How We Protect Your Data Under GDPR
Avo is built on Google Cloud infrastructure. All data is encrypted in transit via TLS and encrypted at rest using Google Cloud platform-managed encryption. We do not sell personal data and do not use it for ad targeting.
Specific technical measures include:
- •Authenticated sessions use secure browser cookies and server-side verification for protected requests.
- •Protected browser mutations use request validation such as CSRF checks where applicable.
- •Firestore rules and server authorization checks enforce account ownership or verified administrative access.
- •Content Security Policy, transport security, framing restrictions, and related browser headers reduce common web risks.
- •Selected AI, authentication, and integration endpoints use request validation and abuse controls.
- •Automated tests cover authentication gates, administrative routes, privacy-sensitive behavior, and known security contracts.
Infrastructure partners (Google Cloud, Firebase, Vercel) operate under contractual data protection obligations. AI processing providers receive the information needed for requests you make or background features you enable. The privacy policy describes current providers and feature-specific data flows.