Last updated May 11, 2026
Ave is an identity and authorization service operated by Lantharos. This policy explains what Ave stores, what stays on your device, what connected apps can receive, and how to ask us about your data.
We do not sell personal information, run third-party ad tracking, or use your Ave data to build advertising profiles. We do process account, device, security, and authorization metadata because the service cannot work without it.
Contact us about privacy at data@lantharos.com.
When you create or use an Ave account, we store:
* Your user ID and identity IDs.
* Your display name, handle, optional verified email, optional birthday, avatar URL, and banner URL or color.
* Passkey credential IDs, public keys, counters, transports, device type, backup status, friendly passkey names, and encrypted PRF master-key material when supported by your passkey.
* Trusted device records, including device name, type, browser, operating system, last seen time, local device fingerprint, and optional push subscription.
* Session records with hashed session tokens, expiration time, authentication method, IP address, and user agent.
* Recovery-code records as hashes only. We do not store the recovery code text after it is shown to you.
* Encrypted master-key backups, encrypted identity private keys, signing public keys, encrypted signing private keys, and encrypted per-app keys.
Your handle, display name, verified email, birthday, avatar URL, and banner URL are readable by Ave servers. Encrypted key material is stored so Ave can help you recover or use keys, but we do not have the plaintext master key needed to decrypt it.
We collect IP addresses, user agents, request timing, and event details for authentication, rate limiting, abuse prevention, account activity, and security investigation. This includes events such as account creation, login, passkey changes, recovery-code use, device changes, identity updates, OAuth authorization, authorization revocation, exports, and deletion attempts.
Activity logs are kept for about 5 days and then removed by scheduled cleanup. Stale trusted devices are removed after about 14 days without being seen. Login approval requests expire after about 5 minutes. Email verification codes expire after about 15 minutes. Sessions normally last up to 30 days and may be refreshed while you keep using Ave.
Ave stores some data in your browser so sign-in and encryption can work:
* Your master key is stored in IndexedDB when available, with a localStorage fallback for older browser paths.
* A local device fingerprint is stored in localStorage to recognize the browser as the same trusted device.
* Short-lived OAuth, PKCE, route return, and database bookmark values may be stored in sessionStorage.
The Ave SDK may also store PKCE state in sessionStorage. Quick Ave integrations can store an identity and token data in the connected app's localStorage; that storage belongs to the connected app, not to the Ave dashboard.
If you upload an avatar, banner, or workspace logo, the image is stored in object storage and served from Ave's public asset domain. Anyone with the asset URL may be able to view it.
Replacing or deleting an avatar or banner removes the old object when Ave can identify it. Account deletion removes the account database records, but public asset caches and copies already fetched by browsers, CDNs, or connected apps may remain until they expire or are separately removed.
When you authorize an app, Ave shares only the scopes you approve or that the flow requires:
* "openid" gives the app your stable identity ID.
* "profile" can include display name, handle, and avatar URL.
* "email" can include your verified email address.
* "offline_access" lets the app receive refresh tokens so it can keep a session.
* "user_id" can include your account-level user ID when the app requests that scope. You will see a warning on the consent screen.
Apps may also receive OAuth access tokens, ID tokens, connector delegation tokens, and, for E2EE app flows, app keys through the browser flow after you approve access. Revoke access from your dashboard to stop future Ave-issued access, but connected apps may keep data they already received under their own privacy policies.
Developers and workspace members can create apps, resources, redirect URIs, client credentials, workspace names, workspace logos, verified domains, and team invitations. The developer portal also shows app-level counts, recent authorization activity, connected identities for the app, refresh-token activity, revocations, connector grants, and delegation audit logs.
Developer app records, workspace records, OAuth authorizations, refresh-token hashes, connector grants, and delegation audit logs are kept while they are needed to operate the service, until the relevant account, workspace, app, authorization, or grant is deleted or revoked, unless we need to keep limited records for security or legal reasons.
Ave uses infrastructure and service providers to operate the service. This includes Cloudflare for hosting, Workers, D1, Durable Objects, R2 object storage, email verification messages, caching, and network security. Browser push notifications also pass through the push service used by your browser or operating system.
These providers process data for Ave so the service can run. We do not share Ave data with data brokers or advertising networks.
We may disclose information if required by law, court order, or a valid government request. We will limit what we provide to what we believe is legally required.
Some data is encrypted in a way that Ave cannot decrypt because we do not hold your plaintext master key. If we cannot technically access plaintext key material or encrypted user-controlled data, we cannot provide it.
From the Ave dashboard, you can export your Ave data, update profile details, remove an email, revoke trusted devices, revoke connected apps, revoke connector grants, disable push notifications, delete non-primary identities, and delete your account.
Account deletion is permanent for Ave account records and breaks future Ave access for connected apps. It does not delete data that connected apps already copied, messages you sent us by email, public asset copies already cached outside our direct control, or records we must keep for security, fraud prevention, compliance, or dispute handling.
Depending on where you live, you may have rights to know, access, correct, delete, export, or limit certain uses of your personal information. You can exercise many of these controls directly in the dashboard or contact data@lantharos.com.
We do not discriminate against you for using privacy rights. We do not sell personal information or share it for cross-context behavioral advertising.
Ave is not directed to children. If you believe a child provided personal information without the consent required by local law, contact data@lantharos.com so we can review and delete it where appropriate.
We may update this policy as Ave changes. When we make material changes, we will update the date above and use a reasonable notice method, such as the website or dashboard.