How we keep your data safe
You share real things here, about your kids, your partner, the moments that hurt. The least we can do is be specific about what happens to those words after you send them.
What Avani is, and what it is not
- Avani is a coaching tool for stressed parents. It reflects what is happening, offers one concrete next step, and gives words you can say to your child.
- Avani is not a therapist, not a medical provider, and not a substitute for clinical care.
- Avani will not diagnose, prescribe, or give legal or financial advice. When a conversation heads there, the coach steers back to what is happening for you and your child right now.
- When a message signals imminent danger, Avani surfaces crisis resources at the top of the reply. It never tries to handle a crisis alone.
- Avani is for parents and caregivers 18 and over. AI companion chatbots may not be suitable for some minors.
Where Avani stands on Colorado’s AI psychotherapy law
In June 2026 Colorado passed HB26-1195, which sets rules for how AI can be used in and around mental health care. It took effect on August 12, 2026. We are a Colorado company, so it applies to us directly. Here is where we stand.
Avani is not therapy, and it is not a substitute for clinical care
It is a parenting coach. It helps you steady yourself in a hard moment, understand what is happening, and choose what to say next. It does not diagnose, it does not treat mental health conditions, and it does not replace a professional who knows you and your family.
Avani is not a therapist and does not speak as one
Mirra Wicker, our founder, is a licensed therapist, and her method shapes how Avani listens and what it says. That is a statement about how the product was designed. It is not a claim that a therapist is answering you. Every reply comes from an AI system.
Your conversations are private, but they are not legally privileged
What you share is encrypted, never used to train AI models, never sold, and you can delete it whenever you want. Those are real protections and we hold ourselves to them. What we will not tell you is that they are the same as therapist-client confidentiality, because they are not. That protection exists inside a licensed clinical relationship, and Avani is not one.
When a moment needs a person, Avani says so
If a conversation signals crisis, Avani surfaces crisis resources at the top of the reply and points to human help. It never tries to handle a crisis alone.
The law asks products like ours to be clear about what we are. We think that is right. A parent typing at 2am deserves to know exactly what is on the other end.
How your data is protected
Encrypted in transit and at rest
Your messages are scrambled while they travel to us and while they sit in our database. Technical detail: all client-to-server traffic is TLS 1.2+ with HSTS enforced; data at rest is encrypted with AES-256 inside our managed Postgres database.
Never used to train AI
What you share is never used to teach any AI model. Anthropic does not train on data submitted through its API; that is the default on the commercial terms we use. Zero-retention configuration with each AI vendor is in progress rather than finished. We keep your conversations in full for as long as your account exists, because Avani uses that history to hold context between sessions.
Least-privilege access
Only a small number of approved engineers can ever look at production data, and only for a real reason such as fixing a bug or responding to abuse. Admin surfaces are gated behind an explicit role flag, and every read of a conversation transcript writes an audit-log row naming the operator, the conversation and the time. Hardware-backed two-factor on administrator accounts is in progress and not yet in place.
How safety works on every turn
Every message you send and every reply you receive passes through a layered pipeline. Each layer is independent, so a single failure cannot let an unsafe turn through: signed-in authentication and per-user rate limits; an input check against a crisis-keyword list that adds real crisis resources to the reply when one matches; token budgets, per-user daily caps and a global kill switch an operator can set without a deploy; admin-curated guidance the coach paraphrases rather than fabricates; an output check for forbidden patterns; and full audit logging of every guard trip and configuration change. Classifiers for injection and scope, and automatic masking of emails and phone numbers, are built and staged but not switched on yet.
If you are in crisis
Avani is not a crisis service. If you or someone in your home is in danger, call or text 988 (the Suicide and Crisis Lifeline) in the US, text HOME to 741741 to reach the Crisis Text Line, or call 911. The same resources appear in the app whenever you ask for human support.
Our crisis protocol, written down
This is exactly what happens when a message signals crisis, published here so you can read it before you ever need it. Every message is checked for crisis signals before it reaches the model. When one matches, Avani does not try to counsel you through the moment: the reply opens with real crisis resources, the ones listed above, and points you to a person who can help right now. The same resources are one tap away any time you ask for human support. Avani is not a crisis service, it does not assess risk, and it never handles a crisis alone.
California asks operators of AI companion chatbots to publish this protocol on their website rather than keep it internal. This section is that publication.
Controls you have as a user
- Delete your reflections, saved phrases, children's profiles and uploaded documents yourself, at any time, from inside the app. There is no per-message or per-conversation delete yet.
- Request deletion of the whole account from privacy settings. We complete it, including with our sub-processors, within 30 days.
- There is no self-serve export yet. Email hello@askavani.com and we will assemble a portable copy of the data we hold about you, free of charge, within 30 days.
Our sub-processors
A sub-processor is a vendor that handles data on our behalf. We keep this list short on purpose, and every vendor that touches what you write is on it. Each receives only what it needs to deliver the service. Formal Data Processing Agreements are still being put in place.
- Supabase: database, authentication, and edge-function hosting.
- Anthropic (Claude): powers the conversational responses you receive. Anthropic does not train on this data.
- Stripe: subscription billing and payment processing. Card numbers never touch our servers.
- Vercel: static site and application hosting.
- PostHog: privacy-aware product analytics. Pseudonymous events only, no conversation content.
For the legal text covering CCPA, CPRA, GDPR, and COPPA, see the privacy policy. Questions? Write to hello@askavani.com.