What we collect, in plain terms
AvaLists is a working tool. We only collect what we need to run the service and to make Ava — your AI Listing Concierge — actually useful. There are four categories of data.
1. Account & billing data
Your name, work email, phone number, brokerage or company affiliation, role, password hash, and (if you're on a paid plan) billing details. Billing is processed by Stripe — we never see or store full card numbers.
2. Listing data
Anything you, your team, your invited owners, or your seller's disclosure upload tells us about a property: address, photos, price, square footage, age, upgrades, neighborhood notes, HOA details, showing instructions, and the disclosure answers themselves. Showing instructions, lockbox codes, and other "private to Ava" fields are flagged and never exposed in any buyer- or renter-facing reply unless you explicitly mark them otherwise.
3. Conversation data
When a buyer, renter, cooperating agent, or curious neighbor reaches Ava by phone, SMS, or chat, we record the conversation so you have a complete record of what Ava said on your behalf. That includes the audio recording, the transcript, the caller's phone number or email, the time and duration, and any lead details Ava captured (preferred showing times, budget, must-haves, etc.). Where required by law, Ava announces that the call is with an AI assistant and may be recorded.
4. Product telemetry
Standard server logs (IP address, browser, pages visited, error traces) so we can keep the product up and fix bugs. We do not run third-party advertising trackers on the AvaLists app.
Where your data is stored
All AvaLists data is stored in managed infrastructure operated by Supabase on AWS, in United States data centers. The database, file storage (photos, disclosures, recordings), and AI inference traffic all flow through this stack.
- Encryption in transit. Every request between your browser, our servers, and our database is over TLS 1.2+.
- Encryption at rest. Databases and file storage are encrypted at the disk level using AES-256 by the underlying cloud provider.
- Row-level security. Each listing, conversation, and document row is tagged with its owner. The database itself enforces — at the row level — that one account can never read or modify another account's data, even if a bug in our app code tried to.
- Backups. Daily encrypted backups are retained for 30 days for disaster recovery, then permanently destroyed.
- Secrets. API keys, telephony credentials, and service passwords are stored in an isolated secrets vault and rotated on a regular schedule.
Who can see your data
You and the people you invite
Only you, the teammates you add to your AvaLists account, and the property owners or co-listing agents you explicitly invite to a specific listing can see that listing's data and its conversations. Invites can be revoked at any time and access is removed immediately.
AvaLists staff
A small number of AvaLists engineers may access account data when strictly necessary to support you, investigate a bug, or respond to a security incident. Every such access is logged. We do not browse customer data for any other purpose.
Subprocessors
We rely on a short list of vetted vendors to run the service. Each is bound by a written data processing agreement that prohibits them from using your data for their own purposes:
- Supabase / AWS — database, file storage, authentication.
- Cloudflare — application hosting and DDoS protection.
- Twilio & VAPI — voice and SMS delivery infrastructure. They process phone numbers, call audio, and message content solely to provide AvaLists telephony services, and are contractually prohibited from using customer mobile numbers or messaging consent for their own marketing or promotional purposes.
- OpenAI & Anthropic — large-language-model inference for Ava's responses. API traffic on these vendors is contractually excluded from model training.
- Stripe — payment processing.
- Resend / Postmark — transactional email (showing notifications, lead alerts).
Law enforcement
We disclose data to law enforcement only when compelled by a valid legal process (subpoena, court order, or warrant) and we narrow the disclosure to what the request actually requires. We notify the affected account holder unless legally prohibited.
How Ava uses AI — and what AI vendors do not see
Ava is built on top of large-language-model APIs from OpenAI and Anthropic. When a buyer or renter asks Ava a question, the relevant pieces of your listing context (description, disclosure answers, details, FAQs) are sent to the model along with the question so Ava can answer accurately.
- We only send the data Ava needs to answer the question in front of it. Account credentials, full lead histories, and other listings are not included.
- Our vendor agreements with OpenAI and Anthropic prohibit them from using AvaLists API traffic to train their foundation models. Your data is processed transiently to generate a response and is not retained by the model provider for training.
- AvaLists does not train its own public models on your private listing data or on identifiable buyer/renter conversations.
- If we ever use anonymized, aggregated data to improve Ava's prompts or evaluation set, it is stripped of property addresses, names, phone numbers, and email addresses first.
Buyers, renters, and call recording
Ava talks to the public on your behalf, so a portion of the data in AvaLists belongs to people who never signed up with us directly. We take that seriously.
- Disclosure. Ava identifies itself as an AI assistant when asked, and announces call recording at the start of phone calls in every U.S. state that requires two-party consent.
- Use. Buyer/renter contact information and conversation content are used to answer their questions, schedule showings, follow up on the property they inquired about, and to show you what was said on your behalf. They are not used for unrelated marketing. We do not share, sell, rent, or otherwise provide mobile phone numbers, SMS opt-in information, or messaging consent to any third parties or affiliates for marketing or promotional purposes.
- Their rights. A buyer or renter can email privacy@avalists.com at any time to request a copy of the data we hold about them, or to ask us to delete it.
SMS Communications
AvaLists may send SMS text messages related to customer care, appointment scheduling, showing coordination, maintenance updates, property inquiries, account notifications, follow-up communications, and other service-related communications.
- Message frequency. Message frequency varies depending on your interactions with AvaLists and the listings you manage or inquire about.
- Rates. Message and data rates may apply based on your mobile carrier plan.
- Opt-out. You may reply STOP to any SMS message to opt out of receiving further text messages from AvaLists.
- Help. You may reply HELP to any SMS message for assistance, or contact us at privacy@avalists.com.
- Consent and sharing. We do not share, sell, rent, or otherwise provide your mobile phone number, SMS opt-in information, or messaging consent to any third parties or affiliates for marketing or promotional purposes. Our SMS delivery providers (such as Twilio) only process the information necessary to deliver messages on our behalf and are contractually prohibited from using your information for their own marketing or promotional purposes.
Retention and deletion
- Active listings. Listing data, documents, and conversations are retained as long as the listing is active in your account.
- Archived listings. When you archive a listing, the data is retained for 12 months so you can reactivate or export it, then permanently deleted.
- Deleted listings. When you delete a listing, the row, documents, recordings, and transcripts are removed from primary storage within 7 days, and from encrypted backups within 30 days.
- Closed accounts. When you close your account, all account data is permanently deleted within 30 days, except records we are legally required to retain (billing records for tax purposes, for example).
- Export. At any time you can export your listings, leads, and conversation transcripts as CSV/JSON from the dashboard, or by request to privacy@avalists.com.
Your rights
Depending on where you live, you may have specific legal rights over your personal data — for example under the California Consumer Privacy Act (CCPA/CPRA), Virginia's CDPA, Colorado's CPA, or the EU/UK General Data Protection Regulation (GDPR). AvaLists honors all of them, regardless of your jurisdiction:
AvaLists does not sell, rent, or share mobile phone numbers, SMS opt-in information, or messaging consent with third parties or affiliates for marketing or promotional purposes.
- The right to know what data we hold about you.
- The right to access a copy of it.
- The right to correct inaccurate data.
- The right to delete your data.
- The right to opt out of any sale or "sharing" of personal information — which is moot here, because we do neither.
- The right to non-discrimination for exercising any of the above.
To exercise any of these rights, email privacy@avalists.com. We respond within 30 days.
Security practices
- TLS 1.2+ on every public endpoint.
- Database row-level security policies on every table containing customer data.
- Principle-of-least-privilege access for staff, with hardware-key-protected SSO.
- Audit logging on every privileged data access.
- Automated dependency scanning and prompt patching of critical CVEs.
- Annual third-party security review of the AvaLists application.
If you believe you've found a security issue, please email security@avalists.com. We'll acknowledge within one business day.
Questions about your data?
We're a small team and we read every message. For privacy-specific requests, email privacy@avalists.com. For anything else: