VAVUS

Legal

Privacy Policy

How Vavus AI collects, protects, uses, and deletes account, translation, audio, file, billing, cookie, and support data.

Last updated: September 3, 2026 - Version 2.0

1. Who we are

Vavus AI and Vavus Keyboard are operated by DCI Brands LLC, a Wyoming limited liability company, 312 W 2nd Street, Casper, WY 82601, United States. We are the controller of the personal data described here, except where a signed enterprise or healthcare agreement makes us a processor or business associate acting on your organization's instructions.

Privacy contact: constantine@vavusai.com.

Our representative in the European Union under GDPR Article 27 is Dragoș Ignat, Str. General Șova nr. 21, Letea Veche, jud. Bacău, 607270, Romania. You may contact the representative on any matter relating to the processing of your personal data, in addition to or instead of contacting us. We have not appointed a UK representative or a data protection officer. Privacy questions and rights requests go to constantine@vavusai.com and are handled by DCI Brands LLC directly.

2. What we collect

We collect what is needed to create and secure your account, provide the features you use, take payment, answer support requests, and keep the service running.

  • Identifiers and account data - email address, name, login method, organization membership, security settings, device and session identifiers.
  • Content you submit - translations, transcripts, audio recordings, messages, documents, files, and images you choose to process or save.
  • Audio and voice data - speech you dictate or translate. Where it is used to identify or characterize you, this can be sensitive personal information under US state law.
  • Health-related content - only in accounts approved for healthcare use under a Business Associate Agreement.
  • Commercial data - plan, subscription, token balance, purchase and refund history. Card numbers are handled by Stripe, Apple, or Google; we never receive or store them.
  • Technical and security data - device type, app version, crash diagnostics, IP-derived security signals, abuse and rate-limit records.
  • Website data - cookies and local storage, your consent record, and, only after you consent, analytics and campaign attribution.

3. Why we use it, and our legal basis

Where the GDPR or UK GDPR applies, the legal basis for each purpose is set out below.

  • To provide the service - translation, speech-to-text, text-to-speech, keyboard dictation, AI features, messaging, calls, documents, and account management. Performance of a contract (Art. 6(1)(b)).
  • To bill you and keep tax and accounting records. Performance of a contract and legal obligation (Art. 6(1)(b), 6(1)(c)).
  • To keep accounts and the service secure - authentication, abuse prevention, rate limiting, fraud detection, audit logging. Legitimate interests in protecting users and the service (Art. 6(1)(f)).
  • To answer support requests. Performance of a contract and legitimate interests.
  • To send service, billing, and security notices. Performance of a contract and legal obligation.
  • Website analytics, marketing measurement, and all non-essential cookies. Consent (Art. 6(1)(a)), which you can withdraw at any time.
  • To meet legal requirements and to establish or defend legal claims. Legal obligation and legitimate interests.
  • Health information in healthcare accounts. We process it as a business associate on the customer's documented instructions; the customer determines the lawful basis, and where the GDPR applies that is normally Art. 9(2)(h) or the customer's explicit-consent basis.

4. What we never do with your content

We do not use your content to train our models, and we contract with our speech, translation, and AI providers to keep your content out of the training of theirs.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act as amended and in comparable US state privacy laws.

We do not make automated decisions producing legal or similarly significant effects about you (GDPR Art. 22).

Providing account and payment data is necessary to open and keep an account; without it we cannot provide the service. Everything else - optional cookies, marketing preferences - is genuinely optional.

5. AI output

Translation, transcription, and AI output can be wrong. It is not medical, legal, or financial advice, and it is not for emergency use. Review output before you rely on it, and never use it as the sole basis for a clinical, legal, financial, or safety-critical decision. A person should review anything that matters.

6. Encryption, and what we can and cannot read

New history entries, saved documents, and saved audio are encrypted on your device before upload, so our servers hold only ciphertext we cannot decrypt. Messaging uses the Signal Protocol and is end-to-end encrypted between participants.

There are exactly two exceptions, and both require you to use the feature:

  • Group polls. The server has to read a poll to tally votes and show results, so polls are not end-to-end encrypted. They are disabled in healthcare conversations.
  • Voice-message translation. Translating a voice message requires decrypting that one message on our servers. We ask for your consent first, record the consent, and audit the access. It never happens unless you choose it.

7. Retention

Content you do not save is not retained as history once your result has been produced. Live speech exists briefly in memory during processing and is not written to storage.

  • Saved history, documents, and files - until you delete them or close your account.
  • Account and profile records - for the life of the account, then up to 30 days after closure.
  • Billing, tax, and transaction records - 7 years, as tax and accounting law requires.
  • Security, fraud, and abuse logs - 12 months.
  • Support conversations - 24 months.
  • Healthcare audit logs - 6 years, as HIPAA requires. These hold metadata only: who did what, when, from which device. Never PHI, never content.
  • Cookie and consent records - your consent choices are stored in your browser's local storage and last until you clear your browser data or we publish a new consent version, at which point we ask again.

8. Who we share it with

We use service providers by function: cloud hosting and storage; speech recognition and synthesis; machine translation and AI models; payment processing; email delivery; push notification delivery; and support operations. Each receives only what its function requires, under written data-processing terms.

Providers that process your content for speech, translation, or AI are configured to exclude it from their model training and to minimize retention wherever the service supports it, and they receive the content alone - not your name, account, or identity. Payment and app-store providers necessarily do receive identifying and transaction data, because a payment cannot be processed without it.

Our support chat is self-hosted on our own infrastructure, so support transcripts are not handed to a third-party vendor.

A named sub-processor list is provided to enterprise and healthcare customers under a data processing agreement. We may also disclose data to comply with law or a lawful request, to enforce our Terms, to protect rights and safety, and in connection with a merger or acquisition, in which case this policy continues to apply.

9. Where your data is processed

We operate from the United States, with edge infrastructure in the European Union and Asia. Your data may be transferred to and processed in the United States and other countries whose laws differ from those of your own.

For transfers out of the EEA, the UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses (Decision 2021/914), with the UK Addendum and the Swiss annex where they apply, together with the technical measures described in Section 6 - principally client-side and end-to-end encryption, which means that for most stored content the receiving infrastructure holds only ciphertext. A copy of the relevant transfer terms is available on request.

10. Your rights in Europe and the UK

If you are in the EEA, the UK, or Switzerland you may request access, rectification, erasure, restriction, and portability, object to processing based on legitimate interests, and withdraw consent at any time without affecting processing already carried out.

You may also lodge a complaint with a supervisory authority: in the EU, the authority in your country of residence, place of work, or the place of the alleged infringement; in the UK, the Information Commissioner's Office.

11. Your rights in the United States

If you live in California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, or another state with a comprehensive privacy law, you may request to know and access the personal information we hold, correct it, delete it, and receive a portable copy, and you may opt out of sale, sharing, targeted advertising, and profiling with legal or similarly significant effects.

We do none of those things. We honor the Global Privacy Control and other recognized opt-out preference signals anyway: when your browser sends one, we treat it as an opt-out of the analytics and marketing categories for that browser, with no further action from you.

California residents may also ask us to limit the use of sensitive personal information. We already use it only to provide the service you asked for and to keep it secure, which are permitted purposes. We will not discriminate against you for exercising any privacy right.

Appeals. If we decline a request, you may appeal by replying to our decision or emailing constantine@vavusai.com with "Privacy appeal" in the subject line. We respond within 45 days - 60 in Colorado - with our decision and the reasons for it. If we deny the appeal you may complain to your state attorney general. Utah does not provide an appeal right, but we will still review your appeal.

12. Financial incentives

We grant bonus tokens for verifying your email address and for referrals. These are financial incentive programs under California Civil Code section 1798.125(b). The material terms are on our pricing and referral pages: the tokens are promotional, carry no cash value, and can be used only for Vavus features.

We estimate the value of the personal information involved as approximately the retail price of the tokens granted, using our published token price. We calculate it that way because the data involved - an email address and a referral relationship - generates no separate revenue for us, since we do not sell personal information. Participation is voluntary and you can withdraw at any time by emailing us; withdrawing does not reclaim tokens you have already spent.

13. How to exercise your rights

Use the in-product controls where they are available, or email constantine@vavusai.com. We verify requests by matching what you give us against account, billing, support, or security records, and we may ask for more information when a request is sensitive. An authorized agent may act for you with written authorization. We respond within 45 days and may extend once by a further 45 days, telling you why.

14. Healthcare accounts

HIPAA protections apply only to accounts we have approved for healthcare use under an executed Business Associate Agreement. If you have not signed a BAA with us, your account is not a HIPAA workflow and you must not upload protected health information to it.

Approved healthcare accounts use 8-hour session tokens, a 15-minute idle timeout, PHI-handling controls, secure deletion of PHI assets, and 6-year audit retention, and application logs are designed to exclude PHI. In those accounts we act as a business associate, so your organization - not we - decides what happens to the data, and we act on its instructions.

15. Security

We use TLS in transit, the client-side and end-to-end encryption described above, authentication with rotating tokens, separate stream tokens for real-time sessions, SSO for enterprise accounts, brute-force protection, token revocation on logout and password change, rate limiting, access controls, and audit logging.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authorities without undue delay and within 72 hours of confirming a breach affecting your personal data, as the law requires.

16. Children

Vavus is not directed to anyone under 16, and an account requires you to be 16 or older. We do not knowingly collect personal information from anyone under 16.

A parent or guardian who believes a child has created an account can email constantine@vavusai.com. We will verify the report and delete the account and its data promptly. We also close any account we discover belongs to someone under 16.

17. Changes

We may update this policy. The Last updated line shows the current version. Where a change materially affects how we handle personal data, we will give notice in the product or by email before it takes effect.

Contact

DCI Brands LLC, 312 W 2nd Street, Casper, WY 82601, United States. For legal, privacy, billing, or deletion requests, email constantine@vavusai.com.