Privacy Policy
Version 1.0 · Effective date 4 August 2026 · Last updated 4 August 2026
1. Who we are
Alliva (“Alliva”, “we”, “us”) provides a personal productivity application that turns your spoken or written notes into tasks, notes and topic threads.
Data controller: Vladimir Shaplin, acting as sole controller until the incorporation of the Spanish S.L.
Address for correspondence: Vladimir Shaplin, Alabyana Street 3, korpus 3, Moscow 125057, Russia
Contact for privacy matters: shaplinvova@gmail.com
We are not required to appoint a Data Protection Officer under Article 37 GDPR or Article 34 of Spanish Organic Law 3/2018 (LOPDGDD). We have nevertheless designated an internal privacy owner, reachable at the address above.
2. Scope
This policy covers the Alliva application (staging.alliva.tech and, when launched, app.alliva.tech), our API (api.alliva.tech) and our website (alliva.tech).
3. What data we process
a) Account data. When you sign in with Google we receive your Google account identifier, email address, name, profile picture and locale. We do not receive your Google password.
b) Your content. Everything you put into Alliva: text you type, audio you record, and the transcripts of that audio. This is the substance of the service.
c) Derived objects. Tasks, notes, titles, source spans, threads, shadows, mentions and summaries that Alliva produces from your content.
d) Vector representations (embeddings). Numerical representations of your titles and source spans, used to find related material. These are computed locally on our own servers by a model built into our application image. They are never sent to any third party.
e) Corrections. When you correct something Alliva got wrong, we store the correction so that the system does better next time for you.
f) Technical data. Session records, background job records, idempotency keys, event delivery records and usage counters.
g) Early-access list. If you submit your email address on our website, we store that address, the page it came from, your language preference and the timestamp. We also store a random identifier that your browser tab creates for that visit: it lets us connect the signup to the pages of this site that were viewed before it and to the campaign link that brought you here. It says nothing about you and it is never used on any other website. Your browser forgets it when you close the tab; the copy stored with your list entry is kept for as long as the entry itself (section 9). If you answer our question about how you would prefer to pay once we open payments, we store that answer as well — a single word, monthly or annual. Because that list runs on your consent, we also record the moment you ticked the consent box and the version of the wording you agreed to, so that we can demonstrate the consent as Article 7(1) GDPR requires. We do not add your address to the list unless the box is ticked.
We do not collect advertising identifiers, we do not track you across other websites, and we do not buy personal data from anyone.
4. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Create and operate your account; authenticate you | Article 6(1)(b) GDPR — performance of a contract |
| Store and display your notes and recordings | Article 6(1)(b) |
| Transcribe your audio into text | Article 6(1)(b) |
| Automatically extract tasks and notes and organise them into threads | Article 6(1)(b) |
| Improve results for you from your own corrections | Article 6(1)(b) |
| Keep the service secure; prevent abuse; rate limiting | Article 6(1)(f) — our legitimate interest in the integrity of the service |
| Monitor technical health and usage volumes | Article 6(1)(f) |
| Back up and restore data | Article 6(1)(c) with Article 32(1)(c), and Article 6(1)(f) |
| Send you early-access news if you joined the list | Article 6(1)(a) — your consent |
| Process any special-category information you choose to enter | Article 9(2)(a) — your explicit consent |
Where we rely on legitimate interests, we have balanced those interests against your rights. You may object at any time under Article 21 GDPR by writing to shaplinvova@gmail.com.
5. Sensitive information — please read this
Alliva is designed for you to write down whatever is on your mind. That means you may enter information that data protection law treats as a special category: information about health, mental health, medication, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation — about yourself or about people you mention.
We do not ask for this information and our system does not look for it. Alliva's categories are tasks, notes, threads and life areas. There is no “health”, “mood”, “diagnosis” or “belief” category, and our AI is explicitly instructed not to draw medical or psychological conclusions about you or anyone else.
However, because such information may be present in your text and is transmitted for processing, we ask for your explicit, separate consent to process it. You give this consent during sign-up through a dedicated, non-pre-ticked checkbox. You can withdraw it at any time by deleting the relevant content or your account. Withdrawal does not affect processing carried out before withdrawal.
If you prefer not to have such information processed at all, simply do not enter it.
6. Automated processing
Alliva uses artificial intelligence to read what you wrote and propose tasks, notes and threads. You should know:
- The AI proposes; it does not decide. Every object it creates is visible to you, editable by you, and deletable by you.
- The original phrase stays visible. Every task and note shows you the exact words from your own input that produced it. Our system enforces this technically: content that is not a verbatim quotation from your input is rejected before it is stored.
- You can reject a new thread. When Alliva proposes to start a new thread, you can decline it.
- Your corrections stay yours. We use up to your ten most recent corrections as examples within your own session context. We do not train any AI model on your data, and your data is never used to improve results for any other user.
We do not carry out automated decision-making producing legal effects or similarly significantly affecting you within the meaning of Article 22 GDPR. Alliva decides which of your own lists a note of yours appears in; nothing more.
You are informed, in accordance with Article 50 of Regulation (EU) 2024/1689 (the AI Act), that Alliva is an artificial intelligence system and that you are interacting with one. Generative summaries produced by Alliva are marked as AI-generated in the interface.
7. Who processes your data on our behalf
| Provider | What they do | What they see | Where |
|---|---|---|---|
| Railway Corp. | Hosting, database, file storage | Infrastructure-level access to stored data | Deployed in the EU (Netherlands); company in the USA |
| OpenRouter, Inc. | Routes our AI requests | Card text and routing context; audio sent for transcription | USA |
| Google LLC (Vertex AI) | AI model that organises your notes | Card text, thread names, aliases, your corrections | Global endpoint — processing region is not guaranteed |
| ElevenLabs, Inc. | Speech-to-text — our current primary provider | The full audio file of your recording | USA |
| OpenAI, L.L.C. | Speech-to-text — fallback provider | The full audio file of your recording | USA |
| Google LLC (Identity Services) | Sign-in | Your Google account identity | Global |
| IONOS SE | Domain and email | Correspondence you send us | Germany (EU) |
| PostHog, Inc. | Product analytics: how the application and this marketing site are used | A pseudonymous account identifier, event names, counts and timings. No note, card, thread or query text. From this marketing site: the random per-visit identifier described in section 3(g), the page address without its query string, the campaign labels of the link you followed, the domain of the site that referred you and your language. We switch geolocation off and instruct PostHog not to record your IP address. Never your email address. | Deployed in the EU (Frankfurt, Germany); company in the USA |
| Cloudflare, Inc. | Audience measurement for this marketing site | Aggregate page views. No cookies and no cross-site identifier. | USA |
We require, and our configuration enforces, that the AI provider handling your text retains nothing (“zero data retention”), does not use your data for training, and that requests are not redirected to any substitute provider if the designated one is unavailable.
An honest limitation: the zero-retention configuration we enforce for text routing does not automatically establish the same properties for speech-to-text. We are in the process of obtaining written confirmation of the transcription provider's terms, and will update this policy accordingly. Until then, if you do not want your voice sent to a transcription provider, please type instead of recording.
The table above is our current subprocessor register. We will give notice of new subprocessors before they begin processing.
8. International transfers
Our servers, databases and file storage are located in the European Union (Netherlands).
Some of our providers are established outside the EEA. For those transfers we rely on the Standard Contractual Clauses adopted by the European Commission (Decision (EU) 2021/914), supplemented by a transfer impact assessment. Where a provider also participates in the EU-U.S. Data Privacy Framework, we treat that as an additional, not a substitute, safeguard.
We are migrating AI inference to an EU-region endpoint so that this category of transfer is eliminated rather than merely documented.
You may request a copy of the relevant safeguards at shaplinvova@gmail.com.
9. How long we keep data
| Data | Retention |
|---|---|
| Your content, tasks, notes, threads, audio | Until you delete it, or until you delete your account |
| Account and session data | Duration of the account; refresh sessions 30 days |
| Idempotency keys and stored responses | 72 hours |
| Event delivery records | 15 minutes |
| One-time sign-in codes | 60 seconds (stored as a hash) |
| Signed audio links | 15 minutes |
| On-device cache | 24 hours |
| Threads with no activity | Archived after 56 days of dormancy; not deleted |
| Backups | 30 days after deletion of the underlying data |
| Early-access list | 24 months, or until you unsubscribe |
10. Your rights
Under Articles 15 to 22 GDPR you have the right to: access your data; have it corrected; have it erased; restrict processing; receive your data in a portable format; object to processing based on legitimate interests; and withdraw consent at any time.
Within Alliva you can already view all of your content together with its origin, edit it, reclassify it, and delete individual items or your entire account.
Account deletion removes your data physically: your per-user databases are detached from replication and deleted, your audio files and backup copies are removed, your sessions are revoked immediately and your usage records are anonymised. We verify completion by scanning until nothing remains. This is irreversible.
Data export in machine-readable form is not yet available in the interface. Until it is, write to shaplinvova@gmail.com and we will provide your data manually within the statutory one-month period.
To exercise any right, contact shaplinvova@gmail.com. We respond within one month (extendable by two further months for complex requests, with notice).
Right to complain: you may lodge a complaint with the Spanish Data Protection Agency — Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid — www.aepd.es, or with the supervisory authority of your country of residence.
11. Security
We protect your data using: TLS in transit; per-user database isolation with restrictive filesystem permissions; short-lived access tokens held only in memory; httpOnly, Secure, SameSite cookies for refresh credentials with rotation on every renewal; one-time sign-in codes stored only as hashes; private object storage accessible only through links that expire in 15 minutes; secrets held outside source control and validated at start-up; automated scanning of our code, dependencies and container images on every build; and continuous replication with daily verified snapshots.
We do not claim any security certification we do not hold.
12. Children
Alliva is not intended for anyone under 18. We do not knowingly collect data from children. If you believe a child has provided us data, write to shaplinvova@gmail.com and we will delete it.
13. Cookies and similar technologies
Our application uses only strictly necessary storage: authentication cookies and a local device cache that lets the app work offline. We do not use advertising or analytics cookies. Where we introduce any non-essential technology, we will request your consent beforehand in accordance with Article 22(2) of Spanish Law 34/2002 (LSSI-CE) and the AEPD cookie guidance.
14. Changes
We will post any change here and update the version number. For material changes we will notify you in the application or by email before the change takes effect.
15. Legal notice · Aviso legal
Identification of the service provider, published under Article 10 of Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).
| Service provider | Vladimir Shaplin. Alliva is operated in his own name until the incorporation of the Spanish S.L., after which this notice will be replaced with the company's registered name, registered office and tax identification number (NIF). |
|---|---|
| Address for correspondence | Vladimir Shaplin, Alabyana Street 3, korpus 3, Moscow 125057, Russia |
| shaplinvova@gmail.com | |
| Website | alliva.tech |
| Activity | Provision of a personal productivity application (software as a service), currently in pre-release. No registration in a professional register is required for this activity. |
| Company register / NIF | Not yet applicable — no legal entity has been incorporated. This entry will be completed on incorporation of the S.L. |
| Applicable law and courts | Spanish law; courts of Madrid, Spain, without prejudice to the rights of consumers resident in the EU. See Terms of Service, section 15. |
| Supervisory authority | Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es. You may lodge a complaint with the AEPD or with the supervisory authority of your country of residence. |
Consumer dispute resolution: the European Commission's online dispute resolution platform is available at ec.europa.eu/consumers/odr.