Privacy Notice
This notice explains what personal data AVA (operated by AIVAS Pte. Ltd., "we", "us") collects when you use the AVA AI-partner service at ava.aivas.co, how we use and protect it, and the choices and rights you have. It is written to be read alongside our Terms of Service.
1. Who we are
AVA is provided by AIVAS Pte. Ltd., a company incorporated in Singapore. For any privacy question, or to exercise the rights described below, contact us at [email protected].
2. What we collect
- Account data — the email address you sign up or sign in with (including via Google sign-in), and authentication data such as password hashes and session tokens. We never store your password in plain text.
- Your conversations with AVA — the messages you exchange with AVA, and, when you take voice calls with AVA, the call audio (transcribed so AVA can understand and reply), so it can respond, remember context, and act on your requests.
- Memory and profile — facts, preferences, goals, tasks and reminders AVA learns or that you give it, kept so your AI partner is useful over time.
- Connected-account credentials — when you choose to connect a model provider or a third-party account (for example Google), the access tokens or API keys needed to act on your behalf. These are stored encrypted (see section 5).
- Operational data — logs and technical records needed to run, secure and debug the service.
3. AI model providers
AVA may begin on an included starter model funded by us. For starter-model requests, the messages, memory and task context needed to provide AVA are sent to Google Cloud under our service account. The starter allowance is limited; when it is used, you can connect your own supported model provider and continue with the same AVA memory.
You may connect your own model provider at any time using your account or API key. Requests then go to that provider under your credentials and its terms and privacy policy. AVA does not send the same request to the starter provider while a user-connected model is selected.
4. How we use your data
- To operate your AI partner — respond to you, remember context, pursue the goals and tasks you set, and send you proactive updates within your settings.
- To act on your behalf only with the connections and permissions you grant.
- To secure, maintain, debug and improve the service.
- To meet legal and regulatory obligations.
We do not sell your personal data, and we do not use the content of your conversations to train models.
5. Security and isolation
- Your messages with AVA travel over the messaging service you use with it. On Telegram they are carried by Telegram’s Bot API: encrypted in transit, but — like every Telegram bot conversation — not end-to-end encrypted, and handled by Telegram’s servers under Telegram’s own privacy policy (see section 6). On Matrix (via the Element X app) they are end-to-end encrypted between your device and AVA’s own account. On either channel AVA is a processing endpoint: to understand and act on your messages, AVA reads and processes them (and, as described in section 3, sends the relevant content to the selected model provider). This “trusted server” design is what lets AVA act as your assistant — it means AVA, not only you, can access the content of your conversations. Voice calls run on our own media infrastructure and are transcribed on our servers so AVA can take part.
- Connected-account credentials are sealed in a per-user encrypted vault (AES-256-GCM, with a per-user key wrapped by a master key). Only your own AVA instance can unseal your credentials.
- Each user’s data is isolated per account; it is not commingled with or exposed to other users.
6. Third parties we share with
We share your data only as needed to run the service you asked for:
- Telegram — when you chat with or call AVA through Telegram, your messages, files and call signaling pass through Telegram’s servers under Telegram’s privacy policy. Using Telegram is your choice — the Matrix app remains available if you prefer an end-to-end-encrypted channel.
- Google Cloud — provides the included starter model (and the speech synthesis used for AVA’s voice on calls) and receives the messages and context needed for those starter requests. Paid service data is not used to train Google models; provider security and abuse-monitoring retention may still apply.
- The model provider you connect — receives the messages and context needed to generate AVA’s responses under your own account (see section 3).
- Accounts you connect (e.g. Google Gmail, Calendar, Drive) — accessed only with your explicit, per-connection consent and only for the actions you ask AVA to take. You can disconnect them at any time.
- Infrastructure providers — the service is hosted on Google Cloud Platform in the Singapore region.
AVA’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If you connect your Google account, AVA accesses your Gmail, Google Calendar, Google Drive and Google Contacts only with your explicit permission and only to perform the tasks you ask of it. We do not sell this data, use it for advertising, or use it to train AI or machine-learning models, and human access is limited to what you authorise or what is required for security, legal or abuse-prevention reasons.
7. Retention
We keep your data for as long as your account is active, or as needed to provide the service and meet legal obligations. Operational logs are automatically discarded on a rolling basis (currently after 30 days). When you delete your data or close your account, we erase your facts, conversation history, memory, credentials, connected accounts and sessions; we deactivate both Matrix messaging identities assigned to you and remove your conversation room and uploaded media from our messaging server; and we unlink your Telegram account from AVA (removing the stored link between your Telegram identity and your AVA account, any unused connect links, and any files you sent AVA on Telegram that we stored). Messages already delivered to your own Telegram chat history remain in your Telegram account, under your control. Deletion is checkpointed across these systems and retried after a temporary failure. We keep your sign-in available and show the request as pending until every required store verifies completion; unusual infrastructure failures may require operator intervention. Historical audit positions and cryptographic hashes may be retained to preserve AVA’s shared tamper-evident chain, but their user identifier and event content are replaced by a signed, content-free redaction marker. A minimized pseudonymous erasure receipt is also retained. Because operational logs are discarded on the rolling cycle above rather than one entry at a time, a deletion request does not separately purge past log entries; they age out automatically.
8. Your controls and rights
- Export — download the complete data manifest as JSON or Markdown, or a ZIP that also contains your artifact files, from Settings → Privacy. Reusable authentication material (password verifiers, API/OAuth tokens, session/reset-token hashes and service encryption keys) is excluded for security; provider, model and scope metadata is included.
- Delete — start verified erasure from Settings → Privacy. AVA reports completion only after every required store verifies it. Completed erasure cannot be undone.
- Withdraw consent — you can withdraw your consent at any time; deleting your data records that withdrawal.
- Access and correction — you may ask what we hold and ask us to correct it.
We handle personal data in line with Singapore’s Personal Data Protection Act (PDPA). If you are in the European Union, we also honour the access, rectification, erasure, portability and objection rights provided under the GDPR. To exercise any right, contact [email protected].
9. Changes to this notice
If we materially change this notice we will update the version and effective date above and, where the change affects what you agreed to, ask you to review and accept it again.
10. Contact
AIVAS Pte. Ltd. — [email protected].