Draft

Unreviewed draft. This inventory is written from the system as built, but it has not been checked by a lawyer and it is not a statement of legal compliance. Several of the open questions for counsel — particularly whether a queue identifier is personal data at all — would change how parts of it must be worded.

Legal · data inventory

Everything that exists, and where.

A privacy policy tells you our intentions. This tells you the inventory. Every category of data that exists anywhere in this system is below, including the many where the honest entry is none — because “we don't collect that” is only meaningful next to the list of things we could have.


01 — Your identity and account

There is no account, so this section is short.

Phone numberNever collectedNot required, not requested, not storable. There is no field for one.
Email address (for the app)Never collectedThe messenger asks for no email. The website's early-access form is separate and is covered below.
Name, username or handleNever collectedYou may set a display name; it lives on your device and is shown to contacts you have paired with. It is never uploaded to us.
Account recordDoes not existThere is no accounts table anywhere in our infrastructure. Not empty — absent. Nothing records that you exist, when you first used Avano, or when you last connected.
Your identity keyOn your device onlyDerived on the phone from a recovery phrase you hold. Never transmitted to us. We could not produce it, and nor could we recognise it if somebody showed it to us.
Payment or billing identityNone todayThere is nothing to pay for. If a paid tier ever exists it is designed to settle without linking a payment to a user, and it will get its own entry here before it ships, not after.
02 — Your messages and contacts

On your phone. Nowhere else.

Message contentsYour device onlySealed end-to-end before they leave and sealed again at rest. We never hold a key that opens one. A relay carries them as opaque fixed-size blocks.
Your contact listYour device onlyNever uploaded, never synchronised, never backed up. There is no contacts table on any server of ours. Note the at-rest caveat: on a seized device the names you gave contacts are currently still recoverable, because some housekeeping records are stored under keys built from them. See the threat model.
Group membershipYour device onlyNo membership list exists on any server. A relay can nevertheless infer which addresses belong to one group by watching arrival times over a period — stated on what a relay sees, because it is a real leak even though we do not store the data.
Files and photos you sendTransiently, sealedSplit into identical padded pieces under unrelated random names, each with its own key and expiry, held in relay memory until collected or expired. The relay cannot tell the size, the type or the destination. Location and camera tags are stripped from photos before they leave your device.
Undelivered messagesRelay memory, time-limitedA sealed block waits in memory until the recipient collects it or its time-to-live expires. Its arrival time is held coarsened to the hour, which exists so an expiry can work at all and is real state we would rather you knew about.
Message backupsDo not existNo cloud copy, no export, no restore. A lost phone is lost messages.
03 — At the relay

What the server in the middle actually has.

This is the part a legal request would reach, so it is the part worth reading slowly. The full explanation is here.

Your IP addressNever receivedThe relay is reachable only as a Tor onion service and binds to loopback. Connections arrive from inside the Tor network. Your address does not reach us and is therefore not something we discard — it never arrives.
Sender identity on a messageNot in the protocolA deposit carries no sender field of any kind. It is not anonymised or hashed; the field does not exist. There is nothing to authenticate and nothing to log.
Connection logsNoneThere is no logging on the connection path. No access log, no error log naming a peer, no metrics tied to a connection.
Queue identifiers and their keysIn memory, while liveThe relay must know which slot a block belongs to in order to route it, and holds the key that authorises collection. These are random values not linked by us to any person. Whether that makes them personal data is an open question for counsel and we are not going to answer it ourselves.
Anything written to the diskNothingNo database, no state directory, no spool on the drive. Undelivered mail is checkpointed to memory-backed storage so a crash does not destroy it; those pages are never written to the block device and the machine has no swap. The relay refuses to start against a non-memory-backed directory rather than warning about it.
A copy of the relay's memoryObtainable by the hostStated because the row above is easy to over-read. The company that owns the physical machine can be compelled to image its memory without our knowledge. That image would contain live queue identifiers, their keys, undelivered blocks and the relay's own identity key. In-memory operation defeats a disk warrant. It does not defeat the machine underneath.
04 — This website

What avano.app collects when you read it.

CookiesNoneThe site sets no cookies of any kind — not analytics, not preference, not session. There is no consent banner because there is nothing to consent to. The detail →
AnalyticsNoneNo analytics service, no tag manager, no pixel, no session recorder, no heat mapping.
Third-party requestsNoneEvery asset — stylesheets, scripts, fonts, images — is served from this origin. The fonts were moved off a third-party font service precisely because it handed that company the address and browser of every visitor to a site about not creating records. The page is served with a policy that blocks any request to another host, so a regression would break the page rather than leak quietly.
Early-access email addressIf you submit oneStored for one purpose: sending you builds and related updates. Nothing else is collected with it — no name, no company, no source tracking. Ask us to delete it and we will. Retention period: not yet set, and that is one of the questions for counsel rather than an oversight we are hiding.
Hosting logsHeld by our host, not usThe website runs on third-party hosting which may keep transient technical records for security and abuse prevention. We do not use them to profile anyone and we do not have a copy. We cannot currently state the retention period because it is the host's, and saying otherwise would be a claim we have not checked.
Anything linking the site to the appNothingThere is no identifier shared between this website and the messenger. Reading this page and using Avano are unconnected events and there is no mechanism by which we could join them.
05 — Third parties

Who else is involved, and what they can see.

Website hostingSees visitorsThe site is served by a commercial hosting provider, which necessarily sees the connection that fetches these pages. Nothing about the messenger passes through it.
Relay hostingOwns the machineOur relays run on rented virtual machines from commercial providers in two countries. They cannot see message contents or user identities; they can, under compulsion, see the machine — see the memory-image row above.
The Tor networkCarries the trafficIndependent relays we do not operate and do not control carry your connection. This is the point: no single party, including us, sees both who you are and what you are doing. Your use of Tor is subject to how Tor works, which is documented publicly by its own project.
Apple / Google push servicesNot usedThere is no push integration on either platform. Avano posts no notifications and nothing arrives in the background. This row exists because earlier drafts of our own material described an iOS push limitation for a feature that does not exist — an inherited claim we had not checked, corrected here.
App storesNot yetAvano is not in any store today; the build is installed by hand. When it is, the store operator will know who downloaded it, which is a real and unavoidable consequence of that distribution channel and will be stated here at the time.
Advertising, data brokers, analytics vendorsNone, everThere is no advertising in Avano, no data is sold or shared for marketing, and there is essentially nothing that could be sold. This is a structural claim, not a policy one — the data does not exist to be sold.
06 — What this means for a legal request

The list above is the answer to a subpoena.

Compulsion produces what the records contain. Read the inventory again with that in mind: for the messenger there is no account, no identifier, no address, no sender, no contact list, no group list, and nothing on a disk. The most an order could reach is a set of random queue codes and sealed blocks that nobody, including us, can attribute to a person or open.

The exception is the early-access email list on this website, which is a plain list of email addresses and would be produced if lawfully ordered. If that matters to you, do not submit the form — write to us instead, or simply wait.

How we handle a legal request → · How many we have received →