Orvia · information
Orvia privacy policy
Updated October 7, 2026
This policy explains how ninetynine.systems LLC handles data in the Orvia Android app and its hosted services. Contact sazid@ninetynine.systems with privacy questions.
Orvia is currently in internal testing. Features depend on your installed version. Hosted account deletion is available through the web; the Android deletion entry and response-reporting update are being prepared. Their availability is explained below.
Data on your phone
Orvia keeps conversations, bots, notes, reminders, automations, mini-apps, attachments, settings, permissions and activity counters in the app’s private storage. Saved provider, connector and login secrets use Android Keystore-backed encryption. This app data is excluded from Android backup.
Local data remains on your phone until you remove it. Deleting a hosted account does not erase your local conversations or settings. You can remove local data in Orvia, clear app storage in Android Settings, or uninstall the app.
Google sign-in and hosted accounts
Google sign-in supplies an identity token, account identifier and email address. Our gateway verifies the token and creates or restores your Orvia account and session. Google sign-in is required for hosted access.
We store account and session information while your hosted account exists. Refresh-token lookup uses hashes; recoverable secrets are encrypted. Expired sessions are removed through scheduled cleanup. Application logs exclude identity, access, refresh and purchase tokens.
AI providers and connected services
AI requests send your prompt, relevant conversation context, tool results and needed attachments to the selected provider. Hosted requests pass through our gateway to OpenRouter, which can route them to another model provider. Providers and connected services you configure separately receive the data needed for the features you request.
This data can include personal, health, financial, contact, calendar, document, image or audio information that you supply or allow a tool to use. Review the information and permissions before sending it.
Our gateway does not save ordinary prompts, media, tool arguments or tool results in its database or application logs. It stores account, usage and billing metadata to meter access, recover interrupted requests and prevent duplicate credits. Hosted provider calls include a stable account identifier derived with a secret key; it does not use your Google email as that identifier, but it is not anonymous.
OpenRouter, downstream model providers and connected services have their own retention and processing rules. Some endpoints may retain data or use it for training. We do not promise zero retention for every AI request. Read OpenRouter’s data collection guide, provider logging guide and privacy policy.
Google Play subscriptions
Google Play handles payments. Orvia receives purchase tokens, product and plan identifiers, order and billing-period information, acknowledgement status and subscription state to grant the correct access. We associate this information with your hosted account and keep usage and allowance records. Recoverable purchase tokens are encrypted; lookup identifiers are hashed.
Orvia does not receive your card number or bank account details through the Play purchase API. Google maintains its own payment records under its policies.
Conversation reports
Reporting is optional. The response-reporting update lets you review and consent to sending the selected AI response text, optional reason, response/conversation references, report reference, app version and creation time to sazid@ninetynine.systems. Other messages, reasoning, tool records and attachment files are excluded. Very long answers use an explicitly labelled excerpt of up to 65,536 characters. Sensitive information in the selected text or your reason is included.
Optional: email the full conversation has separate consent. Its ZIP contains conversation metadata, current messages, reasoning, tool inputs/results and referenced attachments. It excludes deleted entries, other conversations, saved credentials and phone databases. Sensitive information you wrote or attached to the selected conversation is included. Missing or oversized data makes this full export fail rather than silently omit content; that does not block preparing the response-only report.
Open email app prepares a draft and ZIP in a compatible email app. You choose the sending account and tap Send there. The recipient can see that account’s email address, and your email app may add a signature. This path sends no ZIP to our gateway. Opening the draft does not prove that it was sent.
Prepared ZIPs stay in memory until email handoff. Orvia then makes a private cache copy and grants temporary read access to that file. Copies become eligible for cleanup after 24 hours, on startup, another handoff, reboot/update and an inexact Android alarm that can be delayed. The cache is excluded from Android backup.
Send in Orvia submits only the selected-response report when the gateway’s email delivery is configured. It is currently disabled. A disabled request sends and stores nothing. If enabled, the gateway forwards the response report through Cloudflare Email Service to the company inbox without unpacking, saving in its database, queuing or logging its contents. Service acceptance is not proof of inbox delivery. The full conversation ZIP uses the separate email-app path.
Reports are used to investigate unsafe or offensive responses and improve safeguards. They are not sold or used for advertising. Our retention policy for company report emails, ZIPs and downloaded review copies is 30 days from receipt, using manual cleanup. Closing or reopening a review does not extend that period. You can request earlier removal with the report reference.
The company mailbox uses Zoho Mail. Zoho has a separate server recovery period that can retain removed email for another 30 days after it leaves Trash. See Zoho’s deletion policy. Your own drafts, sent copies and email provider’s records follow their own policies. Hosted-account deletion does not automatically identify or remove emailed reports; include their references in a separate removal request.
Account deletion and retention
You can request hosted-account and associated-data deletion without reinstalling Orvia. The web flow requires fresh Google verification and final confirmation. Support email remains available if you cannot use it. Sending an email or opening the webpage is not confirmation that deletion has finished. The Android Accounts entry needs the upcoming app update.
The self-service flow stops and verifies future Play payments, waits for running usage to settle and removes hosted Google identity/email, sessions, usage, allowance records, subscriptions and recoverable purchase tokens. It does not issue a refund. It keeps only hashed identifiers and a deletion receipt for 180 days from acceptance to handle late billing events and repeated requests; scheduled cleanup removes these after expiry. Unlinked completed billing-event receipts expire 180 days from completion. A service outage can leave a pending request that is retried; it is not reported as completed.
Until a verified deletion request is completed, hosted account and billing records remain in the active service. Backups have a separate lifecycle, so older copies can remain after removal from the active database. We cannot currently guarantee a specific expiry date for every backup copy; contact us for the retention information relevant to your request. Google, AI providers and other services retain their own records under their policies.
Service providers and operational records
Google provides sign-in, Play payments and billing notifications. Cloudflare runs the gateway and database connection service. Aiven/MySQL stores hosted account and billing metadata. Zoho Mail handles company emails. OpenRouter and downstream model providers process hosted AI requests. Any provider or connector you add has separate terms and privacy practices.
The inspected Cloudflare configuration retains queryable Worker logs for seven days. Google billing-notification subscriptions have separate seven-day retention windows; forwarding a failed notification can extend its overall lifetime. The Google project’s default operational logs have 30-day retention and its required audit logs have 400-day retention. These are operational records, not the ordinary conversation contents described above, and do not cover every provider-held security or billing record.
Device permissions
Permissions are requested for the related feature: microphone for voice, camera for input you start, contacts or calendar for requested lookups and changes, notifications for alerts, and Do Not Disturb access for interruption settings you request.
Double-tap to lock is optional. Its Accessibility service locks the screen only after your direct double-tap on empty home-screen space or a labelled Lock screen action. It does not read screen content, monitor other apps, take screenshots or collect accessibility data. You can refuse or disable it without losing other launcher features.
Advertising, security and your choices
Orvia has no advertising, general analytics or crash-reporting SDK in this app version. The Usage page is calculated locally. Its separate aggregate export excludes conversation content; a full conversation report has different contents, described above.
Remote gateway, provider and connector connections require HTTPS. Plain HTTP is allowed only for a provider running on the same device. AI processing and report email are not end-to-end encrypted against the receiving services or company reviewer.
Orvia is not directed to children under 13. You can ask about access, correction or removal of data by emailing sazid@ninetynine.systems. Do not include passwords or login/purchase tokens. We may need to verify that the request concerns your account.
We update this notice when practices change. The date above identifies this version. The company website has a separate website privacy notice.