Privacy Notice
This notice describes what happens to data in the Noyvia preview. It takes effect on 28 August 2026.
1. What is processed
- The text you choose to send and the necessary recent context from the same conversation.
- Audio only if you choose dictation, give separate consent, and grant microphone access.
- Technical connection data needed for transport, security, and abuse prevention, such as the IP address in Cloudflare infrastructure. The Worker derives a cryptographic hash of the IP for temporary rate limiting and does not write it to a conversation database.
Content may reveal health data or other special categories of personal data. AI processing therefore does not start without separate explicit consent.
2. Why it is processed
Text is used only to generate a response. Audio is used only for transcription. Technical data is used for operation, security, and abuse prevention. There is no automated decision-making that produces legal or similarly significant effects for you.
3. Legal basis and consent
In the preview, sending text and audio to the AI relies on your explicit consent. You can refuse consent or stop using the service. Final documentation of legal bases, together with a data protection impact assessment, must be completed before commercial release.
4. Where it is sent
Messages and audio, when dictation is selected, are sent through Cloudflare Workers and Cloudflare Workers AI. Cloudflare acts as a technical provider. Noyvia cannot promise that all technical processing is geographically limited to Greece.
Noyvia does not use analytics services, advertising trackers, or cookies. There is no Noyvia account and no email is requested for the conversation. Stripe remains inactive in the preview.
5. Storage and retention
Noyvia does not write conversation history or audio to its own database. Optional saving is off by default. If you choose it, the conversation is encrypted with AES-GCM and stored only in the browser's IndexedDB. The passcode stays on the device, is not sent, and cannot be recovered. The local file remains until you delete it or clear browser data.
When payments are enabled, Stripe will process the billing email and payment details for checkout, receipts, and subscription management. Noyvia will not store the email in its own database. The access entitlement database will contain only cryptographic hashes of access and recovery codes, Stripe identifiers, the selected plan, status, and access times. Conversation text, audio, and transcripts will not be linked to payment records.
Cloudflare infrastructure may process and retain limited technical data under its contractual terms and policies. Final retention periods and safeguards must be documented in the processing agreement before commercial release.
6. Your rights
Depending on the circumstances, you may have rights to information, access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Withdrawal does not affect the lawfulness of earlier processing. You may also submit a complaint to the Hellenic Data Protection Authority.
The official channel for exercising rights will be published with the controller's identity before commercial release.
7. What you can do now
- Do not enter names, addresses, contact details, financial details, or information about another person.
- Use local saving only on a personal, secure device.
- Delete the local file from the start screen when you no longer need it.