Privacy Policy · beta-2026-09-02
Aevia Beta Privacy Policy
BETA DRAFT — requires legal review before broad commercial launch.
This policy explains the information the closed beta may process, why it is used, and the controls that exist today.
1. Information Aevia may process
- Account and profile details, including name, email, time zone, and beta acceptance.
- Household members, roles, preferences, language, routines, schedules, and communication endpoints.
- Food preferences, allergies, dietary rules, meal plans, nutrition estimates, cooking-person setup, inventory, and shopping-needed items.
- Senior and medication context supplied by users. Uploaded medical documents are not part of the current M5 product.
- WhatsApp or development-transport messages, replies, reactions, delivery state, and provider identifiers.
- Agent runs, ordered steps, corrections, feedback, exceptions, and operator-review information.
- Privacy-safe product usage events such as landing views, onboarding progress, activation, and task outcomes.
2. Why this information is used
Aevia uses information for personalization, scheduling, task execution, communication, memory and context, safety and exception handling, debugging, user support, evaluation, beta improvement, and product analytics.
3. Source and certainty
Aevia should distinguish user-provided facts, another person’s self-report, extracted candidate information, and agent inference. A self-report is not independent verification. An estimate is not professional advice.
4. Service providers
The current product uses Convex for application data/runtime and can use messaging providers behind a replaceable transport layer. Development transport remains available. Twilio is retained as a fallback adapter, and Meta WhatsApp Cloud API is the current real test provider. Provider services process data under their own terms and policies.
5. Beta operator access
Authorized Aevia operators may need controlled access for debugging, exception resolution, safety review, support, evaluation, and product improvement. Operator tools should mask sensitive fields by default and require deliberate reveal where that control is implemented. M5 adds a household-scoped run viewer; a complete access-controlled admin system is not yet built.
6. Analytics limits
Product analytics must not receive phone numbers, medicine names, raw WhatsApp text, prescription content, secrets, or unnecessary personal information. M5 records allowlisted, pseudonymous product events. A third-party product analytics service is not configured in this milestone.
7. User controls
Where currently supported, you can review setup, correct active context, update preferences, and pause or change routines. Full self-serve export, account deletion, and rich memory history controls are not yet implemented; do not rely on them until they appear in the product.
8. Third-party information
Only provide another person’s information when appropriate, and introduce Aevia before automated messages begin. A parent, senior, cooking person, or family member should not receive surprise recurring messages.
9. Medical documents
Prescription image/PDF extraction is not implemented in M5. Formal production privacy and regulatory handling for future medical-document ingestion remains open and requires review before launch.
10. Security and retention
Aevia uses application ownership checks and provider webhook validation in the current beta. No system is perfectly secure. We do not claim encryption, retention, deletion, or compliance guarantees beyond what is actually implemented. Beta data may be retained while needed for the purposes above and handled through operator-supported requests.
Hello Aevia