Request Access

Legal

Privacy Policy.

Effective 2026-10-02

This page says what personal information this website collects, why we hold it, who else sees it, and how you get it back or get it deleted.

Who we are

Avatise is operated by its founder, Tanvir Singh Virk, in Washington State, USA. Anything to do with this policy, or with your data, goes to tanvir@avatise.ai.

Avatise does not create AI versions of anyone

Many visitors arrive here from advertising about AI, so this is worth stating plainly. We do not clone, generate or synthesize anyone’s voice, face or likeness, and we do not produce content. Avatise is the permission side: talent set the terms for any AI use of their face and voice, and a company gets that permission in writing. This website does not collect voice recordings, face scans or biometric templates.

What we collect

  • What you type into the access request form. Talent: name, email address, optional phone number, location (city, state, country) and talent type. Companies: company name, contact name, role, work email address, optional phone number and location (city, state, country).
  • Whether you confirmed your email address. When you submit the form we email the address you gave us with a link to confirm it is yours. We store the date we sent it, the date you clicked it, and a one-way hash of the link’s token. It is only there so a reply does not bounce without anyone noticing. Confirming is not required and nothing waits on it.
  • Technical data any website receives. Your browser’s user agent and your IP address. We do not store a raw IP address anywhere. Our anti-abuse ledger keeps only a keyed hash of it, and the key is held outside the database.
  • Cookies. A session cookie if you sign in. When advertising is running, Meta’s own first-party cookies _fbp and _fbc, written on avatise.ai by the Meta Pixel. We run no other analytics cookies.

Why we hold it

  • To read and answer your access request.
  • To contact you about the founding cohort.
  • To operate a pre-launch platform, including sign-in, and to stop bots and duplicate submissions.
  • To measure whether our advertising works.

Legal basis

In the United States we rely on your consent. You filled in a form asking to be contacted, and we use what you gave us for exactly that.

If you are outside the US, including in the UK or the EEA, the GDPR bases are consent for the access request and our contact with you (Article 6(1)(a)), and legitimate interests for site security, anti-abuse and advertising measurement (Article 6(1)(f)), which we have weighed against your privacy. You can withdraw consent at any time by email, and withdrawal does not affect anything already done. Your data is processed in the United States. If a licensing agreement is signed later, that agreement becomes the basis for data processed under it.

Who receives it

  • Supabase, our database and authentication host. It holds every row at rest.
  • Resend, which delivers the internal notification of your request and the confirmation emails we send you.
  • Vercel, which hosts the site. Server logs can contain email addresses.
  • Meta Platforms, for advertising measurement only, as described below.

That is the whole list. We do not sell or rent personal information, and we share nothing for cross-context behavioural advertising beyond the ad measurement below.

Advertising measurement

When advertising is switched on, this site runs the Meta Pixel in your browser and reports the same events again from our server through Meta’s Conversions API. The browser half sends a page view and, on a successful form submission, a Lead event carrying the type of applicant and the campaign tags from the ad link. It carries no name, address or phone number. The server half sends the same Lead plus a SHA-256 hash of your email address, your IP address, your user agent and the two Meta cookies. Meta uses these to match the conversion back to an ad. The hash is one way: nobody holding it can read an address back out. None of it runs when the pixel is not configured.

How to opt out:

  • Block cookies or turn on your browser’s tracking protection. Without _fbp and _fbc the match does not work.
  • Use Meta’s own ad settings at facebook.com/adpreferences to limit how Meta uses off-platform activity.
  • We do not currently detect the Global Privacy Control signal automatically, so we will not claim that we honour it. Email us and we will apply the opt-out by hand.

How long we keep it

  • Requests flagged as spam: deleted 30 days after they arrive.
  • Requests we invited: deleted 12 months after the invitation.
  • Requests we declined: deleted 12 months after they arrive.
  • Requests we have not answered yet: kept while the request is active. An unanswered application is not stale data. Ask us and it goes.
  • Anti-abuse hashes: 90 days.
  • Accounts and listings: for the life of the account.
  • Issued licences: kept indefinitely. A licence is a contract record, and being provable later is the point of it.
  • Server logs: our host’s default retention.

Your rights

You can ask for a copy of what we hold, have it corrected, have it deleted, withdraw consent, object to processing, or complain to your data protection regulator. We do not treat you any differently for asking.

If you have an account, “Delete my account and all my data” at the bottom of your profile does it yourself, in one step. It removes your listing, your account, your access requests, your activity, your anti-abuse hashes and your sign-in record, and sends a confirmation. If you do not have an account, email us and we will do it.

Two things survive a deletion on purpose. A single suppression entry holding your email address, so we can guarantee you are never contacted again (deleting that entry would undo its own promise). And any licence already issued, because it is a contract record. Admin audit entries and host log lines age out on their own schedules.

Children

Avatise is not for anyone under 18. Do not submit a request if you are. If we learn that we hold information about a minor, we delete it.

Security

Every database table is reachable only by server-side code holding a single credential that never reaches a browser. There is no public read path and no per-user database access. Sign-in is by emailed link. Addresses in the anti-abuse ledger exist only as keyed hashes. No system is perfectly secure and we will not claim otherwise, but we keep the number of places your data sits small.

Changes to this policy

We will post any revision here with a new effective date. If a change materially affects how we use your information and we hold your address, we will email you.

Contact

tanvir@avatise.ai · Avatise, Washington State, USA.