← Aguvo

Privacy policy

# Aguvo Privacy Policy

Revision 1.1, effective 8 September 2026.

Aguvo is a voice-first child care journal. You press a button, say what
happened, check what was recognised — and the event lands in your family's
shared journal. This document describes what is collected along the way, why,
who it is shared with, and how long it is kept.

## In short

- We collect what the journal needs to work: your recordings, events about your
  children, who is in the family, and a minimum of technical data.
- Recordings and text are **not used to train models** and are not passed to
  anyone for their own purposes.
- Off-device processing can be turned off entirely. Aguvo then runs on what the
  phone itself can do.
- You can delete your account in the app. Deletion is irreversible.

## What we store

**Recordings.** The audio and its transcript, who recorded it and when. This is
what you said; we do not rewrite what was said after the fact.

**Events about children.** The category (feeding, sleep, diaper, health,
growth, skills, note), the time, values such as a feed volume or a temperature,
and which family member recorded it.

**Children.** Name and nicknames, date of birth, avatar. The date of birth is
used to show an age next to events; nothing else is derived from it.

**Family.** Members, their names, roles and avatars, and invitations.

**Account.** Your email address if you provided one, and your device identifier
as an irreversible fingerprint — enough for the app to recognise your phone
without knowing the identifier itself.

**Technical data.** App and OS version, platform, time zone, and the country
from your device settings. Needed so we answer in your time zone and can tell
which builds break.

**Crash reports and support messages** — only what you send yourself.

**Anonymous usage statistics.** Tied to a random install identifier rather than
to your account, and containing neither recording text nor children's names.
Each measurement carries: a random install identifier, the event name and when
it happened, a latency bucket (how quickly a step ran), an error code if the
step failed, the app version and build, the iOS version, the platform and
the country code. Statistics can be turned off.

## Data about children

Records about a child are a special category of data, and we treat them
accordingly:

- event content never enters usage statistics and takes no part in any
  analytics;
- the language model, unless you have turned it off, receives the recording's
  text, your children's names and nicknames, and the time of the recording —
  and nothing else; the audio is not sent to it, and neither is your journal of
  past events;
- the journal is visible only to members of your family.

## What leaves the device, and where it goes

**Speech recognition.** Audio is processed on our own infrastructure, with no
third-party services. What is sent is the recording itself and the language you
speak. Turn it off with the "Smart transcription" switch: recordings then never
leave the device, and transcription is done by the phone.

**Turning a recording into events.** The recording's text is processed by a
third-party language model to work out which child you meant, what happened and
when. The provider receives only the recording's text, your children's names
and the time; it is required not to use what it receives for training. Turn it
off with the "Turning a recording into events" switch: you then add events by
hand, and recordings are kept in full.

Both switches live on the Processing screen. Turning something off applies
going forward: it stops future processing but does not erase what is already
done.

## How long we keep it

- Recordings and events — until you delete them or delete your account.
- Original audio stops being served 180 days after it was recorded; the
  transcript and the events remain.
- Anonymous statistics — 400 days: enough to compare one year against the
  next. Crash reports — 30 days.
- The encrypted emergency copy of a deleted account — 30 days (see below).

## Deleting your account

You can delete your account in the app, under Account. On deletion:

- your recordings are deleted along with their audio and transcripts;
- if other members remain in the family, the family, the children and the
  already-confirmed events stay with them: it is their journal too, and one
  person leaving should not erase a child's history for everyone else;
- if you were the last member, the family with all its children and events is
  deleted in full.

An encrypted emergency copy of the deleted account is kept for 30 days. It has
no product read path: it exists in case a deletion was a mistake or the result
of a compromise. After 30 days it is deleted automatically. The copy is never
used for training models or for analytics.

## Your rights

You can view and change any of your data directly in the app, turn off any
off-device processing, delete individual recordings, or delete the account
entirely. For questions about your data, write to privacy@aguvo.app.

## Changes

Material changes to this policy get a new revision with a new date. We record
which revision you agreed to — so that the question "what exactly did this
person consent to" has a verifiable answer.