Tavana AI

Privacy Policy

How Tavana AI collects, uses, discloses, retains, and protects information

Effective July 1, 2026

PRIVACY AT A GLANCE: Tavana AI uses information to provide AI-assisted evaluations and related services, protect the Platform, connect users with independent attorneys at the user's request, and improve our products. We may create and use De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, and Derived Learning Data for model training, evaluation, benchmarking, research, product development, and other lawful business purposes. We do not intentionally place direct identifiers into generalized model-training datasets, and we do not sell Personal Information to third parties for their independent AI training.

1. Scope, Agreement, and U.S. Focus

1.1 Scope. This Privacy Policy describes how Tavana AI, Inc. ("Tavana AI," "we," "our," or "us") collects, uses, processes, discloses, retains, and protects Personal Information when you use tavana.ai, tavana.ai/evaluate, accounts, portals, Administrative Services, Attorney Connections, and related Platform features.

1.2 Agreement and Notice. This Privacy Policy is incorporated into our Terms of Use and forms part of the Public Policies you affirmatively agree to through our clickwrap or other acceptance mechanism. It also serves as a privacy notice describing our practices. If you do not agree, do not create an account, submit an Evaluation request, purchase a service, or use a feature requiring acceptance.

1.3 United States Focus. The Platform is presently directed to users in the United States. This Policy is designed around applicable U.S. privacy requirements. We do not represent that the Platform is intended for residents of every non-U.S. jurisdiction.

1.4 Relationship to Other Agreements. For information processed on behalf of a law firm or other business customer, a separate contract or data processing addendum may impose additional restrictions. The more specific agreement controls for the covered data to the extent of a conflict.

2. Key Definitions

2.1 "Personal Information" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an individual or household, as defined by applicable law.

2.2 "Sensitive Information" means Personal Information treated as sensitive under applicable law. Depending on the jurisdiction and what you submit, this may include government identifiers, account credentials, precise geolocation, racial or ethnic origin, religious beliefs, health information, sexual orientation, certain communication contents, or other legally specified categories. Immigration-related information may be treated as sensitive under some laws or may reveal another sensitive category.

2.3 "De-identified Data" means information processed using reasonable measures so that it cannot reasonably be linked to an identified or identifiable individual or household in the relevant context.

2.4 "Aggregated Data" means information combined across multiple records, users, matters, sources, or events and presented as a cohort, statistic, trend, or summary not reasonably intended to identify a particular person or household.

2.5 "Case Statistics" means De-identified Data or Aggregated Data concerning profiles, evidence categories, workflows, document characteristics, processing times, Requests for Evidence, outcomes, user interactions, attorney edits, or system performance.

2.6 "Derived Learning Data" means non-identifying features, patterns, labels, taxonomies, statistical relationships, quality signals, evaluations, benchmarks, error analyses, system configurations, prompts, workflow rules, model parameters, model weights, and other learnings generated from operating, testing, evaluating, or improving the Platform, provided the material is not reasonably intended to identify a person or disclose a User Submission.

2.7 "Synthetic Data" means data generated or transformed for testing, evaluation, training, or development that is not intended to reproduce or expose an identifiable person or a specific confidential submission.

3. Notice at Collection

The summary below describes categories of Personal Information we may collect, common sources, principal purposes, categories of recipients, and our general retention approach. We collect only the categories relevant to the features you use. More detail appears in later sections.

Identifiers and account data

Examples
Name, email, phone, account ID, IP address, device identifiers
Sources
You; device; service providers
Principal purposes
Account creation, service delivery, security, support, communications
Typical recipients
Cloud, security, communications, support providers; attorneys at your direction
General retention
Account period plus up to 3 years; logs often up to 24 months, subject to exceptions

Immigration and profile information

Examples
Citizenship, nationality, visa status, immigration history, education, employment, publications, awards, credentials
Sources
You; authorized third parties; sources you direct us to
Principal purposes
Evaluation, personalization, document organization, service delivery, quality assurance, de-identification and improvement
Typical recipients
AI and infrastructure providers; attorneys at your direction
General retention
Evaluation and related records generally up to 7 years, subject to purpose and law

Government identifiers

Examples
Passport, visa, USCIS receipt, Alien Registration Number, other identifiers when requested
Sources
You; authorized third parties
Principal purposes
Requested service, identity, document handling, security, filing logistics
Typical recipients
Service providers as necessary; government agencies at your direction; attorneys at your direction
General retention
Only as reasonably necessary for the service, security, legal obligations, and dispute records

Professional and education data

Examples
CV, degrees, citations, publications, patents, employment, awards
Sources
You; public or professional sources you identify
Principal purposes
Evaluation, reports, organization, analytics, model and product improvement after de-identification
Typical recipients
AI and infrastructure providers; attorneys at your direction
General retention
Generally up to 7 years for evaluation records; De-identified Data may be retained longer

User content and communications

Examples
Uploads, answers, messages, support requests, feedback, evaluation interactions
Sources
You; authorized representatives
Principal purposes
Service delivery, support, quality assurance, security, improvement, dispute resolution
Typical recipients
AI, cloud, support, communications providers; attorneys at your direction
General retention
Varies by purpose; evaluation records generally up to 7 years

Commercial information

Examples
Purchases, subscriptions, invoices, transaction records
Sources
You; payment processors
Principal purposes
Payment, accounting, support, fraud prevention, legal compliance
Typical recipients
Payment, accounting, fraud, professional advisors
General retention
Tax, accounting, chargeback, and legal periods

Internet and usage data

Examples
Pages, clicks, feature use, timestamps, browser, device, logs, cookies
Sources
Device; browser; Platform
Principal purposes
Security, analytics, debugging, performance, product improvement
Typical recipients
Analytics, cloud, security, monitoring providers
General retention
Often up to 24 months, subject to security and legal needs

Inferences and outputs

Examples
Scores, pathway comparisons, extracted fields, classifications, summaries, quality signals
Sources
Generated from submissions and Platform use
Principal purposes
Evaluation, service delivery, quality assurance, personalization, de-identification, improvement
Typical recipients
AI and infrastructure providers; attorneys at your direction
General retention
Generally tied to evaluation retention; De-identified and Derived Learning Data may be retained indefinitely

Retention periods are estimates and may be shortened or extended based on actual need, legal obligations, security, disputes, technical constraints, or an active relationship. We do not retain Personal Information longer than reasonably necessary for disclosed purposes unless law permits or requires otherwise.

4. Information We Collect

4.1 Information You Provide. Depending on the feature, you may provide contact details; account information; immigration history; citizenship or nationality information; visa or status information; education and employment history; publications, citations, awards, patents, credentials, media coverage, and professional achievements; family or sponsor information; uploaded documents; government identifiers; payment-related information; feedback; and communications.

4.2 Information Collected Automatically. We may collect IP address, browser and device characteristics, operating system, referring and exit pages, timestamps, pages viewed, feature interactions, clicks, session information, diagnostic logs, crash data, security events, cookies, local storage, and similar information.

4.3 Information from Third Parties. We may receive information from service providers, payment processors, identity or security vendors, attorneys or law firms, referral partners, public or professional sources, and other persons who are authorized to provide information. We may combine such information with other information consistent with this Policy.

4.4 Public and Professional Information. Where lawful and relevant, we may process publicly available or professional information, such as publication records, public biographies, professional profiles, citation metrics, company information, public government decisions, or other sources used to provide or improve the Platform.

5. Sensitive Information and Your Consent

5.1 Why Sensitive Information May Be Needed. Immigration-related services can require information that is highly personal or legally sensitive. Certain features may ask for government identifiers, immigration history, nationality, family information, or documents that reveal health, religion, ethnicity, sexual orientation, or other Sensitive Information.

5.2 Affirmative Consent and Instruction. By affirmatively accepting the Public Policies and voluntarily submitting Sensitive Information to a feature that requests or accepts it, you instruct Tavana AI and, to the extent applicable law requires consent, affirmatively consent to our processing of that Sensitive Information for: (a) providing and personalizing the requested feature; (b) generating and delivering outputs; (c) account administration and support; (d) security, fraud prevention, abuse prevention, and integrity; (e) quality assurance and troubleshooting; (f) complying with law and protecting rights; and (g) creating De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, and Derived Learning Data for the improvement purposes described in Section 7.

5.3 Choice. If you do not consent to the processing described above, do not submit Sensitive Information and do not use a feature that requires it. Some AI evaluation features cannot function without processing the information you submit. Where applicable law gives you a right to withdraw consent, you may contact privacy@tavana.ai. Withdrawal is prospective and may prevent continued use of a feature that requires the relevant processing.

5.4 No Hidden Purpose Expansion. We will not materially expand the use of previously collected Sensitive Information to a new, incompatible purpose through a quiet or retroactive policy change where applicable law requires additional notice or consent.

6. How We Use Personal Information

Service delivery: provide Evaluations, accounts, portals, Administrative Services, document processing, communications, support, and requested features;

AI-assisted processing: generate outputs, extract or classify information, organize documents, support workflows, and operate AI-enabled features;

Personalization: tailor questions, workflows, content, and feature presentation based on information you provide and how you use the Platform;

Quality assurance and support: review issues, investigate errors, test outputs, respond to users, and improve service quality;

Platform improvement: improve questions, scoring, extraction, retrieval, document handling, workflows, reliability, safety, and user experience;

Model development and evaluation: create and use the improvement data described in Section 7 to train, fine-tune, test, benchmark, validate, and improve AI Systems;

Research and statistics: develop Case Statistics, benchmarks, cohort analyses, reports, and other De-identified or Aggregated Data;

Security and integrity: authenticate users, detect abuse, prevent fraud, investigate incidents, protect systems, and enforce agreements;

Attorney Connections: route information to an attorney or law firm when you request or authorize the connection;

Payments and business operations: process transactions, maintain records, perform accounting, audit, insurance, corporate planning, and professional-advisor functions;

Communications and marketing: send service messages and, subject to applicable law and your choices, product, educational, event, or promotional communications;

Legal compliance: respond to legal process, satisfy regulatory obligations, exercise or defend claims, and protect rights and safety.

7. AI, Model Improvement, De-identification, and Case Statistics

7.1 AI Service Processing. We use information you submit to operate AI-enabled features and generate outputs. This may involve third-party AI or infrastructure providers acting for Tavana AI under contractual or other appropriate restrictions.

7.2 Creating Improvement Data. We may process User Submissions, Evaluation Outputs, interactions, feedback, reviewer edits, workflow events, usage signals, and available outcome information to create De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, and Derived Learning Data.

7.3 Generalized Model and Product Improvement. We may use De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, and Derived Learning Data to develop, train, fine-tune, test, evaluate, benchmark, validate, secure, and improve our AI Systems and other products and services. Examples include improving extraction, evidence organization, scoring, retrieval, question design, drafting support, workflow automation, hallucination detection, model evaluation, quality control, safety, and reliability.

7.4 Case Statistics and Research. We may analyze, retain, use, publish, disclose, license, and commercialize Case Statistics and other De-identified or Aggregated Data for research, benchmarking, industry analysis, reports, product development, model evaluation, marketing, and other lawful business purposes. Case Statistics may concern evidence patterns, profile cohorts, processing timelines, Requests for Evidence, approval or denial outcomes, user behavior, attorney edits, workflow performance, or aggregate usage trends. We do not intentionally publish such statistics in a form reasonably designed to identify a particular user or household.

7.5 Direct Identifiers and Generalized Training. We do not intentionally place direct identifiers such as names, personal email addresses, phone numbers, Social Security numbers, passport numbers, Alien Registration Numbers, USCIS receipt numbers, or similar government identifiers into generalized model-training datasets. We may process Personal Information to provide the Platform, perform authorized quality assurance, and create De-identified Data and the other improvement data described above.

7.6 De-identification Methods. Depending on the data and purpose, de-identification may include removal, masking, hashing, tokenization, transformation, generalization, suppression, aggregation, separation of keys, filtering, small-cell suppression, access controls, or other measures reasonably designed to reduce linkage risk. De-identification reduces risk but is not a mathematical guarantee.

7.7 Public De-identification Commitment. We maintain and use De-identified Data in de-identified form and do not attempt to re-identify it except to test or validate de-identification, investigate security or integrity issues, prevent fraud or abuse, or comply with law. Where required by law, we contractually require recipients of De-identified Data to observe comparable restrictions.

7.8 Derived Learning Data and Model Weights. Derived Learning Data and model weights may reflect patterns learned from many sources and may be retained indefinitely where they are not reasonably intended to identify a person or disclose a User Submission. A deletion request concerning Personal Information does not require us to delete De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, Derived Learning Data, or model weights when applicable law does not require that result.

7.9 No Sale for Third-Party Independent Training. We do not sell, license, or otherwise provide your Personal Information to a third party for that third party's independent AI model training. AI and infrastructure providers may process information for Tavana AI to deliver or improve our services under applicable restrictions.

8. How We Disclose Information

We may disclose information to the following categories of recipients for the purposes described in this Policy:

Service providers and contractors, including cloud hosting, AI infrastructure, OCR, document processing, analytics, security, communications, support, payment, and professional-service providers;

Attorneys and law firms, when you request, direct, or affirmatively authorize an Attorney Connection or other disclosure;

Government agencies and delivery providers, at your direction or your attorney's direction for administrative filing, fee, mailing, or status-related services;

Affiliates and corporate transaction participants in connection with a merger, financing, acquisition, restructuring, bankruptcy, or sale of assets, subject to applicable law;

Professional advisors, auditors, insurers, and consultants under appropriate confidentiality obligations;

Regulators, courts, law enforcement, and other persons when reasonably necessary to comply with law, protect rights or safety, prevent fraud, investigate security issues, or enforce agreements;

Recipients of De-identified Data, Aggregated Data, Case Statistics, or research outputs, subject to the commitments in Section 7.

Attorney compensation. Tavana AI may receive technology, advertising, listing, marketing, lead-generation, sponsorship, or other service fees from participating attorneys or law firms. We do not disclose your Personal Information to a provider merely because the provider pays Tavana AI. Contact information or evaluation information is shared for an Attorney Connection only when you request, direct, or affirmatively authorize the connection, subject to applicable law.

9. Sale, Sharing, Targeted Advertising, and Universal Opt-Out Signals

9.1 Current Practice. As of the Effective Date, Tavana AI does not sell Personal Information for money and does not share Personal Information for cross-context behavioral advertising as those terms are defined by the California Consumer Privacy Act. We also do not use Personal Information for targeted advertising based on activity across nonaffiliated websites or services.

9.2 Future Changes. If our practices change in a manner that triggers a right to opt out of sale, sharing, or targeted advertising, we will update this Policy and provide required mechanisms before or when the change takes effect.

9.3 Preference Signals. Where required by applicable law, we honor legally recognized universal opt-out preference signals, such as Global Privacy Control, for the browser or device that sends the signal. We may provide a means to confirm opt-out status where required.

10. Cookies and Similar Technologies

We and our providers may use cookies, local storage, pixels, SDKs, logs, and similar technologies for strictly necessary functions, security, preferences, analytics, and performance. We do not currently use these technologies to sell Personal Information or share it for cross-context behavioral advertising. You may control certain technologies through browser settings or any consent-management interface we provide. Disabling necessary technologies may impair functionality.

11. Automated Processing, AI Disclosures, and Profiling

11.1 AI Interaction Notice. The Platform uses AI Systems. When you use an AI-enabled feature, you are interacting with an automated or AI-assisted system. Some outputs are generated automatically and may not be reviewed by a human before delivery.

11.2 No Government or Legal Decision. Tavana AI does not make decisions for USCIS, the Department of State, a court, or another government authority. Tavana AI does not make a binding legal eligibility determination and does not control whether an immigration benefit is granted.

11.3 Significant Decisions. We do not currently use an Evaluation Output as the sole basis for Tavana AI to make a decision granting or denying a user employment, housing, credit, insurance, healthcare, education, or access to an essential government service. If a future covered use of automated decisionmaking triggers notice, access, opt-out, appeal, human-review, risk-assessment, or similar obligations under applicable law, we will provide required rights and disclosures.

11.4 California ADMT. California regulations concerning automated decisionmaking technology, risk assessments, and related consumer rights became effective January 1, 2026, with compliance timing that varies by requirement. To the extent those rules apply to Tavana AI and a particular processing activity, we will provide required notices and rights.

11.5 Colorado and Other AI Laws. Certain U.S. laws require disclosure when a consumer interacts with AI and impose additional obligations for high-risk systems or consequential decisions. We design the public Evaluation as an assistive informational tool, not an autonomous government or legal decisionmaker. Where a specific AI law applies, we will assess and comply with the duties applicable to our role and use case.

12. Data Security

We maintain reasonable administrative, technical, and physical safeguards designed to protect Personal Information against unauthorized access, acquisition, destruction, loss, misuse, alteration, or disclosure. Measures may include encryption in transit and at rest, access controls, authentication, logging, monitoring, vendor diligence, vulnerability management, personnel confidentiality obligations, and incident-response processes, as appropriate to the system and risk. No security method is perfect, and we cannot guarantee absolute security.

13. Data Retention

We retain Personal Information for as long as reasonably necessary for the purposes described in this Policy, including service delivery, account administration, security, fraud prevention, quality assurance, legal compliance, dispute resolution, and business operations. Our general ranges include: evaluation submissions, outputs, communications, and reviewer notes for up to seven (7) years; account and contact records during the relationship and for up to three (3) years afterward; security and diagnostic logs often for up to twenty-four (24) months; and transaction records for applicable tax, accounting, chargeback, and legal periods. We may retain records longer when necessary for security incidents, legal holds, disputes, fraud prevention, or legal obligations. De-identified Data, Aggregated Data, Case Statistics, Synthetic Data, and Derived Learning Data may be retained indefinitely.

14. Your U.S. Privacy Rights

14.1 Rights May Vary. Depending on your state, applicable law, and whether Tavana AI meets a law's coverage thresholds, you may have rights to access, confirm processing, correct, delete, obtain a portable copy, opt out of sale, sharing, targeted advertising, or certain profiling, limit certain uses of Sensitive Information, withdraw consent for certain Sensitive Information processing, obtain information about certain automated processing, or appeal a denied request.

14.2 Requests. Submit a request to privacy@tavana.ai with enough information for us to understand the request. We may provide an online request form or privacy center. We will verify identity and authority as required and respond within applicable timeframes. We may deny or limit a request where law permits and will provide an explanation and appeal process where required.

14.3 Authorized Agents. Where law permits an authorized agent to act for you, we may require proof of authorization and may verify your identity directly.

14.4 California. If the CCPA applies, California residents may have rights to know or access categories and specific pieces of Personal Information, correct inaccurate information, delete information subject to exceptions, obtain information about disclosures, opt out of sale or sharing, limit certain uses and disclosures of Sensitive Personal Information, access information concerning certain ADMT uses, and receive non-discriminatory treatment. We will provide any required "Do Not Sell or Share" or "Limit" mechanism if our practices trigger those requirements. As of the Effective Date, we do not sell Personal Information for money or share it for cross-context behavioral advertising.

14.5 Other States. Residents of states with comprehensive privacy laws may have similar rights, including rights concerning sensitive data, targeted advertising, sale, certain profiling, and appeals. We avoid a static state list because coverage and effective dates continue to change; requests may be submitted through the same method.

14.6 Non-Discrimination. We will not unlawfully discriminate against you for exercising an applicable privacy right. A feature may, however, be unavailable if the information you ask us not to process is reasonably necessary to provide that feature.

15. Minors

The Platform is not directed to persons under 18, and persons under 18 are not permitted to create an account or use features requiring acceptance of the Public Policies. We do not knowingly collect Personal Information from persons under 18 through those features. If you believe a minor has provided information in violation of this restriction, contact privacy@tavana.ai.

16. Business Transfers and Legal Process

We may transfer information in connection with a merger, acquisition, financing, restructuring, bankruptcy, or sale of assets. We may also preserve or disclose information to comply with law, respond to valid legal process, protect rights and safety, investigate fraud or security incidents, and enforce agreements. We will provide notice or obtain consent when required by applicable law.

17. Changes to This Privacy Policy

We may update this Policy as our practices, technology, or legal obligations change. We will update the Effective Date and provide additional notice where required or appropriate. We will not use a quiet or retroactive amendment to materially expand rights to use previously collected Personal Information for a different AI-training purpose where applicable law requires additional notice or consent. For existing users, a material change may be presented for renewed acceptance through the Platform.

18. Contact Us

Tavana AI, Inc.
Attention: Privacy Officer
Privacy requests: privacy@tavana.ai
Legal notices: legal@tavana.ai
General information: info@tavana.ai
Website: tavana.ai