Legal · Aravo

Privacy Policy

Last updated: July 2026

1. Who we are

Aravo is a professional platform for turning tracked hours into clear reports, invoices, and quotes for freelancers, independent professionals, and small teams. It offers a free Starter plan and a paid Professional plan processed by Polar. If you have questions about this policy, you can contact us at [email protected].

We have not appointed a data protection officer because, given the current nature and scale of the service, it is not mandatory. The privacy and security contact channel is [email protected].

2. Information we collect

To provide the service, we collect the following information:

  • Account and authentication data: email address, user identifier, and, if you choose Google OAuth, basic information provided by Google to sign you in.
  • Work data: time entries, descriptions, tasks, tags, clients, projects, invoices, quotes, Toggl-compatible imports or exports, amounts, statuses, and generated documents.
  • Workspace data: workspace name, members, roles, invitations, invited emails, access requests, and preferences such as language, time zone, numbering, branding, or document settings.
  • Shared report data: links, permissions, visibility settings, comments, and names or emails of invited people or access requesters.
  • Plan and billing data: active plan, subscription status, usage limits, Polar customer/subscription IDs, billing cycle, payment events, and operational metadata needed to activate or cancel Professional access. Aravo does not store your full card details.
  • Technical and session data: session tokens, language preference, theme, active workspace, analytics consent, minimal security logs, and data required to keep the session active and operate the app.
  • Agent connection data: if you connect an AI agent or another external tool, we store the connection name, its permissions, technical token identifiers (never the token itself), creation, usage, and revocation dates, and minimal security logs of its requests.

Most of this data is entered by you directly or generated through normal product actions.

3. How we use the data

We use your data to provide and maintain Aravo: authenticating accounts, saving and displaying content, calculating reports, generating PDFs, managing workspaces, sending invitations, processing imports, applying plan limits, operating documents, answering support requests, preventing abuse, and improving the product.

The basis for this processing is mainly the service you request from us. We may also process certain data based on our legitimate interest in security, fraud prevention, and operational improvement; legal obligations where applicable; and consent for product analytics.

In addition, Cloudflare processes technical logs and aggregated metrics needed to deliver the website and application, protect the network, detect abuse, measure availability and performance, debug errors, and operate the infrastructure. This data may include IP address, request metadata, requested URL, technical headers, approximate country, data center, status codes, response times, and equivalent traffic or security data. We do not use this data for advertising, profile sales, or individual commercial tracking.

In addition, we use Sentry (sentry.io) to monitor technical errors in the product. When an error occurs in your browser or in our server functions, Sentry automatically records the error type and message, the stack trace, the URL where it occurred, your browser and operating system, and the source IP address of the request. The goal is to detect and fix technical failures, not to analyze your behavior or build advertising profiles. This processing is based on our legitimate interest in the security and stability of the service, so it does not depend on the analytics consent notice described in section 4. Error events are stored on Sentry's European infrastructure and are retained according to our plan's standard retention policy. We do not use Sentry for advertising, data sales, or commercial tracking.

4. Analytics and usage metrics

With your explicit consent, we use PostHog (posthog.com) to collect behavioral metrics inside the product. The goal is to understand which features are used, detect friction, and improve the overall experience. PostHog is not initialized and does not record events in your browser until you accept the analytics notice.

When you accept the analytics notice, PostHog may register:

  • Pages visited inside the panel and on the public website.
  • Actions performed, such as creating time entries, invoices, quotes, projects, tasks, or shared links.
  • Your user identifier, email address, and active plan, so events can be associated with an account when you are signed in.

Important: automatic form capture is disabled. We do not deliberately send PostHog client names, time descriptions, invoice amounts, quote contents, or equivalent work data. We record interaction events and limited properties, not the contents of your documents.

Analytics data is stored exclusively on servers in the European Union (PostHog's EU infrastructure), which complies with the requirements of the General Data Protection Regulation (GDPR). Analytics data is retained for a maximum of 12 months.

We do not sell, rent, or share your analytics data with third parties for advertising or commercial purposes.

How to control your consent

The analytics notice appears on your first visit. If you decline it, PostHog will not load or record any activity. If you accept and later change your mind, you can revoke your consent by writing to [email protected] or by deleting the aravo-analytics-consent entry from your localStorage.

5. Service providers

To operate Aravo we use the following third parties as data processors:

  • Supabase — authentication, database, storage for PDFs, and operational files.
  • Cloudflare — web hosting, CDN, serverless functions, network protection, technical logs, aggregated traffic/performance metrics, and scheduled tasks.
  • Sentry — technical error monitoring (legitimate interest in security and stability; does not require consent).
  • Resend — transactional email, such as invitations, security notices, and account lifecycle messages.
  • Google — OAuth authentication if you choose to sign in with Google.
  • PostHog — product analytics (only with consent).
  • Polar Software, Inc. — checkout, pagos, impuestos, facturas, recibos, portal de suscripción y eventos de billing del plan Profesional.

Each provider operates under its own terms, security measures, and privacy policy. Some providers may process data outside your country of residence; where relevant, we use providers with reasonable contractual and operational safeguards for SaaS services.

Tools and agents connected by you

If you authorize the connection of an AI agent or another external tool to your account, that tool and its providers do not act as our processors: they are services you choose and contract, and they access your data at your instruction through a token under your control. Any data that tool retrieves or receives is processed under its provider's terms and privacy policy. Review those conditions before connecting a tool, and revoke the token from your settings if you stop using it.

Processing on behalf of professional customers

When you use Aravo to manage data about your clients, providers, collaborators, or report recipients, you decide which data to enter, share, or keep. In that context, you act as controller of that data and Aravo acts as processor, following your instructions within the normal use of the service.

El Acuerdo de tratamiento de datos recoge las condiciones aplicables a ese tratamiento profesional, incluyendo subencargados, medidas de seguridad, asistencia en derechos, supresión/devolución e incidentes de seguridad.

6. Security and storage

Work data is stored mainly in Supabase/Postgres and, when you generate documents, in Supabase Storage. We apply reasonable measures such as session-based authentication, user and workspace access controls, Row Level Security on exposed tables, restricted use of service keys, encryption in transit through HTTPS/TLS, and provider security measures for storage at rest.

Aravo does not provide end-to-end encryption for the content you enter. This means the application and its backend services must be able to process your time entries, clients, projects, invoices, quotes, and reports to display data, generate documents, share links, and provide support where needed. Do not use Aravo to store passwords, private keys, technical secrets, medical data, or other highly sensitive information that is not necessary to manage your professional activity.

No system is completely secure. If you suspect unauthorized access or a security issue, contact us as soon as possible.

7. Data retention and deletion

We retain your data while your account or workspace remains active and for as long as needed to provide the service, comply with legal obligations, resolve incidents, prevent abuse, or maintain minimal operational and security records.

Como criterio general: los datos operativos del producto se conservan mientras el workspace o cuenta sigan activos; los datos de analytics se conservan hasta 12 meses; los registros técnicos, seguridad y auditoría se conservan durante el tiempo razonablemente necesario para proteger el servicio y depurar incidencias; y los datos de billing se conservan durante el tiempo necesario para gestionar la suscripción, resolver incidencias, prevenir abuso y cumplir obligaciones legales o contables.

Puedes solicitar la eliminación de tu cuenta desde la configuración del panel. La eliminación se programa con un período de gracia de 60 días; durante ese plazo puedes reactivar la cuenta iniciando sesión de nuevo. Si tienes una suscripción Profesional activa, deberás cancelarla desde el portal de Polar o la configuración de billing cuando esté disponible; la eliminación de cuenta no sustituye automáticamente obligaciones de facturación ya gestionadas por Polar.

When the grace period ends, we delete from production the authentication account and associated data we directly control, including time entries, clients, projects, tasks, invoices, quotes, shared links, generated PDFs, and account settings, except for minimal data we must retain for legal, accounting, anti-fraud, security, or audit reasons. Backups may retain traces temporarily until they rotate or are overwritten according to our providers' technical cycles.

If you own a workspace with other active members, you may need to transfer ownership before scheduling account deletion to avoid affecting shared data belonging to other people.

8. User rights

Users in the European Union (GDPR)

If you reside in the European Economic Area, you have the following rights under Regulation (EU) 2016/679 (GDPR):

  • Right of access (Art. 15): request which personal data we hold about you.
  • Right to rectification (Art. 16): correct inaccurate data.
  • Right to erasure (Art. 17): request deletion of your data.
  • Right to restriction (Art. 18): request that we restrict processing in certain cases.
  • Right to portability (Art. 20): receive your data in a structured format.
  • Right to object (Art. 21): object to data processing for analytics.
  • Right to withdraw consent: withdraw analytics consent at any time without affecting the lawfulness of prior processing.

We do not make automated decisions with legal or equivalent effects about you. To exercise your rights, contact us at [email protected]. We aim to reply in under 30 business days. You can also manage certain data directly from the panel, including editing, document exports, and account deletion. If you live in Spain or the European Economic Area and believe we have not handled a request properly, you may complain to the Spanish Data Protection Agency (AEPD) or to the data protection authority that applies in your jurisdiction.

Users in California, United States (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) grants you additional rights:

  • The right to know what personal information we collect.
  • The right to request deletion of your personal information.
  • The right not to be discriminated against for exercising your privacy rights.

Aravo does not sell personal information. We do not transfer your data to third parties for commercial or advertising purposes.

Users in Latin America

If you live in a Latin American country with data protection legislation, you may have rights of access, rectification, erasure, objection, or equivalent rights depending on your jurisdiction. Contact us to exercise them.

9. Children's privacy

Aravo is a professional platform built for adults (freelancers, independent professionals, and operational agencies). Our software service is not directed to minors under any circumstance, and we do not intentionally collect or store personal data relating to anyone under 18 years of age. If you have legal responsibility for a minor and confirm that they have provided us with information, contact us so we can stop processing and delete that data.

10. Changes to this policy

We may update this privacy policy to reflect product changes, providers, technical measures, or legal requirements. If changes are material, we will try to notify you through the website, the panel, or the email associated with your account. The last updated date indicates the current version.

11. Contact

For questions about the processing of your data, this policy, or the exercise of your rights, contact us at:

[email protected]