Legal
Privacy Policy
Effective date: August 21, 2026
Who we are
Drevanto is operated by ARMM General LLC, doing business as Drevanto. ARMM General LLC is the controller of the information described here. This policy covers the Drevanto public website, the Drevanto Android app, and the Drevanto Cloud service.
For privacy questions or requests, email hello@drevanto.com.
Information we collect
Website forms
When you use the beta application, contact, or product-update forms, we collect what you submit: name, company, email, optional phone number, trade or industry, team size, current software, your beta answers or contact message, your consent, and the page or source your subscription came from.
Accounts and authentication
For Drevanto accounts we hold your account email, password-derived authentication data (we do not store your password as readable text), user and company identifiers, your name, your role, email verification, recovery, invitation and deletion records, beta authorization and agreement acceptance, session records, and security events.
Business data you sync to Cloud
If you choose to use Drevanto Cloud, the records you sync may include company and team details; customer names, contacts, addresses and notes; catalogs and materials; estimates and line items; jobs, schedules and tasks; costs, payments received, payment method, reference and notes, balances, change orders, and other records you enter.
Local files and images
Job photo and document attachments and measurement sources currently remain local to your device or are referenced on the device; those features do not upload the files. If you deliberately attach a supported text file to an AI Workforce request, the filename and basic file metadata, plus an excerpt of at most 4,000 characters, are sent to Drevanto Cloud for that request.
AI features
Only when you deliberately invoke an AI feature, the app sends the project description or instructions needed for the task, the record context you selected, recent conversation context, and any supported selected-file excerpt to Drevanto Cloud. Cloud sends the necessary input to OpenAI and returns a result for you to review. Deterministic Instant Estimate workflows can run locally without any provider call.
Operational metadata
Drevanto Cloud records limited request metadata (route, status, duration, request ID) and AI usage metadata (provider, model, success, token counts, timing). The AI usage records we inspect do not store prompt text, model output, customer content, or secrets.
This Beta 2 Android client contains no advertising SDK, analytics SDK, or crash reporting SDK, and does not use an advertising identifier or request address book, calendar, microphone, or device-location permissions.
How we use information
We use information to provide accounts and beta access, to provide optional Cloud synchronization, to run estimating, job, schedule and customer operations, to provide AI-assisted drafting, to produce documents, to provide support, to send communications you requested, for security, for abuse and rate-limit protection, for diagnostics, and to respond to legal and compliance requests.
We do not use your information for targeted advertising. We do not sell your information or share it with advertisers.
Service providers
- DigitalOcean — Drevanto Cloud API hosting, managed PostgreSQL, and recovery points/backups.
- OpenAI — processing for AI requests you deliberately start. Drevanto sends these requests with
store=false. OpenAI states that data submitted through its API is not used to train its models unless the API customer opts in; under default API controls, abuse-monitoring logs may contain prompts and responses and may be retained for up to 30 days. We do not claim Zero Data Retention or Modified Abuse Monitoring. - Lovable — hosting and build of this public website.
- Supabase — website form, auth, and database functions used by this website project.
- Zoho — delivery of requested operational and account-deletion email.
- Google Play — Android app distribution and closed-testing administration.
These providers process data in order to deliver their services under their own terms.
Security
The release Android client uses HTTPS for production Cloud requests and Android secure storage for Cloud session tokens. Drevanto Cloud uses HTTPS with HSTS, authenticated tenant and company isolation, active-account checks, rate limits, serializable deletion scope checks, and TLS connections to managed PostgreSQL. No system is perfectly secure.
Retention
- Active Cloud accounts and synced business records remain in the primary database while the account or service relationship is active, or until authorized deletion or lifecycle removal.
- External deletion tokens expire after one hour and are single use; we store only SHA-256 hashes of them.
- Delivered email-outbox records are permanently purged after 30 days.
- Expired or used account-deletion token records are purged 30 days after expiry or use. A successful account deletion removes its token and the related outbox message immediately.
- Minimal pseudonymous deletion receipts are purged after 90 days.
- DigitalOcean managed PostgreSQL point-in-time recovery points and backups are retained for seven days, so deleted primary data ages out as those recovery points expire.
- DigitalOcean build and deploy logs are retained for 90 days. Drevanto has no separate runtime-log forwarding destination configured.
- OpenAI abuse-monitoring retention applies as described under Service providers.
- Website beta, contact, and support submissions are kept only as long as needed to evaluate them, respond to you, support your participation, operate the beta, protect security, or meet applicable legal obligations.
- Copies of email may remain with Zoho or with recipients under their own mailbox or provider controls even after our Cloud outbox record is purged.
Deletion
You can request deletion of your Drevanto Cloud account on the Delete account page, or from inside the app at Settings → Drevanto Cloud → Delete Account.
If you are an owner, admin, or member and you are not the final active owner, deletion removes your personal Cloud identity, credentials, sessions, action tokens, beta records, outbox records for your address, and AI usage linked to your user. Shared company business records remain for the rest of the team.
If you are the final active owner, deletion removes the entire Cloud tenant, including team identities, customers, contacts, catalogs, estimates and lines, jobs, costs, payments, change orders, commercial records and access grants, Cloud AI usage, beta records, sessions, tokens, and related outbox messages.
After deletion, already-issued access tokens and stale sessions are rejected on their next request. Records and files that exist only on your device remain there until you clear the app's data or uninstall Drevanto.
We keep a minimal pseudonymous deletion receipt for 90 days, which is then purged automatically. It contains only a random receipt ID, the deletion scope, the affected user count, the completion time, and one-way hashes of deleted UUIDs — not names, email, password data, business content, prompts, or AI responses.
Because DigitalOcean managed PostgreSQL recovery points expire after seven days, deleted data may remain in protected backups until those recovery points expire. Backups are used only for disaster recovery.
Your choices
Using Drevanto Cloud, the AI features, and text-file attachments is optional. You can unsubscribe from product update emails at any time using the link in each email. To request access, correction, deletion, or to make another privacy request, email hello@drevanto.com. Never send a password or a deletion token to support.
Drevanto is a business tool for contractors and service businesses and is not designed for children.
Changes to this policy
If we change this policy we will update the effective date above and, when appropriate, describe the change on this page.