Privacy

About this notice

Effective September 2, 2026. This notice explains how Avrelius collects, uses, and protects personal data about website visitors, waitlist members, and app users. Avrelia Inc. (in formation) is responsible for that processing.

Data we process

We process account and preference data, including your email address, language, time zone, communication choices, versioned product-analytics and session-research choices, session-research eligibility, and access or subscription status.

If you give Avrelius a preferred name, we store it encrypted and use it only so the counselor can address you. It is never used to judge you or to describe you in your portrait. You can change or remove it at any time in Settings, and Avrelius works without one.

To open an account you confirm that you are at least 18 years old. We record that confirmation, the moment you gave it, and the version of the statement you agreed to. We do not collect your date of birth and do not ask for an identity document.

Avrelius content includes your text and voice notes, transcripts, onboarding answers, counselor chats, decisions and outcomes, and the observations, links, portrait, and digests generated from that material.

We also process technical data needed to operate, understand, and protect the service, such as session and browser-window identifiers, request times and statuses, email and notification delivery data, push-subscription endpoints, selected product actions, website visits, and error codes. If you separately allow a limited session-research recording, PostHog receives masked screen structure and interactions for an eligible research session. Our application logs, product events, and replay controls do not intentionally contain the text of your notes or chats.

If you join the waitlist, we receive your email address and, if you choose to provide it, a short description of a decision you are facing.

Feedback you send from the app — a rating of a generated text or a written note — is stored with your account and read by the Avrelius team to improve the product. It is exported and deleted with the rest of your data.

Why we use data

We use data to create and maintain your account; receive and process entries; build your digital portrait; provide chat, decision follow-ups, and digests; deliver communications you select; protect the service; provide exports; and carry out deletion requests.

We process this data to perform these Terms and respond to your requests. We use waitlist data to manage beta access, tell you when Avrelius launches, and understand who we are building for. Limited analytics helps us understand how the website and product operate. We may also process data to secure the service, prevent abuse, and comply with law. Where consent is required, you may withdraw it at any time.

Voice and sensitive information

Raw audio from a saved voice note is deleted seven days after processing finishes, whether processing succeeds or fails. Its transcript remains part of the entry until you delete your account. Avrelius does not store short audio clips used only to dictate text.

Your saved entry is kept exactly as you wrote it. The quoted text in each extracted observation points at that entry and may differ from it only in case, word form, and where the quote begins and ends. Medical, genetic, diagnostic, medication, clinical, and other vocabulary does not by itself suppress an observation. Avrelius does not add a diagnosis or other fact that your entry does not state.

Service providers

We use a limited set of providers to run Avrelius:

Avrelius sends entry text and derived context directly to OpenAI to generate memory statements and the knowledge graph. OpenAI does not train its models on API data by default. OpenAI may retain abuse-monitoring logs for up to 30 days. Avrelius sends store=false for these requests, but does not claim Zero Data Retention.

OpenRouter routes text for other selected language features. OpenAI also transcribes voice notes and creates technical text embeddings used to search your records.

Resend delivers login codes, digests, export links, invitations, and other service emails. Email data may be processed in the United States. Resend also reports each email's delivery state, such as delivered, failed, or bounced, and we keep that state in our service records. When we email you an invitation to Avrelius, its link leads through our server, and we record the moment the link is first opened.

Telegram delivers waitlist submissions to the Avrelius team. If you choose to link Telegram to your account, it also carries your text or voice entries to Avrelius and delivers responses.

If you enable push notifications, your browser or operating system's push service participates in delivery.

PostHog's European Union cloud provides cookieless website analytics, product analytics, scrubbed application error reports, and a technically available but inactive targeted session-research recorder. Website events do not use an account UUID or create a person profile. Website analytics reads your internet address and browser identifier to derive a daily-changing identifier and an approximate location. Neither the address nor the browser identifier is stored with the event, and the identifier does not carry over to the next day. Product events use your account UUID only after you give a current product-analytics permission and every service control passes. They may include a closed screen name, session and browser-window identifiers, locale, device layout, action status, and bounded counts. They do not include your notes, chats, email address, request bodies, headers, cookies, query strings, or dynamic route identifiers. Application logs record what the server did: the severity level, a short technical message, the component, an error code, a request identifier, a duration, and your account UUID. They are not meant to carry your notes, chats, or email address, and an automatic filter shortens web addresses to the site name and removes access tokens before a log record leaves our servers.

Session research is a separate optional choice. It is available only to a manually selected group of at most 20 accounts and remains inactive until legal, access, retention, and technical checks are complete. If activated and you allow it, the recorder masks every text node and input, blocks regions that display your material, removes dynamic route identifiers, and excludes audio, console logs, request headers and bodies, streamed network content, canvas, performance capture, and cross-origin frames. Identity, Settings, export, deletion, legal, payment, administration, malformed, and unknown routes are never recorded. Authorized reviewers may review the masked recording and use automated analysis to support that review. First-sprint recordings are retained for 14 days.

You can withdraw either analytics permission in Settings. Withdrawal closes the corresponding browser capture before the request is sent and stops new product events or recordings for your account. It does not stop scrubbed error reports, which use fixed anonymous service identities and do not contain your account UUID. It does not stop application logs, which do contain your account UUID. It also does not affect cookieless website analytics. PostHog keeps application logs for 14 days and then they expire. Deleting your account does not remove those logs sooner, because that log store has no per-person deletion.

Avrelius hosts its primary database, files, and application server in Switzerland: the primary infrastructure in Zurich, the backup infrastructure in Geneva.

International processing and payments

Persistent user data is stored in Switzerland, which the European Commission recognizes as providing an adequate level of protection for personal data transferred from the EU. Data needed for specific tasks is transferred to providers outside Switzerland, including in the European Union and the United States, under applicable contractual or other lawful safeguards. For users in Russia, this means that foreign cloud services process some data.

Avrelius accepts no payments and collects no payment details during the closed beta. Before payments are enabled, we will identify the payment provider in this notice and publish updated payment terms.

How long we keep data

We keep account data and Avrelius content while you use the service or for as long as needed to provide it. Your preferred name, versioned analytics choices and their history, session-research eligibility, and age-confirmation record are kept while the account exists. Operational records, login codes, sessions, and temporary files have shorter retention periods based on their purpose. A prepared export and its download link expire after 72 hours. First-sprint session-research recordings, if later activated with all required controls, are retained in PostHog for 14 days. PostHog applies its own retention period to product analytics and error events.

We keep a waitlist submission only while needed to manage the beta and launch, unless you ask us to delete it sooner. Legally required retention applies only where the law requires it.

Your rights and deletion

From Settings, you can update account preferences, review or withdraw each analytics permission, export your entries and digital-portrait data, or delete your account. An export includes your preferred name, both analytics-consent histories, current session-research eligibility, and age-confirmation record. A deletion request deactivates the account immediately. You may email hello@avrelius.com within seven days to cancel deletion. After that period, local account data, entries, portrait data, preferred name, consent history, eligibility, age-confirmation record, stored audio, and related files are permanently erased. Avrelius then requests deletion of the UUID-linked PostHog person, events, and recordings. This provider deletion runs asynchronously and is retried until PostHog reports completion for events and recordings. Fixed-identity error reports, application logs, and cookieless website events cannot be linked to your account for deletion.

Depending on applicable law, you may also request access, correction, restriction, or portability; object to processing; withdraw consent; and complain to a data-protection authority. To exercise a right, email us from the address associated with your account.

No ads or sale of data

Avrelius has no advertising. We do not sell personal data or use your entries to train third-party models. Limited analytics is used only to understand how the website and product operate. Service emails and notifications support features you select; waitlist messages relate to your waitlist request.

Security, changes, and contact

User data is scoped to each account at the application layer, with database row-level access policies as defense in depth. We use reasonable organizational and technical safeguards, but no internet service can guarantee absolute security.

We may update this notice as the product changes and will provide reasonable notice of material changes. For questions, rights requests, or complaints, email hello@avrelius.com. Avrelius is operated by Avrelia Inc. (in formation).

Terms of Service