Privacy Policy

Last Updated: July 29, 2026

1. Information We Collect

Avori collects the minimum account and product data needed to provide the service. This includes:

2. How We Use Information

We use your information to:

3. Project Data and AI Requests

Avori is local-first by default. Core project files, GDDs, chats, pages, project rules, and project memory stay on the device unless you choose a feature that requires cloud storage or processing. When you submit an AI request, Avori sends the relevant prompt and context to the selected model provider so it can answer that request.

Pro multi-device continuity is optional. When enabled, it synchronizes supported history and context through Avori's cloud services so the same Avori account can continue on trusted devices. A Cloud Loop is separately and explicitly enabled with Continue when this device is off; Avori then uploads the approved project workspace to an isolated cloud worker that processes the files needed to run the Loop and return a reviewable result.

Your source code, design docs, prompts, chats, and project context are not used to train Avori or shared with other customers. You explicitly choose whether a compatible request uses a personal provider key or prepaid Avori balance; Avori does not silently switch to paid balance. Model providers process request data under their applicable API terms.

4. Data Security

Authentication and application data are handled through Supabase. Payment details are handled by Stripe; Avori does not store raw card data. Provider API keys are encrypted at rest, scoped to the authenticated account or organization, never returned after saving, and never bundled into the desktop installer or engine plugins. Cloud workspaces and trusted-device access are account-isolated and protected by server-side authorization.

Automatic error reports are disclosed during Avori setup and can be turned off at any time in Settings. They are limited to the Avori version, operating-system version, failing Avori component, error class and code, sanitized stack-frame names, and bounded correlation details. They do not include prompts, chats, project files or snippets, GDD content, API keys, credentials, payment details, balances, or absolute file paths. Reports are encrypted in transit, stored in a private support queue, and visible only through founder-authenticated support administration. Manual reports use the same technical limits and may also include the description you type after Avori removes recognizable paths and secrets.

5. Third-Party Services

We use Supabase for authentication and database services, Stripe for payment processing, Resend for transactional email, Google Analytics for public-website traffic and engagement measurement, cloud infrastructure providers for opt-in Pro sync and Cloud Loops, and model providers for AI responses. These services process data only as needed to provide the feature you use.

6. Retention and Deletion

Local project data remains under your control. Active Pro or Studio cloud workspaces are retained while the service is active. After Pro cloud entitlement ends, the encrypted workspace becomes read-only and remains available for export or renewal for 30 days before deletion. Confirming Delete Cloud Data also schedules the encrypted workspace for deletion after a 30-day recovery window; local project files are not deleted. Resolved or dismissed support reports are normally deleted after 90 days, and all support reports are deleted after no more than 180 days. Billing records may be retained as required for legal, tax, dispute, and fraud-prevention purposes.

7. Contact Us

If you have any questions, contact us at help@avorihq.com