legal

Privacy Policy

Version 1.0 · Effective date 4 August 2026 · Last updated 4 August 2026

1. Who we are

Alliva (“Alliva”, “we”, “us”) provides a personal productivity application that turns your spoken or written notes into tasks, notes and topic threads.

Data controller: Vladimir Shaplin, acting as sole controller until the incorporation of the Spanish S.L.
Address for correspondence: Vladimir Shaplin, Alabyana Street 3, korpus 3, Moscow 125057, Russia
Contact for privacy matters: shaplinvova@gmail.com

We are not required to appoint a Data Protection Officer under Article 37 GDPR or Article 34 of Spanish Organic Law 3/2018 (LOPDGDD). We have nevertheless designated an internal privacy owner, reachable at the address above.

2. Scope

This policy covers the Alliva application (staging.alliva.tech and, when launched, app.alliva.tech), our API (api.alliva.tech) and our website (alliva.tech).

3. What data we process

a) Account data. When you sign in with Google we receive your Google account identifier, email address, name, profile picture and locale. We do not receive your Google password.

b) Your content. Everything you put into Alliva: text you type, audio you record, and the transcripts of that audio. This is the substance of the service.

c) Derived objects. Tasks, notes, titles, source spans, threads, shadows, mentions and summaries that Alliva produces from your content.

d) Vector representations (embeddings). Numerical representations of your titles and source spans, used to find related material. These are computed locally on our own servers by a model built into our application image. They are never sent to any third party.

e) Corrections. When you correct something Alliva got wrong, we store the correction so that the system does better next time for you.

f) Technical data. Session records, background job records, idempotency keys, event delivery records and usage counters.

g) Early-access list. If you submit your email address on our website, we store that address, the page it came from, your language preference and the timestamp. We also store a random identifier that your browser tab creates for that visit: it lets us connect the signup to the pages of this site that were viewed before it and to the campaign link that brought you here. It says nothing about you and it is never used on any other website. Your browser forgets it when you close the tab; the copy stored with your list entry is kept for as long as the entry itself (section 9). If you answer our question about how you would prefer to pay once we open payments, we store that answer as well — a single word, monthly or annual. Because that list runs on your consent, we also record the moment you ticked the consent box and the version of the wording you agreed to, so that we can demonstrate the consent as Article 7(1) GDPR requires. We do not add your address to the list unless the box is ticked.

We do not collect advertising identifiers, we do not track you across other websites, and we do not buy personal data from anyone.

4. Why we process it, and on what legal basis

PurposeLegal basis
Create and operate your account; authenticate youArticle 6(1)(b) GDPR — performance of a contract
Store and display your notes and recordingsArticle 6(1)(b)
Transcribe your audio into textArticle 6(1)(b)
Automatically extract tasks and notes and organise them into threadsArticle 6(1)(b)
Improve results for you from your own correctionsArticle 6(1)(b)
Keep the service secure; prevent abuse; rate limitingArticle 6(1)(f) — our legitimate interest in the integrity of the service
Monitor technical health and usage volumesArticle 6(1)(f)
Back up and restore dataArticle 6(1)(c) with Article 32(1)(c), and Article 6(1)(f)
Send you early-access news if you joined the listArticle 6(1)(a) — your consent
Process any special-category information you choose to enterArticle 9(2)(a) — your explicit consent

Where we rely on legitimate interests, we have balanced those interests against your rights. You may object at any time under Article 21 GDPR by writing to shaplinvova@gmail.com.

5. Sensitive information — please read this

Alliva is designed for you to write down whatever is on your mind. That means you may enter information that data protection law treats as a special category: information about health, mental health, medication, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation — about yourself or about people you mention.

We do not ask for this information and our system does not look for it. Alliva's categories are tasks, notes, threads and life areas. There is no “health”, “mood”, “diagnosis” or “belief” category, and our AI is explicitly instructed not to draw medical or psychological conclusions about you or anyone else.

However, because such information may be present in your text and is transmitted for processing, we ask for your explicit, separate consent to process it. You give this consent during sign-up through a dedicated, non-pre-ticked checkbox. You can withdraw it at any time by deleting the relevant content or your account. Withdrawal does not affect processing carried out before withdrawal.

If you prefer not to have such information processed at all, simply do not enter it.

6. Automated processing

Alliva uses artificial intelligence to read what you wrote and propose tasks, notes and threads. You should know:

We do not carry out automated decision-making producing legal effects or similarly significantly affecting you within the meaning of Article 22 GDPR. Alliva decides which of your own lists a note of yours appears in; nothing more.

You are informed, in accordance with Article 50 of Regulation (EU) 2024/1689 (the AI Act), that Alliva is an artificial intelligence system and that you are interacting with one. Generative summaries produced by Alliva are marked as AI-generated in the interface.

7. Who processes your data on our behalf

ProviderWhat they doWhat they seeWhere
Railway Corp.Hosting, database, file storageInfrastructure-level access to stored dataDeployed in the EU (Netherlands); company in the USA
OpenRouter, Inc.Routes our AI requestsCard text and routing context; audio sent for transcriptionUSA
Google LLC (Vertex AI)AI model that organises your notesCard text, thread names, aliases, your correctionsGlobal endpoint — processing region is not guaranteed
ElevenLabs, Inc.Speech-to-text — our current primary providerThe full audio file of your recordingUSA
OpenAI, L.L.C.Speech-to-text — fallback providerThe full audio file of your recordingUSA
Google LLC (Identity Services)Sign-inYour Google account identityGlobal
IONOS SEDomain and emailCorrespondence you send usGermany (EU)
PostHog, Inc.Product analytics: how the application and this marketing site are usedA pseudonymous account identifier, event names, counts and timings. No note, card, thread or query text. From this marketing site: the random per-visit identifier described in section 3(g), the page address without its query string, the campaign labels of the link you followed, the domain of the site that referred you and your language. We switch geolocation off and instruct PostHog not to record your IP address. Never your email address.Deployed in the EU (Frankfurt, Germany); company in the USA
Cloudflare, Inc.Audience measurement for this marketing siteAggregate page views. No cookies and no cross-site identifier.USA

We require, and our configuration enforces, that the AI provider handling your text retains nothing (“zero data retention”), does not use your data for training, and that requests are not redirected to any substitute provider if the designated one is unavailable.

An honest limitation: the zero-retention configuration we enforce for text routing does not automatically establish the same properties for speech-to-text. We are in the process of obtaining written confirmation of the transcription provider's terms, and will update this policy accordingly. Until then, if you do not want your voice sent to a transcription provider, please type instead of recording.

The table above is our current subprocessor register. We will give notice of new subprocessors before they begin processing.

8. International transfers

Our servers, databases and file storage are located in the European Union (Netherlands).

Some of our providers are established outside the EEA. For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented by a transfer impact assessment. Where a provider also participates in the EU-U.S. Data Privacy Framework, we treat that as an additional, not a substitute, safeguard.

We are migrating AI inference to an EU-region endpoint so that this category of transfer is eliminated rather than merely documented.

You may request a copy of the relevant safeguards at shaplinvova@gmail.com.

9. How long we keep data

DataRetention
Your content, tasks, notes, threads, audioUntil you delete it, or until you delete your account
Account and session dataDuration of the account; refresh sessions 30 days
Idempotency keys and stored responses72 hours
Event delivery records15 minutes
One-time sign-in codes60 seconds (stored as a hash)
Signed audio links15 minutes
On-device cache24 hours
Threads with no activityArchived after 56 days of dormancy; not deleted
Backups30 days after deletion of the underlying data
Early-access list24 months, or until you unsubscribe

10. Your rights

Under Articles 15 to 22 GDPR you have the right to: access your data; have it corrected; have it erased; restrict processing; receive your data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time.

Within Alliva you can already view all of your content together with its origin, edit it, reclassify it, and delete individual items or your entire account.

Account deletion removes your data physically: your per-user databases are detached from replication and deleted, your audio files and backup copies are removed, your sessions are revoked immediately and your usage records are anonymised. We verify completion by scanning until nothing remains. This is irreversible.

Data export in machine-readable form is not yet available in the interface. Until it is, write to shaplinvova@gmail.com and we will provide your data manually within the statutory one-month period.

To exercise any right, contact shaplinvova@gmail.com. We respond within one month (extendable by two further months for complex requests, with notice).

Right to complain: you may lodge a complaint with the Spanish Data Protection Agency — Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es, or with the supervisory authority of your country of residence.

11. Security

We protect your data using: TLS in transit; per-user database isolation with restrictive filesystem permissions; short-lived access tokens held only in memory; httpOnly, Secure, SameSite cookies for refresh credentials with rotation on every renewal; one-time sign-in codes stored only as hashes; private object storage accessible only through links that expire in 15 minutes; secrets held outside source control and validated at start-up; automated scanning of our code, dependencies and container images on every build; and continuous replication with daily verified snapshots.

We do not claim any security certification we do not hold.

12. Children

Alliva is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, write to shaplinvova@gmail.com and we will delete it.

13. Cookies and similar technologies

Our application uses only strictly necessary storage: authentication cookies and a local device cache that lets the app work offline. We do not use advertising or analytics cookies. Where we introduce any non-essential technology, we will request your consent beforehand in accordance with Article 22(2) of Spanish Law 34/2002 (LSSI-CE) and the AEPD cookie guidance.

14. Changes

We will post any change here and update the version number. For material changes we will notify you in the application or by email before the change takes effect.

Identification of the service provider, published under Article 10 of Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).

Service providerVladimir Shaplin. Alliva is operated in his own name until the incorporation of the Spanish S.L., after which this notice will be replaced with the company's registered name, registered office and tax identification number (NIF).
Address for correspondenceVladimir Shaplin, Alabyana Street 3, korpus 3, Moscow 125057, Russia
Emailshaplinvova@gmail.com
Websitealliva.tech
ActivityProvision of a personal productivity application (software as a service), currently in pre-release. No registration in a professional register is required for this activity.
Company register / NIFNot yet applicable — no legal entity has been incorporated. This entry will be completed on incorporation of the S.L.
Applicable law and courtsSpanish law; courts of Madrid, Spain, without prejudice to the rights of consumers resident in the EU. See Terms of Service, section 15.
Supervisory authorityAgencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es. You may lodge a complaint with the AEPD or with the supervisory authority of your country of residence.

Consumer dispute resolution: the European Commission's online dispute resolution platform is available at ec.europa.eu/consumers/odr.