Security

Protecting your data is one of our priorities.

Avrelius holds personal records: thoughts, decisions, relationships, finances, and other parts of life you may not discuss even with the people closest to you. The more honest and complete that history is, the more context Avrelius can draw on — and the more useful it can become. That makes protecting personal data a requirement for the product itself, not a separate technical feature.

We use Avrelius ourselves, and we understand how important it is to be able to speak openly with it and feel safe doing so.

This page explains where your data is stored, how it is protected, when and why external services are used, how backups work, and how Avrelius architecture will evolve.

§ 01 — Data protection

What goes into protecting your data.

We treat data protection as one system. It includes:

  1. secure storage;
  2. data encryption;
  3. separate storage for encryption keys;
  4. access controls;
  5. backups;
  6. data recovery;
  7. archive export and import;
  8. deletion at the user’s request.

These safeguards work together. Our goal is to protect your data both from unauthorized access and from accidental loss.

Eight parts of one system form a ring around a personal notebook: storage, encryption, separate keys, access control, backups, recovery, export and import, deletion.

§ 02 — Avrelius Cloud

How data is protected in Avrelius Cloud.

Avrelius Cloud is the architecture designed for the first production release. Data will be stored and processed in cloud infrastructure, while the app can be used from a phone or computer.

A record is sealed with wax before it is carried into the vault at Zurich and copied to a second vault at Geneva; the key waits alone in a tower on the ridge above.

Storage

Data is stored and processed in Switzerland. The primary infrastructure is in Zurich, with backup infrastructure in Geneva. Switzerland is not a member of the European Union and has its own data-protection law; the European Commission formally recognizes Switzerland as providing an adequate level of protection for personal data transferred from the EU1,2.

Encryption

Personal records are encrypted before they are written to the database. Each user has a separate encryption key. Keys are stored separately from user data and are themselves protected by a higher-level key in a dedicated key-management system3.

Processing

Avrelius uses only the data needed for the specific function being performed — for example, to transcribe speech, update your digital twin, or prepare a response. The content of personal records is not written to system logs.

External AI services

For speech recognition and certain stages of analysis, Avrelius sends external AI providers only the portions of text or audio required for that specific operation. Our terms with these providers prohibit them from using user data to train their models. The full list of services and what each one is used for is published on the privacy page.

Access by Avrelius employees

The internal console used to manage accounts, billing, and technical errors does not display personal records, audio transcripts, prompts, or AI responses. Access to personal content for support is possible only when requested by the user and is limited to a named operator, a specific purpose and scope, a short access window, and an auditable record.

Backups

Encrypted backups are stored separately from the production infrastructure. They are protected from modification and deletion for 35 days. We regularly test that the recovery system works4.

Export and deletion

You can download a complete archive of your data at any time. After you request account deletion, you have seven days to change your mind. After that, your user data is permanently deleted.

§ 03 — Storage

Store it yourself or use Avrelius Cloud?

A personal archive can live on your own computer, in a cloud service, or on a remote server. Where it is stored does not by itself determine how well it is protected: encryption, access controls, backups, recovery, and regular updates matter in every case.

Local storage can keep access to your data extremely limited, but it also creates the risk of losing the archive with the device unless you maintain a separate backup. A cloud service removes some of that operational burden, but its provider sets the rules for how data is stored and processed. A remote server gives you more control, but leaves you responsible for maintaining the infrastructure yourself.

With Avrelius Cloud, we take that work on. We design protection as one system, test it in practice, and improve it based on user experience, testing results, and guidance from information-security specialists.

§ 04 — Comparison

Ways to keep a personal archive with AI.

CapabilityPersonal computerCloud serviceRemote serverAvrelius CloudAvrelius Local*
Access from multiple devicesusually requires setupdepends on the serviceyou configure itdepends on implementation
Automatic backupsyou configure themdepends on the serviceyou configure themrecovery under user control is planned
Tested recovery systemyou configure itdepends on the serviceyou configure itunder user control
Control over what data AI receivesyou configure itdepends on the serviceyou configure it
No model training on your datadepends on the models you choosedepends on the serviceyou configure itdepends on the connected service
The system tracks how your data and decisions change over timeyou have to build it yourselfrarelyyou have to build it yourself
AI conclusions link back to source records and datesyou have to build it yourselfrarelyyou have to build it yourself
No server infrastructure to maintain
Risk of losing the archive if the device is damaged or lostyes, without a separate backuplowlow with backupslowdepends on the recovery setup
Fully isolated environment with no data sent to external servicespossiblepossiblepossible
* Avrelius Local is in development.

Self-built setups can create a strong sense of control, but real security depends on many details that are easy to miss — from access configuration to the terms under which AI models handle your data. There is also a tradeoff: the more strictly data is isolated, the fewer options remain for processing it with the most advanced algorithms.

§ 05 — Roadmap

Four ways Avrelius can work.

Avrelius is designed to support four ways of running the system over time. Each shifts the balance between convenience, AI capability, and control over the underlying infrastructure. You will be able to choose the level of isolation you need without giving up the value of the product.

Four vessels in a row: Avrelius Cloud, available now, stands open to a broad stream from outside; Sealed, Local and Sovereign, in development, close further and further until the stream stops.

Avrelius Cloud — the first production architecture

Data will be stored on servers in Switzerland. We will be responsible for the infrastructure, encryption, and backups. For analysis, Avrelius can use the most advanced external AI models available.

Avrelius Sealed — in development

Data is processed inside an isolated, protected environment. It is decrypted there only for the duration of the task and remains encrypted outside that environment.

Avrelius Local — in development

Source records, search, and core processing stay on the user’s device. Data is sent to external services only for functions that require external processing, with each such use under the user’s control.

Avrelius Sovereign — in development

The entire data and AI environment runs on your own infrastructure: storage, encryption keys, and AI models are under your control. No user data is stored on Avrelius infrastructure. We provide the software and the method; responsibility for safeguarding the data moves to its owner.

There are no fixed launch dates yet for Sealed, Local, or Sovereign. The development sequence will depend on what we learn from the closed beta, technical readiness, and real demand.

§ 06 — Portability

Your archive remains portable.

Your records, decisions, and change history are designed to remain portable. Your digital twin, the connections between records, and Avrelius’s conclusions can be rebuilt from the source data when you move to a different architecture or AI model.

That means a future move from Avrelius Cloud to Sealed, Local, or Sovereign will not require starting over. The archive you have built is already yours, and you can download it at any time.

You can start using Avrelius now: the more meaningful history you build, the more of your own context the system can draw on later — regardless of which setup you choose in the future.

§ 07 — Documents & contact

Privacy documents and security contact.

  • The privacy page lists the external services involved in processing data, explains what each one is used for, and sets out the rules for storing, deleting, and exporting user data.
  • To report a potential security issue, email security@avrelius.com.

We will update this page whenever the architecture, infrastructure, or data-processing practices change.

§ 08 — Sources

Sources behind the security approach.

  1. Federal Act on Data Protection (FADP), in force since 1 September 2023. Fedlex.
  2. European Commission. Adequacy decisions, Switzerland.
  3. Barker, E. (2020). Recommendation for Key Management: Part 1 — General. NIST Special Publication 800-57 Part 1 Rev. 5.
  4. CISA. #StopRansomware Guide.

Titles are given in English, as published.

Join the waitlist →← Back to the main page