Privacy policy
What Anvyll processes, where it lives, and the rights you have over it.
Engineering draft — not legal advice; requires review by qualified counsel before publication.
Derived from data map. If this policy and the schema disagree, the schema wins until counsel updates both.
Who we are
Anvyll is a Windows desktop application that refines prompts for large language models. The operator of the service is the Anvyll publisher (contact via https://anvyll.app/support).
What we process
- On your device: prompts, history, sessions, projects, and related product data in an encrypted local vault. Device preferences (hotkey, theme) in a separate local file.
- On our servers (Supabase): account profile (email, display name), subscription status, credit ledger, usage meters (token counts — not prompt text), and limited anti-abuse fingerprints.
- Payment (Stripe): billing identity, payment methods, invoices, and tax data. Stripe is merchant of record.
- AI provider (OpenAI): prompt and context text in transit for refinement, via our hosted proxy (Railway).
- Sign-in (Google and/or email): identity claims needed to create and secure your account.
Why we process it
To provide the service you request (contract), to meter free credits and subscriptions, to prevent abuse of free and trial offers, to meet tax/invoicing duties, to operate and diagnose our own infrastructure (server-side error reporting with pseudonymous references — not gated by the in-app telemetry checkbox), and — only if you opt in — to collect basic client reliability signals via the telemetry setting.
Retention
See the data map. Highlights: usage events 13 months then aggregated; Stripe webhook payloads 30 days; abuse fingerprints up to 12 months after account deletion; Stripe invoices for the statutory period (accountant-owned).
Your rights (EEA/UK)
Access, rectification, erasure, restriction, portability, and objection where applicable. In the app: Settings → Privacy & data for export and deletion. Deletion cancels Stripe subscriptions immediately; invoices remain with Stripe as legally required. Contact support for other requests.
Sharing
Subprocessors are listed in subprocessor list (Supabase, Railway, OpenAI, Stripe, Google, Sentry). We do not sell personal data.
International transfers
See EU residency notes. Prefer EU hosting; where processors are outside the EEA, transfers rely on appropriate safeguards (e.g. SCCs) once counsel confirms.
Contact
Bug reports
When you choose Report a bug, Anvyll sends the description and screenshots you review to our private support service, linked to your account. We process requested support reports under documented legitimate interests in investigating product faults. Reports are not sent to AI providers for analysis and are not used for training.
A separate, unchecked choice allows a technical diagnostic summary for that report. It contains app/system versions, capture outcomes, timings, backend status/error codes and request references. It excludes prompt text, clipboard text, vault data, window titles, paths, credentials and request/response bodies. This consent is independent of the telemetry preference. You can report an issue without diagnostics.
Descriptions and screenshots are retained for up to 90 days; diagnostics for up to 30 days. You can review/export your reports, remove diagnostics or delete a report in Help → My reports. Account deletion also removes reports and queues screenshot deletion. Access is blocked immediately on deletion; active-storage cleanup retries complete within the operational 24-hour target. Backup erasure is subject to the verified processor schedule, with a launch requirement of at most 30 days; the operator must confirm this schedule before publishing the policy.
Unsent descriptions and screenshots stay in memory only and are discarded when you close the form, change accounts or exit Anvyll; no report draft is saved on your device. Repeated capture failures may cause a local suggestion; this sends nothing automatically. Disable suggestions in Settings → Data and Privacy. Only manually selected screenshots are attached; descriptions and screenshots may contain personal data, so review and redact them before sending. Authorized support staff can read submitted reports. Contact support@anvyll.app to exercise applicable data rights.