Privacy
Privacy at Agentic Verification Architecture
We build verification software. The shortest honest summary of our privacy posture is that we verify credentials, not people, and we keep as little data as the job allows. Each product's practices are below.
AVA Pay
AVA Pay verifies the cryptographic credentials carried by AI shopping agents and lets merchants set policy for verified traffic.
What we process. When a merchant's store forwards an agent request for verification, we process the request's signature headers, the agent's public key material, and the URL and method being verified. These describe software agents and their operators, not the merchant's customers. Merchants are instructed to strip cookies, authorization headers, and session data before forwarding, and the verifier does not want or use them.
What the Shopify app stores. For merchants who install AVA Pay for Shopify, the app records verification events and commerce events so the merchant can see which agent visits become orders: shop domain, order and checkout identifiers, discount codes, amounts, timestamps, and the verification outcome. It stores no customer names, no email addresses, no phone numbers, and no postal addresses. The app requests no access to those fields from Shopify.
What we do with it. Event data renders the installing merchant's own dashboard. We do not use it for cross-merchant profiling, advertising, model training, or any purpose beyond showing each merchant their own traffic. We do not sell or share personal data with third parties.
Automated decisions. AVA Pay's automated decisions (admit an agent, apply a merchant-configured discount) evaluate the agent's cryptographic credentials against the merchant's policy. They are not decisions about any customer's personal data, and no profiling of customers occurs.
Retention and deletion. Event data is kept while the app is installed. When a merchant uninstalls, access tokens are invalidated. We honor Shopify's redaction webhooks: a shop redaction request purges all records for that store, and customer redaction or data requests are answered accurately (ordinarily: we hold no customer personal data for the request to cover).
Security. All data moves over TLS. Production data is hosted on Railway, which is SOC 2 Type II and SOC 3 certified and lists encryption at rest among its published data security controls (trust.railway.com).
Open source. The verifier is public at github.com/AVA-PAY/ava-pay, so what a verdict means can be read rather than trusted.
AVA Ready
AVA Ready scans a website the way an AI agent reads it and returns a plain-English report on what agents can and cannot understand.
What you give us. A website address, an email address so we can send the report, and optionally a business name. That is the whole form. We ask for nothing else and there is no account to create.
What a scan reads. Only the public pages of the site you name, fetched the way any visitor or search crawler fetches them, without executing JavaScript and without signing in. A scan reads at most a dozen pages plus a handful of well-known files (robots.txt, /llms.txt and similar). It never attempts to log in, never submits a form, never adds anything to a cart, and never places an order. If you scan a site you do not own, we still only read what that site already publishes to the open internet.
What we send to an AI model. Text from those public pages, capped at a few thousand characters, goes to Anthropic's Claude, which writes the narrative part of the report. Your email address is not included in what we send. The score itself is computed by our own code from measurements, not by the model.
Your email, and the follow-up we are explicit about. We use it to send your report. We may also contact you about AVA products that address what your scan found, and we say so on the form before you submit, in these words: "We'll email your report. We may also follow up about AVA products that address what the scan finds. Unsubscribe anytime." Concretely, that means a free scan produces an internal notification to our own team at help@avalayer.com containing your email, the domain scanned, the scan's score and findings, and which AVA product looks relevant. That notice goes to us and to no one outside Agentic Verification Architecture LLC. To stop follow-up, reply to any message from us or write to help@avaready.com, and one message is enough.
Reports and links. Each report is saved under an unguessable identifier so you can revisit it. Anyone you share the link with can read the report, so treat the link as you would any private URL. The saved report contains the scan findings; the email you gave us is stored alongside it in our own records and is not part of what a link recipient sees.
Payment. Paid scans are processed by Stripe. Card details go to Stripe directly and never reach our servers. We keep the fact of the purchase, the receipt email, and the scan it paid for.
What we count, and what we refuse to. Our own first-party counter records that a page was viewed and which site referred the visit. It stores no IP address, no device fingerprint, no cookies, and no identifier of any kind. There is no third-party analytics script and no advertising technology on the site. To keep the free tier from being abused we apply a short-lived rate limit keyed on the requesting network address; that value is held in memory only, for a matter of hours, and is never written to disk or associated with your email or your scan.
Who else touches the data. Three service providers, each receiving only what its job needs: Stripe (payments), Anthropic (the model that reads the public pages and writes the report), and Resend (report delivery email). We do not sell, rent, or share your information with anyone for their own purposes.
Retention and deletion. Reports and purchase records are kept so your link keeps working and so we can meet bookkeeping obligations. Write to help@avaready.com from the address you used and we will delete your report, your email, or both within 14 days, except records we are legally required to keep, such as payment records.
TOVA
TOVA is a nutrition app with an AI assistant, Tova. Because it handles personal health information, it maintains its own full privacy policy at tova.coach/privacy.html, and that policy governs TOVA. In brief:
Your data exists to power your own coaching and nothing else. The app stores what you log (foods, water, weight, exercise, goals) and what you tell Tova, on your device and in a private cloud backup locked to your account. Chat messages are processed by our AI provider (Anthropic's Claude) to generate replies, and the provider does not train on your data. Photos are processed to answer you and are not stored on our servers. Apple Health data, if you connect it, stays within the app. Food and barcode lookups query public food databases and carry the food, not your identity. No advertising, no selling or sharing of personal data, no third-party analytics or tracking SDKs. Deleting your account in the app permanently removes your data and we keep no copy. Anonymous facts about foods (never about you) may be contributed to improve the shared food database, as described in the full policy.
Questions about TOVA specifically: help@tova.coach.
This website
avalayer.com itself is an informational site: it does not require an account, does not collect personal information through forms, and does not use advertising or cross-site tracking cookies. Our hosting provider may log standard technical data such as IP address, browser type, and pages visited to keep the site running and secure. If you email us at help@avalayer.com, we use your message and address only to respond, and we never sell or share your information.
The company
Agentic Verification Architecture LLC, Raleigh, North Carolina, US. Contact for privacy matters: help@avalayer.com. If we change this policy, the effective date above changes and material changes are noted here.