1. Who We Are
Allvyu is operated by [Legal Entity Name] (ABN [number]), a company registered in Australia.
Allvyu is intended for use by individuals 18 years or older. It is not directed at children, and we do not knowingly collect personal information from anyone under 18.
2. What We Collect
- Account information: email, password (hashed by Supabase Auth — never stored or visible to us in plaintext), profile preferences, plan tier, and billing data (handled by Stripe).
- Financial data you enter: trades, holdings, properties, private investments, cash balances, liabilities, notes, and any documents you upload.
- Connected-account data: when you link a brokerage or crypto wallet, we receive read-only data about that account from the relevant data provider — see section 3.
- Error reports (with consent): if you accept cookies, Sentry collects anonymised error reports — error messages and browser/device type, no financial data.
3. Connected Accounts
When you connect an account in Allvyu, we receive read-only data about that account through a regulated data provider. We never receive your broker or exchange credentials, and we cannot move money or place trades on your behalf.
Public blockchain wallets (read directly from the public ledger):
- Public addresses you supply
- Transactions and balances visible to anyone on the chain
- We do not hold private keys, seed phrases, or any custody.
You can disconnect any connected account at any time. Disconnection stops further data sync; deletion of historic data is governed by section 8 below.
Gmail add-in and Google user data
Allvyu Capture is an optional Gmail add-in. It requests the gmail.addons.current.message.readonly scope, which grants access to a single message at a time — the one open in front of you — and only while that message is open. It cannot search, list or browse your mailbox, and it cannot read any message you have not opened. Google issues a token per message; the add-in cannot obtain a broader one.
The add-in acts only when you tap Send to Allvyu on a message. We then read that message and its attachments once, server-side, and file them into your own Allvyu document queue. What persists is the filed document, the figures extracted from it for your review, and the message's sender, subject and text — kept as the record of what you filed and when. We do not store your Google access token (Google issues a fresh token for each message), and we never read any other message in your mailbox. Everything captured this way is erased when you delete your account.
- Google user data is never sold, and never shared for advertising.
- It is never used to develop, improve or train generalised AI or machine-learning models. Extraction runs against your document to produce your result, and nothing from it is retained for model training.
- It is not transferred to third parties except the sub-processors listed on our sub-processors page, acting on our instructions to provide the service.
- No human at Allvyu reads it except with your explicit permission, or where the law requires it.
Allvyu's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can remove the add-in's access at any time from your Google account's third-party access settings, which revokes it immediately.
4. What We Do NOT Do
- We do not sell or share your data with third parties for marketing.
- We do not use advertising trackers or third-party analytics for advertising.
- We do not track you across other websites.
- We do not move money on your behalf — we are an aggregator, not a payment service.
- We do not provide financial product advice. See our Terms of Service.
5. How We Use Your Data
- Provide the service: calculate net worth, generate charts, produce tax packs, sync connected accounts, and surface insights.
- Fetch market data: ticker symbols are sent to Yahoo Finance, CoinGecko, and Frankfurter API to retrieve prices. These services receive only the ticker/coin identifier, never your personal or financial information.
- AI features: Allvyu's assistant (Otto), document extraction and digests are powered by Anthropic's Claude. What is sent depends on what you do: uploading a statement sends that document; asking the assistant about your portfolio sends the holdings, trades, tax figures and entity structure it needs to answer; and for a question that needs current public information the assistant may run a web search, in which case the search query derived from your request goes to the search provider. This data is processed only to produce your result and, under Anthropic's API terms, is not used to train Anthropic's models. Documents and results are stored in your account only.
- Fix bugs: error reports via Sentry, only with cookie consent.
6. Cookies
Allvyu uses:
- Essential cookies: Authentication session cookies managed by Supabase. Required for the app to function.
- Error tracking (optional): Sentry error monitoring, only activated if you click "Accept" on the cookie banner.
We use localStorage to remember your cookie preference, theme choice, and privacy mode setting. These are stored locally on your device and never transmitted to us.
7. Storage & Security
- All data is stored in Supabase (PostgreSQL) with row-level security: each user can only access their own data.
- Data is encrypted in transit via HTTPS/TLS and at rest via Supabase's standard encryption.
- Passwords are hashed by Supabase Auth; we never see them in plaintext.
- Application hosted on Vercel.
Data breaches. If a breach occurs that is likely to result in serious harm, we will notify affected users and the Office of the Australian Information Commissioner in line with the Notifiable Data Breaches scheme (Privacy Act 1988, Part IIIC). Where the GDPR applies, we notify the relevant supervisory authority within 72 hours of becoming aware of the breach and affected individuals without undue delay.
8. Your Rights
Under the Australian Privacy Act 1988 and (where applicable) the GDPR, you have the right to:
- Access all data we hold about you (Settings → Export, or contact us)
- Correct inaccurate data (edit directly, or contact us)
- Delete your data (Settings → Delete Account)
- Withdraw cookie consent (clear your browser's localStorage)
- Make a complaint to the Office of the Australian Information Commissioner (oaic.gov.au) or your local data protection authority.
9. Data Retention
- Account data: retained while your account is active. Deleted within 30 days of account deletion, except for records we are legally required to retain.
- Backups: rolling 30-day backups; data may persist in backups for up to 30 days after deletion before being overwritten.
10. Sub-processors
We use the following sub-processors. A current and dated list is also published at /sub-processors:
- Supabase Inc. — database, authentication, storage
- Vercel Inc. — application hosting
- Stripe Inc. — payment processing for subscriptions
- Sentry — error monitoring (optional, with consent)
- Anthropic PBC — AI document extraction (data sent is limited to the relevant document; no broader account data)
- Yahoo Finance, CoinGecko, Frankfurter — market data (ticker/coin identifiers only)
11. International Transfers
Some sub-processors may host data outside Australia. We use sub-processors with equivalent privacy protections and where applicable rely on Standard Contractual Clauses or equivalent safeguards. Specific hosting regions are listed at /sub-processors.
12. Changes to This Policy
We may update this policy from time to time. Material changes will be notified to you in-app and by email at least 14 days before they take effect. The "Last updated" date will reflect the most recent revision.
13. Contact
For privacy questions, data requests, or to make a complaint: contact@allvyu.com.