Privacy Policy
Last updated: June 28, 2026
This Privacy Policy explains how Alvara ("Alvara", "we", "us") collects, uses, shares, and protects your information when you use the Alvara personal finance assistant, including our web dashboard at www.alvara.aeand our chat assistants on WhatsApp and Telegram (together, the "Service"). By using the Service you agree to the practices described here.
Who we are
Alvara is a personal finance assistant that lets you record and understand your spending by chatting with it in plain language, by text, voice note, or a photo of a receipt, and by reviewing your finances in a web dashboard. If you have any questions about this policy or your data, contact us at m.zeeshan.mec@gmail.com.
Information we collect
We only collect what we need to run the Service for you:
- Account information. Your email address, an encrypted password, and your plan. Authentication is handled by our provider (Supabase Auth); we never store your password in plain text.
- Financial information you provide. The transactions, amounts, categories, accounts, budgets, vehicle and fuel logs, and investment entries you choose to record. This data exists because you entered it, and it is yours.
- Messaging identifiers and content. When you connect a WhatsApp or Telegram account, we process your WhatsApp or Telegram user identifier and the messages, voice notes, and images you send to the assistant so we can log and answer questions about your finances.
- Voice and images. Voice notes are transcribed to text and receipt or statement photos are read to extract the transaction details. We use these only to fulfil the request you made.
- Security and technical data. Sign-in events and a coarse device or browser description (from your User-Agent), used to send you new sign-in alerts and power optional two-factor authentication.
How we use your information
- To provide the Service: record, categorize, and display your finances.
- To understand your messages, transcribe voice notes, read receipts, and answer your finance questions.
- To generate the analytics, budgets, and insights you ask for.
- To keep your account secure, including two-factor authentication, new sign-in alerts, and abuse prevention.
- To communicate with you about the Service (for example password resets, invites, and the reports you opt into).
We do not sell your personal information, and we do not use your financial data for advertising.
How we share information
We share data only with the service providers that make Alvara work, each acting on our behalf and bound to protect your data:
- Anthropic (Claude) — to interpret your messages and generate finance insights.
- OpenAI — to transcribe voice notes to text.
- Supabase — database hosting and authentication.
- Meta Platforms (WhatsApp Business Platform) — to deliver and receive your WhatsApp messages.
- Telegram — to deliver and receive your Telegram messages.
- Resend — to send transactional email such as password resets and alerts.
- Railway — application and server hosting.
We may also disclose information if required by law, or to protect the rights, safety, and security of Alvara and its users.
Data retention
We keep your account and financial data for as long as your account is active so the Service can show you your history. Voice notes and images are processed to extract the relevant details and are not retained as media beyond what is needed to complete your request. You can delete individual transactions at any time, and you can ask us to delete your account and associated data (see "Your rights" below).
Security
We protect your data with encryption in transit, hashed credentials, row-level access controls so each user can only reach their own data, and optional two-factor authentication. No method of transmission or storage is perfectly secure, but we work to safeguard your information and to notify you of significant issues where required.
Your rights and choices
You are in control of your data. You can:
- Access and review your data in the dashboard at any time.
- Correct or delete individual transactions and entries.
- Disconnect a linked WhatsApp or Telegram account.
- Request deletion of your account and all associated data by emailing m.zeeshan.mec@gmail.com from the email on your account. We will delete your data within 30 days, except where we are required to retain it by law.
Children's privacy
Alvara is not directed to children. The Service is intended for users aged 18 and over, and we do not knowingly collect data from anyone under that age.
International data transfers
Alvara is operated from the United Arab Emirates and relies on service providers that may process data in other countries. Where your data is transferred internationally, we take steps to ensure it remains protected in line with this policy.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above, and significant changes will be communicated through the Service.
Contact us
For any privacy question or request, email m.zeeshan.mec@gmail.com.
