Privacy policy
What we collect, why we use it, who receives it, and the choices and rights you have under the GDPR.
Last updated 28 September 2026
This policy applies to the Avioverse websites, applications, browser extension, integrations and support channels (together, the Service). It is written for the individual aviation professionals who use the Service, the people invited to a shared workspace or response form, and visitors to our public website.
1. Who is responsible for your data
Avioverse Ltd is the controller for account administration, product operation, billing, security, support, product communications and our public website. If you use Avioverse for another organisation, that organisation may be a separate controller for the material it asks you to handle. You should follow its policies and only upload material you are authorised to use.
2. Personal data we process
Account and identity data
Your name, email address, password hash or sign-in-provider identifiers, account status, authentication records, preferences, workspace memberships, roles and invitation data. We do not receive your password from Google or Microsoft when you use their sign-in.
Content and professional data
Information you create, upload or share, such as chats, Brain content, tasks, procedures, forms, audit material, findings, records, certificates, files, comments and professional profile information contained in those materials. Content may include personal data about other people. You are responsible for having a lawful basis and appropriate authority to provide it.
Avioverse is not designed to infer sensitive traits. If you choose to include health, union, biometric or other special-category data in your content, only do so where it is necessary, authorised and supported by a valid legal condition. We use it only to provide the feature you request, not to profile you from those traits.
AI interaction data
Prompts, conversation history, selected regulatory scope, uploaded documents, tool calls, model output, feedback, safety-filter events and the context needed to produce and meter a response. Depending on your plan and settings, the assistant may also retrieve relevant material from your Avioverse Brain or recent conversations.
Billing and transaction data
Your plan, subscription status, usage balances and purchase history, invoice identifiers, billing country and limited payment metadata. Stripe processes complete payment-card details; we do not store your full card number or security code. When you cancel or withdraw from a contract, we keep what you submitted (including the name and email address you gave), when we received it and what we did, so we can confirm it and prove it later.
Usage, device and security data
IP address, browser and device information, timestamps, pages or features used, request identifiers, diagnostic logs, rate-limit events and security signals. We also store cookie choices and strictly necessary session information. See our cookie policy.
Communications and connected services
Messages you send to support, privacy, security or billing; email delivery events; and the identifiers and content needed when you choose to connect a channel such as Telegram or a supported third-party service. A connected service also processes data under its own terms and privacy notice.
Early-access list
Before Avioverse opens, you can leave your email address to hear when it does. We keep the address, the app you asked about, the page and site you sent it from (avioverse.io, or aviocube.com, which Avioverse Ltd also runs, and which writes to the same list) and the time. We use it only to email you when that app opens, never for other marketing. We delete an app's entries once its opening email has gone out, and yours at once if you ask at privacy@avioverse.io. The list is stored with Cloudflare in the European Union.
3. Where data comes from
Most data comes directly from you. We may also receive data from:
- Google or Microsoft when you choose federated sign-in;
- Stripe in connection with a payment, refund or subscription event;
- a teammate, tracker manager or auditor who invites you or identifies you in shared work;
- a connected service you authorise, within the permissions you grant;
- public authorities and official sources used to build the aviation reference library; and
- your browser or device when you use the Service.
4. Why we use data and our legal bases
- Provide the Service — contract
- Create and secure your account; save, retrieve and share your work; run the features you request; provide support; meter usage; and administer subscriptions.
- Keep Avioverse safe and reliable — legitimate interests
- Prevent abuse and fraud, investigate failures, protect accounts, monitor availability, enforce our terms and improve performance. We balance these interests against your rights and use proportionate data.
- Comply with law — legal obligation
- Keep, or have our payment processor keep, required accounting and transaction records; answer lawful requests, handle data rights and meet security, consumer-protection and regulatory duties.
- Optional analytics and marketing — consent
- We use optional cookies or send promotional email only after the required consent. Joining the early-access list is consent to one email when the app opens. Turning on "Product news and updates" in your account settings is consent to occasional emails about new features, regulation updates, roadmap milestones and offers — for example a discount if you come back after cancelling; each one has an unsubscribe link. You can withdraw consent at any time without affecting earlier lawful processing.
- Protect vital interests or establish legal claims
- Only where the circumstances genuinely require it, such as responding to a serious security incident or preserving evidence for a legal claim.
If data is required to create an account, provide a requested feature or take payment, choosing not to provide it may mean we cannot supply that part of the Service.
5. AI and automated processing
AI features are user-invoked assistance. Relevant prompts, documents and context are sent to model or document-processing providers to produce the requested output. Provider choice may vary by task. We require providers to process the data for delivering the service to us, not to train their general models on your content. Avioverse does not use your data to train AI models.
AI output can be wrong and must be reviewed. Avioverse does not use AI to make decisions about you that produce legal or similarly significant effects. AI does not determine your employment, licence, regulatory compliance, airworthiness status or entitlement to a safety approval. Learn more in our AI transparency statement.
6. Who receives data
We disclose data only as needed to:
- service providers that operate parts of the Service for us under a contract, listed below;
- people you choose to share with, including members of your Teams, invited guests and recipients of protected share links;
- professional advisers and authorities where reasonably necessary to obtain advice, protect rights, investigate abuse or comply with law; and
- a successor operator in a merger, financing, reorganisation or sale, subject to appropriate confidentiality and notice where required.
We do not sell personal data and do not share it for cross-context behavioural advertising.
Service providers
AI providers receive only the prompts, documents and context needed for the request you make, and the model used can vary by task and response mode.
| Provider | Purpose | Data involved | Processing location |
|---|---|---|---|
| Hetzner Online | Servers, database, file storage and backups | All account, workspace and file data | European Union (Germany or Finland; exact data centre to be confirmed) |
| Cloudflare | Domain name service, secure network entry to the Service, rendering documents you export as PDF, and storing the early-access list | Traffic passing to and from the Service; the content of a document you export; early-access email addresses | Global network, early-access list stored in the EU; United States company |
| Stripe | Payments, subscriptions, invoices and tax calculation | Name, email, billing address, payment details and transaction history | Ireland and the United States |
| Resend | Service email: sign-in codes, invitations, notifications and account notices | Email address, name and the content of the message | United States (sending region to be confirmed) |
| DeepSeek | AI answers in the Fast response mode, and document extraction and drafting | Prompts, documents and context sent with the request | People's Republic of China |
| OpenAI | AI answers in the Standard, Deep and Max response modes, and answer checking | Prompts, documents and context sent with the request | United States |
| Anthropic | AI answers when another model is unavailable, and checking answers against their sources | Prompts, documents and context sent with the request | United States |
| Google (Gemini API) | Reading scanned documents (OCR) and AI answers when another model is unavailable | Documents and prompts sent with the request | United States |
| Mistral AI | Reading scanned documents when the primary reader fails, transcribing Telegram voice notes, and AI answers when another model is unavailable | Documents, audio and prompts sent with the request | France (European Union) |
| OpenRouter | Routing coding and tool-execution helper tasks to a third-party model (GLM) | The task instructions and data passed to the helper | United States; the model host's location to be confirmed |
| Voyage AI | Search indexing and ranking of your saved content and your questions | Text of your content and queries | United States |
| Tavily | Live web search when the assistant searches the web for you | Search queries written from your request | Location to be confirmed |
| Daytona | Isolated sandboxes that run code the assistant writes to analyse your data | The files and data you ask it to analyse | Location to be confirmed |
| Google Analytics | Visit measurement on the public website only, after you consent | Browser, device and page-journey data (never your account identity) | United States |
| Microsoft Clarity | Heatmaps and session replays of the public website only, after you consent | Clicks, scrolling and page views, with everything typed masked (never your account identity) | United States |
When you create a password, only a five-character fragment of its hash is checked against the Have I Been Pwned breach list; the password itself never leaves our servers.
Services you choose to connect
If you sign in with Google or Microsoft, that provider confirms your identity to us. If you connect Telegram, the messages and voice notes you exchange with the assistant pass through Telegram. These services act under their own terms and privacy notices; we receive only what is needed for the feature you use.
7. International transfers
As the list above shows, some service providers process data outside the European Economic Area. Where the destination is not covered by an EU adequacy decision, we use an available lawful transfer mechanism, such as the European Commission's Standard Contractual Clauses, together with supplementary safeguards where appropriate. You may ask us for information about the safeguard relevant to your data.
8. Deleting your account
You can delete your account yourself in Settings → Account. The request starts a 30-day window before anything is erased:
- You can still sign in and read everything, download your files and use Download my data. You cannot create or change content during the window, and scheduled assistant tasks are paused.
- You can restore the account at any time during the window and continue as before.
- A renewing subscription stops renewing at the time of the request. Paid access continues until the end of the period already paid for; payments already made are not refunded, as described in our Terms. If you restore the account and we stopped the renewal, the renewal resumes. Any subscription still active when erasure happens is cancelled then.
- We email you when deletion is scheduled, if it is cancelled, and when erasure is complete.
Teams you own. At the end of the window, ownership of each Team you own passes to a remaining active member (an administrator before a member, then the longest-standing member). Its members are told in advance who is expected to take over, and the new owner is told when the handover happens. A Team with no other eligible member is erased with your account.
What is erased. Your account and profile, your Personal workspace with all its records and files, any Team erased with your account, your Brain, assistant conversations and memory, certifications, preferences, linked sign-in methods and tokens, any connected Telegram link, the usage and billing history held inside Avioverse, and invitations addressed to your email.
What remains.
- Records you contributed to a Team that continues — such as tasks, forms, audits, risk records and evidence — stay with that Team and remain attributed to you by the name shown at the time. The Team, not the departing member, is the keeper of those records. We rely on our and the Team's legitimate interest in the integrity of shared aviation records.
- Notifications in other members' accounts that mention you expire on their normal schedule, within 90 days.
- A minimal deletion log — an internal account number, the date, the reason recorded and the country — with no name, email address or content, kept to show that the erasure took place.
- Stripe, our payment processor, keeps your customer and invoice records for the period required by tax and accounting law. We do not delete those statutory billing records.
If you later sign up again with the same email address, you receive a new, empty account. Nothing from the erased account is linked to it.
9. How long we keep data
- Account and workspace content: while your account exists, then as described in section 8.
- Shared Team work: for as long as the Team keeps it, including after you leave the Team or delete your account.
- Billing records: kept by Stripe for the statutory period required by tax and accounting law.
- Cancellation and withdrawal records: after your account is erased, kept only as statistics, without your name, email address or payment identifiers.
- Security and diagnostic logs: for a limited period based on security, fraud-prevention and troubleshooting needs, then deleted or aggregated.
- Backups: we keep one daily backup, replaced by the next one, so erased data leaves our backups within about 24 hours (48 hours if a backup run fails). Backups are used only to recover the Service after a failure. If we ever restore one, any account erased after that backup was taken is erased again automatically.
10. Security
We use access controls, encryption in transit, restricted administrative access, per-user storage boundaries, signed file access, rate limiting, security logging and tested erasure procedures. No online service can promise absolute security. If you believe your account or data is at risk, contact security@avioverse.io.
11. Your GDPR rights
Depending on the circumstances, you can ask for access, correction, erasure, restriction or portability of your personal data; object to processing based on legitimate interests; and withdraw consent. You also have the right not to be subject to solely automated decisions with legal or similarly significant effects. Some rights have legal exceptions, including where retention is required by law or affects the rights of others.
You can exercise the rights of access and portability yourself with Download my data in Settings → Account, which gives you a machine-readable (JSON) copy of your account data, and the right to erasure with the account deletion described in section 8. You can also email privacy@avioverse.io. We may need to verify your identity. You may complain to the supervisory authority where you live or work, or where an alleged infringement occurred. In Cyprus, this is the Office of the Commissioner for Personal Data Protection.
12. Children
Avioverse is designed for aviation professionals and is not directed to children. You must be at least 18 to create an account. Contact us if you believe a child has provided personal data without appropriate authorisation.
13. Changes and contact
We may update this policy when the Service, our providers or the law changes. We will post the new version here and give additional notice where a change materially affects your rights or how we use data. Questions and rights requests should be sent to privacy@avioverse.io.