Legal
Privacy Policy
What Darvy processes, what stays local, and the reporting choices you control.
Status
Current product behavior. Darvy keeps required service metering, optional product analytics, and optional crash diagnostics as three separate data paths. Optional reporting starts off and requires an explicit choice.
Plain-language summary
What we collect
- Account and download data: email address for installer access, abuse prevention, Darvy follow-up, license delivery, and billing receipts, plus a Polar customer ID after purchase. We never see or store your card details.
- Voice transcripts: when you speak to Darvy, your audio is sent to a speech-to-text provider and your text is sent to a large-language-model provider. Audio is not retained by us after transcription. Transcripts may be stored locally on your machine if you enable history; they are not sent to our servers by default.
- Required service metering: license-linked aggregate session duration, provider, token/call totals, response timings, app version, and platform for quotas, cost accounting, and abuse investigation.
- Optional product analytics: with your consent, static feature/action IDs, outcomes, reason codes, durations, version, and platform tied to a random installation ID.
- Optional crash diagnostics: with separate consent, scrubbed error type, stack locations, OS version, and app version through Sentry.
What we don't do
- We don't sell your data to anyone, ever.
- We don't train AI models on your voice or your transcripts.
- We don't keep audio recordings server-side.
- We don't read your emails, documents, or files. Darvy reads them on your machine, in the moment, to do the task you asked for.
- Service reporting never includes prompts, transcripts, audio, model answers, screenshots, filenames, paths, URLs, document text, browser content, tool arguments, or tool results.
Categories of third parties we use
- Payment processor — PCI-compliant merchant of record (currently Polar).
- Speech-to-text provider — transcribes your microphone audio.
- Large-language-model provider — interprets transcribed text to decide what action to take.
- Text-to-speech provider — generates Darvy's spoken replies.
- Web hosting — serves this website.
- Service data hosting — stores required aggregate metering and consented content-free product events.
- Crash reporting — receives separately consented scrubbed diagnostics.
The current vendor in each category is available on request — email support@darvy.ai with subject "Sub-processor list" and we'll send the up-to-date list. We list categories rather than vendor names because our infrastructure choices change over time; the categories of data handled do not.
How to ask for your data, or delete it
Change either optional choice from the Darvy tray menu under Privacy and data. Turning product analytics off removes its local random ID and queued reports. Raw product events are retained for at most 90 days and daily aggregates for at most 13 months. Email privacy@darvy.ai with your support code for an access or deletion request.
More detail
The canonical detailed policy is maintained in legal/privacy.md. Privacy questions and requests go to privacy@darvy.ai.
Last updated: 2026-07-13.