Privacy Policy

Last updated: August 20, 2026

1. Introduction

Avery Labs Inc (“Company,” “we,” “us,” or “our”) operates Avery, an AI-powered coordination and follow-through service (the “Service”). Avery helps users coordinate meetings, remember commitments, follow up, make room for work, and keep outcomes current across messages and calendars.

This Privacy Policy explains the personal information we collect, how we use and share it, how long we keep it, and the controls available to you. If you do not agree with these practices, do not use the Service.

2. Information We Collect

2.1 Information You Provide

  • Account and profile: name, email addresses, timezone, title, availability, communication preferences, notification settings, standing instructions, and autonomy settings.
  • Messages and instructions: chat messages, web commands, forwarded or CC’d email, replies in Avery-managed threads, and feedback or support requests.
  • Commitments and outcomes: who owes what, deadlines, reminders, status changes, follow-up instructions, collection progress, completion evidence, and source references.
  • Contacts and counterparties: names, email addresses, relationship context, and preferences you or a relevant conversation provide. Avery does not request Google Contacts permission.
  • Documents and attachments: files you route to Avery and extracted text, page references, processing status, and bounded evidence needed to explain captured commitments. Avery does not retain downloaded attachment bytes or temporary signed download links after processing.
  • Phone and SMS: a phone number you provide, verification status, carrier metadata, SMS commands from your verified number, and Avery’s replies. Carrier message and data rates may apply.

2.2 Billing, Trials, and Team Information

  • Billing and trials: plan, billing interval, trial dates, subscription status, paid-through and grace dates, Stripe customer and subscription references, hosted billing-action status, and Team seat capacity. Payment card details are collected by Stripe through its hosted surfaces and are not collected or stored by Avery.
  • Team administration: Team name, role, verified work email, invitation state, onboarding completion, reserved-seat state, ownership-transfer state, and whether Team sponsorship is active.
  • Signup and trial protection: privacy-bounded enrollment, request, and trial-claim signals used to detect duplicate trials, automated signup, abusive bursts, and delivery risk. Where feasible, Avery stores keyed hashes or bounded classifications instead of the underlying signal.

Team managers may see only a member’s name, verified work email, Team role, invitation state, onboarding completion, reserved-seat state, and whether Team sponsorship is active. They cannot see a member’s conversations, commitments, calendars, connected accounts, phone or trust status, usage, personal plan, or reason for any non-Team entitlement. A Team sponsors access but does not receive ownership of a member’s private Avery data.

2.3 Google Calendar and Gmail

Connecting Google grants the permissions shown in Google’s consent screen. Avery currently requests identity information, read-only Calendar access, permission to create or update Calendar events, and read-only Gmail access. Connection credentials are stored in encrypted form.

  • Calendar: Avery reads availability, event details needed for coordination, and relevant calendar changes. It may create or update events and private work blocks when the product action and your authority settings permit. Avery does not maintain a separate full copy of your calendar.
  • Received-mail monitoring: separately opt-in for each connected account. After you enable it, Avery may inspect newly added inbox messages for explicit commitments, deadlines, changes, cancellations, or completion signals. Messages that do not contain relevant work are not retained.
  • Sent-mail monitoring: separately opt-in for each connected account. Avery may inspect a bounded initial window and new sent messages for explicit promises you made. Unrelated sent messages are not retained.
  • Sender follow: a narrower mode may look for updates from a known sender about an existing open commitment. It can update that commitment but cannot create unrelated work.

Received-mail and sent-mail monitoring are off by default. You can enable them independently, pause all monitoring, export monitoring data, request deletion, or disconnect the account in Settings. Monitoring and private capture never authorize Avery to contact another person.

2.4 Information Collected Automatically

  • Service and activity data: actions taken, processing outcomes, delivery status, errors, security events, and product activity shown to you or used to operate and debug the Service.
  • Session data: essential authentication cookies and request information needed to keep the Service secure and functional.

We do not use third-party advertising trackers, behavioral advertising pixels, or cross-site analytics cookies. We do not sell personal information.

3. How We Use Information

  • Provide scheduling, commitment capture, reminders, work blocks, follow-up, collection, completion, multilingual, and Avery-to-Avery features;
  • Generate drafts, interpret instructions, extract obligations, reconcile changes, and identify likely completion evidence;
  • Send user-authorized email, SMS, push, and in-product notifications;
  • Maintain account settings, integrations, activity history, safety controls, idempotency, and delivery evidence;
  • Administer trials, subscriptions, Team sponsorship, billing recovery, access state, and abuse prevention;
  • Secure, troubleshoot, and improve Service reliability; and
  • Comply with legal obligations and enforce our agreements.

We do not use personal information for advertising or cross-context behavioral profiling.

4. Artificial Intelligence and Automated Actions

4.1 AI Processing

Avery uses OpenAI’s API to interpret messages and documents, extract commitments, reason about calendar constraints, generate and review drafts, continue in the language of a conversation, and assist with other user-facing features. Relevant message content, document content or images, participant context, preferences, calendar context, and instructions may be sent to OpenAI for those purposes.

OpenAI states that API data is not used to train or improve its models unless the API customer explicitly opts in. Avery does not use your content to train a general-purpose Avery model. Under OpenAI’s standard API controls, abuse-monitoring logs may be retained for up to 30 days, and Responses API application state may also be retained under the provider’s then-current standard settings. Provider retention can differ by endpoint, account configuration, legal requirement, or safety event.

4.2 Outbound Authority

Draft Mode requires your approval before Avery sends external email. Smart Autonomy may send bounded routine scheduling messages when confidence and product rules permit. Commitment outreach, sensitive or ambiguous messages, and other consequential actions remain approval-gated. Monitoring, forwarding, private capture, and a detected commitment do not independently grant outbound authority.

You can change autonomy settings, edit or reject drafts, pause Avery, take over a conversation, and correct or close commitments. AI output can be wrong, so important judgment remains yours.

5. Service Providers

We use service providers to operate the Service. Current providers include:

ProviderPurposeData involved
VercelApplication hosting and runtimeRequests and content processed by the application
SupabaseDatabase, authentication, and storage servicesAccount and Service data stored by Avery
OpenAIAI interpretation, extraction, generation, and reviewRelevant messages, documents, context, and instructions
GoogleAuthentication, Gmail, and Calendar integrationGoogle data authorized through OAuth
Resend; Postmark where configuredInbound and outbound emailEmail content, addresses, attachments, and delivery events
TwilioPhone verification and SMSPhone number, verification, message content, and carrier metadata
StripeHosted Checkout, subscription billing, invoices, payment methods, and Customer PortalBilling identity and payment information provided to Stripe; plan, status, and provider references synchronized to Avery
Your browser push servicePush notification deliveryPush subscription and notification payload

Providers process data under their own contracts and policies. We may update providers as the Service evolves and will update this Policy when a change materially affects how personal information is handled.

6. Google API Services

Avery’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

  • Google user data is used only for visible user-facing Avery features and related security, support, and legal needs;
  • Google user data is not sold, used for advertising or market research, or used to train general-purpose AI models;
  • Google user data is transferred only as needed to provide those user-facing features, with user consent, or as otherwise permitted by Google’s policy;
  • Humans do not read Google user data except with affirmative permission for specific data, for security, to comply with law, or where otherwise permitted by Google’s policy; and
  • Google connection tokens are encrypted at rest using AES-256-GCM.

7. Security

We use safeguards designed to protect personal information, including TLS in transit, encrypted integration credentials, row-level database access controls, secure session cookies, webhook signature verification, rate limits, recipient and outbound safety controls, and operational logging. No security measure is perfect, and we cannot guarantee absolute security. You are responsible for protecting your account credentials and verified phone.

8. Retention and Deletion

  • Account, commitments, routed conversations, activity, and settings: generally retained while your account is active or as needed to provide, secure, and document the Service.
  • Monitoring source content: retained source excerpts and monitored message bodies expire after 90 days and are redacted; derived commitment records and provenance may remain so Avery can continue the outcome.
  • Monitoring deletion: a deletion request turns off received and sent monitoring. You have a seven-day undo window, after which Avery deletes the account’s monitoring source rows and monitoring-derived threads and commitments covered by that request.
  • Attachments: downloaded bytes and temporary signed URLs are not retained after processing. Extracted evidence and processing records may remain with the captured outcome.
  • SMS: raw inbound event bodies are redacted after terminal processing; channel-isolated conversation history and resulting Avery records may remain.
  • Billing and Team records: plan, subscription, sponsorship, invitation, capacity, payment-state, and audit records are retained while needed to provide the Service and for bounded accounting, security, dispute, and legal purposes. Billing interruption does not delete conversations, commitments, settings, or other product data.
  • Trial-abuse claims: after account deletion or final Team closure, Avery retains only a privacy-preserving keyed claim marker for 24 months from account deletion or final Team closure, then automatically deletes it unless a concrete legal hold requires longer. Avery uses the marker only to prevent a repeated no-card trial or review a directly related eligibility dispute. It is not used for advertising, Team-manager visibility, general risk scoring, access to deleted account content, or denial of a paid subscription, and does not affect eligibility for paid access. You may request review or object to this use.
  • Team departure: leaving, removal, sponsorship end, or Team closure does not transfer or delete the principal’s private Avery data. Bounded Team commercial and audit records may remain. A Team cannot export or delete a member’s product data.
  • Provider copies: providers may retain data under their own standard controls, security needs, and legal obligations, including the OpenAI retention described above.

You may request account deletion at any time. We will delete or anonymize personal information within a commercially reasonable period, subject to the specific trial-marker period above and other necessary legal, security, dispute, and backup needs.

9. Your Controls and Rights

Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a portable copy of personal information. All users can:

  • View current work, messages, activity, and settings in the Service;
  • Export monitoring data for a connected account and contact us for a broader access request;
  • Correct profile data, preferences, commitments, and status;
  • Enable received-mail and sent-mail monitoring separately, pause monitoring, request deletion, or undo that request during the seven-day window;
  • Disconnect a Google account and remove stored connection credentials;
  • Change autonomy and notification settings, reject drafts, pause Avery, or take over;
  • Review billing and Team sponsorship facts, leave an eligible Team, and use Stripe-hosted billing controls when available; and
  • Request deletion of the account and associated data.

California residents may have rights under the CCPA/CPRA, including rights to know, access, correct, and delete covered personal information and to receive non-discriminatory treatment. We do not sell personal information or share it for cross-context behavioral advertising. EEA and UK residents may have additional GDPR or UK GDPR rights, including access, rectification, erasure, restriction, portability, objection, and complaint to a supervisory authority. We process data as needed to provide the Service, for legitimate security and operational interests, with consent where required, and to comply with law.

To exercise a right, contact us below. We may need to verify your identity.

10. International Processing

Avery is operated from the United States. We and our providers may process information in the United States and other countries. Where required, transfers are supported by applicable contractual or other lawful safeguards.

11. Children

The Service is not intended for anyone under 18, and we do not knowingly collect personal information from children under 18. Contact us if you believe a child provided information to the Service.

12. Changes to This Policy

We may update this Policy as our practices, providers, or legal requirements change. We will provide notice of material changes as required by law and, where required, seek updated consent before using Google user data for a newly disclosed purpose.

13. Contact

Avery Labs Inc
6 Liberty Square, Boston, MA 02109
privacy@helloavery.com