Last updated: May 5, 2026
This Privacy Policy explains how Narius OÜ ("Avocado AI", "we", "us") collects, uses, and protects personal data when you use avocadoai.co, the Avocado AI web app, mobile app, Telegram Mini App, MCP server, and related services (together, the "Service").
We are the data controller for the personal data we process. If you have questions or want to exercise your privacy rights, contact us at privacy@avocadoai.co.
1. Who we are
Avocado AI is operated by Narius OÜ, a private limited company registered in Estonia.
- Company: Narius OÜ
- Registered address: Liivalaia tänav 28-1, Kesklinna linnaosa, 10118 Tallinn, Harju maakond, Eesti
- Registry code: 16779497 (registered in Estonia on July 18, 2023)
- Email: privacy@avocadoai.co
If you are in the EU/EEA or the UK, Narius OÜ is your data controller.
2. Data we collect
2.1 Information you provide
- Account data: name, email, password (handled by our authentication provider), profile image, organization name, role.
- Billing data: billing name, address, country, VAT/Tax ID, payment method details. Payment card numbers are collected and stored by Stripe, not by us.
- Content you upload: images, video, audio, brand assets, reference materials, URLs you submit for brand extraction, text prompts, project metadata.
- Storyboards and collaboration data: canvas state, comments, cursor positions, presence indicators when collaborating in real time.
- Communications: messages sent to support, survey responses, replies to our emails.
2.2 Information generated through your use
- Generated content: images, videos, music, voice clips, agent outputs, and intermediate artifacts produced when you use the Service.
- Usage data: features used, generations performed, credits consumed, error logs, session timestamps, device and browser information, IP address, referrer.
- Cookies and similar technologies: session cookies for authentication, analytics cookies (where consent is given), and security cookies. See Section 9.
2.3 Information from third parties
- Authentication providers: if you sign up via Google or another SSO, we receive basic profile information from that provider.
- Telegram: if you use the Telegram Mini App, we receive your Telegram user ID and basic profile information from Telegram.
- Payment provider: Stripe sends us non-sensitive metadata about your transactions (status, amount, last 4 digits of card, country) so we can fulfill your subscription.
3. How we use your data
We process personal data for the following purposes:
| Purpose | Legal basis (GDPR) |
|---|
| Provide the Service (account, generation, storage, collaboration) | Contract |
| Process payments and manage subscriptions | Contract |
| Communicate about your account, billing, security, and product changes | Contract / Legitimate interests |
| Send marketing emails (only with your consent or where permitted) | Consent / Legitimate interests |
| Improve the Service, debug, prevent abuse and fraud | Legitimate interests |
| Comply with legal, tax, and regulatory obligations | Legal obligation |
| Defend legal claims (including chargeback disputes) | Legitimate interests |
You can withdraw consent at any time where consent is the legal basis.
4. AI processing: how prompts and content are handled
This is the part most AI policies get wrong, so we want to be specific.
- We do not train AI models on your prompts, uploads, or generated content. Avocado AI does not own or train foundation models. We route requests to third-party AI providers (see Section 6) who run inference on our behalf.
- Each provider has its own data policy. When you generate content, your prompt and any uploaded reference material are sent to the provider whose model you selected. Most providers we use (including OpenAI, Anthropic, Google, fal.ai, ElevenLabs, and Replicate) commit in their enterprise/API terms not to train on customer-submitted data, but you should review their policies if this matters to you.
- Brand DNA extraction: when you submit a URL for brand extraction, we crawl that public page and pass content through vision and synthesis models to extract brand attributes. We store the extracted brand profile against your account; we do not retain the source HTML beyond the extraction step.
- Generated content ownership: subject to our Terms of Service, you own the content you generate, within the limits set by the underlying model providers' terms.
5. How we share your data
We share personal data only as described below. We do not sell personal data.
- Sub-processors and service providers: see Section 6.
- Within your organization: if you are part of a team workspace, your name, email, and project activity are visible to other members.
- Public sharing you initiate: if you publish a storyboard, share a generation publicly, or post to a public gallery, that content becomes accessible to anyone with the link.
- Legal disclosures: we may disclose data if required by law, court order, or to protect our rights, users, or the public from harm or fraud.
- Business transfers: if Narius OÜ is involved in a merger, acquisition, or asset sale, your data may transfer to the successor entity, subject to this Policy.
6. Sub-processors
We use the following sub-processors to deliver the Service. This list is current as of the date above and may change. Material changes will be reflected here.
[VERIFY: confirm or correct this list against your actual stack before publishing.]
| Sub-processor | Purpose | Location |
|---|
| Stripe | Payment processing, subscription billing, fraud prevention | US / EU |
| Clerk | User authentication and account management | US |
| Supabase | Database and storage | EU / US |
| Vercel | Application hosting and edge delivery | Global |
| Cloudflare | CDN, DDoS protection, DNS | Global |
| PostHog | Product analytics | EU |
| OpenAI | AI inference (language and image models) | US |
| Anthropic | AI inference (language models) | US |
| Google (Gemini, Vertex) | AI inference (vision, language) | US / EU |
| fal.ai | AI inference (image and video models) | US |
| Replicate | AI inference (multi-model gateway) | US |
| ElevenLabs | Voice synthesis | US |
| Firecrawl | Web crawling for Brand DNA extraction | US |
| Resend / Flodesk | Transactional and marketing email | US |
| Telegram | Mini App authentication and delivery | Global |
7. International data transfers
We are based in Estonia and many of our sub-processors are located outside the European Economic Area, primarily in the United States. When we transfer personal data outside the EEA or UK, we rely on appropriate safeguards, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission;
- Adequacy decisions, where available;
- Supplementary technical and organizational measures.
You can request a copy of the safeguards in place by emailing privacy@avocadoai.co.
8. Data retention
| Data type | Retention period |
|---|
| Account data | For the lifetime of your account, plus up to 90 days after deletion |
| Generated content and uploads | For the lifetime of your account, or until you delete them |
| Billing records | 7 years after the transaction (legal and tax requirement) |
| Usage and analytics logs | Up to 24 months |
| Support communications | Up to 3 years after the last interaction |
| Marketing email subscription state | Until you unsubscribe, plus a suppression record indefinitely |
You can delete your account from your account settings, or by emailing privacy@avocadoai.co.
9. Cookies and tracking
We use the following categories of cookies and similar technologies:
- Strictly necessary: authentication, session management, security. These cannot be disabled.
- Analytics: PostHog, used to understand how the Service is used. Where required by law (EU/EEA, UK), we ask for your consent before setting these.
- Marketing: we currently do not run third-party advertising trackers on the Service. If this changes, we will update this Policy and seek consent where required.
You can manage cookies through your browser settings or our cookie banner where presented.
10. Your rights
Depending on where you live, you have the following rights:
10.1 If you are in the EU/EEA or UK (GDPR)
- Access your personal data
- Rectify inaccurate data
- Erase your data ("right to be forgotten")
- Restrict processing
- Data portability
- Object to processing based on legitimate interests
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority. In Estonia, this is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), www.aki.ee.
10.2 If you are in California (CCPA/CPRA)
- Know what personal information we collect, use, and share
- Delete your personal information
- Correct inaccurate personal information
- Opt out of the sale or sharing of personal information (we do not sell personal information)
- Limit the use of sensitive personal information
- Non-discrimination for exercising your rights
10.3 How to exercise your rights
Email privacy@avocadoai.co. We respond within 30 days. We may need to verify your identity before fulfilling certain requests.
11. Security
We use industry-standard technical and organizational measures to protect personal data, including encryption in transit (TLS), encryption at rest for stored content, access controls, audit logging, and regular review of our sub-processors.
No system is perfectly secure. If we become aware of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
12. Children
The Service is not directed to children under 18. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@avocadoai.co and we will delete it.
13. Changes to this Policy
We may update this Policy from time to time. The "Last updated" date at the top reflects the most recent version. For material changes, we will notify you by email or through the Service before the changes take effect.
14. Contact
Narius OÜ
Liivalaia tänav 28-1, Kesklinna linnaosa, 10118 Tallinn, Harju maakond, Eesti
Privacy: privacy@avocadoai.co
General support: support@avocadoai.co