Draft

Every document linked from this page is an unreviewed draft. None has been read by a qualified lawyer, none is in force, and none may be relied on by anybody — including us. They exist so that counsel has something concrete to mark up. The open questions are listed on this page and each one blocks publication.

Legal

Drafts, and the list of what we don't know.

A privacy policy published as fact, without review, is a worse liability than no page at all — it is a set of promises to users and regulators made by somebody who did not check. So here is what exists, marked as what it is, alongside the register of everything a lawyer still has to settle.


02 — Why they are marked this way

Two reasons, and the second is the one people miss.

The obvious reason. A privacy policy is a binding representation to users and to data-protection authorities. A terms of service is a contract. Publishing either as settled when nobody qualified has read it means making commitments we have not checked we can keep — which is the same defect as an overstated security claim, in a place where it is directly enforceable.

The less obvious reason. This is a communications product whose users may face states, and the operators of comparable services have been prosecuted — not for the code, but for how the service was described. Phantom Secure's chief executive; the operators behind EncroChat and Sky ECC. The charge in each case turned substantially on marketing a service as being for people with something to hide.

That makes our claims discipline a legal control, not a stylistic one. Every sentence on this site that says what Avano cannot do is doing legal work. It is why we will not print "untraceable", why the verification page leads with the rows that say no, and why counsel needs to review not only these documents but the security claims on the rest of the site.

03 — The register

Questions counsel must answer.

Each of these blocks something. They are grouped, and within each group the first is the one that gates the rest. Nothing on this list is rhetorical — every one was reached by trying to write a document and finding we could not finish a sentence.

A · The entity, before anything else

  1. What legal entity operates Avano, and where is it established? The site currently says “Aere Network”. Confirm the registered name, form, number and address, or tell us to stop using it. Almost every other question below changes answer depending on this one.Blocks: imprint, terms §1, privacy controller identity, governing law
  2. Is a published imprint legally required for us, and what must it contain? Several European regimes require operator identification on a website, with different mandatory fields, and the Digital Services Act adds its own contact-point duty.Blocks: imprint
  3. Do we need an EU representative, and do we need a data protection officer? If the entity is established outside the EU while offering a service to people in it, an Article 27 representative may be required. Our processing is unusual — very little data, but arguably systematic monitoring-adjacent infrastructure.Blocks: privacy policy, imprint

B · Data protection

  1. Are we a controller for the early-access email list, and what is the lawful basis? Consent or legitimate interest, and if consent, what record of it must the form capture — which currently captures none.Blocks: privacy policy, the signup form itself
  2. Is a sealed block sitting in a relay's memory under a random queue code “personal data”? This is the central question for the whole product. The identifiers are random and unlinked to any person by us, but they are stable for a period and pseudonymous data is still personal data. If the answer is yes, we are processing personal data we cannot identify, access, correct or export — and we need to know what that obliges.Blocks: privacy policy, data inventory, law-enforcement policy
  3. What do we say about access and erasure requests we cannot fulfil? A user asking us for “all data you hold about me” is asking for something that does not exist and that we could not locate if it did, because nothing maps a person to a queue. Confirm the correct wording; the wrong wording reads as a refusal.Blocks: privacy policy
  4. What retention periods must we state, and for what? Specifically: the early-access list; hosting-provider access logs we do not control; and undelivered messages held in relay memory, which have a time-to-live but no durable record.Blocks: privacy policy, data inventory
  5. Which of our infrastructure providers are processors, and do we need agreements and a published sub-processor list? The website host, the relay hosts in two countries, and any future email provider. One of them is a US company, which raises a transfer question.Blocks: privacy policy, data inventory
  6. Do we set anything requiring consent? We believe not: no cookies, no analytics, no third-party requests of any kind, self-hosted fonts. Confirm that this genuinely removes the consent obligation rather than merely reducing it, including for the one form on the site.Blocks: cookie page, and whether a banner is needed at all

C · Communications regulation and compulsion

  1. Are we a regulated interpersonal communications service, and what does that trigger? If we fall inside the European electronic communications framework as a number-independent service, obligations may attach that we currently do not meet and in some cases structurally cannot — security notification, lawful interception, emergency access.Blocks: terms, law-enforcement policy, and possibly the product
  2. What is our exposure to a UK Technical Capability Notice? Such a notice is secret, can be served on a provider of any size, and compels the building of a capability that does not yet exist. Our structural answer is that we hold no message access to hand over — but a notice compels building, and our update channel is the mechanism by which anything built would be delivered. Is the exposure real for an entity of our size and location?Blocks: law-enforcement policy, threat model, and possibly where the entity sits
  3. What is the current state of the EU scanning proposals, and what would compliance require? Our own research flags this as the least reliable paragraph we hold and says to re-verify against the primary register before relying on it. We would rather be told than guess.Blocks: law-enforcement policy, public statements
  4. How must we handle an order from a jurisdiction that is not the entity's own? Directly, or only through mutual legal assistance or a European Production Order? Who is authorised to accept service? What is the correct response to an order that is invalid on its face?Blocks: law-enforcement policy
  5. May we publish a transparency report, and are there gag provisions that would prohibit it? Including: is publishing an accurate count of zero itself problematic, given that the count changing is informative?Blocks: transparency page
  6. Confirm our position on warrant canaries. We have decided not to run one — the legal theory has never been tested, practitioners expect removing a canary to be treated as disclosure, and a secret order can simply forbid triggering it. We want that decision confirmed or overturned by someone qualified, not left as an engineering opinion.Blocks: transparency page
  7. Does a national data-retention obligation attach to a relay operator in either country we host in? Our relays deliberately retain nothing. If retention is mandatory somewhere, we need to know before it is discovered rather than after.Blocks: law-enforcement policy, hosting decisions

D · The terms themselves

  1. Is an “as is” disclaimer with liability capped at zero enforceable against consumers? Particularly in the EU, where unfair-terms rules limit what a consumer contract can exclude. What must be carved out, and what does the clause have to look like to survive?Blocks: terms §7
  2. How do we word acceptable use without creating a monitoring duty we cannot discharge? We genuinely cannot see how the service is used. Does saying so plainly help us or hurt us? Does an acceptable-use clause we cannot enforce create an expectation that we will?Blocks: terms §3
  3. Does intermediary-liability law apply to us, and at what point? If it does, we may owe a designated point of contact and a notice-and-action process — neither of which exists.Blocks: terms, imprint
  4. Governing law and dispute resolution. Follows directly from Q1 and cannot be drafted before it.Blocks: terms §9
  5. If a paid tier launches, what consumer rights attach? Withdrawal periods, price presentation, cancellation, and how any of that works when we deliberately do not know who the customer is.Blocks: terms §5, the whole billing design

E · Distribution, code and claims

  1. Does distributing this software require an export or dual-use notification anywhere? Strong cryptography, distributed internationally, with some infrastructure in the United States.Blocks: publishing the source, store submission
  2. Is AGPL-3.0-or-later compatible with app-store distribution, and what does its network clause mean for third-party relay operators? There is a known and long-running tension between copyleft licences and one major store's terms. We intend to recruit independent relay operators, which makes the network clause operative rather than theoretical.Blocks: publishing the source, store submission, the relay-operator programme
  3. Do the app-store age-verification statutes now in force in several US states apply to us, and what do they require of a developer? Reporting suggests they apply regardless of whether an app is aimed at minors.Blocks: store submission
  4. Is “Avano” clear to use and registrable in our target territories and classes? No search has been commissioned.Blocks: brand, store submission
  5. Which security claims on this site would you remove? This is the question we most want answered and it is not really a legal formality. Everything on this site is written to be defensible, but “we believe it is true” and “it will not be read as a warranty” are different tests and we have only applied the first.Blocks: nothing formally — and it is the most valuable review we could buy
  6. Is our safe-harbour statement for security researchers binding? We tell researchers we will not pursue good-faith work. Is that enforceable, does it need to bind successors, and does it need reworking to be worth the paper?Blocks: vulnerability disclosure page
  7. Are we exposed to the prosecution theory that reached the encrypted-phone operators? Those cases turned on running a service marketed to criminals. We believe our claims discipline is a direct answer to it. We would like that belief tested by someone who has read the actual charges rather than the coverage.Blocks: nothing — and it is the question with the largest downside if the answer is bad
The status of this register

Twenty-eight open questions, none answered. No lawyer has been engaged. This page is not a plan — it is the specification for the first conversation, written so that conversation does not start from a blank page and so nobody mistakes silence for a clean bill of health. When a question is answered it will be struck through here with the date and the document it unblocked, rather than quietly disappearing.