Privacy Policy
AVYA · Last updated: 23 September 2026 · Effective: 23 September 2026
AVYA is a relationship intelligence platform that helps you organize, search, and act on your personal and professional network. This policy explains what we collect, why, and the control you keep over it.
01. Who we are
AVYA ("AVYA", "we", "us") is a beta-stage product acting as the data controller responsible for the personal information described in this policy. AVYA is currently in beta and is not yet operated by a registered company.
- Website: joinavya.com
- Contact (general and privacy requests): info@joinavya.com
For the purposes of the EU General Data Protection Regulation (GDPR), the operator of AVYA is the data controller for personal data processed through the Service.
02. Definitions
- Service — the AVYA website at joinavya.com, the AVYA application, and any affiliated software we operate.
- Personal Data — information about a living individual who can be identified from that information, alone or combined with other information we hold.
- Usage Data — information collected automatically through use of the Service or generated by its infrastructure (for example, the duration of a session).
- Aggregated / Anonymized Data — information processed so that no individual can be identified, directly or indirectly. This is not Personal Data.
- Cookies — small files placed on your device.
- Data Controller — the party that determines the purposes and means of processing personal data. For your account data, AVYA is the controller.
- Data Processor / Subprocessor — a party that processes data on behalf of the controller.
- User — the individual using the Service.
03. Information we collect
Information you provide
Waitlist. If you join our waitlist before creating an account, we collect only your email address. We use it to send you occasional, relevant updates about AVYA, including launch information. We do not import your contacts, connect any services, or process any other data until you create an account. You can unsubscribe or request deletion at any time by contacting info@joinavya.com.
- Name and email address
- Profile and onboarding information (including details about you and your goals provided during onboarding)
- Notes, tags, and Spaces you create
- Relationship information you manually enter about people in your network
Information imported from connected services — only when you explicitly connect a service and grant permission:
- Google — your Google account profile; Google Contacts, Google Calendar events, and Gmail information, each only if you connect that specific service.
- LinkedIn — your profile information and the contacts or connection information you choose to import.
- Apple Contacts — the contacts you choose to import from your device.
Where you connect an account using OAuth, we use that protocol so you can authorize access without exposing your third-party password to us. Connecting any external service is optional and is not required to use AVYA.
Information from invitations and other users — When you invite someone to AVYA, you provide contact information so we can send the invitation. We may also receive limited information about you from another user — for example, if they invite you or add you to their network.
Usage Data — We collect information your browser or device sends when you use the Service. This may include your IP address, browser type and version, the pages or screens you visit, the time and date of your visit, time spent, and diagnostic data. On mobile, it may include your device type, operating system, mobile device identifiers, and similar diagnostics.
04. How we use information
We use information to operate, maintain, and improve the Service — specifically to:
- Build a searchable relationship database for you
- Surface relevant people and context about your relationships
- Generate insights, summaries, reminders, and recommendations
- Suggest introductions you may want to make
- Power AI-assisted search and discovery
- Provide customer support and respond to your requests
- Monitor usage, detect and prevent abuse, and address technical issues
- Develop, test, and improve current and future features of the Service
- Send service and account notices, and — only with your consent — occasional product updates you can opt out of at any time
Contacts and relationship information are used solely to provide functionality, insights, recommendations, and search results to the user who uploaded or connected that information.
Where we analyze your Personal Data specifically to improve and develop the Service, we do so only with your consent, which you give when you opt in and may withdraw at any time. Withdrawing consent does not affect processing necessary to provide the Service to you.
Our legal bases under the GDPR are: performance of our contract with you (providing the Service); your consent (for connecting third-party services, optional communications, and product-improvement analysis of Personal Data); and our legitimate interests (securing the Service and preventing abuse).
05. Ownership of uploaded data
You may only upload, import, or connect contact and personal information that you lawfully possess and are authorized to use. You are responsible for ensuring that any contact information you add to AVYA belongs to your own network and was obtained in accordance with applicable laws.
With respect to the personal data of third parties that you import, you act as the controller and AVYA processes that data on your behalf to deliver the Service to you.
06. Privacy of searches and insights
AVYA is designed for private relationship management. Contact records, searches, relationship insights, notes, and recommendations are visible only to the account owner unless that user explicitly chooses to share them. Information you import or upload is never made searchable, accessible, or visible to other users.
Individual searches you perform within AVYA are private to your account.
07. AI processing
AVYA may use automated systems, including artificial intelligence and machine learning technologies, to analyze information you provide in order to generate recommendations, relationship insights, summaries, reminders, and search results.
We do not use your contacts, the content of connected Google services, or your relationship data to train generalized or third-party AI models, and we do not sell personal information to third parties.
07a. Aggregated and anonymized insights
We may create aggregated and anonymized data from use of the Service — for example, statistical trends, usage patterns, and benchmarks that do not identify any individual. Because this data is not Personal Data, we may use, retain, share, publish, and commercialize it for any purpose, including improving the Service, research, and reporting.
Aggregation and anonymization are applied so that no individual — and no contact, message, or relationship — can be identified, directly or indirectly. We never sell or commercialize your contacts, your relationship records, or any other Personal Data; only data that has been irreversibly anonymized may be used in this way. This does not apply to data received through Google APIs, which is governed by Section 09.
08. AI assistant integration (MCP)
If you connect AVYA to a supported AI assistant (such as ChatGPT or Claude) through the Model Context Protocol (MCP), categories of your stored AVYA data — such as contact names and details, notes and interaction history, reminders, tags, and custom fields — may be shared with that assistant at your request.
Data is shared only when you explicitly invoke a query or action through the AI assistant. The assistant has no passive or background access to your account. Your use of any AI assistant integration is also subject to that provider's own terms and privacy policy.
09. Google API disclosures
If you connect Google services, AVYA may access information from Google Contacts, Google Calendar, and Gmail solely to provide the functionality you have requested. AVYA requests read access to Gmail (gmail.readonly) to extract relationship-relevant signals — such as who you correspond with, when you last interacted, and contextual details about how you know each person — and to identify and import new contacts and their profile images into your private database.
What we store: AVYA does not store the raw content or full message bodies of your emails. We process messages to extract a limited set of derived fields (for example: contact name, contact email, interaction dates, and short relationship context). Only these extracted fields are retained; the underlying email content is not saved.
AVYA's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we only use Google user data to provide and improve the user-facing features of AVYA; we do not use it for advertising; we do not sell it; we do not transfer it except as needed to provide those features, comply with law, or as part of a merger or acquisition with adequate notice; we do not use Google user data to create aggregated or anonymized commercial datasets; and we do not use Google user data to train, develop, or improve generalized AI or machine-learning models. Humans do not read your Google data except where you give explicit consent for specific items, where required for security or to comply with law, or in aggregated and anonymized form for internal operations only. Providing Google or Gmail data is not required to use the Service.
You can revoke AVYA's access to your Google account at any time via your Google account permissions page.
10. Integrated account data
We retain integrated account data and credentials you provide, on an opt-in basis, only to deliver syncing functionality across the platforms you connect. Where you grant access to an external source, AVYA uses that access only to read the data needed for the features you use. We do not allow humans to access these credentials except with your affirmative consent (for example, when you request support), where necessary for security such as investigating abuse, to comply with law, or for internal operations and then only in aggregated and anonymized form. Providing integrated account data is not required to use the Service.
11. Calendar actions
AVYA may create, modify, delete, or send invitations for calendar events only when you explicitly authorize each such action. AVYA does not alter your calendar without your express instruction.
12. Contacts are never modified
AVYA does not modify, delete, or overwrite contacts stored in Apple Contacts, Google Contacts, LinkedIn, Gmail, or any other external source. Imported contact data is read into your private AVYA account; your original contact sources are left unchanged.
13. Cookies and tracking
We use cookies and similar technologies to operate, secure, and analyze the Service. You can set your browser to refuse cookies or to alert you when one is sent, but some parts of the Service may not function without them. The types we use:
- Session cookies — to operate the Service.
- Preference cookies — to remember your settings.
- Security cookies — for security purposes.
- Analytics cookies — to understand how the Service is used so we can improve it.
We do not use advertising cookies and we do not allow third-party advertising networks to track you through AVYA.
14. Data sharing
We do not sell your personal data. AVYA does not sell your personal information, contact information, or relationship data, and does not use it for third-party advertising.
Aggregated and anonymized data. As described in Section 07a, we may share, publish, or commercialize aggregated and anonymized data that does not identify any individual. This is not Personal Data.
When we may share Personal Data:
- Subprocessors — vetted providers acting under contract on our behalf (see below).
- Legal requirements — where required by law or in response to valid requests by public authorities.
- Business transfer — if AVYA is involved in a merger, acquisition, or asset sale, with notice to you.
15. Subprocessors
We share data only as necessary to operate the Service, with providers acting under contract on our behalf:
| Provider | Purpose | Privacy policy |
|---|---|---|
| Supabase | Database hosting and storage (data processor) | supabase.com/privacy |
| Lovable | Application build and hosting | lovable.dev/privacy |
| Google LLC | Authentication, Gmail/Calendar/Contacts access (with consent), and analytics (Google Analytics 4, measurement ID G-V5MRHTQX0E) | policies.google.com/privacy |
As AVYA moves out of beta we will update this list. To request the current list at any time, email info@joinavya.com.
16. International transfers
Some providers may process data outside the European Economic Area, including in the United States. Where they do, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, so that your data receives a level of protection consistent with EU law. We do not rely on the EU-U.S. Privacy Shield, which is no longer a valid transfer mechanism.
17. Data retention
We retain account data for as long as your account is active and as needed to provide the Service. Google-derived fields are retained only as long as needed to provide the Service. We retain Usage Data for a shorter period, except where it is used to strengthen security or improve functionality, or where we are legally required to keep it longer. Aggregated and anonymized data, which does not identify you, may be retained indefinitely. You may request deletion of your account at any time. Upon deletion or revocation of Google access, AVYA will delete or anonymize the associated personal information within a reasonable period — some information may remain in archived backups for up to one month — except where retention is required by law.
18. Your rights (GDPR)
If you are in the European Economic Area, you have the right to: access the personal data we hold about you; correct inaccurate data; request deletion ("right to be forgotten"); receive your data in a portable format; object to certain processing; request restriction of processing; and withdraw consent at any time.
To exercise any of these rights, email info@joinavya.com. You also have the right to lodge a complaint with your local supervisory authority — in Spain, the Agencia Española de Protección de Datos (AEPD), www.aepd.es.
19. Changing or deleting your data
You can access and update the personal information on your account in the app's settings, or by contacting info@joinavya.com. If you signed up through a third-party account, you may also need to update information held by that provider. To delete your account and associated data, use the deletion option in your account settings or email info@joinavya.com. We will act on your request as soon as practicable, subject to the retention limits described above.
20. Security
AVYA is built and deployed using Lovable and is served over encrypted HTTPS/TLS connections. Your data is stored in a managed cloud database provided by Supabase, which acts as a data processor on our behalf. Our security measures include:
- Encryption in transit — all connections between your device, the application, and the database use TLS encryption.
- Encryption at rest — data stored in the database is encrypted at rest at the infrastructure level.
- Access isolation — database-level Row-Level Security restricts each user's data so it is accessible only to that user's authenticated account.
- Credential protection — privileged database credentials and OAuth tokens are held server-side only and are never exposed in the client application.
- Certified infrastructure — our database provider, Supabase, maintains SOC 2 Type II compliance.
Like other relationship-intelligence and CRM platforms, AVYA does not use end-to-end encryption. This is a deliberate design choice: AVYA's features — search, enrichment, insights, briefings, and reminders — require our systems to process your data on your behalf, which is not possible under end-to-end encryption. Your data is instead protected by the measures above.
No method of transmission or storage is completely secure, but we take reasonable measures to protect your information consistent with the sensitivity of the data and the early-stage nature of the Service. As AVYA moves toward general availability we continue to strengthen our security and data-governance practices, including logging and monitoring of access to personal data.
21. Links to other sites
The Service may contain links to sites we do not operate. We are not responsible for the content or privacy practices of those sites, and we encourage you to review their policies before sharing information.
22. Children
AVYA is not directed to children under 16 and we do not knowingly collect their personal data. If you believe a child has provided us with data, contact info@joinavya.com and we will delete it.
23. Changes to this policy
We may update this policy from time to time. We will revise the "Last updated" date above and, for material changes, notify you through the Service or by email before the change takes effect.
24. Contact us
Privacy questions or requests: info@joinavya.com