Ori

Privacy Policy

Effective September 8, 2026 · Last updated September 8, 2026

This Privacy Policy (“Policy”) explains how Adverio OÜ (“Ori”, “we”, “us”, “our”) collects, uses, discloses, transfers, retains, and protects personal data when you use the Ori mobile application, our website, and related services (together, the “Service”), and the rights and choices available to you. It applies to all users of the Service. Capitalized terms not defined here have the meaning given in our Terms of Use.

If you do not agree with this Policy, please do not use the Service. If you have questions or requests, contact help@adverio.co.

1. Who we are (Controller)

Adverio OÜ, located at Harju maakond, Tallinn, Kesklinna linnaosa, Tuukri tn 19-315, 10120, is the “controller” (and “business” under US law) responsible for your personal data. When we process content solely to generate your results, the AI providers in §6 act as our processors (service providers) under our instructions.

2. Summary

3. Personal data we collect

We collect the categories below. We minimize what we collect and do not require an account to use core features.

CategoryExamplesSource
Account & identityEmail address, authentication provider, app-assigned user id, and (if you sign in with Apple/Google) the identifier they returnYou / your sign-in provider
Content you submitChat messages and prompts, attached photos and files, and voice audio you dictateYou
Generated contentText, images, video, and audio produced in response to your prompts; feedback you give (e.g. a thumbs rating or a report)Created in the Service
PurchasesSubscription status, plan, trial state, and purchase history (we do not receive your full card number)Apple / Google / RevenueCat
Usage & interactionsFeatures used, screens viewed, actions taken, in-app search activity, session and diagnostic eventsAutomatic
Device & technicalDevice model, operating system, app version, language, time zone, coarse region (not precise GPS), and network informationAutomatic
IdentifiersAn installation id and, only with your consent, an advertising identifier (IDFA on iOS / Advertising ID on Android)Automatic (consent-gated)
DiagnosticsCrash reports, error logs, and performance dataAutomatic
CommunicationsSupport requests and the contents of messages you send us; a push token if you enable notificationsYou / Automatic

We do not intentionally collect special-category / sensitive data (e.g. health, biometrics, precise location). Please do not submit such data unless necessary; if you do, you consent to our processing it to provide the Service.

4. How and why we use your data (purposes & legal bases)

Where the GDPR/UK GDPR applies, we rely on the legal bases below.

PurposeLegal basis (GDPR Art. 6)
Provide the Service — run chats, generate images/video/voice, AI apps, discover, and memoryContract (Art. 6(1)(b))
Send your prompts/content to AI providers to produce results (§6)Contract; consent where required
Operate accounts, subscriptions, trials, entitlements, and usage limitsContract
Send notifications you enableConsent
Security, abuse/fraud prevention, and content-safety moderation (incl. handling reports)Legitimate interests; legal obligation
Measure performance, diagnose crashes, and improve the ServiceLegitimate interests
Measure marketing/campaign performance and attributionConsent (via App Tracking Transparency / equivalent)
Comply with law and enforce our TermsLegal obligation; legitimate interests

You may withdraw consent at any time (e.g. by changing tracking or notification settings); this does not affect processing carried out before withdrawal.

5. Content-safety moderation

To keep the Service safe and comply with app-store and legal requirements, we and our providers apply automated and manual safeguards to detect and act on prohibited content. If you report an AI response (for example by tapping “Unsafe or harmful”), we process that report and the referenced content to review and improve safety. We may retain records of violations and reports as needed for safety, legal, and enforcement purposes.

6. AI processing and third-party AI providers

To generate responses and media, we transmit your prompts and the content you submit (including attached images and, for voice input, audio) to third-party AI providers that act as our processors and return output to us for you:

These providers process your content under their terms and our agreements. We instruct providers not to use your content to train their models except as necessary to provide the service or as required by law; some providers may retain content for a limited period for safety and abuse-prevention. Processing may occur outside your country (see §10). AI output can be inaccurate or inappropriate and is not professional advice — see our Terms of Use.

7. When we disclose your data

We share personal data only as described here:

We do not sell your personal data for money.

8. Analytics, attribution & tracking technologies

The mobile app does not use browser cookies, but it uses software development kits (SDKs) and device identifiers that function similarly:

App Tracking Transparency & advertising IDs. On iOS we request permission before accessing the advertising identifier for cross-app measurement; if you decline, we do not use it. On Android you can reset or delete your Advertising ID, or opt out of personalization, in system settings. We honor recognized opt-out preference signals (such as Global Privacy Control) where required by law.

9. Retention

We keep personal data only as long as necessary for the purposes above, then delete or de-identify it. Indicative periods:

DataRetention
Account & profileUntil you delete your account
Chats, prompts, attachments, generated mediaUntil you delete them, or your account
Voice audio submitted for transcriptionTranscribed then deleted; provider retention per §6
Usage & diagnostics / crash dataUp to 24 months, then aggregated/deleted
Purchase recordsAs required for tax, accounting, and audit (typically 7 years)
Safety/abuse and legal recordsAs needed for the purpose or as law requires
Back-upsPurged on our routine back-up rotation after deletion

10. International data transfers

We and our providers may process your data in countries other than yours, including the United States and, for certain video generation (Kling / Kuaishou), China, which may not provide the same level of protection as your home country. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum/IDTA) or reliance on an adequacy decision, together with supplementary measures where needed. You may request a copy of the relevant safeguards at help@adverio.co.

11. Security

We use technical and organizational measures appropriate to the risk, including encryption in transit (TLS/HTTPS), access controls and least-privilege, network protections, and monitoring. No method of transmission or storage is completely secure; we cannot guarantee absolute security. If we become aware of a personal-data breach affecting you, we will notify you and regulators where required by law.

12. Automated decision-making

The Service uses AI to generate content in response to your input. This is not automated decision-making that produces legal or similarly significant effects about you within the meaning of GDPR Article 22, and we do not use it to make such decisions. Safety systems may automatically flag or block prohibited content; you can contact us to contest an action.

13. Your rights (EEA, UK, Switzerland)

Subject to conditions and exemptions in applicable law, you may:

To exercise these rights, email help@adverio.co or use the in-app controls. We will respond within the timeframe the law requires (generally one month for the GDPR) and may need to verify your identity.

14. US state privacy rights

If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, or other states with comprehensive privacy laws, you may have rights to know/access, correct, delete, obtain a portable copy, and opt out of “sale,” “sharing”/targeted advertising, and certain profiling. In the preceding 12 months we collected the categories in §3 and disclosed them to the service providers in §6–§8 for the purposes described.

15. Children’s privacy

The Service is not directed to, and we do not knowingly collect personal data from, children under 16. If you believe a child has provided us personal data, contact help@adverio.co and we will delete it. We do not knowingly sell or share the personal data of minors.

16. Third-party links and services

The Service may link to or rely on third-party services with their own privacy practices. We are not responsible for those practices; please review their policies.

17. Changes to this Policy

We may update this Policy from time to time. We will post the updated version with a new effective date and, for material changes, provide additional notice (for example, in the App). Your continued use after the effective date constitutes acceptance of the updated Policy.

18. Contact us

Adverio OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Tuukri tn 19-315, 10120
Privacy: help@adverio.co · Support: help@adverio.co