← Tvaily

Privacy

What this site and app collect, and what they do not.

Effective September 21, 2026. This notice covers this website and Tvaily app builds for macOS, iOS, and visionOS, including TestFlight and App Store features enabled in your build. The feature set and protected-resource permissions differ by platform. macOS desktop controls, iOS mobile and companion features, and visionOS spatial scenes are available only where the corresponding build and setting provide them. Screen Awareness is unavailable on visionOS. Features marked experimental or unavailable in your build are not promises about the current release.

Website, App Store, and TestFlight

The download link opens the Mac App Store. When offered, the public beta link opens Apple TestFlight. Neither link requires email registration on this website. Apple handles App Store downloads and TestFlight participation under its own privacy policy and terms.

The earlier beta form collected the email address you typed. This site sent that address to WorkOS, which created a pending waitlist entry with its review state and timestamps. It is used for beta registration and beta updates, including registration, service, and invitation emails. Email registration is no longer required to open TestFlight. The address is not sold, rented, or shared with an advertiser, and it is not added to a general marketing newsletter.

The site runs on Cloudflare, which handles requests and keeps ordinary server logs, including IP addresses, to serve and protect the site. WorkOS processes the email and signup status needed to operate the waitlist and send its registration, update, or invitation emails. See Cloudflare's privacy policy and WorkOS's privacy policy.

Removing website or account data

Email support@tvaily.com from the address you registered with to request removal of the WorkOS waitlist entry. Removing a waitlist entry does not remove you from Apple TestFlight; manage TestFlight participation in Apple's TestFlight app.

The app can delete local conversation history and local measurement details from Help & Diagnostics. These actions do not cancel Apple purchases or remove server-side purchase records. To delete your Tvaily account, open Avatar Store, open the account controls, choose Delete Account, and confirm. This deletes the WorkOS account and the server-side profile and account linkages. It does not cancel Apple purchases or subscriptions. The macOS avatar store can restore purchases with the same Apple Account after the Tvaily account is deleted. Required Apple transaction and purchase event records remain for purchase access, refund, and fraud handling. A limited D1 security marker retains the former WorkOS subject ID and deletion timestamp so a still-valid signed session cannot recreate the deleted account. This marker and the unlinked financial records mean deletion does not remove every historical identity reference.

Local conversation and permissions

Tvaily is AI software with a generated character and voice. The default local conversation lane keeps its journal on your device, including your transcript, generated replies, summaries, durable facts, and recent conversation history. It can use local models or an AI service that you configure yourself. Tvaily does not set a remote retention period for this local data. Use the in-app deletion control to remove it; do not treat uninstalling the app as a reliable deletion method for local data.

Microphone input and speech recognition are optional protected resources. When enabled, the app processes speech for conversation on the device under the permissions for your Apple platform. Eye Contact uses camera frames locally to estimate where you are sitting on supported macOS and iOS builds; frames are not sent to Tvaily or a model provider.

Screen context is separate. On platforms where Screen Awareness is available, the app sends no screen pixels to a Tvaily service. It can use screen capture and include extracted screen text only after you enable Screen Awareness and give the separate consent shown in the app. Either switch can stop that text from leaving the device. Ambient lighting on supported builds computes average screen colours locally and sends them nowhere.

Accounts, purchases, and configured providers

The macOS avatar store uses your Apple Account for purchases and restore. No separate Tvaily account is required. The avatar service verifies Apple-signed transactions and stores Apple product and transaction identifiers, purchase status, and purchase events in Cloudflare D1 for download access, refunds, and fraud handling. Tvaily does not receive your Apple Account password. If you use a separate Tvaily account, WorkOS handles that sign-in and the avatar service retains any existing account linkages until account deletion. The app stores the WorkOS session and user-configured credentials in Apple Keychain, including the macOS Keychain on Mac. Local conversation does not require an account.

If you configure an online endpoint or provider, the text you submit is sent to that endpoint only after you enable the relevant app setting and consent. Your endpoint, model, and credentials are your responsibility; the provider's terms, privacy policy, retention, and training practices apply. Credentials are stored in Keychain and are sent only to the configured endpoint as needed to authorize a request; Tvaily does not control that provider's handling of them.

The app can sync the selected agent profile identifier through Apple iCloud key-value storage when that capability is enabled. It does not sync the conversation journal there. When configured, Sentry receives scrubbed crash and error diagnostics, and PostHog is limited to optional feature-flag configuration. Neither is a conversation transcript service. See Sentry's privacy policy and PostHog's privacy policy.

Premium cloud conversation, realtime voice, and internal experimental paths are not part of the default release described here. Questions about this notice go to support.