Privacy Policy
Last updated 4 October 2026. What Aevora collects, why, and who else sees it.
What we collect
- Account details: your name, email address and a hashed password, or your Google account identifier if you sign in with Google.
- Runs: the web addresses you test, the pages Aevora visited, screenshots of those pages, page text, console and network errors, and the findings it produced.
- Test accounts: if you save a test account or turn on agent sign-up, the login details are stored encrypted. They are only decrypted to sign in to the target app during a run and are never shown in reports.
- Feedback: your “useful / minor / wrong” ratings on findings.
- Waitlist: the email address and optional app address you give us, and your country (see below).
- Country-level visit counts: when you open our public pages we count the visit once per browser session, together with your country (taken from our hosting network, or from your browser’s time zone) and the website that linked to us. We store only daily totals per page, country and source. We don’t store IP addresses, don’t set cookies for this and don’t keep any ID, so these numbers can’t identify you or follow you across sites. We also note the country of each account, to understand where Aevora is used.
How we use it
To run the tests you ask for, show you reports, keep your account secure, apply plan limits, and improve the accuracy of checks. We do not sell personal data and we do not use it for advertising.
Who else processes it
- AI review (OpenAI): when AI review is on, page text and screenshots from the target app are sent to OpenAI’s API to produce the review and report. We ask the API not to retain this data for training. You can turn AI review off per run (“Fast run”).
- AgentMail: if you use agent sign-up, a test email inbox is created for you with AgentMail, which receives the target app’s verification emails.
- Hosting and storage: run data and screenshots are stored on our hosting and storage providers.
Sharing
Reports are private to your account unless you create a share link. A shared report shows the journey, findings and screenshots, but never test-account details, your email, or your account identifiers. You can turn a share link off at any time.
Retention and deletion
Run data is kept so you can compare builds over time. You can delete test accounts and agent identities yourself. To delete your account and all of its data, contact us and we will do so within 30 days.
Security
Passwords are hashed, test-account details are encrypted at rest, sessions expire, and target apps are opened in an isolated browser that blocks requests which would change data.
Contact
Privacy questions or deletion requests: reply to the message that brought you your beta invite. A dedicated privacy address will be added before public launch.
This draft is written in plain language for the beta and has not yet been reviewed by a lawyer.