Audit logging for important lifecycle actions.
No online service can guarantee absolute security. If you believe your account has been compromised, use Security contact promptly.
We do not claim formal certifications (such as SOC 2 or ISO 27001) unless and until we publish them on our Trust Centre.
8. Your rights
If you are in the UK, EEA, or another region with similar rights, you may have the right to:
- Access your personal data;
- Rectify inaccurate or incomplete personal data;
- Erase your personal data, subject to legal and operational limits;
- Restrict or object to certain processing;
- Port your data in a structured, machine-readable format, where applicable;
- Withdraw consent where processing is based on consent; and
- Complain to a supervisory authority.
How to exercise your rights
- Use Settings → Privacy in the app, or our Privacy rights contact page. We may need to verify your identity.
- Use Settings → Privacy in the app for data access and account deletion requests.
- Update profile information in the app under Account → Profile.
- Delete or purge Space content using in-app controls, subject to the recovery windows above.
Data export is available in Settings. Export my data generates a zip and emails you a secure download link. Request my data (DSAR) creates a formal privacy request on our compliance record; export delivers the data. Re-downloading does not require a new DSAR. Account deletion is subject to a short cooling-off period before deletion begins. We will explain what will be deleted, what cannot be deleted immediately, and any limited records we must retain.
Exports reflect content currently available in the app, and include items you deleted that remain in the recovery window (see section 6.2). Items past their purge date are excluded.
Automated account deletion with a cancellable cooling-off window is rolling out in beta. We will not ignore valid requests while features are being completed.
Complaints
If you are unhappy with how we handle your personal data, you have the right to complain to a supervisory authority.
- United Kingdom: Information Commissioner's Office (ICO) — you can also contact us first at privacy@invena.app so we can try to resolve your concern. Our ICO registration number is ZC219043.
- EEA: you may lodge a complaint with your local data protection authority in the country where you live or work.
9. Children
Invena is not directed at children under 18, and we do not knowingly collect personal data directly from children.
Adults may use Invena to organise household information. That information may incidentally include details about children or other family members (for example in documents you upload). If you include information about others, you must have authority or a lawful basis to share it, as described in section 3.3.
If you believe a child has provided us with personal data directly, use our Contact hub and we will take appropriate steps.
10. Document extraction and preview tools
Invena may use automated tools to help you preview information from documents — for example PDF text extract or optional Photo Extract via Google Cloud Vision — before you decide what to save.
Important principles:
- extraction is optional and user-directed;
- previews are for your review, not automatic record-keeping;
- tools do not replace your ownership or authority over your data;
- tools do not access data outside your permissions; and
- we do not take hidden actions on your behalf.
More detail is in our AI Policy and section 3.4 above.
If we introduce new analytics or automation features, we will update this policy and, where required, ask for any additional permissions or consents.
11. Cookies and similar technologies
We do not use non-essential marketing cookies or advertising trackers on the website. Essential cookies or similar technologies may be needed for security and basic site function.
Marketing site analytics: when enabled, cookieless Plausible Analytics runs on invena.app / www.invena.app only. It does not set analytics cookies in this configuration. Details are in our Cookie Policy.
Beta app: the beta app may use session technologies needed to keep you signed in and operate the service. It does not load Plausible.
If we add technologies that require consent under UK law, we will update this policy and our Cookie Policy, and we will ask for consent where required.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on invena.app/privacy with a new "Last updated" date. Where we make material changes, we may also notify you in the app or by email. If you continue to use Invena after an update takes effect, the updated policy will apply from that date, to the extent permitted by law. This does not affect any rights you may have under applicable law.
13. Contact us
| Controller | Invena Labs Limited (trading as invena) |
| Address | 167-169 Great Portland Street, 5th Floor, London W1W 5PF, United Kingdom |
| Privacy | privacy@invena.app · Contact hub |
| Support | support@invena.app · Contact hub |
For terms of use, see invena.app/terms (when published).
invena® — UK registered trade mark UK00004392095.