Ovyaro AI · Effective August 8, 2026
Privacy Policy
This policy explains Ovyaro's data boundaries, AI processing, user controls and security responsibilities.
01
Data we process
- •Account and authentication data such as email, user ID, session and MFA assurance.
- •Content you choose to provide, including chats, files, memories, prompts and generated media requests.
- •An optional Self Voice sample is processed only after explicit own-voice consent. Ovyaro does not persist the raw sample in its database; the configured voice provider receives it to create and retain the deletable synthetic profile.
- •Subscription, usage and transaction references. Ovyaro does not store complete payment-card details.
- •Security and reliability data such as request IDs, salted fingerprints, audit events, provider usage and error logs.
- •Optional connector data only after you grant permission, including calendar, email, device, social or travel information.
02
Why we use data
We process data to provide requested features, authenticate accounts, enforce plan limits, prevent abuse, recover failures, support users, meet legal obligations and improve measured reliability. We do not sell personal data or use hidden surveillance to infer sensitive traits.
03
AI providers and subprocessors
A request may be sent to the provider selected by you or by Ovyaro's governed router. Files, web results, memories and tool output are treated as untrusted context. Provider retention and regional processing depend on the configured production contracts. Sensitive or vault-backed requests can be routed to Private AI when supported.
04
Memory and user control
- •You can inspect, correct, expire or delete saved Ovyaro memories.
- •Automatic memory extraction excludes credentials, payment details and highly sensitive health, legal or financial facts.
- •Deleting a conversation or file removes active access; backup retention and legally required records may expire on a separate documented schedule.
- •Connected services can be disconnected, and stored connector tokens should be revoked and deleted through the relevant control.
05
Retention
Production retention periods must be documented by data class. Ovyaro aims to keep content only as long as needed for the requested service, security, billing, dispute handling and legal compliance. Temporary memories use their selected expiration. Provider logs and disaster-recovery backups may have separate bounded schedules.
06
Security
Ovyaro uses server-side authorization, row-level database controls, owner MFA, capability kill switches, signed webhooks, encrypted connector tokens, bounded inputs and audit trails. No system can guarantee zero risk. Users must protect their login and immediately report suspected compromise.
07
Your rights
Depending on your location, you may request access, correction, deletion, restriction, portability or objection, and may complain to a data-protection authority. Signed-in users can open the Account Privacy Center to submit or cancel a seven-day reversible deletion request. Identity verification may be required before final fulfillment. Some billing, fraud-prevention, provider or legal records cannot be deleted immediately.
08
Children and high-impact use
Ovyaro is not directed to children below the applicable digital-consent age and must not be used to make unreviewed decisions about health, employment, credit, housing, education, insurance, legal rights or public services.
09
International transfers and changes
Cloud providers may process data in other countries under their contractual safeguards. Material policy changes will be dated and communicated through the service when required.