Legal
Privacy Policy
Effective date: August 11, 2026
This Privacy Policy explains how Approv ("Approv," "we," "us," or "our") collects, uses, stores, and shares information when you use getapprov.com, app.getapprov.com, related APIs, and integrations (the "Services").
By using the Services, you agree to this Policy. If you do not agree, please do not use the Services. See also our Terms of Service.
1. Who we are
Approv is an access governance product that helps organizations run request → approve → grant workflows for tools and resources (for example repositories and cloud files).
Contact: jharold.dev@gmail.com
Website: https://getapprov.com
2. Information we collect
Account and workspace data
- Name, email address, organization/workspace details, roles, and authentication identifiers
- Access requests, approvals, grants, audit logs, and related workflow metadata you create in Approv
- Resource records you import or configure (names, types, links, and non-secret metadata)
Early access / waitlist
- Contact details and messages you submit through early-access or waitlist forms
Technical and usage data
- Log data such as IP address, browser/device type, timestamps, and approximate location derived from IP
- Product analytics (if enabled), including page views and feature usage, via providers such as Google Analytics
- Cookies or similar technologies needed to run the site
Integration credentials and tokens
- OAuth tokens, refresh tokens, and similar credentials required to connect third-party systems (stored encrypted at rest where applicable)
- Optional credentials you provide for provision (for example API tokens), stored with encryption controls
3. Google API services and Google user data
Approv’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What Google data we access
When an organization administrator connects Google (Google Drive / Docs / Sheets / Slides), we may access:
- Basic Google account profile information (such as email and name) for the connecting account
- Google Drive metadata needed to list and import folders and Workspace files (for example file IDs, names, MIME types, and links)
- Permission information needed to grant or revoke sharing on those files/folders according to approved Approv grants
How we use Google data
- To connect the organization's Google account to Approv
- To import selected Drive items as governed resources
- To provision and deprovision share permissions when access grants are approved, revoked, or expire
- To validate connection health and troubleshoot sync failures
What we do not do with Google data
- We do not sell Google user data
- We do not use Google user data for advertising or personalized ads
- We do not use Google user data to train generalized AI/ML models
- Human access to Google user data is limited to cases needed to operate or secure the Service (for example support you request, or investigating abuse/security issues), consistent with Limited Use
Sharing and retention of Google data
Google OAuth tokens are stored encrypted and used only to call Google APIs on behalf of your organization. Tokens are cleared when you disconnect Google in Approv. Imported resource metadata and grant/audit records may remain in Approv after disconnect so your organization retains governance history, unless you delete them or request deletion as described below.
4. How we use information
- Provide, operate, and improve the Services
- Authenticate users and secure accounts
- Run access workflows (requests, approvals, grants, sync, notifications)
- Respond to support and early-access inquiries
- Monitor reliability, prevent fraud/abuse, and comply with law
- Communicate product updates where permitted (you may opt out of non-essential marketing)
5. How we share information
We may share information with:
- Service providers that help us host, email, monitor, or analyze the Services (bound by confidentiality and processing terms)
- Integration providers you choose to connect (such as Google, GitHub, or Bitbucket) to perform the actions you authorize
- Organization administrators within your workspace (who can see users, requests, grants, and resources for their organization)
- Legal and safety recipients when required by law or to protect rights, safety, and security
- Business transfers in connection with a merger, acquisition, or asset sale (with notice where required)
We do not sell personal information.
6. Retention
We retain information for as long as needed to provide the Services, meet legal obligations, resolve disputes, and enforce agreements. Workspace administrators can disconnect integrations and manage resources/grants. You may request deletion of personal data by contacting jharold.dev@gmail.com, subject to legal and operational retention needs (for example audit trails your organization requires).
7. Security
We use industry-standard measures appropriate to the sensitivity of the data, including encryption in transit (HTTPS), encryption of certain secrets at rest, access controls, and monitoring. No method of transmission or storage is 100% secure; please use strong credentials and limit admin access in your organization.
8. International transfers
We may process information in countries other than where you live. Where required, we use appropriate safeguards for cross-border transfers.
9. Your choices and rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, or to object to / restrict certain processing. Contact jharold.dev@gmail.com to exercise these rights. Organization-owned workspace content may also be controlled by your administrator.
You can disconnect Google and other integrations in Approv Settings. You can also revoke Approv's access in your Google Account permissions.
10. Children
The Services are not directed to children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children.
11. Changes
We may update this Policy from time to time. We will post the updated version on this page and revise the effective date. Material changes may also be communicated via the Services or email where appropriate.
12. Contact
Privacy questions: jharold.dev@gmail.com
Questions? jharold.dev@gmail.com · Back to home