Effective July 28, 2026.
Egosi OS LLC ("Egosi OS", "we", "us"), a Delaware limited liability company, exists because of one belief: your life belongs to you. Ava only works if she knows you, and that knowledge is only possible if you can trust completely where it lives and who can touch it. This policy covers both this website and the Ava platform.
This section covers egosios.com, avadisplay.io and oneava.io. If you only visit them, we collect very little: your email when you join the early access list or ask us to get in touch (with the page you were on), anything you send through our contact options, and standard server logs (IP address, browser type, pages requested) kept for security and reliability. We run no advertising trackers, no third-party analytics, and nothing that follows you to anyone else’s website. Our pages load fonts from Google Fonts, so your browser makes one request to Google when a page loads; Google’s own policy applies to that request. If a signup form cannot reach our server, your browser may keep your email briefly in its own local storage so it is not lost. And if you talk with Ava here, what you tell her is kept on your own device, so she can remember you if you return; ask her to forget you, or clear your browser’s site data, and it is gone.
We advertise, and we want to know which of our own advertisements actually reach people rather than paying for ones that do not. To answer that we set a single cookie on our own websites, and it is worth being exact about it.
What it holds: the label on the link you arrived through, the page you first landed on, and the date you first arrived. That is all.
What it does not hold: your name, your email, any account, anything about your use of the Ava platform, and no record of the pages you read. It cannot identify you, and we do not try to work out who you are from it.
What it is used for: if you later choose to contact us, that label travels with your enquiry so we can tell which advertisement led to a real conversation. If you never contact us, it is never sent to us at all and it simply expires. It measures our advertising, not you. It is never sold, never shared with anyone, and never readable by another website.
How long: ninety days from your first visit, and coming back does not extend it. It lasts that long because deciding on something like this takes weeks, and a shorter window would credit whichever link you happened to use last rather than the one that actually reached you.
How to refuse it: if your browser sends a Global Privacy Control or Do Not Track signal, we do not set it at all, and we do not record which link brought you even for that one visit. The label is not read, not stored and not sent, and any cookie already there is removed. You can remove it at any time by clearing your browser’s site data. Everything on our sites works identically without it, and we will never make it a condition of reading anything or of getting in touch.
If you are a customer, none of this applies to you. We do not track the people who use the Ava platform in order to advertise to them. What the platform holds for you is covered by the rest of this policy, and it is yours.
Ava is not an app that holds a profile. She is a partner who comes to know your life, and that means the platform holds far more than a name and an email. Depending on what you choose to share and connect, that can include:
We tell you this plainly because the depth is the point: Ava can only care for what she knows. Everything below exists to make that depth safe.
One purpose: to serve you. Ava uses what she knows to remember what matters, understand what you mean, notice what needs attention, and act on your behalf when you ask her to. We do not use your life to advertise to you, to profile you for others, or to serve anyone else’s interest. There is no second customer for your information.
Your information is stored on infrastructure operated by us, encrypted at rest, with each file protected by its own key. Accounts are isolated: a breach of one account cannot fan out into another’s, and an organization’s data sits under that organization’s own authority. Access inside our company is limited to what is necessary to operate the platform, and reads of customer information are logged and auditable.
You. That is the default, in full. From there, sharing is consent all the way down: connecting with another person requires both sides to agree; what flows to a family member, a co-parent, a teacher, or a colleague is governed by permissions you control; and a secure share you send can be limited to a single viewing, expire on its own, and keep a complete record of who opened it. When you share something sensitive, Ava is built to handle it as carefully as you would.
Ava devices are designed so that the most sensitive sensing never leaves the room. Presence detection happens on the device itself; raw camera feeds are not streamed to our servers. Images leave a device only when you deliberately capture or scan something. Every device has its own controls: what categories of your life it may show, whether its camera or microphone is active at all, and when it sleeps. Those controls are yours, and Ava enforces them.
Parents are in charge of a child’s experience: what a child can use, see, and who they can communicate with is controlled by you. Where a school runs Ava, student information is handled under our agreement with the school and the laws that protect student records, and it stays within the school’s context. The bridge between school and home activates only when a family chooses it, and each family controls what flows in each direction. Nothing about your home life reaches a school, and nothing about school reaches your home account, without that consent.
Some of our customers are organizations rather than individuals: a business running Ava for its operations, or a school running one of our products. In these deployments the organization is the customer. Accounts inside a deployment belong to the organization’s own staff or members, are created only by the organization’s invitation, and carry only what the organization provides, such as a name, a work email address, and a role. Where the organization has its own sign-in system, staff use it, and we never hold their passwords. The organization controls who has access and what each role can do.
An organization’s information is isolated under that organization’s own authority: it does not sit in third-party marketing, sales, or analytics databases, it is never sold, and no advertising is shown. If a staff member also uses Ava personally, the two lives stay separate. When a deployment ends, we return or delete the organization’s data.
This applies to whichever Egosi OS products an organization runs. Where a particular product involves different information, we describe it separately.
Ava Display is our display system for schools and workplaces: digital signage, staff screen casting, and administrator announcements. It holds no information about the people who see the screens. They do not sign in to it, have no account in it, and are not asked for anything by it; it carries content from authorized staff to the screens. There is one deliberate exception, and the host controls it: a teacher or a meeting host can put a code on the screen, shown as digits and as a QR code, and invite somebody in the room to present. Nothing reaches the screen until the host accepts that request, and anything the person types on the join screen exists only so the host can see whose request they are accepting. It is not an identity, it is not verified, and it is not joined to any record. What it stores is operational: which screens exist and where they hang, the announcements and schedules staff have written, and a record of which staff member cast or broadcast what, where, and when. Those activity records exist for the organization’s own accountability, are visible to its administrators, and are kept for as long as our agreement with the organization requires.
The screens themselves sign in with their own device credentials, not with anyone’s personal account. Each device’s access can be revoked individually, and a screen only shows what authorized staff have put on it.
Some of Ava’s understanding is computed with the help of external processing services. When that happens, they receive only the minimum needed for the moment, for the duration of the request, and they do not keep a store of your records on our behalf. They are processors, never owners. We continue to move more of this processing onto infrastructure we run ourselves.
Ava improves by understanding you better, for you. Where we learn from usage in aggregate to improve the platform, it is from patterns, not from exposing your identifiable life, and never by giving one customer’s information to another.
Ava’s value is memory, so by default she keeps what you give her until you remove it or close your account. Website signups are kept until early access opens or you ask to be removed. Operational logs are kept only as long as security and reliability require. Where law requires us to keep specific records longer, we keep only those, only that long.
The platform is built on a least-privilege, zero-trust posture: encryption at rest with per-file keys, isolated tenancy, a single authentication chain with no weaker side doors, internal services that each hold only the minimum access they need, and audit logging of access to customer information. No one can promise that breaches are impossible; we can promise the shape of the system bounds what any single failure can expose.
If a breach affects your information, we will tell you plainly what happened, what was exposed, and what we are doing about it, as quickly as responsible investigation allows and as the law requires. No burying it.
If this policy changes, we will update this page and its effective date, and we will not weaken what is promised here without saying so plainly before it takes effect.
Questions, access requests, or removal requests: use the Contact option on this site, or write to Egosi OS LLC.