The Collective by Levistus
Privacy Policy
Last updated: 27 July 2026
Draft notice: this policy was written to accurately describe what the product does, based on the current codebase. It has not been reviewed by a lawyer.
1. Who we are
The Collective is a product of Levistus (“we”, “us”, “our”). If you have questions about this policy or your data, contact us at [email protected].
2. What we collect
- Account information — the email address you sign in with, and an optional separate delivery email if you choose to receive briefings somewhere else.
- Gmail access — when you connect Gmail, we request OAuth access scoped to reading messages, and store the refresh token (encrypted) so we can fetch newsletter emails from the senders you choose. We do not read your inbox beyond the senders you explicitly add.
- Calendar access — if you connect Google Calendar, Microsoft Calendar, or an ICS feed, we store the connection credentials (encrypted where applicable) and fetch your event data so it can be woven into your briefing and shown on your Calendar page.
- Voice and briefing preferences — your chosen narration voice, briefing length, delivery schedule, timezone, and which days count as “weekend” for display purposes.
- Newsletter senders — the list of email addresses you subscribe to for briefing generation.
- Generated content — the text transcript and audio recording of each briefing we generate for you, and your conversation history with Louie, stored so you can revisit them.
- Billing information — if you subscribe, Stripe collects and stores your payment details directly; we never see or store your card number. We keep your Stripe customer ID, subscription ID, and subscription status.
- BYOK API keys — if you use the “bring your own key” tier, any API keys you provide are encrypted at rest with AES-GCM before being stored.
3. How we use it
- To fetch, read, and synthesise your newsletter emails into a spoken briefing script (via Anthropic’s Claude).
- To convert that script into audio (via ElevenLabs).
- To incorporate your calendar into the briefing and the Calendar view.
- To deliver the finished briefing to you by email (via Resend) and host the audio file for playback.
- To power follow-up conversations with Louie, using your most recent briefing, sources, and calendar as context.
- To process subscription payments and manage your billing status (via Stripe).
- To operate, secure, and improve the product — including debugging failed briefings and notifying you if one fails.
We do not use your newsletter or calendar content to train AI models, and we do not sell your data to third parties.
4. Third-party processors
We share data with the following providers strictly to operate the service:
| Provider | Purpose | Data involved |
|---|---|---|
| Anthropic (Claude) | Briefing script generation, Louie chat | Newsletter text, calendar summaries, chat messages |
| ElevenLabs | Text-to-speech | Briefing script text |
| Resend | Transactional email delivery | Delivery email address, briefing content |
| Stripe | Payment processing | Billing/payment details, subscription status |
| Google / Microsoft | OAuth for Gmail and Calendar | OAuth tokens, email and calendar data you authorise |
| Cloudflare | Hosting, database, object storage, edge network | All of the above, as the underlying infrastructure |
Each of these providers processes data under their own privacy terms; we only send them what’s necessary for the feature they support.
5. Data retention
- Briefing transcripts and audio are retained so you can access your history in the app. You may request deletion at any time.
- OAuth tokens and encrypted API keys are retained until you disconnect the relevant integration or delete your account.
- If your account is deleted, we remove your stored briefings, subscriptions, calendar connections, and chat history within a reasonable period, except where we’re required to retain billing records for legal/accounting purposes.
6. Your rights
- Disconnect Gmail or any calendar connection from Settings.
- Change or remove your newsletter subscriptions.
- Delete individual briefings, or request deletion of your full account and associated data by emailing [email protected].
- Cancel your subscription via the Billing Portal.
7. Security
We use passwordless magic-link authentication — we never store a password. Session identifiers and magic-link tokens are stored only as one-way hashes, never in raw form. BYOK API keys are encrypted at rest. All traffic to the app is served over HTTPS.
8. Children’s privacy
The Collective is not directed at, and we do not knowingly collect data from, anyone under 16 years of age.
9. Changes to this policy
We may update this policy from time to time. Material changes will be reflected here with an updated “Last updated” date.
10. Contact
Levistus — [email protected]