Privacy
Avalos AI never trains on your chats. No opt-in, no opt-out, no exceptions.
This page is based on the Terms & Privacy panel in the app (Settings → Terms & Privacy). “The Company” means the operator of Avalos AI.
Where your conversations go
Your conversation list is stored in your browser on your device (IndexedDB / LocalStorage). To answer you, your messages are processed on the Company's servers and by the GPU hosting provider that runs the Company's open-weight model; when a question needs the web, the search words are sent to search providers.
What the Company keeps
- The Company's service logs record technical details (times, sizes, error codes) but not the text of your messages.
- Access logs keep IP addresses for about 10 days.
- Searches that contain nothing personal may be kept in a search cache for reuse, without anything that identifies you.
- The conversations of API and command-line sessions, with the account that created them, until you delete them.
- The goal and result of agent tasks, so you can open them, until you delete them.
- Coder Engine runs (the file you send, the result and its test log), the most recent 500.
- Encrypted backups of account data are kept, and a backup made before a deletion may still contain what was deleted.
- If you use the app without signing in, a cookie named
__Host-avalos_gid: a random number signed by the server, so a guest's usage allowance is counted per browser instead of being shared by everyone on the same network address. It holds nothing about you, page scripts cannot read it, it lasts up to 400 days, and clearing your cookies resets it.
Training
Your conversations are never used to train the Company's models. There is no opt-in, and no setting changes this.
Deleting
Deleting a chat, or all your history, in the app removes it from your device and deletes the server copies listed above. To delete all your history: Settings → Data controls → Delete all history.
You can also delete your account (with your signed-in session: DELETE /v1/account?confirm=delete-my-account). It deletes the server copies listed above that were made while signed in, your profile, projects, scheduled tasks and their results, your invite code, the feedback you sent and your sign-in record, and signs out every device. Billing records are kept for accounting, and deleting an account does not cancel a subscription. The answer lists what was deleted and what was kept.
On your device
The app's conversation ledger is bounded: it holds at most 4,000 messages or about 20 MB, whichever comes first, and the oldest entries are removed automatically. When the app opens, and about every 30 minutes after that, an on-device sanitizer deletes entries older than 30 days and redacts card-like number sequences from what remains. You can export the ledger as JSON, or erase it, at any time from Data controls.
Your country, without a third party
To show regional settings, your IP address is matched against a country database on the Company's own server, never sent to anyone else. IP geolocation by DB-IP, licensed under CC BY 4.0.
Contact
For anything else, write to us through the feedback option in the app.