Privacy Policy
Last updated 10 October 2026
This Privacy Policy explains how Avly Tech Group Limited processes information when you use Avly account. It is a product-facing draft and should be completed with the responsible legal entity, contact address, retention schedule, and jurisdiction-specific rights before launch.
1. Information we process
We process account identifiers, display name, avatar, verified phone numbers and email addresses, Google identity claims when you choose Google sign-in, product authorizations, session and security metadata, and audit events. We also process the minimum technical information needed to deliver the service, such as IP address and user-agent details.
2. How we use information
We use this information to create and secure your Avly account, verify sign-in methods, link one identity across Avly products, issue tokens and sessions, prevent abuse, provide administration and support, and meet security and legal obligations.
Google sign-in data
When you choose Google sign-in, Avly Account requests only the OpenID Connect scopes openid, email, and profile. Google supplies a stable Google account identifier, your email address and its verification status, and available profile information such as your name and profile picture. We use these claims to authenticate you, link your Google identity to your Avly account, and provide your account profile. We do not request access to your Gmail messages, contacts, calendars, or Google Drive files, and we never receive your Google password.
The server exchanges the authorization code with Google and validates the returned identity token. Your Google identity and relevant profile claims are stored with your Avly account. This sign-in integration does not keep Google access or refresh tokens for accessing other Google services. Sessions and tokens issued by Avly Account are used to sign in to connected Avly products.
Infrastructure and protection
Account records are stored in our PostgreSQL database on infrastructure hosted with OVHcloud. Uploaded account avatars are held in private S3-compatible object storage, currently Cloudflare R2. Service providers process the information needed to operate these services. We protect account access using HTTPS, secure session cookies, access controls, and limited product authorization scopes. Security and operational records may contain technical metadata needed to investigate faults or abuse.
3. Sharing
We share identity information with an Avly product only when you authorize that product and only for the scopes displayed in the authorization request. We use infrastructure providers such as PostgreSQL hosting and OTP delivery providers to operate the service. We do not receive your Google password; Google returns identity claims through its OAuth/OpenID Connect flow.
4. Retention and choices
We retain account and authorization records while your account or the associated product connection is active, and retain security and audit records for as long as reasonably necessary for protection, dispute handling, and legal obligations. You can manage connected products and verified contacts in your account, and you may request account assistance through the applicable Avly support channel.
Contact and account requests
Contact [email protected] for questions about Google sign-in data, access to your account information, correction, or an account deletion request. We may need to verify your identity before handling a request. Removing Avly Account from your Google account stops future Google authorizations; it does not automatically delete an existing Avly account. You can also revoke connected Avly products from your account.
5. Policy changes
We may update this Policy as Avly account changes. The version accepted during account creation is recorded with the account so that material changes can be managed transparently.