Data Inventory
Last updated 2026-10-09
What this inventory covers
This page describes the data used by the current website and installed MAVYR app. “Server-visible” means the running service can read the information, even when its storage is encrypted. Encrypted content and pseudonymous identifiers can still be personal data.
Account and profile
- Username, internal account identifier, MAVYR ID and account creation time: identify your account and address messages. These are server-visible.
- Display name: show the identity you choose to other participants. It is optional and server-visible.
- Plan entitlement and the original account creation time: determine the 30-day MAVYR Trail with Plus benefits, the applicable plan and monthly allowance periods. The original timestamp prevents a new sign-in from restarting the trial. The operator account has a separately configured permanent entitlement. No attachment usage counters or card or bank details are collected in this release; paid checkout and attachment transfers are unavailable.
- Invitation code, expiry and use state: admit one account within two hours. Each account has three lifetime places. A temporary reservation links the issuing account to a code hash, expiry, settlement state and a flag for a confirmed abandoned registration attempt; the application does not store the raw code in this reservation. Creating a new account permanently consumes one place, including when two-factor setup is later abandoned. The retained account total does not identify invited people, and MAVYR does not create a lasting inviter-to-new-user relationship in its account records.
Authentication
- Password verifier: check your password without storing the original password. The password is processed during registration or sign-in over an encrypted connection.
- Encrypted authenticator secret, used-code counter, failed-attempt state and hashed backup codes: enforce the second factor and prevent replay.
- Temporary authentication challenge, encrypted pending session and expiry: complete sign-in or authenticator setup. The challenge expires after ten minutes.
- Session token records, token hashes, device binding and expiry: authorize requests and revoke access. The underlying messaging service can read its native session tokens; these are not message-decryption keys.
Conversations and devices
- Encrypted messages, message identifiers, sender identifiers, room identifiers and timestamps: relay and synchronize conversations. Message bodies are end-to-end encrypted; routing identifiers and timing are server-visible.
- Room membership, room names, access rules and encryption settings: operate private conversations and groups. This room information is server-visible.
- Read receipts, synchronization positions and archive preferences: keep conversation state consistent across sessions. These are server-visible.
- Device identifiers, editable device names, public encryption keys and signatures: address and authenticate devices. Public keys can be distributed to intended peers.
- Device-access policy: account identifier, known device identifiers, the current selected device identifiers and initialization/selection flags enforce the device allowance. Known identifiers prevent a previously excluded device from silently reconnecting. This policy does not duplicate device names or store a history of device selections.
- Encrypted key backups and encrypted recovery information: recover message keys when you provide your Recovery Key. MAVYR does not receive that key in plaintext.
Prepared subscription processing
Paid checkout is not enabled. The prepared Stripe integration would retain only the billing references and entitlement state needed to operate a paid plan; no card number or bank credentials are stored in the MAVYR billing tables.
A checkout record links an account to a checkout reference, plan/price/currency, an idempotency hash, creation and expiry times, and the provider checkout reference and URL. Subscription records retain the latest provider subscription reference, status, effective end, paid plan period, latest payment hash and update time.
Payment proofs retain a hashed provider/payment reference, account and subscription references, plan and paid period end. A payer record retains first-payment time, allocation order, continuous-paid-through time and any Founder eligibility loss date. A cumulative payer counter prevents reallocating previously used Founder places. Webhook deduplication stores an event hash and expiry, not a raw webhook body.
Financial records held by Stripe have a separate provider lifecycle. These prepared local retention periods are described in the Retention Matrix; they do not authorize starting payment processing before provider and contract information are complete.
Subscription cancellation declarations
The public cancellation form does not require a login. When submission is enabled and you send a declaration, it contains the name or MAVYR username you supply, contract reference, receipt email, cancellation type, any extraordinary reason, and requested end date. The stored encrypted declaration also identifies the submission page.
A separate record stores an opaque request identifier, keyed hashes for duplicate detection, receipt time, email acceptance time, delivery attempt count and retry/lease timing, and the time the case is marked resolved. The declaration fields are encrypted in the database; the operator can decrypt them to process the request. They are not chat messages or end-to-end encrypted correspondence.
The receipt email contains your declaration. Its delivery uses the configured email service and your mailbox provider; it is not end-to-end encrypted by MAVYR. The delivery provider and its retention terms have not yet been configured for launch. An unavailable form sends no declaration.
Optional notifications
If you enable notifications, we store an encrypted browser push endpoint and its delivery keys, linked to your account, device and approved session. An expiry and enabled state control delivery. Your local notification preference prevents automatic re-enabling after you switch it off.
The browser platform uses an Apple, Google or Mozilla push service. It receives delivery routing and transport information and an encrypted generic notification payload. We do not send message text, sender names or conversation names to that service. The notification shown on your device says “New MAVYR message”.
To diagnose delivery failures, the service keeps temporary aggregate counts by push provider and fixed result category. These counts contain no account or device identifiers, browser endpoints, message identifiers or message content. Raw provider responses are not logged.
On your device
The app stores its session vault, encryption state and conversation history in protected local storage. Message history is encrypted before it is written. The public offline cache contains application files, not private API responses or decrypted conversations.
Unlocked message text and previews are present in memory so you can read them. When this device is remembered, a local, nonextractable browser key can reopen the encrypted session without saving your password. Anyone able to use that browser profile may be able to open the app. This does not attest that the device is locked or provide a hardware security guarantee. Removing the app or its site data can remove local keys and history.
Connections, support and legal requests
Web requests expose a connection IP address and technical request information to the infrastructure that receives them. Public HTTP access logging is disabled on the MAVYR application route. Short-lived native session records and restricted administrative security records are separate from access logs.
The messaging gateway removes browser User-Agent and forwarded client-address headers before forwarding requests. The messaging engine can still record an internal transport address, device activity times and daily account/device visit records. Optional connection fields and visit records are cleared hourly; device last-active times remain separate account/device metadata. This is not a guarantee that the operator cannot observe connections.
If you contact the operator, the information you choose to provide is processed to answer you. A valid legal request may require a separate restricted case record and preservation of existing data. Neither category is an additional source of message-decryption keys.
Information not requested for registration
MAVYR does not request your telephone number, legal name, address, date of birth, payment details or address book. It has no advertising profile. Avoid placing information in usernames, device names or group names that you do not want to disclose to the service or relevant participants.