Privacy Policy — Awaira
Effective date: July 10, 2026
This Privacy Policy explains how Awaira handles personal data through the Awaira desktop application, the awaira.app website, purchases, support, and feedback.
1. Who is responsible for your data
Awaira ("we", "us") operates the Awaira website and desktop application. We are the data controller for the server-side processing described in this policy.
Privacy requests can be sent to hello@awaira.app. We have not appointed a Data Protection Officer because we do not currently meet the legal thresholds requiring one. Awaira is established in Armenia and has not appointed an EEA or UK data-protection representative. EEA and UK users may contact the controller directly at hello@awaira.app. This statement does not limit any rights or remedies available under applicable law.
2. The privacy boundary: detection stays on your device
Awaira uses your device's camera to detect when a hand approaches your face. Camera frames are analysed live on your device using on-device computer vision and discarded from memory after analysis. We do not receive camera video or frames.
The following remain on your device and are not sent to Awaira's servers:
- detections and daily or weekly progress;
- the behaviour you select, onboarding answers, trigger reflections, and preferences;
- locally generated insights and exported reports; and
- optional camera snapshots. Snapshots are off by default and are uploaded only if you deliberately attach one to a support or feedback submission.
Local information is stored in the application's support/container directories. Removing the app does not always remove these files. You can delete snapshots from the app's screenshots folder. To remove all local Awaira data, delete Awaira's application support/container data using your operating system's storage tools. Contact us if you need platform-specific instructions.
Because Awaira does not receive this local information, we cannot access, recover, or delete it for you remotely.
3. Information we process on our systems
We do not use advertising or third-party analytics SDKs in the app, and we do not sell personal data or disclose it for behavioural advertising.
| Activity | Information and purpose | Lawful basis where GDPR/UK GDPR applies | Retention |
|---|---|---|---|
| Free trial | Stable device identifier and trial dates, used to provide one trial per device and prevent resets. | Contract; legitimate interest in preventing abuse. | Three years after the last trial check, then deleted or anonymised. |
| Licence activation | Licence key, installation identifier, activation instance, plan, expiry, and last check, used to provide and protect a one-device licence. | Contract; legitimate interest in licence security. | While active and 24 months afterwards; longer only for a dispute or legal claim. |
| Purchases | Order/event IDs, email, plan, and status received from Lemon Squeezy, used for fulfilment, support, accounting, and fraud prevention. | Contract; legal obligations; legitimate interest in fraud prevention. | For the applicable tax/accounting period, ordinarily seven years after the transaction. |
| Discovery question | Random response ID, source, optional other text, platform, and timestamps, used to understand product discovery. | Legitimate interest. The answer is optional. | 24 months, then aggregated and the response-level record deleted. |
| Downloads | Platform, referring page, user-agent, timestamp, and a short-lived, non-reversible hash used only to de-duplicate download counts (derived from your IP and user-agent with a salt that changes daily; no IP or persistent identifier is stored, and it cannot be used to track you across days). Used to deliver and troubleshoot installers and measure platform demand. | Legitimate interest in operating distribution. | 90 days, then deleted or aggregated. |
| Waitlist | Email, optional name, source/referrer, user-agent, and timestamps, used to send a requested availability notice. | Consent. | Notice plus 30 days, withdrawal, or 24 months after signup—whichever comes first. |
| Support and bugs | Email, message, platform, user-agent, optional attachment and filename, used to respond and investigate. Attachments are emailed to hello@awaira.app. | Contract or requested steps; legitimate interest in support/security; explicit consent for health data you include. | Messages and attachments: 24 months after submission. |
| Feedback | Rating, message, optional name/email, platform, attachment, and consent records, used to review and improve Awaira. Attachments are emailed to hello@awaira.app. | Legitimate interest; consent for follow-up; explicit consent for health data you include. | Feedback and attachments: 24 months. |
| Testimonials | Feedback and name specifically selected for publication, plus the consent record. | Consent; explicit consent where health information is revealed. | Until withdrawal or three years, with annual review. |
| Security logs | IP address and request/device metadata processed by hosting infrastructure to secure and troubleshoot the service. | Legitimate interest in service security. | No longer than 30 days unless investigating a specific incident. |
Where we rely on legitimate interests, those interests are limited to operating, securing, and improving Awaira in ways users reasonably expect. You may object as described below. We do not use server data to profile BFRB behaviour.
4. Health and other sensitive information
Awaira does not receive the behaviour, detections, or progress stored in the app. A support message, feedback, attachment, or testimonial may nevertheless reveal information about your health or BFRB if you choose to include it. We do not require that information. Please share only what is necessary.
The support and feedback forms ask for explicit consent before processing health information you voluntarily include. Testimonial publication uses a separate, unchecked opt-in. You may withdraw consent at any time by emailing hello@awaira.app. Withdrawal does not affect processing that was lawful before withdrawal. We will remove a published testimonial and delete consent-based sensitive data unless another legal ground requires limited retention, such as a legal claim.
5. Service providers and other recipients
- Vercel hosts the website/API and stores support/feedback records.
- Neon provides the managed PostgreSQL database.
- Resend delivers support and operational email, including attachments, to hello@awaira.app.
- Lemon Squeezy is our merchant of record and handles checkout, payment details, subscriptions, refunds, tax, and licence issuance. It acts under its own privacy notice for those activities. We do not receive full card details.
- Meta receives website page-view events and related browser/device information through the Meta Pixel for advertising measurement and optimisation. Meta processes that information under its own privacy notice.
- Professional advisers, courts, regulators, law enforcement, or a purchaser of Awaira may receive relevant information where necessary and subject to legal/confidentiality protections.
We do not sell or rent personal data. The website's Meta Pixel is the exception to our general statement about sharing website activity with advertising providers, and is described above.
6. International transfers
Our providers may process data in the United States and other countries outside your country. Where data is transferred from the EEA or UK to a country without an applicable adequacy decision, we use the European Commission's Standard Contractual Clauses and, where relevant, the UK International Data Transfer Addendum or another legally approved safeguard. You may request information about the applicable safeguard at hello@awaira.app.
7. Whether information is required
Camera permission is needed for detection, but camera frames remain on your device. A stable device identifier is required for the free trial, and a licence key/installation identifier is required to activate Pro. Without them, we cannot provide that feature. Purchase information required by Lemon Squeezy is necessary to complete a purchase.
The discovery question, feedback, testimonial, waitlist, optional support fields, and attachments are voluntary. Declining them does not affect the core on-device detection experience.
8. Automated decisions
Trial and licence systems automatically return whether access is active, expired, revoked, or already bound to another device. This is necessary to provide the selected edition. We do not use solely automated decision-making that produces legal or similarly significant effects, and we do not profile users based on health or BFRB activity. Contact us if an access result is wrong and you would like a human review.
9. Security
We use HTTPS in transit, access controls, private attachment storage, service-provider security features, and data minimisation. No system is completely secure. Please do not send passwords, payment-card details, or unnecessary sensitive images or recordings through support or feedback.
10. Your data-protection rights
Depending on your location, you may have rights to access, correction, deletion, restriction, portability, objection, withdrawal of consent, and complaint to a data-protection authority.
Email hello@awaira.app to exercise a right. Tell us enough to locate the relevant record. We may request proportionate proof of identity. We normally respond within one month and do not charge unless a request is manifestly unfounded or excessive.
EEA residents may complain to the supervisory authority in their country; the Irish Data Protection Commission is available online. UK residents may contact the Information Commissioner's Office. We would appreciate the opportunity to address your concern first.
11. Children
Awaira is not directed to children under 16, and we do not knowingly collect their server-side personal data. A parent or guardian who believes a child submitted information should contact us so we can delete it. Local on-device data remains under the device user's or guardian's control.
12. Website storage and tracking
The website stores a theme preference in your browser's local storage. Each public page also loads the Meta Pixel, which sends a PageView event and related browser/device information to Meta for advertising measurement and optimisation. Meta may use cookies or similar technologies and may associate website activity with information it already holds about you; see Meta's privacy notice for details. Our hosting provider necessarily processes basic request metadata to deliver and secure the site as described above.
13. Changes to this policy
We may update this policy when Awaira or its legal obligations change. We will update the effective date and provide additional notice in the app or website when a change materially affects your rights or how we use personal data.
14. Contact
Awairahello@awaira.app