Privacy policy
Last updated: 02 May 2026
AVA AI (“we”, “us”) is a Brisbane-based software business. This page describes what data we collect, why, and what your rights are. We’re writing this in plain English on purpose.
1. What we collect
- Business owner contact details (name, email, mobile, business name, business type) — you give us this when you sign up. We use it to set up AVA, contact you about your account, and personalise the dashboard.
- SMS conversation transcripts between AVA and your customers — stored so you can review them, and used to score leads. Hosted in Supabase Postgres with row-level security per business.
- Booking records — what was booked, when, by whom. Same hosting + isolation.
- Standard server logs — IP address, user agent, request paths. Retained 30 days for security and debugging.
- Stripe billing data — handled by Stripe, not stored by us. We see the metadata (your plan, status), not card numbers.
2. Why we collect it
To run AVA on your behalf, send you receipts, debug issues, and improve the product. We do not sell or rent your data, ever. Period.
3. Sub-processors
- Anthropic — processes SMS message text to generate AVA’s replies. Anthropic’s privacy policy applies. We do not feed Anthropic any PII you didn’t provide via SMS.
- Twilio — voice and SMS routing.
- ClickSend — AU mobile SMS sending.
- Supabase — database + auth host (AWS Sydney region for AU customers).
- Stripe — subscription billing.
- Vercel — hosting for this website.
4. Your rights (Australian Privacy Principles)
- Request a copy of all data we hold about you.
- Request correction or deletion at any time.
- Withdraw consent — cancel your subscription one tap, and we delete all conversation data within 30 days.
- Lodge a complaint with the OAIC (oaic.gov.au).
To exercise any of these, email dean@avaai.com.au.
5. Data location
Your business data lives in Supabase’s AWS Sydney (ap-southeast-2) region. Anthropic processes message text in the United States; we do not feed them anything beyond the message body and minimal context required to reply.
6. Cookies + analytics
This website uses minimal first-party analytics to count page views and conversion events. We do not use third-party advertising trackers. We do not sell session data.
7. Changes
If we make material changes to this policy, we’ll email all active subscribers and update the “last updated” date above.