What we collect, how we use it, and your rights.
Last updated: February 2026
We collect data needed to operate the platform safely and provide requested features:
We do not require government ID or your legal name to use Navilla.
Exposure context is generated from confirmed network data using aggregation rules and delayed snapshots. The product is designed to avoid exposing direct identity-path details in user-facing exposure responses.
Most statuses are currently self-reported. If provider/lab verification features are enabled in the future, verification type will be displayed as a label to indicate confidence level. Additional consent requirements may apply for those features.
We use a limited set of vendors for infrastructure operations (such as auth, database, email delivery, and hosting). Each provider receives only the data needed to perform its service under applicable contractual safeguards.
Account data is retained while your account is active. After account deletion, personal data is deleted within 30 days, except where temporary retention is required for legal/security obligations. Non-attributable aggregate statistics may be retained for service reliability and product improvement.
Depending on your jurisdiction, you may have the right to:
Navilla complies with the Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) for users in Mexico and aligns with GDPR principles for users in the EU.
We use essential cookies required for authentication and session continuity. See Cookie Policy for details.
To exercise any of your rights or ask questions about this policy, contact us at contact@navilla.app.