Avis de confidentialité · 2026-08
Confidentialité.
Aviana fonctionne sans compte et sans publicités, sans traceurs tiers ni technologie publicitaire. Ce que nous collectons est de première partie et sans identifiant personnel : des événements d'utilisation associés à un ID d'appareil aléatoire, sans nom ni email. Votre adresse IP est stockée uniquement sous forme de hash unidirectionnel salé, jamais comme l'adresse elle-même, et nous conservons la chaîne user-agent de votre navigateur car c'est ainsi que nous distinguons les personnes des bots. La version courte se trouve ci-dessous ; la version longue suit la même structure.
The short version
- No sign-up. No email. No password.
- No third-party analytics (no Google Analytics, no Meta, no Mixpanel).
- No advertising — and no ad slot in the app to retrofit later.
- Affirmation prompts are held in memory for one request, then dropped. The generated audio is kept; the prompt isn't.
- Health data (heart rate, sleep stages) is read locally and used to drive the adaptive layer. Readings leave the device only if you opt in.
- De-identified sleep research: with your opt-in, readings with no name or email help us study what improves sleep. 90-day retention, never sold.
- De-identified usage events (which buttons you tap, decode errors) are sent to our server for product improvement. No PII. Retained 90 days.
- We store a salted one-way hash of your IP address, never the address. We do keep your browser's user-agent string, because it is how we tell people apart from bots.
- Our CDN's standard server access logs do contain raw IP addresses, like every web server's logs. They are used for security and abuse prevention only.
- The marketing site you're reading right now runs zero third-party scripts.
The long version
What identifies you to us
A random device ID is generated the first time the app runs and stored locally. It's how your saved mixes, settings, and affirmation history get linked to "you" without an account. Re-installing the app generates a new UUID, so previously-generated custom affirmations will not be visible after a reinstall today. Cross-device persistence is on the roadmap.
What we send to our server
Telemetry events: which screen you opened, which sound you played, buttons you tapped, errors that occurred. Each event carries your random device ID, the app version, and the platform (iOS / Android / Web). It does not carry an email, your name, or your IP address. Retention: 90 days.
One thing you type does get stored, and on purpose: if you send a sound or mix request from the app, we keep the full text of it. Reading what you asked for is the whole point of that feature. It is stored against your random device ID, with no name and no email.
What we send to third parties
When you generate a custom affirmation, the prompt you typed is sent to AWS Bedrock (Anthropic Claude Haiku, hosted by AWS in us-east-1) and the generated text is sent to ElevenLabs for synthesis. We hold the prompt in our server's memory for the duration of the request and drop it afterwards; the generated audio file is kept on our CDN so you can replay it.
There is a third, and it is the one nobody expects, so we would rather name it: if you use the Dictate button in the affirmation composer on the web app, the speech-to-text is your browser's own, which means the audio of what you say is sent to Google's speech recognition service on Chrome, or to Apple's on Safari, each under that company's privacy policy. The audio never reaches Aviana. We do not record it, store it, or route it through our server. We receive only the text your browser returns, and only if you go on to generate an affirmation with it, at which point it is handled exactly like a prompt you typed. The iPhone and Android apps have no Dictate button, so none of this happens there.
What we ask for, and what we don't
Camera, location, contacts, photos: Aviana does not request any of these permissions. The microphone is different, and only since dictation shipped. It is requested in exactly one place and only on demand: tapping Dictate in the affirmation composer on the web app hands the request to your browser, which asks you before anything is recorded. Never tapping it means the microphone is never requested, and the iPhone and Android apps have no Dictate button at all, so they never ask. Notification permission is asked only when you opt into the bedtime reminder or smart alarm.
Health data
With your permission, Aviana reads heart rate, HRV, and sleep stages from Apple HealthKit or Android Health Connect to drive the adaptive sound layer and the smart alarm. These values are read locally on your device and are not transmitted to our server unless you opt in. If you turn on "Contribute to sleep research" (an explicit toggle in Settings that defaults to off), Aviana sends de-identified sleep readings (heart rate, breathing rate, and inferred sleep stage) keyed to a random ID with no name or email, so we can research what actually improves sleep. Retained 90 days, never sold. Turn it off any time and nothing further is sent.
On iPhone, the Health permission sheet also asks for Workouts write access. Apple requires it so Aviana on Apple Watch can run an overnight heart rate session. Aviana does not save workouts or any other data to Health.
Cookies and the marketing-site beacon
The marketing site (this domain) sets no cookies and runs no third-party scripts. It does send a first-party, de-identified pageview beacon (the page path, the referrer, and a random ID stored in localStorage, with no name and no email) to our own server so we can count visits. The beacon honors your browser's Do Not Track setting: with DNT on, it never fires. The app (app.aviana.life) sets one localStorage key for your random device ID and one for your app preferences. No tracking cookies, no consent banner needed.
Your IP address and your user-agent
When you load this site or the app, our server needs some way to count one visitor once and to throttle abuse. It stores a salted one-way hash of your IP address, never the address itself. The hash cannot be reversed into an address, and the secret salt is not stored beside it. Nothing is derived from your IP: no city, no region, no ISP.
Your browser's user-agent string we do keep, deliberately. Most of the traffic that reaches a small app is automated (scanners, crawlers, app-store review robots), and the user-agent is how we tell a person from a machine. Without it our own usage numbers would be fiction, so we would rather retain it and say so.
One honest carve-out: our content delivery network (Amazon CloudFront) writes standard server access logs, and those logs do contain raw IP addresses, as every web server's logs do. We use them for security, abuse investigation, and measuring how many real people reach the app, and we keep them only as long as that requires. They are never used to build a profile of you, and never sold or shared for advertising.
Children
Aviana is not directed at children under 13. We don't collect data knowing you're under 13. If you believe a child has used the app and you'd like the associated UUID deleted, write to privacy@aviana.life.
Contact
Questions or deletion requests: privacy@aviana.life. Include your random device ID (Settings → About → Device ID) so we can locate the right rows.