Privacy
Privacy Policy
Effective and last updated 12 August 2026 · Version 2026-08-12
Erynva processes documents on your computer. This policy explains the smaller amount of personal information used for the website, accounts, subscriptions and support.
1. Who is responsible
Peter Stoney, a sole trader operating under the registered business name Erynva (ABN 42 423 397 171), based in Victoria, Australia, operates Erynva and is responsible for the personal information described in this policy. Where another law uses the term “controller”, Peter Stoney is the controller. “Erynva”, “we”, “us” and “our” refer to that business.
The current launch offering is intended for people and organisations in Australia. Privacy questions, access or correction requests, deletion requests and complaints can be sent to support@erynva.com. Address the email to the Privacy Contact and do not attach documents, filenames, OCR text or extracted document content.
2. Document processing stays local
Erynva’s document workflow does not upload your PDFs, images or extracted document text to Erynva’s account service or a cloud AI service. The following remain on your device:
- documents, pages, previews and crops;
- filenames, file paths, file hashes and source identities;
- OCR text, extracted fields and reviewed values;
- local corrections, learned locations and rename history; and
- the daily free-use date and count.
Text recognition uses Apple Vision on macOS or Windows OCR on Windows. Document understanding uses a model downloaded to and run on your computer. A model download discloses ordinary network information, such as your IP address, to the download provider, but it does not include your documents or extracted content.
If you explicitly publish a reusable rule to a shared Erynva account, only the privacy-reduced rule data shown by the app is sent. Do not publish a rule that contains personal, confidential or identifying text.
3. Personal information we collect
Depending on the features you choose, we collect:
- Account and identity: email address, authentication provider, provider account identifier and internal account identifier.
- Billing and purchase eligibility: billing name and address collected by Stripe, payment status and references, plan and renewal details, Australia-only purchase attestation, and billing country retained with the acceptance record. Erynva does not receive or store your full card number.
- Device and entitlement: a random installation identifier, user-provided device label, platform, activation and last-seen times, plan status and entitlement dates.
- Shared-account data: account roles and privacy-reduced presets, aliases or reusable rules you explicitly publish.
- Billing: Stripe customer and subscription identifiers, plan, payment and renewal status, invoice or transaction references and billing contact details made available by Stripe. We do not receive or store your full payment-card number.
- Support: your email, message and non-sensitive diagnostic information you choose to provide.
- Website and security: IP address, browser and device information, requested page, referral information, timestamps and security events produced by Cloudflare and hosting infrastructure.
We collect information directly from you, from the desktop app, automatically from website requests, or from Google, Supabase and Stripe when you use their connected services. You can use the daily free allowance without an Erynva account, and Erynva does not send a document-usage ledger to its service.
4. Why we use it
We use personal information only as reasonably needed to:
- create and secure an account, complete sign-in and provide requested features;
- verify subscriptions, enforce device limits and deliver shared rules you choose to publish;
- take payment, administer renewal, provide billing statements or receipts and handle refunds or disputes;
- deliver, protect and troubleshoot the website and account services;
- answer support, privacy and legal requests; and
- prevent fraud or abuse and comply with legal, accounting and consumer obligations.
In plain terms, these uses are necessary to provide the service or take steps you request, to meet legal obligations, or for proportionate security and service-administration purposes. We ask for consent where the law requires it, including when you choose an optional sign-in method or explicitly publish shared rule data. You may withdraw consent for future processing, but that does not undo lawful processing already completed.
We do not sell personal information, build advertising profiles from it, or use your document content to train models.
5. Providers and their roles
- Cloudflare delivers and protects the website, downloads and network traffic and produces request and security logs on our behalf.
- Supabase supplies authentication, database and server-function infrastructure for accounts, devices, entitlements and explicitly shared rules.
- Stripe hosts checkout and the billing portal and processes payments. Stripe handles information for Erynva and also makes its own decisions where required for payment security, fraud prevention and legal compliance.
- Google supplies the optional Google Identity Services interface. Its script loads automatically on Erynva’s website-account and desktop-app sign-in pages; Google receives connection and browser information even if you instead use email. If you choose Google, Google supplies an identity credential used to create or access your Erynva account.
- Software distribution providers deliver installers, local models and updates and receive ordinary download request information.
These providers may use approved subprocessors. We disclose only the information needed for the relevant service, and document content is not intentionally disclosed through Erynva’s document workflow.
6. Overseas processing
Erynva is operated from Australia, but its global providers may process personal information outside Australia. A known or likely location is the United States, where Cloudflare, Google, Stripe, Supabase group companies or their subprocessors operate. Cloudflare may process network and security data through points of presence in Australia, the United States and other countries selected automatically by its global network. Provider support, fraud, resilience and subprocessor operations may involve additional countries listed in each provider’s current subprocessor documentation.
The exact Supabase project hosting region and the complete launch-date subprocessor country list must be confirmed before paid launch. You may request the current configured region and likely disclosure countries from support@erynva.com. Using an overseas provider can mean the information is subject to the laws of that country. Where Australian privacy law applies, we take reasonable steps required for overseas disclosures and may remain accountable for the handling.
7. Retention schedule
We keep personal information only for the following periods, unless a longer period is reasonably required by law, a chargeback, dispute, fraud or security investigation:
- Desktop sign-in codes: unusable after five minutes and deleted when used; expired records are removed by the authentication service’s cleanup process.
- Account, active device and shared-rule records: while the account or relevant shared account remains active, then deleted or de-identified through the verified deletion process.
- Billing, receipt, refund and transaction records: ordinarily five years after the relevant transaction or the period required by applicable accounting and consumer law.
- Support and privacy correspondence: ordinarily 24 months after the matter is closed.
- Erynva-accessible website and security logs: targeted to no more than 30 days in ordinary operation; relevant extracts may be kept for up to 12 months when needed to investigate a specific security, fraud or legal matter.
Providers may keep their own payment, fraud, security and compliance records under their published policies. Deleted records may remain temporarily in restricted backups until the relevant provider’s backup cycle overwrites them; they are not used for ordinary business purposes and deletion must be reapplied if a backup is restored. The maximum backup windows and infrastructure log settings remain launch-configuration facts to be verified.
8. Account deletion and local data
You can permanently delete your account from the signed-in Delete your account page without emailing support. A fresh sign-in verifies control, and the page requires you to enter the account email and acknowledge permanence. If paid access remains, cancel renewal in Stripe and delete the account after the paid period ends. If another member depends on an account container you own, automated deletion stops so ownership can be transferred or those members removed first.
Deleting the online account does not uninstall Erynva or delete documents, local corrections, settings, rename history, models or the local free-use counter from your computers. Those remain under your control and must be removed locally. Transaction, Terms-acceptance, billing, fraud, dispute, security and backup records may remain only for the periods and purposes described above. Ordinary eligible account data is removed immediately; unusual ownership or provider failures may require support.
9. Access, correction and choices
You may ask what personal information we hold about you, request access or correction, or ask us to explain a refusal. You may also request deletion, object to particular processing, withdraw consent where processing relies on consent, or ask for a usable copy where applicable. We may verify identity and may refuse or limit a request only where the law permits. We ordinarily respond within 30 days and do not charge for making a request.
You can avoid an account by using the free local allowance, choose email instead of Google for authentication, decline to publish shared rules, deactivate devices, cancel future renewal, or stop using the online services.
10. Privacy complaints
Email the Privacy Contact at support@erynva.com with the subject “Privacy complaint”, a description of the concern and how you would like it resolved. Do not include document content. We will acknowledge the complaint, investigate it fairly, may request more information, and aim to provide a written outcome within 30 days.
If you are not satisfied and the Australian Privacy Act applies, you may complain to the Office of the Australian Information Commissioner. Other consumer and privacy remedies may also be available. We follow this policy as an operational commitment even where a particular Privacy Act provision does not apply to a small business.
11. Security and data incidents
Erynva uses row-level database controls, restricted service roles, short-lived access tokens, single-use browser sign-in codes, operating-system credential protection in the desktop apps and Stripe-hosted checkout. Access is limited to what is reasonably needed to operate and support the service. No internet or device system is risk-free, so protect your device and email account and report suspected unauthorised access promptly.
We assess suspected data incidents and will notify affected people and regulators when required by applicable law.
12. Children
Erynva’s current Australian offering is for adults and organisations and is not directed to children. You must be at least 18 to create an account or purchase a subscription. Do not send a child’s personal information to Erynva support.
13. Changes
We may update this policy when the product, providers or law changes. The updated date identifies the version. We will give reasonable notice through the website, app or account email before a material change takes effect where practicable. We will not use information already collected for a materially incompatible new purpose without any notice or consent the law requires.
