Privacy Policy for Avandar Labs
Avandar Labs, Inc.
InfoEffective Date: June 24, 2026
Last Updated: June 24, 2026
447 Broadway, Fl 2 PMB 2804, New York, NY 10013, United States
privacy@avandarlabs.com
This Privacy Policy describes how Avandar Labs, Inc. (“Avandar,” “we,” “our,” or “us”) collects, uses, stores, shares, and protects personal information when you use our platform, website, desktop application, and related services (collectively, the “Platform”). By accessing or using the Platform, you acknowledge that you have read and understood this Privacy Policy.
This Privacy Policy applies to both registered users and unregistered visitors who access publicly available content on the Platform. It covers our web application at https://app.avandarlabs.com and our website at https://www.avandarlabs.com, and, when released, our desktop application downloadable from our website.
1. Who We Are and How to Contact Us
Avandar Labs, Inc. is a Delaware corporation operating a cloud-hosted data management platform designed for nonprofits, social enterprises, and mission-driven organizations. We enable organizations to integrate, analyze, and visualize program and operational data.
For any questions, concerns, or requests relating to this Privacy Policy or your personal data, please contact us at:
Avandar Labs, Inc.
447 Broadway, Fl 2 PMB 2804
New York, NY 10013, United States
Email: privacy@avandarlabs.com
For users in the European Economic Area (“EEA”), the United Kingdom, or Switzerland: where required by applicable law, Avandar Labs, Inc. acts as the data controller with respect to personal data processed through the Platform. If you have unresolved privacy concerns that we have not addressed satisfactorily, you have the right to lodge a complaint with your local data protection supervisory authority.
2. Information We Collect
We collect information in the following categories:
2.1 Information You Provide Directly
- Account registration information: your name and email address when you create an account.
- Payment information: if you subscribe to a paid plan, billing and payment information is collected and processed directly by our payment processor, Polar (which uses Stripe). Avandar does not directly receive, store, or process your full payment card details.
- Profile and workspace information: optional profile photo; workspace name, description, and settings that you configure.
- Communications: messages, feedback, comments, or other content you submit to us or post within the Platform.
- AI interactions (LLM inputs and outputs): prompts you submit to AI features and the AI-generated responses, along with any feedback you provide on those responses (e.g., ratings or in-app interactions).
2.2 Data You Upload or Connect (“User Data”)
The Platform allows you to work with your own datasets in two ways:
Manually uploaded files (e.g., CSV or Excel files): When you upload a file, the raw data is transmitted to and stored on our servers. We treat the act of uploading as your grant of permission for this storage. At the time of upload, we will clearly indicate that your file will be synced to the cloud. You may opt out of cloud storage at the time of upload or at any time thereafter by unchecking the cloud-sync option in your settings. If you do so, we will promptly delete the file from our servers.
Connected third-party services (e.g., Google Sheets, Airtable, or your own databases): Your underlying data remains in those third-party services. We access it solely to perform the analytics queries you request. We do not copy connected data to permanent storage on our servers. We may, however, copy it temporarily in two limited ways:
- In-memory processing: raw data accessed to answer a query exists in our server memory only for the duration of that query and is purged immediately upon completion.
- Short-term cache: to improve performance for teams asking similar or related questions, we may temporarily cache a copy of accessed data. This cache is automatically cleared once our systems determine there is no further speed advantage to retaining it (e.g., once the team is no longer actively querying those rows). This storage is always ephemeral.
We will never copy connected data to permanent storage on our servers without your explicit prior consent. Currently no features require this; if we introduce such features in the future, we will seek your consent before doing so.
2.3 Metadata
Regardless of whether you upload or connect your data, we collect and retain metadata about your datasets, including data size, file formats, data types, and column names. This metadata is retained in our databases and used to operate, improve, and secure the Platform. It does not include the raw contents of your data.
2.4 Automatically Collected Information
When you use the Platform, we automatically collect certain technical and usage information, including:
- IP address and approximate geographic location (country or region level).
- Browser type, version, and operating system.
- Pages or features accessed, actions taken, and time spent on the Platform.
- Referring URLs and session identifiers.
- Client-side storage technologies (browser localStorage, IndexedDB, and operating system credential store on desktop). See Section 5 for additional details.
- Product usage events: when you are signed in, we record metadata about your activity on the Platform. See Section 3.6 for additional details.
For unauthenticated users who view public dashboards, we collect only the above technical and analytics data. No personal account information is collected from unauthenticated visitors.
For workspace eligibility-monitoring purposes, we run a weekly automated algorithm that analyzes workspace metadata (including workspace name and description provided by you, dataset titles, column titles, and dashboard titles and descriptions). This algorithm does not incorporate or analyze raw data from your datasets.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 To Provide and Operate the Platform
- Create and manage your account and workspaces.
- Process subscription payments through our payment processor.
- Enable data integration, analytics, and dashboard functionality.
- Deliver AI-powered features by routing your inputs to our LLM service provider.
- Send transactional communications (account confirmations, billing notices, support responses).
3.2 To Improve and Develop the Platform
- Analyze aggregated usage patterns and platform performance.
- Use dataset metadata (not raw data) to optimize our infrastructure and services.
- Train and improve our machine learning models, subject to the limitations described in Section 3.3.
3.3 AI and Machine Learning Training
Our use of your data to train or improve AI and machine learning models depends on your subscription plan:
Free plan users: By using the free tier, you agree that we may use your LLM inputs (prompts), LLM outputs (AI responses), and your feedback on AI outputs to train or improve our machine learning models.
Paid plan users: By default, we do not use your LLM inputs or outputs to train or improve our models. However, we do use feedback signals (for example, thumbs up or thumbs down ratings on AI responses) to train and improve our models. Providing feedback on any AI response is entirely optional. When you provide feedback on a specific AI response, that act is treated as your consent for us to use the full conversation associated with that response, including the prompts and AI outputs, for training purposes, in addition to the feedback signal itself. This consent applies only to the specific conversation on which you provided feedback; it does not extend to any other conversations.
Regardless of plan tier or opt-in status: we will never use the raw contents of datasets you have imported or connected to the Platform for AI training purposes. We will use only prompts, AI responses, and interaction feedback. We note, however, that if you include raw data within your own prompts or if the AI incorporates raw data in its responses, that content becomes part of the interaction record; we cannot retroactively exclude data you chose to include in a prompt.
The following safeguards apply to both the free plan and paid plan users:
- De-identification: any feedback, inputs, and outputs used for training are de-linked from your user account and any customer identifier before entering our training pipeline.
- No raw dataset contents: we will never include the raw contents of your imported or connected datasets in training data, beyond any data you or the AI included within the conversation itself.
- PII masking: before any LLM input or output enters our training pipeline, we apply automated personal information detection and masking. Any personal information identified by this process is masked (rather than removed) to preserve the structure and context of the interaction while protecting personal information.
3.4 For Marketing and Communications
We will not use your content or data for marketing without your specific prior authorization. If we wish to feature your work, we will contact you directly and obtain your express consent before doing so. You may opt out of any marketing communications at any time.
3.5 For Safety, Security, and Compliance
- Detect, investigate, and prevent fraudulent transactions, abuse, or security incidents.
- Enforce our Terms of Service, including verifying eligibility for social-sector pricing plans.
- Comply with applicable legal obligations.
3.6 Product Usage Analytics
When you use the Platform while signed in, we record the following metadata about your activity and associate it with your account: features used, login timestamps, dataset operations performed, and API requests. We use this information to understand which features are valuable, identify active and at-risk accounts, prioritize improvements, detect abuse, and inform billing and eligibility decisions. We do not share this information with advertising networks or external analytics vendors, and we do not use it to build behavioral profiles for marketing purposes.
Open-source transparency: our product analytics are developed entirely in-house and are not delegated to a third-party analytics tool. The implementation is publicly reviewable in our open-source codebase at https://github.com/AvandarLabs/avandar.
Storage location: product usage event data is stored in our primary application database, managed by Supabase, alongside other application data. It is subject to the same regional routing, infrastructure controls, and security measures described in Section 4. No separate third-party analytics vendor or data warehouse is involved.
Retention: individual-level product usage event data is retained for a period of 13 months. After that period, we retain only aggregated, non-identifying statistics.
Legal basis (EEA, UK, and Swiss users): we process product usage data on the basis of our legitimate interests in operating, securing, and improving the Platform. EEA, UK, and Swiss users have the right to object to this processing; see Section 8.2 for how to exercise this right.
4. How We Store and Protect Your Data
4.1 Infrastructure and Data Centers
We host the Platform on infrastructure provided by Vercel (for application delivery) and Supabase (for database management), both of which operate globally across multiple geographic regions. These providers are built on Amazon Web Services (“AWS”) and, as a result, we rely on AWS regional infrastructure for physical data storage and processing.
Our infrastructure is configured to route and store data in the AWS region geographically closest to the user. This means that data from users located in the European Union will be directed to, processed in, and stored within EU-based AWS data centers, and will not be transferred outside the EU region. This regional routing applies globally: your data is processed in and stored within the AWS region nearest to you. We control the data center region but not the specific data center within that region.
Because Vercel and Supabase operate on AWS and use EU-region data centers for EU users, transfers and storage of EU personal data comply with the requirements of the GDPR regarding data localization and cross-border transfers without requiring separate transfer mechanisms for storage.
4.2 Third-Party Infrastructure Providers
We share data with the following infrastructure partners as necessary to operate the Platform:
- Supabase – database management service. Application and account data is stored here.
- Vercel – application hosting and content delivery.
- Upstash – ephemeral caching service used for temporary, short-term data access acceleration. User data is never stored permanently in Upstash; all cached data is automatically purged.
- OpenRouter – LLM routing service. When you use AI features, your prompts are sent to OpenRouter, which routes them to the AI model you select from a list curated by Avandar. We restrict the available models to those whose underlying providers contractually guarantee that they will not use customer inputs or outputs to train their own models. This ensures that upstream AI providers’ practices remain consistent with the commitments Avandar makes in this Privacy Policy.
- Resend – email delivery service. Your name and email address are shared with Resend solely for the purpose of sending and receiving transactional and service emails.
- Polar / Stripe – payment processing. Payment information you provide during checkout is collected and processed by Polar, which uses Stripe. Avandar does not store your full payment card details.
- Featurebase – customer support and product feedback. Our web application embeds the Featurebase widget on every page. This widget is initialized with your user ID, email address, full name, avatar URL, and workspace metadata in order to enable feedback submission and customer support. Featurebase may set cookies on its own domain (do.featurebase.app) in connection with the widget. Featurebase is contractually required to process this data only to operate the feedback functionality. See Featurebase’s own privacy policy for further details.
Each of these providers is contractually required to process your data only as directed by us and in a manner consistent with applicable data protection laws.
4.3 Security Measures
We implement appropriate technical and organizational safeguards to protect your personal data against unauthorized access, disclosure, alteration, or destruction. These measures include encryption in transit (TLS/HTTPS), access controls, and monitoring. No method of transmission over the Internet or electronic storage is completely secure; we cannot guarantee absolute security. We will notify affected users in the event of a personal data breach, as described in Section 7. For data designated for AI training use, we apply an automated personal information detection step and mask any detected personal information before the data enters our training pipelines.
4.4 Data Retention
We retain personal data and metadata for as long as your account is active or as needed to provide the Platform’s services. References in this Policy to data being stored “permanently” mean that it is retained indefinitely unless and until you request deletion, terminate your account, or we are otherwise required to delete it. Upon account deletion or a verified deletion request, we will promptly request deletion of your data from all our infrastructure providers. We cannot guarantee the timing of deletion by third-party providers, as they may be subject to their own retention schedules.
5. Cookies and Tracking Technologies
Avandar does not use cookies to authenticate users or to analyze usage. We do not run third-party analytics, advertising, or behavioral tracking on the Platform.
We do use the following client-side storage technologies, which are similar in nature to cookies and are described here for transparency:
- Browser localStorage (web application): used to persist your authentication session and to remember user interface preferences such as your selected AI chat model and panel layout. No personal data beyond what is necessary for these functions is stored.
- Browser IndexedDB (web application): used to store local caches of data to improve system performance. This local data remains on your device and is only transmitted to Avandar’s servers in accordance with Section 2.2.
- Operating system credential store (desktop application): the desktop application (currently in development) uses your operating system’s secure credential store (Keychain on macOS, Credential Manager on Windows, libsecret on Linux) to persist your authentication refresh token. No HTTP cookies are used by the desktop application.
Third-party cookies: the only third-party script embedded on the Platform is the Featurebase feedback widget (see Section 4.2). Featurebase may set cookies on its own domain (do.featurebase.app) in connection with the widget. See Featurebase’s privacy policy for details.
Disabling browser storage may prevent the Platform from functioning correctly, including signing in. We do not sell data collected through any of these technologies, and we do not use it for third-party advertising.
6. Sharing of Personal Data
We do not sell your personal data. We share personal data only in the following circumstances:
- With infrastructure and service providers as described in Section 4.2, solely to operate the Platform.
- With payment processors to facilitate subscription billing.
- As required by law, regulation, court order, or governmental authority.
- To protect the rights, property, or safety of Avandar, our users, or the public.
- In connection with a merger, acquisition, or sale of assets, in which case we will notify you and the acquirer will be bound by this Privacy Policy or a materially equivalent policy.
- With your explicit consent for any other purpose not listed here.
We do not share your data with marketing partners or sell it for advertising purposes.
7. Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you and, where required, the relevant supervisory authority without undue delay. For breaches subject to GDPR, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. Our cloud infrastructure providers (Vercel and Supabase) are themselves subject to GDPR and contractually obligated to notify us of any breaches affecting our data, enabling us to meet this obligation.
8. Your Rights and Choices
Depending on your location, you may have the following rights with respect to your personal data:
8.1 Rights Available to All Users
- Access: request a copy of the personal data we hold about you.
- Correction: request that we correct inaccurate or incomplete personal data.
- Deletion: request that we delete your personal data. Upon receiving a verified deletion request or account termination, we will initiate deletion from our systems and request deletion from our infrastructure providers.
- Portability: request your personal data in a structured, commonly used, machine-readable format.
- Opt-out of marketing: unsubscribe from marketing communications at any time via the unsubscribe link in our emails or by contacting privacy@avandarlabs.com.
- AI training opt-in / opt-out: paid plan users may opt in to AI training use via their account settings; free plan users may contact us to discuss their options.
8.2 Additional Rights for EEA, UK, and Swiss Users (GDPR and UK GDPR)
If you are located in the EEA, United Kingdom, or Switzerland, you have the following additional rights under the General Data Protection Regulation (GDPR) or equivalent legislation:
- Right to object: object to processing of your personal data where we rely on legitimate interests as the legal basis, including for direct marketing and product usage analytics (see Section 3.6). To object to product usage analytics processing, please contact us at privacy@avandarlabs.com.
- Right to restrict processing: request that we restrict processing of your personal data in certain circumstances (e.g., while you contest its accuracy).
- Right to withdraw consent: where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: you have the right to lodge a complaint with your local data protection supervisory authority. In the EU, this is the authority in the member state of your habitual residence, place of work, or place of the alleged infringement.
Legal bases for processing: we process personal data on the following legal bases:
- Performance of a contract: to provide the Platform services you have subscribed to.
- Legitimate interests: to operate and improve the Platform, ensure security, and detect abuse, where such interests are not overridden by your rights.
- Consent: for AI training use (free plan), marketing, and optional platform features. You may withdraw consent at any time.
- Legal obligation: to comply with applicable laws.
8.3 California Privacy Rights (CCPA / CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), including:
- The right to know what personal information we collect, use, disclose, and sell (we do not sell personal information).
- The right to delete personal information we have collected from you, subject to certain exceptions.
- The right to correct inaccurate personal information.
- The right to opt out of the sale or sharing of personal information (we do not sell or share personal information for cross-context behavioral advertising).
- The right to non-discrimination for exercising your privacy rights.
To submit a request, contact privacy@avandarlabs.com. We will verify your identity before processing your request and will respond within the timeframes required by law.
8.4 How to Exercise Your Rights
To exercise any of the rights described above, please contact us at privacy@avandarlabs.com. We will respond to verified requests within 30 days (or within any shorter period required by applicable law). We may need to verify your identity before fulfilling a request.
9. International Data Transfers
Avandar is incorporated in the United States. If you are located outside the United States, your data will be processed in the AWS region closest to you. For EEA, UK, and Swiss users, this means your data is stored and processed within EU-region data centers and does not leave the EEA, consistent with GDPR requirements on data transfers.
Where transfers outside the EEA are nonetheless required (for example, for certain service-provider relationships), we will rely on appropriate legal mechanisms such as Standard Contractual Clauses approved by the European Commission or equivalent safeguards.
10. Data Processing Agreement
For users who are subject to the GDPR, UK GDPR, or other data protection laws that require a written data processing agreement between a data controller and a data processor, Avandar Labs, Inc. makes a Data Processing Agreement (“DPA”) available upon request.
The DPA governs the terms under which Avandar processes personal data on behalf of organizational users acting as data controllers, and includes provisions required by Article 28 of the GDPR, including the subject matter and duration of processing, the nature and purpose of processing, the type of personal data processed, the categories of data subjects, and the obligations and rights of the controller.
To request a DPA, please contact us at privacy@avandarlabs.com. Individual users on personal accounts who are not acting in a business or organizational capacity do not typically require a separate DPA, as their relationship with Avandar is governed by this Privacy Policy and our Terms of Service.
11. Children’s Privacy
The Platform is not directed to individuals under the age of 13 (or under 16 in the EEA where applicable), and we do not knowingly collect personal data from children. If you believe we have inadvertently collected information from a child, please contact us at privacy@avandarlabs.com and we will promptly delete it.
12. User Content and Intellectual Property
You retain ownership of the data, dashboards, analyses, and other content you create or upload to the Platform (“User Content”). By using the Platform, you grant us a limited, non-exclusive license to access, store, process, and display your User Content solely as necessary to provide the Platform’s services.
We will not use your User Content for marketing or promotional purposes without your express prior consent. We may use anonymized, aggregated, or metadata-level information derived from User Content to improve the Platform’s services, as described in Section 3.2.
We reserve the right to moderate, remove, or restrict access to any User Content that violates our Terms of Service or applicable law, including content that promotes violence, discrimination, harassment, or any other form of harm.
13. Prohibited Uses
You may not use the Platform or any content posted on it to engage in:
- Harassment, abuse, or threats against any person.
- Illegal activity of any kind.
- Solicitation, advertising, or spam directed at other users.
- Misuse or unauthorized disclosure of personal data.
- Promotion of violence, racism, sexism, homophobia, xenophobia, antisemitism, ableism, or any other form of bigotry or dehumanization.
These prohibitions apply to public dashboards, workspace comments, messages to team members, and any other content or communications features available on the Platform, now or in the future.
14. Account Suspension and Termination
We reserve the right to suspend or terminate any account or workspace for the following reasons:
- Plan misuse: our standard-rate plans are designed exclusively for social-sector and mission-driven work. Any workspace on a standard-rate plan that we determine, through our automated eligibility-monitoring process (see Section 2.4), is being used for for-profit, non-social-cause purposes, is subject to suspension or termination. Such workspaces must subscribe to our commercial-rate plans.
- Prohibited content or conduct: any workspace or account, on any plan, that we determine is being used for projects or communications intended to promote oppression, violence, or discrimination (as described in Section 13) is subject to immediate suspension or termination.
You may terminate your account at any time. Upon termination, we will initiate deletion of your personal data and request deletion from our infrastructure providers as described in Section 4.4.
15. Communications
We send transactional emails related to your account, such as account confirmations, billing notices, and service announcements. We may also send you marketing communications if you have opted in or if permitted by applicable law. You can unsubscribe from marketing emails at any time using the unsubscribe link in those messages or by contacting privacy@avandarlabs.com.
We do not currently send push notifications or SMS messages. If we introduce these channels in the future, we will provide appropriate notice and opt-in or opt-out mechanisms.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date at the top of this Policy and post the revised version at https://www.avandarlabs.com/privacy-policy. We encourage you to review this Policy periodically. Your continued use of the Platform after the posting of changes constitutes your acceptance of those changes.
17. Governing Law, Venue, and Dispute Resolution
This Privacy Policy and any disputes arising from or relating to it, or to our collection, use, or disclosure of your personal data, are governed by the laws of the State of New York, without regard to its conflict of laws principles.
Any legal action or proceeding arising out of or relating to this Privacy Policy that is not subject to arbitration shall be brought exclusively in the state or federal courts located in New York County, New York. You hereby irrevocably consent to the personal jurisdiction of, and venue in, those courts and waive any objection that such courts are an inconvenient forum.
17.1 Class Action Waiver
TO THE FULLEST EXTENT PERMITTED BY APPLICABLE LAW, YOU AND AVANDAR LABS, INC. EACH AGREE THAT ANY CLAIM OR DISPUTE ARISING OUT OF OR RELATING TO THIS PRIVACY POLICY, OR TO OUR COLLECTION, USE, OR DISCLOSURE OF YOUR PERSONAL DATA, SHALL BE BROUGHT SOLELY IN YOUR INDIVIDUAL CAPACITY AND NOT AS A PLAINTIFF, CLASS MEMBER, OR PARTICIPANT IN ANY PURPORTED CLASS ACTION, COLLECTIVE ACTION, PRIVATE ATTORNEY GENERAL ACTION, OR OTHER REPRESENTATIVE PROCEEDING.
This class action waiver is governed by and construed in accordance with New York law. Under New York law, a class action waiver in a consumer contract is enforceable provided it is not unconscionable. By using the Platform, you represent that you have had a meaningful opportunity to review this waiver, that you understand its effect, and that you agree to its terms. If a court of competent jurisdiction finds this waiver unenforceable as applied to a particular claim or plaintiff, that determination shall not affect the enforceability of the waiver as to any other claim or plaintiff.
Nothing in this section limits your right to pursue an individual claim in small claims court in New York County, New York, provided your claim qualifies and remains in small claims court.
For EEA, UK, and Swiss users: nothing in this section limits your right to lodge a complaint with your local data protection supervisory authority, or to bring claims before the courts of your country of residence as provided under applicable EU or UK consumer protection law.
18. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
Avandar Labs, Inc.
Privacy Officer
447 Broadway, Fl 2 PMB 2804
New York, NY 10013, United States
Email: privacy@avandarlabs.com
We will respond to your inquiry within a reasonable time and, for formal rights requests, within any timeframe required by applicable law.