Narella Privacy Policy
Effective date: July 24, 2026
Narella, Inc. (“Narella,” “we,” “us,” or “our”) provides relationship intelligence software designed to help people understand, maintain, and strengthen their professional and personal networks.
This Privacy Policy explains how Narella collects, processes, stores, uses, and discloses information when you use our websites, applications, and related services (collectively, the “Services”).
Our approach to privacy
Narella is designed around three levels of information access:
- Communications content is processed locally. The contents of connected emails, messages, and similar communications are generally processed on your device. Narella will transmit communications content or information derived from it for server-side processing only when you expressly authorize a feature or action that requires such processing.
- Your private relationship insights are for you. Narella may extract information from your communications to help you understand your relationships, remember relevant context, and stay connected. These private insights may be stored as part of your social graph, but they are associated with your account and made accessible only to you, except when you expressly choose to share or use them through a feature that requires disclosure.
- Public professional information may be available through the broader network. Professional and other information that is publicly available—such as a person’s name, employer, job title, professional history, education, and similar profile information—may be included in Narella’s social graph. This information may be discoverable by other Narella users where an appropriate network connection or access path exists, including through extended-network relationships.
These distinctions are central to how Narella handles information.
1. Information we process
A. Communications and connected-source information
When you connect an email, messaging, calendar, contact, professional-network, or similar account, Narella may process information made available through that account, including:
- Email and message content;
- Sender, recipient, participant, date, time, thread, and similar metadata;
- Contact information and address-book entries;
- Calendar events, participants, and related details;
- Professional-network connections and profile information; and
- Other information available through a source you choose to connect.
The contents of your communications are processed locally on your device. We do not transmit or store that content on Narella’s servers unless you expressly authorize a feature or action that requires server-side processing, storage, delivery, synchronization, or sharing.
Examples may include asking Narella to deliver an insight to you through another channel, synchronize selected information across devices, generate a result using a server-based service, share information with another person, or submit information for customer support.
Where permission is required, we will seek it through the relevant product experience. Your authorization for one feature does not constitute authorization for unrelated uses of your communications.
B. Private relationship insights
Narella may analyze your connected information to generate insights that help you manage your relationships. Depending on the features you use, these insights may include:
- The existence and apparent strength of a relationship;
- Topics or interests associated with a contact;
- Prior interactions and relevant relationship history;
- Important dates, events, or milestones;
- Commitments, follow-ups, reminders, or “open loops”;
- Preferences or other context that may help you communicate thoughtfully; and
- Recommendations about people you may wish to contact.
These insights may be represented in your personal social graph. Insights derived from your private communications are accessible only through your account and are not made available to other Narella users, unless you expressly choose to share them or use a feature that requires their disclosure.
The underlying communications content does not become public or visible to other members merely because Narella generates a relationship insight from it.
C. Network and contact information
To identify relationships, extended-network paths, and potential introductions, Narella may process:
- Names;
- Email addresses;
- Telephone numbers;
- Usernames, account identifiers, or professional-network handles;
- Contact-list and connection-list information;
- The existence of a relationship between people;
- General indicators of relationship relevance or strength; and
- Other information used to distinguish or match people and organizations.
Where appropriate, Narella may pseudonymize or otherwise transform identifiers used for matching. Pseudonymized information remains personal information where it can reasonably be linked to a person and is handled accordingly.
We do not use contact information obtained from your private sources to contact people on your behalf unless you direct us to do so.
D. Public and professional information
Narella may collect professional and other information that is publicly available or that users provide for network-discovery purposes, including:
- Name and profile image;
- Current and previous employers;
- Job titles and professional roles;
- Education;
- Professional biographies;
- Publicly listed location;
- Professional skills and interests;
- Public websites and social or professional profiles; and
- Other comparable information available through public sources.
This information may come from users, connected professional-network accounts, public websites, publicly accessible databases, or other lawful sources.
Public and professional information may be included in Narella’s broader social graph and may be visible to other Narella users who have an applicable network connection or extended-network access path to the person.
Narella does not represent that public information is always complete, current, or accurate.
E. Account and authentication information
When you create or use a Narella account, we may collect:
- Your name;
- Email address;
- Profile information;
- Authentication identifiers;
- Sign-in provider information;
- Account preferences;
- Invitation or waitlist status; and
- Information about your subscription or access level.
If you sign in through a third-party authentication provider, we receive the information that provider makes available in accordance with your settings and authorization.
F. Connected-source configuration
We may receive information about the sources you connect, such as:
- The type of connected service;
- The account address or identifier;
- Connection status;
- Authorization status; and
- Synchronization or configuration settings.
This information helps us operate and restore connections, provide support, and make the Services available across supported devices. It does not necessarily include the contents of the connected source.
G. Briefs, notifications, and other delivered insights
If you enable a feature that delivers relationship insights outside your local application—such as by email, notification, web interface, or another device—Narella may receive and temporarily store the information necessary to provide that feature.
This information may include:
- Names of people included in a brief or notification;
- A short explanation of why a person was surfaced;
- Reminders or suggested follow-ups; and
- Other relationship context selected for delivery.
Because these materials may be derived from your communications, enabling such a feature constitutes permission for Narella to transmit and process the relevant information for that purpose.
Delivered insights remain associated with your account and are not made available to other users unless you choose to share them.
You can disable these features through the available settings.
H. Information you choose to share
We collect information you voluntarily provide when you:
- Contact customer support;
- Send diagnostic information;
- Respond to surveys;
- Join a waitlist;
- Submit feedback;
- Participate in research or testing;
- Invite another person;
- Request or facilitate an introduction; or
- Otherwise communicate with Narella.
Before sending diagnostic information from the application, you may be given an opportunity to review or approve the information being submitted.
I. Usage, device, and diagnostic information
We may automatically collect limited technical and usage information, including:
- Device and application type;
- Operating-system and application version;
- IP address and approximate location derived from it;
- Log-in and activity timestamps;
- Features used and interactions with the Services;
- Performance information;
- Error reports and crash data; and
- Referral and website interaction information.
We design product analytics to avoid collecting communications content.
If session-replay or similar diagnostic technology is used, we apply measures intended to exclude or obscure sensitive text and communications content. Where required, we provide controls to disable nonessential analytics or obtain consent before using them.
2. How we use information
We may use information to:
- Provide, maintain, personalize, and improve the Services;
- Create and maintain your personal social graph;
- Generate private relationship insights;
- Identify professional connections and extended-network paths;
- Surface publicly available professional information;
- Support introductions and other user-directed interactions;
- Process connected sources and maintain their authorization status;
- Deliver briefs, reminders, notifications, and other features you enable;
- Authenticate users and secure accounts;
- Respond to support requests and troubleshoot technical issues;
- Understand how the Services are used;
- Develop and evaluate new features;
- Prevent fraud, abuse, and security incidents;
- Comply with law and enforce our agreements; and
- Communicate with you about the Services.
We do not sell the contents of your communications. We do not use communications content for third-party behavioral advertising.
We will not use information obtained through Google APIs to develop, improve, or train generalized artificial-intelligence or machine-learning models.
3. Local and server-side processing
Local processing
Narella is designed to perform the primary analysis of your connected communications on your local device.
Local information may nevertheless leave your device when:
- You expressly enable or request a feature requiring server-side processing;
- You request synchronization or delivery across devices or channels;
- You share, export, or send information;
- You submit information to customer support;
- You enable a cloud-based or third-party processing feature;
- Transmission is reasonably necessary to protect the security of the Services; or
- We are legally required to collect or disclose particular information.
Where feasible, the product will identify the relevant feature or action before the information is transmitted.
Social-graph storage
The Narella social graph may contain different kinds of information subject to different access rules:
- Private relationship insights derived from your communications are associated with your account and accessible only to you, unless you expressly choose to disclose them.
- Relationship and network information may be used to determine that a connection or potential path exists.
- Public and professional information may be accessible to other users with an applicable direct or extended-network connection.
The fact that two people are connected may be used to identify a potential introduction path. It does not make the content or private context of their relationship available to other users.
4. Introductions and extended-network discovery
Narella may help users discover paths to people through direct or extended professional networks.
A person may appear in Narella even if that person does not have a Narella account. This may occur because:
- A Narella user has that person in a contact or professional-network list;
- The person has a relationship with another member of the network; or
- Professional information about the person is publicly available.
Narella may show that a network path exists and may display publicly available professional information about the person. Narella will not disclose the private contents of another user’s communications or private relationship insights as part of that discovery.
Any introduction, outreach, or sharing of private context is subject to the controls provided through the applicable feature.
5. Google user data
If you connect a Google service, Narella accesses Google user data through Google’s authorization process and only within the permissions you grant.
Google user data is used to provide and improve user-facing Narella features, such as:
- Understanding and organizing your relationships;
- Surfacing reminders and relationship context;
- Identifying relevant contacts;
- Drafting communications at your request; and
- Providing other features you choose to use.
Google communications content is processed locally. It may be transmitted for server-side processing only when you expressly authorize a feature that requires such processing and only to provide that feature.
Narella does not:
- Sell Google user data;
- Use Google user data for targeted or behavioral advertising;
- Permit people to read Google communications content except when necessary for security, legal compliance, support requested by you, or other circumstances permitted by Google’s policies; or
- Use Google user data to train generalized artificial-intelligence or machine-learning models.
Narella’s use and transfer of information received from Google APIs is subject to the Google API Services User Data Policy, including its Limited Use requirements.
You can revoke Narella’s access through the applicable Google account settings or by disconnecting the source within Narella.
6. How we disclose information
We may disclose personal information in the following circumstances.
Service providers
We use service providers to support functions such as:
- Cloud hosting and storage;
- Authentication;
- Email and notification delivery;
- Product analytics;
- Error monitoring and diagnostics;
- Customer support;
- Security;
- Payment processing; and
- Other infrastructure needed to operate the Services.
These providers may process information only as necessary to provide services to Narella and subject to contractual or other applicable restrictions.
Our providers may include Amazon Web Services, Google, PostHog, Stripe, and other vendors providing comparable services. The providers we use may change as the Services evolve.
A service provider’s involvement does not mean it receives the contents of your locally processed communications. It receives only the information necessary for the service it provides or information you authorize Narella to transmit.
At your direction
We may disclose information when you ask us to, including when you:
- Share an insight;
- Request an introduction;
- Send or export information;
- Connect a third-party service;
- Enable a server-based feature; or
- Authorize another person or service to access information.
Legal and safety reasons
We may preserve, access, or disclose information where we reasonably believe doing so is necessary to:
- Comply with applicable law, regulation, legal process, or governmental request;
- Protect the rights, safety, or property of Narella, our users, or others;
- Detect or prevent fraud, abuse, security incidents, or unlawful activity; or
- Enforce our agreements and policies.
Corporate transactions
If Narella is involved in a merger, financing, acquisition, reorganization, bankruptcy, receivership, sale of assets, or similar transaction, information may be disclosed as part of that transaction, subject to applicable law and appropriate confidentiality protections.
Aggregated or deidentified information
We may use and disclose information that has been aggregated or deidentified so that it cannot reasonably be linked to a particular person. We will not attempt to reidentify deidentified information except to test whether our deidentification processes are effective or as otherwise permitted by law.
7. Legal bases for processing
Where applicable law requires a legal basis, we process personal information based on one or more of the following:
- Performance of a contract: to provide the Services you request;
- Consent: when you authorize access to a connected source or enable an optional feature;
- Legitimate interests: to operate, improve, personalize, and secure the Services, provided those interests are not overridden by your rights;
- Legal obligations: to comply with applicable law; and
- Protection of vital interests or legal claims: where necessary to protect people, enforce rights, or address legal matters.
You may withdraw consent at any time. Withdrawal does not affect processing that occurred before consent was withdrawn, and some Services may no longer function after you withdraw the relevant authorization.
8. Data retention
We retain personal information only for as long as reasonably necessary for the purposes described in this Privacy Policy, including providing the Services, maintaining security, complying with legal obligations, resolving disputes, and enforcing agreements.
Retention periods may vary depending on the type of information and how it is used. Generally:
- Account information is retained while your account remains active and for a reasonable period afterward;
- Delivered briefs are retained for 90 days and then deleted; an unpublished draft is deleted after 7 days;
- Support and diagnostic information is retained as reasonably necessary to resolve the relevant issue and maintain security;
- Analytics information may be retained in aggregated, deidentified, or pseudonymized form;
- Public professional information may be retained while it remains relevant or publicly available; and
- Information may be retained longer where required by law, necessary for security, or needed to establish, exercise, or defend legal claims.
Deleting your Narella account removes or deidentifies personal information associated with your account, subject to technical limitations, legal requirements, backup cycles, security needs, and information we are permitted to retain.
Deleting your account does not necessarily remove public information about you or relationship information independently provided by another person. You may separately request review, correction, removal, or suppression of information associated with you.
9. Security
We use administrative, technical, and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure.
Depending on the nature of the information and system, these measures may include encryption in transit and at rest, access controls, authentication safeguards, monitoring, data minimization, and separation of private account information from broader network information.
Information stored locally is also affected by the security of your device, operating system, account credentials, and backups. You are responsible for maintaining appropriate security for your devices and Narella account.
No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed, altered, or destroyed without authorization.
10. Your choices
Depending on the Services and features available to you, you may be able to:
- Connect or disconnect information sources;
- Revoke third-party account permissions;
- Enable or disable briefs and notifications;
- Choose whether to use features requiring server-side processing;
- Review certain information before sharing or submitting it;
- Opt out of nonessential analytics;
- Correct account or profile information;
- Delete locally stored application information; and
- Request deletion of your Narella account.
Disconnecting a source stops future access but may not automatically delete information previously processed or stored. You may need to delete locally stored information separately or submit a deletion request for server-side information.
11. Privacy rights
Depending on where you live, you may have the right to:
- Request access to personal information about you;
- Request correction of inaccurate information;
- Request deletion of personal information;
- Obtain a portable copy of certain information;
- Object to or restrict certain processing;
- Withdraw consent;
- Appeal a decision concerning a privacy request;
- Opt out of certain sales, sharing, targeted advertising, or profiling where applicable; and
- Lodge a complaint with an appropriate data-protection authority.
Narella does not sell personal information for money and does not share personal information for cross-context behavioral advertising as those terms are defined under California law.
You may submit a request by contacting support@narella.io. We may take reasonable steps to verify your identity and authority before completing a request.
You may also use an authorized agent where permitted by law. We will not discriminate against you for exercising an applicable privacy right.
Certain rights may be limited by exceptions under applicable law. For example, we may be unable to provide private information belonging to another person or delete information we must retain for legal or security reasons.
12. Information about people who are not Narella users
Narella’s users may connect accounts containing information about other people. We may also process publicly available professional information about people who do not use Narella.
If you do not have a Narella account but believe Narella maintains information associated with you, you may contact us to request access, correction, deletion, or suppression, subject to applicable law and the rights of other individuals.
Where appropriate, Narella may maintain a limited suppression record to ensure that information subject to a valid opt-out or deletion request is not subsequently reintroduced into the Services.
13. International data transfers
Narella and its service providers may process information in the United States and other countries that may have data-protection laws different from those where you live.
Where required, we use legally recognized safeguards for international transfers, such as contractual protections or other approved transfer mechanisms.
14. Children’s privacy
The Services are not directed to children under 16, and we do not knowingly collect personal information directly from children under 16.
If you believe a child has provided personal information to Narella, please contact us so we can review and, where appropriate, delete it.
15. Third-party services
The Services may contain links to or integrations with third-party services. Their privacy practices are governed by their own policies, not this Privacy Policy.
Connecting a third-party service authorizes Narella to access information within the permissions you approve. You should review those permissions and the third party’s privacy terms before connecting the service.
16. Changes to this Privacy Policy
We may update this Privacy Policy as Narella and applicable laws evolve.
When we make changes, we will update the effective date above. If a change materially affects how we use information, we will provide additional notice through the Services, by email, or through another appropriate method.
Where required, we will obtain consent before applying a materially different use to information previously collected.
17. Contact us
For privacy questions or requests, contact:
Narella, Inc.
Email: support@narella.io
Mailing address: [INSERT BUSINESS MAILING ADDRESS]
If applicable, residents of the European Economic Area, United Kingdom, or Switzerland may also contact our designated privacy representative at: [INSERT IF REQUIRED].