Last updated: 31 August 2026
This notice explains how OverBox s.r.o. (“we”, “us”) processes personal data collected through the Enuva early-access waitlist at enuva.app and through the Enuva iOS app. Where the two differ, each section says so. It applies to everyone who uses them. We are based in Slovakia and follow the General Data Protection Regulation (GDPR) and Slovak Act No. 18/2018 on Personal Data Protection; the rights in section 6 are the ones the GDPR gives EU/EEA residents, and we apply them to everyone.
OverBox s.r.o.
Slovakia
Company ID (IČO): 53938461
VAT ID (IČ DPH): SK2121532721
Contact: hello@enuva.app
When you join the waitlist we collect:
Lawful basis: consent (GDPR Art. 6(1)(a)). You give consent by ticking the checkbox on the form. Your email is used only for Enuva early access contact. If you provide a hear-from answer, we use it only for audience attribution — not for newsletters, advertising, or third-party offers.
When you use the Enuva app we collect:
Lawful basis, by purpose: your account, your settings and the sources you follow are processed to deliver the service you asked for, which is our agreement with you under Art. 6(1)(b) — without them there is nothing to generate. Your feedback is optional: skipping it does not stop Enuva working, it only leaves your briefings less tailored to you, and we rely on the same basis for it because tailoring is what you signed up for. Push notifications are optional: sending you one rests on your consent (Art. 6(1)(a)) — the iOS permission prompt is where you give it, and you can withdraw it in iOS Settings. Holding the token itself, including the flag that records a refusal, rests on our legitimate interest (Art. 6(1)(f)) in knowing which devices to leave alone. The device identifier, the usage and cost records and the fault reports rest on our legitimate interest (Art. 6(1)(f)) in keeping the service working, affordable and debuggable; refusing them is not possible while using the app, which is why we keep them minimal and free of content.
When your briefing is built, the publishers you follow see your device’s IP address and browser details, as they would if you visited them yourself. They are not our processors, and we tell them nothing about you. Article text and the summaries made from it pass through our AI provider, and the briefing you keep lives on your device rather than on our servers. Spoken audio is not switched on yet; when it is, the text to be spoken will go to our speech provider, and the audio will be stored briefly before it reaches you.
We use PostHog (EU region) to count privacy-preserving usage events
(e.g. a custom landing_page_viewed event, referral/UTM source,
“form submitted” and “form completed”).
PostHog is configured with no cookies, no localStorage, and project-side IP discard.
Automatic pageview capture is disabled. We use site and environment labels to keep
production reports separate from development and preview visits.
Full URL and full referrer values are stripped before events are sent.
In this cookieless mode PostHog does not store anything in your browser;
instead its servers derive an identifier by hashing a salt that rotates
daily together with technical signals of the request. Visits from the same
browser can therefore be counted together within one day, and the link
breaks when the salt rotates. Session recording is disabled.
We do not send your email address, your name, or the full URL of the page
you are on. We do send the path, the hear-from answer if you gave one, and
where the visit came from.
Lawful basis: our legitimate interest (GDPR Art. 6(1)(f))
in knowing whether the site works and where our audience comes from. We
rely on it because the measurement is cookieless, its identifier lasts a day
at most, and it cannot be tied back to you. You can object to it (Art. 21).
Because the measurement holds nothing that identifies you, we cannot exclude
one browser on request — blocking eu.i.posthog.com, or using
a browser or extension that blocks analytics, stops the measurement your
browser sends. One event is sent from our server rather than your browser:
when a new waitlist record is created we record that it happened, with the answer
you gave and where the visit came from, and blocking cannot prevent that one.
This event has its own random identifier and is not linked to your browser's
identifier. Browser form-completion counts also include repeat submissions;
the separate server count includes only new waitlist records.
The app has no analytics. It contains no PostHog and no other analytics SDK. Everything it sends is listed in section 2, and none of it exists to study how you behave; the fault reports carry no identifier that could attribute them to you. The app does not track you across other companies’ apps or websites and asks for no tracking permission.
We use the following sub-processors for the website:
The app additionally uses:
Apple delivers the notifications you turn on and handles Sign in with Apple. For those, Apple decides on its own account how it processes the data, so it acts as an independent controller rather than as our processor; Apple’s own privacy policy governs it.
Each provider in the two lists above processes data for us under its own data processing terms, which form the Art. 28 arrangement between us. Ask us at hello@enuva.app for the position on any one of them, or for a copy of a transfer safeguard.
One image in the homepage footer is loaded from ElevenLabs’ content network, so opening the page tells them your IP address and browser, as any image loaded from another site would. We are moving it onto our own domain.
No data is sold or shared with advertisers.
We keep your email until whichever of the following happens first:
In the app:
Under GDPR Arts. 15–22 you have the right to:
These rights apply as the GDPR grants them, which in some cases attaches conditions — erasure, for example, does not reach records we must keep. We will respond within one month (Art. 12(3)), and will tell you if a request is complex enough to need the extension that article allows.
You have the right to object. Where we rely on our legitimate interest — the website measurement in section 3, and the device identifier, usage records and fault reports in section 2 — you can object at any time under Art. 21, on grounds relating to your situation. Email hello@enuva.app and we will stop unless we can show compelling grounds that override yours.
In the app, ask us. Self-service account deletion is not built yet. Email hello@enuva.app and we will delete your account and its data by hand within one month, apart from the usage and cost records described in section 5. The same address gets you a copy of your data.
The app’s “Delete account & data” button does less than its name suggests, and we would rather say so than let you find out. If you signed in with Apple it does nothing at all and tells you so. If you are a guest it signs you out and starts a fresh account — the old one becomes unreachable, but its briefings stay in the app’s storage on this phone, and its rows on our side are removed no sooner than 90 days after your last use. Deleting the app removes everything it stored, except a small random identifier we use for per-device limits, which stays in the system keychain.
This section is about the waitlist. For the app, see section 6.
Email hello@enuva.app with the subject “Withdraw early access consent”. We will delete your record within one month.
The app does profile you, in the GDPR’s sense: it works out which topics you are interested in from the sources you pick and the feedback you give, and uses that to choose what goes into your briefing. That is the product doing what you asked it to.
What it does not do is make a decision about you with legal or similarly significant effects, so the prohibition in GDPR Art. 22 does not apply. We do not profile you for advertising, and we do not sell or share your data. What we store about your interests is a set of weights over subjects and over things in the news — an organisation, a place, a person — which your ratings move up or down. It holds no opinions about you and nothing you typed, and we use it only to order your next briefing. Rating something down changes what you get next; it does not undo what was already generated.
If you believe we have handled your data unlawfully you can lodge a complaint with the Slovak supervisory authority:
Úrad na ochranu osobných údajov Slovenskej republiky
Hraničná 12, 820 07 Bratislava
dataprotection.gov.sk
If we make material changes we will update the “Last updated” date above and, where required, seek fresh consent. The current version number is stored alongside every waitlist record.
Questions about this notice? Email hello@enuva.app