1. Scope and operator
This Privacy Policy applies to products and services offered under the Avora name, including the Avora website, visual backend builder, marketplace, APIs, command-line interface, extensions, previews, and integrations (collectively, the “Service”).
Avora is currently an independent software project operated from Tunisia. References to “Avora,” “we,” “us,” or “our” mean the operator of Avora. The operator of Avora is responsible for the personal information described in this Policy. This Policy does not govern third-party products that have their own privacy notices.
By using the Service, you acknowledge the practices described here and in our Terms & Conditions.
2. Information we collect
Account and profile information
We may collect your username, email address, password in hashed form, profession, country, account role, subscription tier, account status, and creation or last-login timestamps. If you use Google or GitHub to sign in or connect an account, we may receive an account identifier, username, verified email address, and access token or permissions you authorize.
Prompts, projects, and other content
We collect content you submit, import, connect, create, or generate through the Service, including:
- prompts, instructions, feedback, and AI conversations;
- diagrams, nodes, edges, schemas, workflows, workspace versions, and project descriptions;
- source code, configuration, repository content, generated code, and deployment artifacts;
- images, sketches, files, URLs, Figma content, and other material you upload or import;
- environment values, database connection details, database schemas, and records you choose to connect or process; and
- public marketplace templates, descriptions, usage documentation, and related contributions.
Some of this content may contain personal information or confidential data. You control what you submit and are responsible for having the necessary rights and permissions.
Usage and technical information
We may collect IP address, browser and device information, operating system, referring page, dates and times, pages or features used, error and diagnostic data, security events, and approximate location derived from IP address. We also record AI usage details such as provider, model, token counts, endpoint, whether an image was included, response time, and associated user or workspace.
Communications
We collect information you provide when requesting support, reporting a problem, responding to a survey, or otherwise communicating with us. Avora does not currently collect payment-card information or offer paid checkout through the Service.
3. Where information comes from
We receive information:
- directly from you when you create an account or use the Service;
- automatically from your browser, device, application, CLI, or extension;
- from collaborators, workspace owners, or organizations that give you access to a project; and
- from services you connect, such as Google, GitHub, Figma, repositories, databases, and deployment platforms.
4. How we use information
We use information to:
- provide, operate, maintain, and personalize the Service;
- authenticate accounts, enable collaboration, and manage integrations;
- process prompts and generate diagrams, code, previews, explanations, and other outputs;
- train, fine-tune, test, evaluate, benchmark, and improve AI models, datasets, features, safety systems, and product quality;
- monitor usage, enforce limits, troubleshoot errors, and understand performance;
- protect accounts, investigate abuse, and prevent fraud, malware, or security incidents;
- communicate with you about the Service and respond to requests;
- comply with law, enforce our agreements, and protect our users and legal rights; and
- create aggregated or de-identified statistics, research, and product insights.
5. AI processing and training
Avora may use your prompts and submitted content to train and improve AI systems. This includes prompts, responses, code, diagrams, schemas, files, ratings, corrections, tool interactions, and associated technical context. The use may involve automated processing and limited review by authorized personnel or service providers for quality, safety, abuse prevention, and model development.
Content may also be sent to third-party AI providers to produce a requested result. Depending on the model or feature used, providers may include Google Gemini, DeepSeek, OpenRouter, Groq, Azure OpenAI, or OpenAI. Their handling of information is also governed by the applicable provider terms and the arrangements Avora has with them.
We may aggregate, filter, or de-identify content where appropriate, but we cannot guarantee that all submitted content will be anonymous. Deleting content or closing an account may not remove information already incorporated into aggregated datasets, evaluations, backups, or trained model parameters where removal is technically impracticable.
Do not submit passwords, API keys, private signing keys, health or financial records, government identifiers, children's sensitive data, trade secrets, or third-party confidential material unless the feature expressly requires it and you are authorized to provide it.
6. Legal bases
Where data-protection law requires a legal basis, we rely on one or more of the following:
- Contract: processing needed to provide the Service you request and administer your account.
- Legitimate interests: improving the Service and AI systems, maintaining security, preventing abuse, and understanding product performance, balanced against your rights.
- Consent: where we ask for permission or applicable law requires it; you may withdraw consent prospectively.
- Legal obligations: processing needed to comply with law, court orders, or valid government requests.
8. International transfers
Avora and its providers may process information in Tunisia, the European Economic Area, the United States, and other countries where they operate. These countries may have privacy laws different from those where you live. Where required, we use recognized safeguards for international transfers, such as contractual protections, adequacy decisions, or another lawful transfer mechanism.
9. Retention
We retain account information and project content while your account is active and for a reasonable period afterward to provide the Service, support recovery, resolve disputes, enforce agreements, and comply with law. Retention periods vary based on the type and sensitivity of the information, the feature involved, security needs, and legal requirements.
Short-lived previews, test snapshots, and temporary deployment artifacts may expire automatically. Logs, security records, and usage measurements may be retained separately. Backups are deleted on their normal rotation schedule. As explained above, content already included in de-identified datasets, evaluations, or trained model parameters may persist after account or project deletion.
10. Security
We use administrative, technical, and organizational measures designed to protect information against unauthorized access, loss, misuse, or alteration. No system is completely secure, and we cannot guarantee absolute security. You are responsible for protecting account credentials, limiting connected-service permissions, reviewing generated code, and promptly notifying us of suspected compromise.
12. Your rights and choices
Depending on where you live, you may have the right to request access, correction, deletion, portability, or restriction of personal information; object to certain processing; withdraw consent; or file a complaint with a data-protection authority. These rights may be limited by law and do not necessarily apply to de-identified information.
You can change some profile and integration settings within the Service. For other requests, email social.avora@gmail.com. We may need to verify your identity before completing a request. We will not discriminate against you for exercising an applicable privacy right.
13. Children and teenagers
The Service is not intended for anyone under 13. If you are between 13 and the age of legal majority where you live, a parent or legal guardian must review these terms and authorize your use where required by law. Some countries set a higher minimum age for consenting to online data processing; that higher age applies unless valid parental consent is obtained.
If you believe a child under 13 provided personal information, contact us so we can investigate and take appropriate action.
14. Third-party services
The Service may link to or integrate with third-party websites, repositories, AI providers, databases, and deployment platforms. Your use of those services is governed by their own terms and privacy policies. Review requested permissions carefully before connecting an account, and disconnect integrations you no longer use.
15. Changes and contact
We may update this Policy as the Service, law, or our practices change. We will post the revised version and update its effective date. If a change materially affects your rights, we will provide additional notice where reasonably practicable or required by law.
For privacy questions or requests, contact social.avora@gmail.com. For other legal questions, contact social.avora@gmail.com.