Your data
Privacy policy
Last updated:
Your tasks stay on your devices and, if you choose to sync, on a server you control. We cannot see your tasks or activity, and Aven includes no analytics, advertising, or automatic crash-reporting SDK.
This policy covers the Aven terminal app, CLI, iPhone companion, and Android app. Aven is provided by Zendit Oy, Finland ("we" or "us").
Local storage
Aven stores tasks, projects, labels, notes, schedules, and related data in a local database. Image attachments and app settings are also stored on your device. On desktop and iPhone, this data may be included in device or filesystem backups according to your backup settings.
On iPhone, the server address and pairing credential are stored in the system Keychain. They are not synchronized through iCloud Keychain. Aven does not use iCloud to sync tasks.
On Android, tasks, attachments, and keys are kept in no-backup storage. Credentials are protected with the Android Keystore. App backup is disabled, and data-extraction rules exclude app data, including credentials, from cloud backup and device transfer.
On macOS, desktop sync keys are stored in files protected by your login Keychain. On Linux, they are stored in files only your user account can read, under ~/.local/state/aven/protected-keys by default.
Sync to your own server
Desktop sync is optional. The iPhone and Android apps connect to a user-operated sync server. What that server can read depends on the sync protocol used by your version of Aven.
Aven's encrypted sync protocol encrypts tasks, history, and images on each device before upload. The server cannot read task titles, notes, or images. It still sees device identities; random IDs for tasks, workspaces, and images; whether a change creates or deletes something; sizes, counts, and timing; and HTTP request metadata, including authentication information.
Older releases use plaintext sync with a shared server credential (sync.auth_token). With that protocol, the server can read task content, attachments, and changes. HTTPS protects the connection but does not make plaintext sync end-to-end encrypted.
We and our partners have no access to your sync server. Its operator controls access, logs, retention, and backups.
Use HTTPS or a trusted private network such as a VPN. Over plain HTTP, metadata and credentials are visible to network observers; with plaintext sync, task content is visible too. End-to-end encrypted task content remains encrypted even over HTTP. Keep pairing invitations and tokens private.
Images and external links
Synced image attachments are transferred through your configured server. Separately, Markdown descriptions and notes can contain images hosted on other websites. On iPhone and Android, these remote images are not fetched until you tap to load them.
Loading a remote image contacts its host, which receives your IP address, the requested URL, and request metadata. An image URL may contain information that identifies you. The host's privacy policy applies. Links you choose to open are also subject to the destination's data handling.
Camera and local network
The iPhone app can use the camera to scan a pairing QR code. Camera images are not saved or uploaded by this pairing flow; only the decoded invitation is used to connect. Local-network permission lets the app reach a sync server on your network. You can manage these permissions in iOS Settings.
The Android app uses the camera only to scan a pairing QR code. Camera images are not saved or uploaded; only the decoded invitation is used. You can also pair by pasting an invitation without camera access. Android uses the internet permission to connect to your server and does not request a separate local-network permission. You can manage permissions in Android Settings.
Desktop integrations and updates
If you configure a coding agent or a natural-language task intake command, that tool can receive the input and task context you give it. Tools that use a remote AI service handle that information under their own provider's policy. These integrations are your choice, not an Aven-operated AI service.
The desktop app can contact GitHub to check for updates and download releases. GitHub receives ordinary network request information, such as your IP address. These requests do not upload your task database.
Crash reports
Aven has no third-party crash-reporting SDK, advertising SDK, or usage analytics. Zendit Oy does not retrieve, view, export, query, or use Aven reports from Apple's crash feeds, App Analytics, MetricKit, or related APIs.
Apple may collect OS diagnostics under your iOS settings and Apple's privacy policy. Aven does not provide an app-side switch to disable Apple's OS collection or change your diagnostic-sharing choice. Those Apple-controlled automatic feeds are not accessed by Aven or Zendit Oy. If you voluntarily locate and send an iOS .ips crash report through external support, we handle it only to provide support and fix bugs.
An .ips crash report can include technical details, diagnostic messages, paths, and potentially sensitive context. It is not guaranteed to be free of personal information. You can manage diagnostic sharing in iOS Settings; Apple's privacy policy governs Apple's handling of diagnostics it collects.
Google may collect crash and application-not-responding (ANR) diagnostics according to your Android device settings and Google's privacy policy. Zendit Oy does not retrieve, view, export, query, or use Aven crash, ANR, or Android vitals reports from Google Play Console or related APIs. Aven does not provide an app-side switch to disable Google's collection or change your diagnostic-sharing choice. You can manage diagnostic sharing in Android Settings; Google's privacy policy governs Google's handling of diagnostics it collects.
Support correspondence
If you contact us, we receive your contact details, message, and any diagnostics or files you voluntarily provide, including a crash report you choose to send. We use this information only to provide support and fix bugs. We keep it while useful for those purposes and delete it when no longer needed; we do not promise a fixed deletion deadline.
Deleting your data
On iPhone and Android, Disconnect and erase removes the local pairing profile and task replica and may discard unsynced work. It does not delete server data or revoke access. With end-to-end encrypted sync, remove the device from another device that still syncs using aven sync device remove <device-id>. With older plaintext sync, the server operator must revoke or replace the shared server credential. To delete server copies, manage your server or contact its operator.
Deleting a task is not a guarantee of immediate permanent erasure: copies may remain in sync history, other devices, or backups. Local deletion does not erase independently retained backups or diagnostics Apple or Google may have collected under their policies. We cannot delete data from a server we do not control.
Questions and privacy requests
Contact raine@zendit.fi with questions about this policy or requests to access, correct, or delete personal information you have sent us.
Zendit Oy
Finland
Changes to this policy
We will post any changes on this page and update the revision date above.