AvoriContact us ↗

YOUR INFORMATION. YOUR CHOICES.

Privacy policy

A clear account of what Avori handles, why we need it, and the controls you have.

Effective and last updated: September 17, 2026

1. Who we are and what this covers

DREAM TUESDAY LLC operates Avori ("Avori," "we," "us"). This policy covers getavori.com, app.getavori.com, the Avori AI workspace, and the Avori · Your Chrome browser extension. Privacy questions and requests go to hello@getavori.com.

Avori helps people work with AI agents, conversations, files, knowledge, workflows, connected services, and shared work. For account, website, billing, and service-security information, DREAM TUESDAY LLC determines the processing purposes. When an organization supplies work content for us to process on its instructions, that organization may be the data controller and Avori its service provider or processor. Its own policies and any applicable agreement also govern that work content.

2. Information we handle

The information involved depends on the features you actually use. Sources include you, your authorized workspace members, services you connect, authorized browser pages, and operational records generated when you use Avori.

  • Account and workspace details: name, email, account identifiers, company or workspace membership, roles, preferences, login and security records, and subscription status.
  • Work content: prompts, conversations, instructions, uploaded files and media, knowledge, agent configurations, workflow definitions, generated answers, saved work, and comments or messages you share.
  • Connected-account information: account identifiers, granted permissions, authorization tokens or credentials needed to maintain a connection, and the records returned by services you authorize Avori to use.
  • Browser task information: the page content, tab information, commands, approval decisions, and action results described in section 3.
  • Billing and support information: plan, usage and credit records, payment-provider references and payment status, and correspondence you send us. Stripe processes checkout payment details; Avori does not need your full card number in a chat.
  • Operational information: IP address, browser or device information available in requests, timestamps, request identifiers, error and security logs, and task performance and usage records.

Content you provide or authorize can contain other people's information, personal communications, health details, financial information, location, or other sensitive data. These categories are not automatically removed from content. Only provide or authorize information you have the right to use, and avoid unnecessary sensitive information.

3. Avori · Your Chrome

The extension's purpose is to let an Avori conversation read and act on browser tabs you authorize, with local controls and approval for page-changing actions. Installing it alone does not authorize continuous monitoring of your browsing.

What is accessed and transmitted

During an authorized task, the extension can send page text, page titles and URLs, labels and types of visible controls, requested actions (including text you approve for entry), and action results to Avori. Relevant observations can then be included in the conversation and sent to the AI provider processing your task.

In optional all-tabs mode, listing tabs can send titles and URLs of eligible open tabs, including tabs whose page content has not yet been read. Page access on a new website still requires approval in the control window. Titles, URLs, page text, and action results can themselves contain identifying information, private messages, health or financial details, or location information. Task commands and approval records are user-activity information. Setup codes and connection tokens are authentication information.

Permissions and sharing modes

  • Use this tab: shares the chosen tab on its authorized website for 15 minutes.
  • Use any of my tabs: optionally requests Chrome tab and website permissions. The conversation can list eligible tabs, open and switch tabs, and request actions for two hours, extendable up to eight hours. New sites require local approval within the session. Avori may close tabs it created only with approval; it does not close tabs you opened.
  • activeTab and scripting let packaged extension code inspect and operate the authorized page. storage holds temporary connection state. Optional tabs and website permissions support the all-tabs feature. Avori's website permission also supports setup and connecting the conversation.

What the extension does not access

The extension does not read Chrome's stored browsing-history database, cookie store, saved-password store, or whole browser profile. Incognito, Chrome settings, Chrome Web Store pages, and Avori itself are excluded from task-controlled pages; Avori's own page is used separately for connection setup. Information displayed on a permitted page or contained in its URL is different from those browser stores and can be transmitted.

Visible password, payment-card, and one-time-code fields trigger protective checks. Those checks are not a guarantee that every secret in page text, labels, or URLs will be recognized. Use Take over for sensitive entry, and do not authorize pages you do not want included in AI context.

Pause, disconnect, and local storage

Take over pauses agent observation and actions. Stop and disconnect ends extension access, but cannot undo completed actions. Expired authority cannot authorize further work. Interrupted actions are not automatically replayed. You can remove website permissions or uninstall the extension in Chrome's extension settings.

The extension keeps short-lived setup codes, connection tokens, and session state in Chrome session storage, which clears when Chrome restarts. Disconnecting removes that connection's local session state. Disconnecting or uninstalling does not delete observations already saved in Avori conversations, logs, or the provider's systems; see sections 7 and 8. The extension includes no advertising or third-party analytics scripts.

Chrome Web Store Limited Use

Avori complies with the Chrome Web Store User Data Policy, including its Limited Use requirements, for information handled by this extension. This includes browsing information and information obtained through Chrome APIs.

We use extension data only for its disclosed browser-assistance purpose and related operation, security, and reliability. We do not sell it, use it for personalized advertising, provide it to data brokers, use it for creditworthiness or lending, or use it to train general-purpose AI models. These restrictions also apply to derived or de-identified extension data.

Transfers of extension data are limited to what is needed for that purpose, compliance with law, protection against fraud or abuse, or a business transfer with your prior explicit consent. Human reading is limited to your explicit consent for specific data, necessary security investigations, legal obligations, or aggregated and anonymized internal operations permitted by the policy. These stricter rules prevail over any broader provision below.

4. How we use information

We process information to create and secure accounts; carry out your instructions; generate and save work; maintain authorized connections; provide intentional sharing; meter usage and administer payments; diagnose problems; prevent abuse; answer support requests; and meet legal obligations. Service improvements use operational information and feedback. We do not operate an advertising-data business or sell personal information, and we do not share it for cross-context behavioral advertising.

Where a legal basis is required, we rely on performance of our service agreement for requested services, legitimate interests for proportionate service administration and security, legal obligations for required records, and consent where required for optional access or communications. You can withdraw consent for future optional processing without making earlier lawful processing unlawful. Refusing information necessary for a requested feature may prevent that feature from working.

5. Who receives information

We disclose information needed to provide the features you use, not all your data to every provider. The relevant recipients are:

  • Amazon Web Services (AWS): website delivery, application hosting, databases, storage, encrypted credentials, backups, and operational logs.
  • OpenAI, Anthropic, or Google: the provider selected for an available model receives prompts and relevant task context to produce responses. A task may use more than one provider only as its configured features or authorized routing require.
  • Composio: connection authorization and tool requests for integrations routed through its hosted connector service. Other integrations connect directly to the service you select.
  • Stripe: checkout, subscription payments, payment status, and related billing administration.
  • Resend: recipients and email content when Avori email delivery is enabled and used.
  • Your chosen websites and connected services: requests and information required by the tasks you authorize. Examples include Google services, Netlify, Slack, and other accounts you choose to connect. A page-changing browser action sends information to that website through your signed-in browser.
  • People you authorize: colleagues or recipients with whom you share work. Workspace roles and sharing choices determine product access; joining a workspace is not permission to expose private credentials to colleagues.

Authorized personnel may handle information as needed for service operation and support, subject to the stricter extension rules above. We may also disclose necessary information to professional advisers or authorities to satisfy legal obligations, respond to valid legal process, or protect against fraud and security threats. A corporate transaction may require a transfer of relevant records; extension data remains subject to its prior-consent restriction.

6. AI providers and connected subscriptions

AI processing requires sending the prompt and relevant context, which can include conversation history, instructions, files, authorized service results, and browser observations, to the provider running the task. A personal ChatGPT connection changes the account funding eligible models; it does not make processing local to your computer or eliminate Avori's role in storing the conversation.

Provider retention and processing depend on the provider, account type, settings, and applicable terms. We do not promise that every provider has zero retention or identical training settings. Review your provider's controls before sending sensitive material. Avori does not train its own general-purpose models on your private work content. The Chrome-specific restrictions above continue to apply to extension data.

Official subscription sign-in happens with the provider. Avori stores protected authorization state necessary to maintain your connection, not a request for you to paste your provider password into chat. Revoking a connection stops future authorized access; it does not recall previously transmitted data. Third-party websites and services maintain their own privacy policies, including OpenAI, Anthropic, Google, AWS, and Stripe.

7. Storage, retention, and security

Avori's hosted infrastructure is in the United States. Providers and authorized personnel may process information in other countries. Privacy protections can differ by country. Where applicable law requires a transfer mechanism or additional safeguards, those requirements apply; this policy is not a claim of certification under a cross-border privacy framework. Contact us for information about a particular processing route or transfer.

Production safeguards include HTTPS for public transmission, encrypted hosted storage, protected credential storage, scoped authorization, tenant-isolation controls, and access and security records. Browser-command state is encrypted and bound to the user, workspace, and conversation. These are risk-reduction measures, not a guarantee that a system can never be compromised. Do not send passwords or API keys in privacy-support emails.

We retain work content to provide your workspace and saved history until it is deleted or a valid deletion request is carried out, subject to required retention. Account, authorization, billing, audit, and security records are kept for as long as needed for their stated purpose, applicable legal obligations, dispute resolution, and fraud prevention. The criteria include whether your account or connection remains active, the sensitivity and purpose of the record, legal requirements, and whether it is needed to investigate an incident.

Backups and security or transaction records can outlast deletion from active views. Removing a connection or allowing browser access to expire is not deletion of its saved outputs. We do not promise immediate erasure from backups or third-party systems. On a request, we will explain applicable exceptions and the scope and timing of deletion; third parties may require a separate request.

Cookies and browser storage

Avori uses authentication cookies and browser storage for sign-in, security, preferences, drafts, and continuity. The public website and extension do not currently include third-party advertising pixels or session-replay analytics. Hosting services still process request and security information. You can clear browser storage and control cookies in your browser; doing so can sign you out or remove unsent drafts. Avori does not use Global Privacy Control signals to change a sale or advertising-sharing practice because we do not engage in those practices.

8. Your choices and privacy rights

You can choose what to upload, connect, share, or authorize; disconnect accounts; remove extension permissions; and use available account and content controls. For an access, correction, export, deletion, restriction, objection, consent-withdrawal, or account-closure request, email hello@getavori.com with the subject "Avori privacy request." Include the account email and enough detail to identify your request—not passwords or sensitive documents.

Depending on your location and which laws apply, you may have these rights, rights concerning sensitive information and sale or sharing, a right to appeal a request decision, and a right to complain to your local privacy regulator. California residents may have rights to know, access, correct, delete, and limit certain uses of sensitive personal information, and to exercise rights without discrimination. EEA and UK residents may also object to legitimate-interest processing and request portability where applicable. We do not make solely automated decisions with legal or similarly significant effects about you as part of administering your Avori account.

We will verify identity and, where relevant, an authorized agent's authority before disclosing or deleting information. Rights can have legal exceptions; we will explain a refusal and available review options. We respond within the time required by applicable law. If your organization controls the relevant work data, we may direct the request to it or help it respond. You can appeal a decision by replying to our response. We do not discriminate against you for exercising applicable privacy rights.

9. Children, changes, and contact

Avori is intended for adults using a work service, not children under 18. If you believe a child has supplied personal information, contact us so we can investigate and take appropriate action.

We will update the date on this page when this policy changes and provide additional notice or obtain consent when required. A policy update does not itself authorize a new use of extension data.

DREAM TUESDAY LLC · Avori
Privacy and data requests: hello@getavori.com