1. Information we collect
- Account data such as name, email address, role, company, login activity, and plan information.
- Workspace data such as domains, crawl settings, project names, team members, and user preferences.
- Website and search data such as URLs, titles, metadata, headings, links, response codes, Search Console metrics, keyword assets, and reports.
- Support and AI-assistant data such as questions, prompts, feedback, generated answers, and evidence references used to answer a request.
- Technical data such as device information, browser type, IP address, cookies, logs, and security events.
2. How we use information
We use information to operate Novaverb, authenticate users, maintain workspaces, run crawls and audits, connect integrations, generate reports, answer support and AI-assistant requests, protect the service, prevent abuse, improve reliability, and communicate with customers.
3. Google Search Console and third-party integrations
When a customer connects an integration such as Google Search Console, Novaverb processes the connected data only to provide requested product features, such as search performance analysis, keyword mapping, crawl prioritization, and reporting. Customers can disconnect integrations from their account or workspace settings.
4. AI assistant and generated answers
NovaAssistant may use workspace data, crawl evidence, search metrics, standards, and customer prompts to generate answers, and includes supporting evidence when available. Your questions, prompts, the generated answers, and the evidence references used to answer them are stored on our servers and associated with your account, so your conversation history is available to you and syncs across your devices, and so we can operate, support, and improve the assistant.
We do not use your conversations or workspace data to train a shared or third-party AI model, and we do not use them to intentionally misrepresent facts or fabricate crawl evidence. If we ever introduce model training that uses customer content, we will disclose it and obtain any consent required before doing so. You can request deletion or export of your conversation history by contacting contact@novaverb.com.
5. Visitor behavior data from your website
If you install the Novaverb tag on your own website, we process data about the people who visit that site so we can show you how those pages are used. For each visit this can include a randomly generated session identifier, the pages visited and the order they were seen in, time on page and engagement time, clicks including their position on the page and the element clicked, scroll depth, rage and dead clicks, JavaScript errors, screen and viewport size, device class, browser and operating system family, the referring website, and the country the visit came from. We do not ask for or store a visitor's name, email address, or precise location.
On paid plans a recorded session can be played back. How many sessions are stored each month, and how long they are kept before automatic deletion, are set by your plan and shown on the pricing page. Aggregated heatmap and scroll data is kept separately from individual sessions.
For this data you are the controller and Novaverb is the processor: it is your website, your visitors, and your decision to turn the tag on. You are responsible for having a lawful basis for the recording, for describing it in your own privacy notice and cookie banner, and for obtaining any consent your law requires before the tag runs.
How to control it
The session identifier is held in the browser's session storage and disappears when the tab is closed; the tag sets no cookie of its own. Recording stops immediately if the visitor's browser sends a Global Privacy Control signal, if a cookie named nv_consent has the value denied, or if your page sets window.NovaReplayConsent to false. In the default consent mode a visit is recorded unless one of those signals is present, which is an opt-out. If your law requires consent before recording begins, set the project's consent mode to required, and have your banner set the nv_consent cookie to granted once the visitor agrees.
What is hidden before it reaches us
Masking happens in the visitor's browser, before anything is sent to Novaverb. Masked content is replaced with solid blocks at the moment of capture, so we never receive it and it cannot be revealed later from a recording.
Anything typed into a form field is masked in every mode, and this cannot be turned off. Passwords, card numbers, and anything else entered into an input are therefore never captured.
Balanced, the default: in addition to all form input, we mask email addresses, phone numbers, monetary amounts in any of the major currencies we detect, and any run of four or more digits, wherever they appear in the page text. Ordinary page text, such as headings and article copy, is captured so the recording is readable.
Strict: all page text is masked, leaving only layout and interaction. Choose this if your pages display personal or account information as ordinary text.
You can also mark any element on your own pages: elements with the data-nv-mask attribute have their text masked, and elements with the data-nv-block attribute are not recorded at all.
Novaverb also refuses some recordings on your behalf. Where a visit comes from the European Economic Area, the United Kingdom, or Switzerland and the project is not set to ask for consent first, we do not record that visit at all: nothing is stored, so there is no session to delete afterwards. If you want visits from those places recorded, set the project's consent mode to required and have your banner set the nv_consent cookie to granted once the visitor agrees.
Recording can be turned off at any time from your project settings, and stored sessions can be deleted on request.
6. Sharing and subprocessors
We do not sell personal information. We may share data with service providers that help operate hosting, security, analytics, email, payments, support, and AI infrastructure. These providers are listed or summarized on the Subprocessors page when applicable.
7. Retention
We keep data for as long as needed to provide the service, comply with legal obligations, resolve disputes, maintain audit logs, enforce agreements, and improve reliability. Customers may request deletion or export where applicable.
8. Security
We use administrative, technical, and organizational safeguards designed to protect data, including access controls, HTTPS, secure configuration, monitoring, and least-privilege operations. No online service can guarantee absolute security.
9. Your rights and choices
Depending on your location, you may have rights to access, correct, export, delete, restrict, or object to certain processing of personal data. You may contact contact@novaverb.com to make a privacy request.
10. International processing
Novaverb may process data in countries where we or our service providers operate. When required, we use appropriate safeguards for cross-border transfers.
11. Updates
We may update this Privacy Policy as the product, law, or operational practices change. Material updates will be reflected by updating the effective date and, when appropriate, providing additional notice.