Privacy Policy
Effective date: August 1, 2026 · alwyse is in beta.
alwyse is built and operated by CVOYA LLC ("CVOYA", "we", "us"). This policy is the formal record of what we collect, why we collect it, and the control you keep over it. It covers the alwyse.ai website and waitlist, the alwyse apps, and the managed alwyse service we operate (the hosting option we call Cloud — during the beta, the one most people use).
The plain-language version of our posture lives on Privacy & Trust, and the live status of every privacy claim we make, per hosting option, is published on the trust roadmap. This policy is written to match both. If you ever find a disagreement between them, tell us — the disagreement is a bug.
The short version
- Your content exists to serve you, and only you. No ads. No resale.
- Your content lives in an instance of its own — one application, one database, per person. Running the service never requires reading it.
- Nothing crosses your trust boundary unless you choose it — a model you bring a key for, a web search, a source you connect — and every crossing is recorded, content-free.
- You can export everything, and you can delete anything.
- This website sets no cookies and runs no analytics.
This website and the waitlist
alwyse.ai is a static site. It sets no cookies, runs no analytics, and embeds no trackers. If you join the waitlist, we store the email address you give us and use it for exactly one thing: sending you an invite. Ask us to remove it at any time.
What we collect when you use alwyse
Your account
You sign in with your Google or Apple account. We receive your name and email address from them; we never see or store a password. We keep the session credentials needed to keep you signed in on your devices, and — if you enable notifications — the device push tokens needed to deliver them.
Your content
Everything you capture or connect — notes, conversations, images, documents, and what alwyse comes to understand from them — is stored in your own instance: one application, one database, that serve you alone. We store and process this content solely to run alwyse for you. We do not read it to operate the service, we do not use it for advertising, and we do not sell it.
Sources you connect
If you connect a source — a calendar, email, files, contacts — you grant alwyse read access through that provider's own consent screen. alwyse keeps what it understood, never a mirror of your account, and the access tokens are held inside your instance. You can sever any connection at any time, and delete what alwyse derived from it.
Keys you bring
During the beta, alwyse's cloud model is a key you bring from a model vendor. Your key is held by your instance and used only for your own requests. Our control plane sees key metadata — that a key exists and its content-free usage — never your content.
Operational data
To run and pay for the service we keep content-free measurements: request counts, token counts, and bytes — never what the requests said. Our service logs are content-free by construction: when your instance makes a network crossing, the log records the destination, never the content, path, or query. This is not a filtering promise — the content is never captured in the first place.
Feedback
If you send feedback from inside the app, we receive what you chose to send, de-identified. Nothing is sent unless you send it.
What we can and cannot see
We say this precisely, because it is the heart of the product. On Cloud, we do not claim operator-blindness: we operate your instance, and an administrator with infrastructure access could reach the data at rest inside it. What we have built, and do claim, is content-blind operation: your content lives in an instance of its own; the control plane that handles your account never receives it; inference goes from your instance straight to the model vendor, never through us; and our logs cannot hold your content because it is never captured. If you run alwyse on your own hardware, the question does not arise — nobody but you runs it. The full claim-by-claim status lives on the trust roadmap.
When your content crosses the boundary
Everything alwyse holds about you lives inside a trust boundary. Content crosses it only when you choose: when you use a cloud model, the relevant content goes directly from your instance to that vendor under your key and their terms; when you ask alwyse to search the web, your query goes to the search provider; when you connect a source, alwyse reads from it under your grant. Run local models on your own hardware and nothing crosses at all. Every crossing is recorded, content-free, and the record is yours to inspect.
How we share information
We do not sell personal information, and we do not share it for advertising. Information leaves our systems only in these cases:
- At your direction: the crossings above — model vendors under your key, search providers, sources you connect.
- Infrastructure providers: the hosting providers our service runs on, bound by their contractual obligations to us.
- Legal requirements: if the law compels us. Unless we are legally prohibited, we will tell you.
- Business transfers: if CVOYA is acquired or merges, with notice to you before your information becomes subject to a different policy.
Retention and deletion
We keep your content for as long as your account is active — it is your memory, and holding it faithfully is the product. Deletion is in your hands:
"Deleted means gone — removed from everything I show you right away, and then erased for real. Not hidden."
When you delete something in alwyse, it is gone from every screen, search, and answer immediately, and the removal cascades through what alwyse inferred from it. Copies inside backups expire within 30 days. Physical erasure of the underlying record is the final step of deletion, and its live status is published, honestly, on the trust roadmap.
To close your account entirely, contact us at privacy@cvoya.com. We delete your instance and its database, and backup copies expire on the same 30-day ceiling.
Taking everything out
You can export your data in full — your observations, what alwyse derived from them, your media, and your preferences — in open formats. The export is served by your own instance, never by our control plane.
If you self-host
Run alwyse on your own machine and your content never reaches us at all. What we hold is what operating your account requires: your name and email, your instance's registration, and content-free service records. Nothing else.
Your rights
Wherever you live, we honor the same set of rights, because the product is built on them: access what alwyse holds about you, correct it, delete it, export it, and withdraw any grant you made. Most of these you can exercise directly in the app; for anything else, or to exercise rights under the law of your residence (such as the GDPR or the CCPA), contact privacy@cvoya.com. We respond within 30 days. We do not sell personal information, so there is nothing to opt out of, and we will never treat you differently for exercising a right.
Children
alwyse is not directed to children. During the beta you must be 18 or older to hold an account. If we learn we hold an account for someone younger, we will close it and delete its data.
Changes to this policy
When this policy changes, we post the new version here and update the effective date. If a change is material, we tell you in the app or by email before it takes effect — and any change is checked against the trust roadmap, so our promises cannot quietly weaken.
Contact
CVOYA LLC · privacy@cvoya.com · or via the Support page.