Your expertise—not your confidential history

Your decisions are the product; other people’s material is not. Last updated September 6, 2026.

You approve first

No source is submitted until you approve it.

Nobody else’s material

Your calls publish as cases. Client names, employer names and source quotes do not.

Honest limits

No regex can understand every NDA. You still review every case.

From search to publication

The right column is what Avva retains at each step. The drawing is the gate.

01

Your assistant searches

Inside the Claude, ChatGPT, Cursor, or other MCP client you chose, using history and tools it already has.

Avva retention: Nothing by Avva
02

You approve candidates

Titles and dates first. You strike personal, client, NDA, security-sensitive, and unreleased work before any source text reaches Avva.

Avva retention: Nothing by Avva
03

Approved decisions transit

The approved text passes through Studio MCP and is discarded when that response is written. It is not stored. A short-lived receipt keeps only opaque refs and coarse source kinds — never titles, quotes, or case text.

Avva retention: Opaque receipt, up to 7 days
04

A clean draft is handed off

Your decisions stay as cases — situation, call, reason — plus the criteria and stop rules behind them. Other people’s material is rejected: source quotes, client and employer names, private calibration situations.

Avva retention: Draft code + grant, up to 7 days
05

You review and publish

You inspect every field. Avva strips private residue again before saving or serving. Receipts and grants are discarded once they have done their job.

Avva retention: Published Decision Model
You see titles firstWhat publishesstrike anything privateyour model · your name
Your own assistant does the reading, on your machine and your account. It shows you titles first and you strike anything private before a line of text is submitted. Avva stores the finished model, never the decisions it came from.

Never approve

  • Passwords, tokens, credentials, private keys, or internal URLs
  • Personal data about customers, colleagues, patients, or candidates
  • Client or employer material you are not authorized to reuse
  • Security incidents, vulnerabilities, or unreleased product details
  • Exact financial, legal, or contractual facts covered by confidentiality

Good source material

  • Professional decisions you own and are allowed to generalize
  • Explanations of why you accepted, rejected, or changed an approach
  • Repeated trade-offs across different, safely approved contexts
  • Generic review patterns with identifying details removed
  • Lessons you would comfortably explain in a public talk

How we limit exposure

Titles-first approval

The assistant must ask before submitting decision text.

Strict draft format

Quotes and source locations are rejected at hand-off. Your own cases pass.

One-time codes

Eight-character codes are rate-limited and used once.

Automated scan

Publishing blocks obvious emails, URLs, credentials, phone numbers, and confidentiality markers.

Human attestation

You cannot publish without confirming every field is authorized.

Serve-time strip

Every MCP response strips private residue again before it reaches an agent.

Unkeyed calls

A proposal your agent sends through MCP, or through a preview compile, is used for that response only and is not stored.

What we can—and cannot—promise

We can enforce that Avva application code does not persist the source material your assistant read, and that a published model carries no source quotes, no client or employer names, and none of the private calibration situations used during extraction. What a published model does carry — deliberately, because it is the product — is your own decisions: the situation, the call, and your reason, in your words. Approved text still transits the hosting infrastructure while a Studio tool call is processed. We cannot tell whether an otherwise ordinary sentence is contractually confidential. Only you know that boundary, which is why you review every case before it publishes.

What we hold

Building in Studio needs no account. Google is only for publish and ownership.

Sign-in

Two ways in, one account either way: Google, or a one-time link to your work email. Either way we hold an account id, your email, an email-verified flag, and — through Google — a display name and profile image URL, plus session cookies and encrypted OAuth tokens to keep you signed in. A link sign-in stores a hashed, single-use token that expires in 15 minutes and is deleted when used. No password is ever set or stored, and there is no first-name / last-name form. Public expert credit is a Studio field you choose; it is not your sign-in profile.

Consumer MCP keys

Getting a free beta key asks for one thing: a work email. Stored as a contact on its own — never joined to the key, and never to any call your agent makes. We send the key to that address so you have it after the tab is closed; that one message is not a mailing list. Announcements are a separate, unticked box on the same form, kept on its own list, and every one of those emails carries a one-press unsubscribe. Addresses collected before that box existed are never added to it. The key itself (avk_…) is kept only as a hash plus issue time; it raises the daily call limit and returns the complete published model. It is not a login. Request deletion any time via kpdobrinov@gmail.com — the key keeps working, because the two are not linked. Earlier beta addresses that sat on the key record were moved onto this same list and scrubbed off the keys.

Organization keys

A key issued on an organization page is different, and deliberately so: it records which member it was issued to. That link is what lets an owner end someone’s access when they leave — access follows membership, not the key’s expiry. It applies to organization keys only; the free beta keys above stay possession-only.

Published models

The finished Decision Model, including your own cases, associated with your user id. Client names, employer names and source quotes do not publish, and are not retained.

Retention and deletion

Account rows and owned models last until you delete the account or we remove them for abuse or shutdown. Session cookies expire; draft codes, evidence receipts, and assessment grants expire within days. Dashboard delete removes your models from the marketplace. The public addresses stay reserved so a connector URL cannot silently point at someone else. Copies already taken of a public page or MCP response cannot be recalled.

Measurement and cookies

No advertising, no profiles, no data sold or shared for cross-site tracking.

What runs

One visit counter: Google Analytics 4. Page URL, referrer, coarse device and browser data, and an approximate location derived from your IP — Google truncates that IP on collection, and Avva never receives it. It loads from a file on this site, which is what lets the content-security policy keep blocking inline script.

EEA, the UK and Switzerland

There is no cookie banner, so nothing that needs consent may run there. Analytics storage is denied by default in those countries: the counter still reports, cookielessly — no identifier is stored on your device and Google receives aggregate signals only. Advertising storage is denied everywhere, for everyone.

Pages, not payloads

No session recording of any kind. On /studio and /dashboard the URL query string is stripped before measurement. Draft content, decision text, model fields and MCP packets are never sent to the counter — it sees pages, not payloads. The calls your agent makes over MCP never touch it either: those are server to server, with no browser involved.

The cookies themselves

Signing in sets an HttpOnly session cookie and a CSRF cookie. Outside the EEA, the UK and Switzerland the counter adds _ga. It is not used for advertising, and nothing on the site depends on it. There the legal basis is our legitimate interest in knowing whether the product is used at all — and you can refuse below, or with any content blocker.

Who holds this, and how to make us act

One address, answered by a person.

Controller and contact

Avva is an independent beta operated from Cyprus by its author, who is the controller of the data described here. Write to kpdobrinov@gmail.com. We answer within 30 days.

What you can ask for

A copy of what we hold about you, correction, deletion, restriction, objection to processing based on legitimate interest, and portability where it applies. Account deletion is self-service in the dashboard.

Who processes data for us

Netlify (hosting, functions, storage and database), Google (sign-in and analytics) and Mailtrap (delivering the emails described above). Netlify and Google operate in the United States; Mailtrap is in the European Union. No one else receives your data, and Avva sells nothing to anyone.

Complaints, children, breach

We are established in Cyprus, so the supervisory authority is the Office of the Commissioner for Personal Data Protection of Cyprus — you may equally complain where you live. Avva is not for anyone under 16. If a breach affects your data we notify you and the relevant authority as the law requires. Approved decision text is not stored, so it cannot be part of one.

Privacy requests: kpdobrinov@gmail.com. Legal terms: Terms of Use.

Common questions

Does connecting more tools give Avva access to everything?

No. Your MCP client controls tool access. Avva receives only decisions your assistant proposes and you explicitly approve.

Can I open the raw decisions Avva received later?

No — and that is intentional. Approved decision text is not stored, so there is no Avva archive for you (or us) to reopen. During extraction your assistant is told to save the approved set on your side, in a file named for that model — likeavva-decisions-b2b-pricing.json, so building a second model cannot write over the first. That file never reaches us. Keep it, and the titles-first list in the chat. Studio only shows the draft you review before publish. We do not offer a published-model file to download.

Does Avva train a model on my data?

No. Avva does not train an LLM. Your own assistant performs extraction and your users’ own agents apply the published Decision Model.