Privacy Policy
Version 2.1 · Effective date 25 September 2026 · Last updated 25 September 2026
This policy explains in plain terms what Alliva does with your data: what we hold, who else processes it, where it goes, how long it stays, and what you can ask of us. Where we cannot do something yet, we say so.
A short summary of the AI part is in the AI Processing Notice. The rules for using the service are in the Terms of Service.
1. Who we are
Alliva (“Alliva”, “we”, “us”) is a personal organiser. You record voice or text notes, and Alliva turns them into tasks, notes and topic threads. You can also ask questions about your own material.
Data controller: Vladimir Shaplin, a private individual who runs Alliva in his own name.
Location: Moscow, Russia. Contact for all privacy matters: shaplinvova@gmail.com. You can write in English, Spanish or Russian.
We are not required to appoint a Data Protection Officer under Article 37 GDPR or Article 34 of Spanish Organic Law 3/2018 (LOPDGDD).
2. Scope
This policy covers the Alliva app for iOS if and when it is released through the App Store, the Alliva web app that you can install on your device (app.alliva.tech), our API (api.alliva.tech) and our website (alliva.tech). The iOS app and the web app are the same service under one policy. Where they differ, we say so.
Alliva is not directed at people in the Russian Federation and is not offered in the Russian App Store. The Russian-language version of this policy is for Russian speakers who live elsewhere.
3. Beta status and what not to record
Alliva is a free beta, provided as is. Things may break, change or be lost. Please keep your own copies of anything important.
Please do not record passwords, bank card numbers, identity document numbers, or health details you would not want stored. Alliva does not need them to work.
AI output can be wrong. Do not use Alliva for medical, legal, financial or crisis decisions.
This advice does not reduce our own responsibility for protecting what you do store. It only helps you keep the most sensitive things out of a beta product.
4. What data we process
a) Account data. You sign in with Google or with Apple. There is no Alliva password.
- Google: we receive your Google account identifier, email address, name, profile picture and language.
- Apple: we receive your Apple account identifier, and the name and email address you choose to share. If you hide your email, Apple gives us a relay address ending in @privaterelay.appleid.com. We never learn your real address, and Alliva works normally with the relay address.
We also store your time zone and interface language, so that dates and reminders are correct.
b) Your content. The text you type, the audio you record, the transcripts of that audio, and the questions you ask in chat with the answers you receive.
c) What Alliva makes from your content. Tasks, notes, titles, quoted phrases, threads, mentions, reminders and summaries.
d) Embeddings. Numerical representations (vectors) of short pieces of your content, such as a card's title and the quoted phrase. We use them to find related material and to place a new card in the right thread. The text is sent to Google Cloud Vertex AI in the EU to compute the vector. The vector is stored in our database. See section 7.
e) Your corrections. When you correct something Alliva got wrong, we store the correction. Up to your ten most recent corrections are used as examples when Alliva processes your own later notes. They are never used for anyone else.
f) Technical data. Session records, background job records, technical deduplication keys, event delivery records, usage counters (for example, how many transcriptions you used today), and diagnostic records of how your requests were processed. Our server logs are designed to leave out the text of your notes.
g) Reminder delivery. Reminders are scheduled by our server. If you allow notifications, we store what is needed to reach your device: on iOS, the push token issued for your installation and a random installation ID; in the web app, the push subscription your browser gives us. When a reminder is due, the web notification contains the reminder's title or text. The iOS notification contains only a generic message, without the task's title, text or ID. See section 8. If you do not allow notifications, or turn reminders off, nothing is sent.
h) Consent records. Which version of these documents you accepted, in which language, and when; the same for the AI activation screen and for your analytics setting.
i) Usage analytics. Pseudonymous records of how the service is used, never the content of what you wrote. See section 15.
j) Early-access list (website). If you join the list on our website, we store your email address, the page and language you signed up from, the time you ticked the consent box and the version of the wording you agreed to, a truncated description of your browser (user agent), and a one-way hash of your IP address used only to limit abuse. We never store your IP address itself.
We do not collect advertising identifiers, we do not track you across other apps or websites, and we do not buy personal data. Alliva has no advertising.
5. Why we process data, and on what legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Create and run your account; sign you in | Article 6(1)(b) — performance of our contract with you |
| Store and show your notes and recordings; sync them across your devices | Article 6(1)(b) |
| Transcribe your audio; structure your notes into tasks, notes and threads; answer your questions; compute embeddings | Article 6(1)(b) — this is the service itself |
| Process special-category information that appears in your content (for example about health) | Article 9(2)(a) — your explicit consent, given on the AI activation screen (section 6) |
| Send you the reminders you set | Article 6(1)(b) |
| Keep the service secure; prevent abuse; rate limits | Article 6(1)(f) — our legitimate interest in a secure, working service |
| Pseudonymous usage analytics | Article 6(1)(f) — our legitimate interest in finding and fixing problems. You can switch it off (section 15) |
| Daily backups | Article 6(1)(f), and Article 32 GDPR (ability to restore data) |
| Keep a record of the documents you accepted | Article 6(1)(c) and Article 7(1) — we must be able to show your consent |
| Early-access list emails | Article 6(1)(a) — your consent, given by ticking the box |
Where we rely on legitimate interests, we have weighed them against your rights. You can object at any time under Article 21 GDPR by writing to shaplinvova@gmail.com. For analytics, the switch in the app is enough.
Alliva does not make decisions about you that have legal or similarly significant effects within the meaning of Article 22 GDPR. The AI only decides how your own notes are sorted in your own lists, and you can change that.
6. Sensitive information and your explicit consent
Alliva is made for writing down whatever is on your mind. So your notes may contain what the law calls special categories of data: health and mental health, religious or philosophical beliefs, political opinions, trade union membership, sex life or sexual orientation — about you or about people you mention.
We do not ask for this information, and Alliva does not look for it. There is no “health”, “mood” or “diagnosis” category. Our AI is instructed not to draw medical or psychological conclusions about you or anyone else.
But if such information is in what you record, it is processed together with everything else. For that we rely on your explicit consent under Article 9(2)(a) GDPR. You give it on a separate AI activation screen in the app, after you sign in and apart from accepting the Terms. That screen says what leaves your device and to whom. AI processing starts only after you tap Continue on that screen.
We cannot know in advance what you will write, and we cannot process one part of a note with AI and skip another. That is why this consent is needed before the AI features work.
Withdrawing consent. You can withdraw it at any time. There is no switch for this in the app yet, so write to shaplinvova@gmail.com, or delete your account. When you withdraw, we stop all AI processing of your content. The AI features — transcription, structuring, chat — then cannot be used. Your stored content stays until you delete it or your account. Withdrawal does not affect processing that already happened.
If you write about other people, please be considerate. The Terms cover this.
7. How AI is used, and what leaves our servers
Alliva uses AI to transcribe your speech, to turn your notes into tasks, notes and threads, to compute embeddings, and to answer questions about your own material. None of it runs before you have tapped Continue on the AI activation screen.
| Step | What is sent | To whom, and where |
|---|---|---|
| Speech to text | The audio of your recording | OpenAI, global API, processed in the USA (model gpt-4o-mini-transcribe) |
| Structuring into tasks, notes and threads | The text of your note or transcript, with the thread names and recent corrections needed for context | Google Cloud Vertex AI, EU multi-region (processed within the EU), Gemini models |
| Embeddings for search and thread routing | Short pieces of your content, such as titles and quoted phrases | Google Cloud Vertex AI, europe-west4 (model gemini-embedding-001) |
| Chat with your memory; summaries | Your question and the relevant pieces of your own material | Google Cloud Vertex AI, EU multi-region, Gemini models |
What our providers do with it:
- No training. Neither OpenAI nor Google uses your data to train their models. We do not train models either.
- OpenAI may keep the data for up to 30 days solely for abuse monitoring, and longer only if the law requires it. We have a data processing agreement with OpenAI, and the use of our data for training is turned off.
- Google does not use customer data for training. In-memory caching of requests is turned off for our project. Google may process data to detect abuse under its own service terms.
- No silent fallback. If a provider is unavailable, the request fails and is retried later. It is not sent to another provider.
How it behaves:
- The AI proposes; you decide. You can see, edit, move and delete everything it creates.
- Your words stay visible. Each task and note shows the exact phrase from your own input it came from. The short title above it is written by the AI and may be paraphrased.
- You can decline a new thread when Alliva suggests one.
- AI output can be wrong. Check anything you rely on.
Under Article 50 of Regulation (EU) 2024/1689 (the AI Act), we inform you that Alliva uses artificial intelligence and that chat answers are generated by an AI system.
8. Who processes your data
These are our processors. Each processes data only on our instructions, under a contract that meets Article 28 GDPR.
| Provider | What they do | What they see | Where |
|---|---|---|---|
| Railway Corp. | Hosting, database, file storage for audio and backups | Everything we store, at infrastructure level | Servers in the EU (EU West, Netherlands). Platform metadata and logs may be processed in the USA |
| OpenAI | Speech to text | The audio of your recordings | USA |
| Google Cloud (Vertex AI) | Structuring, embeddings, chat answers, summaries | Text of your notes, transcripts and questions; thread names; your recent corrections | EU: Gemini models in the EU multi-region; embeddings in europe-west4 (Netherlands) |
| PostHog, Inc. | Usage analytics (section 15) | Event names, counts, timings, a pseudonymous ID. Never your content or email | EU cloud (Germany); PostHog's own account and support data in the USA |
| IONOS SE | Our email; notifications to us about new early-access signups | Emails you send us; your email address if you join the early-access list | Germany (EU) |
| Cloudflare, Inc. | DNS for our domain; cookieless visitor statistics on the website | DNS queries; page views without cookies or cross-site identifiers | Global network; USA |
| Expo (650 Industries, Inc.) | Delivers reminder notifications to the iOS app, through Apple | Your push token and a generic notification message; no task title, text or ID | USA |
These parties are not our processors. They act under their own terms, and we list them because your data reaches them:
| Party | Why they receive data |
|---|---|
| Google (Sign in with Google) | You chose to sign in with Google. Google confirms your identity to us and shares your identifier, name and email. |
| Apple (Sign in with Apple) | You chose to sign in with Apple. If you hid your email, Apple also forwards our emails to you through its relay. When you delete your account, we ask Apple to revoke Alliva's access. |
| Browser push services (web app only) | If you turn on reminders in the web app, your browser's push service delivers them — for example Apple, Google or Mozilla, depending on your browser. The reminder text is encrypted under the Web Push standard so that the push service cannot read it; it sees only where and when to deliver. |
| Apple (Push Notification service, iOS app only) | Expo passes iOS reminders to Apple, which delivers them to your iPhone. Apple receives a device token and the generic notification message, without the task's title, text or ID. |
A difference between iOS and web. In the web app, the reminder text is encrypted so that only your browser can read it. On iOS, Expo and Apple can read a generic notification message and the token used to deliver it. The task's title, text and ID are not included. You can turn reminders off in the app or in your iPhone's notification settings.
We will announce new processors before they start processing your data.
9. Where your data is, and international transfers
Your data is stored in the European Union: our servers, database and file storage are in the Netherlands. Your text is processed by Google's AI models within the EU (Vertex AI EU multi-region; embeddings in europe-west4, Netherlands).
Voice recordings are processed in the USA. For speech to text, the audio of your recording is sent to OpenAI's global API and processed in the USA; the resulting text comes back to our servers in the EU. OpenAI may keep the audio for up to 30 days for abuse monitoring (section 7). For this transfer we rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework, under which OpenAI is certified (Article 45 GDPR), and on the Standard Contractual Clauses included in OpenAI's data processing agreement (Article 46 GDPR).
Some of our other providers are US companies, and a few other kinds of data may reach the USA (for example hosting platform logs, support data at PostHog, and iOS reminder notifications, which Expo delivers from the USA). For those transfers we rely on the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914) as part of each provider's data processing terms, and on the EU–US Data Privacy Framework where a provider is certified under it. You can ask us for a copy of the relevant safeguards.
We run the service from Russia. The controller lives in Moscow and administers the service by remote access to the EU systems. That means your data can be viewed from Russia when running the service requires it — for example to fix a fault or to answer your request. We keep this access to what is necessary. Your data is not stored in Russia and is not shared with anyone there.
10. How long we keep data
| Data | How long |
|---|---|
| Voice recordings (audio) | 7 days after upload, then deleted automatically. You can play a recording in the app during those 7 days. The transcript stays. |
| Your content: notes, tasks, threads, transcripts, chat, AI results, embeddings | Until you delete it, or until you delete your account |
| Account data | Until you delete your account |
| Push tokens and push subscriptions | While notifications are enabled on that device. When you sign out or turn reminders off, the app requests removal of that device's registration; a network failure may delay removal. Deleting your account removes the server registration. |
| Sessions | Sign-in session up to 30 days; access tokens 15 minutes |
| Technical deduplication keys (which stop a retried action from being applied twice) | Up to 30 days |
| Database backups | Made daily, kept for 30 days, then deleted |
| Early-access list | Until we offer you early access or you ask to be removed, and no longer than 24 months. Automatic deletion after 24 months is being put in place; until then we delete manually. |
| Consent records | See section 11: kept after account deletion without your email |
| Copies on your own device | See section 14 |
Alliva keeps an internal history of changes in your account, so that edits can be undone and your devices stay in sync. Pieces of an item you deleted may stay in that history until you delete your account. If you need a specific item fully erased sooner, write to us.
11. Your rights, and deleting your account
Under Articles 15 to 22 GDPR you have the right to: access your data; correct it; erase it; restrict its processing; receive it in a portable format; object to processing based on legitimate interests; and withdraw consent at any time, without affecting earlier processing.
In the app you can already see all your content and where it came from, edit it, move it and delete it.
Deleting your account. You can delete your account in the app, whichever way you signed in. For safety, the app asks you to sign in again with Google or Apple first. Once you confirm deletion, account access closes and sessions are revoked immediately. Removal of the remaining content and stored objects runs in the background; the request cannot be undone. Account deletion:
- erases your content, recordings, embeddings, sign-in identities, sessions and push registrations;
- anonymises your usage records, so that they are no longer linked to you;
- removes the personal properties from your analytics profile at PostHog. Past pseudonymous analytics events stay there, without your email or name;
- keeps a minimal record of which document versions you accepted, when, and in which language. It is not linked to your email. We keep it to be able to show that consent was given (Article 7(1) GDPR).
Backups taken before the deletion expire within 30 days. We do not restore backups to bring back deleted data.
Getting a copy of your data. There is no export button yet. Write to shaplinvova@gmail.com and we will send you your data in a machine-readable format within one month.
To use any right, write to shaplinvova@gmail.com. We answer within one month. For complex requests this can be extended by two more months; if so, we tell you why.
Right to complain. You can complain to the Spanish Data Protection Agency — Agencia Española de Protección de Datos, C/ Jorge Juan 6, 28001 Madrid, www.aepd.es — or to the data protection authority of the country where you live.
12. Security
We protect your data with: TLS encryption in transit; encryption at rest by our hosting provider; a PostgreSQL database with row-level security, so a query can only reach the rows of the user who made it; short-lived access tokens; refresh credentials that are rotated on every renewal (httpOnly, Secure cookies on the web; the system Keychain on iOS); private file storage reachable only through links that expire quickly; secrets kept out of source code; automated checks of our code and dependencies; and daily backups.
Alliva is not end-to-end encrypted. We and our processors can technically access stored data, and your content must be readable by the AI providers for the service to work.
We do not claim any security certification.
13. Minimum age
You must be at least 16 to use Alliva. We do not knowingly collect data from anyone younger. If you believe a child under 16 has given us data, write to shaplinvova@gmail.com and we will delete it.
14. Storage on your device
The apps store data on your device so that you stay signed in and can work offline. All of it is needed for features you use.
- Your data, cached. A local copy of your material, so the app opens fast and works offline.
- Offline queue. Changes and recordings that have not reached our servers yet. Audio files stay on your device only until they are uploaded.
- Sign-in. On iOS, session credentials are kept in the system Keychain. On the web, in an httpOnly cookie.
- Preferences. Settings such as language and theme, and small conveniences such as recent searches (web app).
This data is removed when you delete the app. On the web you can clear it through your browser's site data settings.
No analytics or advertising cookies. Analytics in the web app keeps its identifier in memory only. The website stores only your language choice in your browser. That is why there is no cookie banner: we store nothing that needs your consent under Article 22(2) of Spanish Law 34/2002 (LSSI-CE). If this changes, we will ask first.
15. Analytics, and how to switch it off
We measure how Alliva is used — which screens people reach, whether a recording was processed, how long things take — so that we can find and fix problems. We use PostHog, EU cloud, on the basis of our legitimate interest (Article 6(1)(f)). We set it up to collect as little as possible:
- No content. No note, card, thread, transcript, search or chat text is sent to analytics, not even in shortened or hashed form.
- No email address and no advertising identifier. Events are linked to a pseudonymous ID.
- No IP address. It is discarded before events are stored, and location lookup is off.
- No session recording and no automatic click capture. Both are switched off in our code.
- No cookies. See section 14. On the website, where there is no account, the identifier lives only in the open page and is gone when you close it.
Some events are sent by our server rather than by the app, so this also covers the iOS app.
To switch it off: use the Product analytics switch in the privacy settings of your profile. It is on by default. Turning it off stops new analytics events about you and changes nothing else. You can also object by writing to us, and we will honour it (Article 21 GDPR).
16. Changes to this policy
When we change this policy, we publish the new version here with a new version number. The app shows you the new version, and you need to accept it before you continue using Alliva. For material changes, we tell you in advance.
17. Legal notice · Aviso legal
Information about the service provider under Article 10 of Spanish Law 34/2002 on information society services and electronic commerce (LSSI-CE).
| Service provider | Vladimir Shaplin, a private individual |
|---|---|
| Place of residence | Moscow, Russia |
| shaplinvova@gmail.com | |
| Website | alliva.tech |
| Activity | A personal organiser app (software as a service), currently a free beta |
| Register and tax ID | None. The service is not provided by a company, and the activity requires no registration or professional licence. |
| Terms | Terms of Service, including applicable law (section 16) |
| Data protection authority | Agencia Española de Protección de Datos (AEPD), C/ Jorge Juan 6, 28001 Madrid — aepd.es, or the authority of your country of residence |
This policy is published in English, Spanish and Russian. The English version is the reference text. If you live in Spain, you may rely on the Spanish version, and your mandatory rights as a consumer apply whichever version you read.