auva

Privacy Policy

Last updated: 18 September 2026

1. Who we are, and what this covers

Auva ("Auva", "we", "us") is a travel platform operated by Mehdi Chamsi, connecting travellers with local hosts in Tunisia. This policy covers both the website at auvatunisie.com and the Auva mobile app. You can reach us at hello@auvatunisie.com.

Auva takes no payment, online or in-app. You settle in cash, directly with your host, on the day. We never see or store card or bank details.

2. Data we collect

On the website

  • Account data: email address and password (hashed, never stored in plain text).
  • Trip preferences: destination, budget, dates, group type and interests you enter in the trip planner.
  • Provider data: name, phone number, city, photos and description if you list as a local provider.
  • Approximate location: only if you tap "use my position" when setting a listing's location, and only in the browser.
  • Usage data: pages visited and itineraries generated, for product improvement.

In the mobile app

  • Account data: email address and password (hashed).
  • Profile: your name, profile photo, city and short bio.
  • Traveller profile (optional): age, nationality, interests, and Instagram or TikTok handles if you add them.
  • Photos you upload: profile photo, trip "memories", and — if you host — photos of your experiences.
  • Messages: the text of messages you send to a host, to another traveller, or in a session group chat, along with who sent them and when.
  • Bookings: which experience, which date, how many seats, and the outcome.
  • Phone numbers: exchanged between a traveller and a host only once a booking is confirmed, so the two of you can meet. Never shown before that.
  • Events and plans: events you post or join, who is going, and the shared plan of a booking (meeting point, what to bring, steps).
  • Push notifications (optional): if you allow notifications, a device token so we can tell you about your bookings, messages, events and plans. It is sent through Expo's push service, removed when you sign out or delete your account, and never used for advertising.
  • Reports and blocks: if you report or block someone, we store that, including the reason you wrote and the message reported.
  • Reviews: what you write about an experience after it happens.

The app does not collect your location. It has no GPS permission and does not track where you are. The map opens on a fixed city view.

The app contains no advertising, no third-party analytics and no tracking SDKs. We do not track you across other companies' apps or websites.

3. What other people can see

This matters more than a list of fields, so it gets its own section.

  • Your profile cannot be browsed or searched. Another traveller can only open it if you attended the same session or if you both accepted a "Reconnect" request.
  • Your age, nationality, interests and social handles are only visible after a mutual Reconnect — not to someone who merely shared a session with you.
  • Messages are visible to the people in that conversation — one host, one traveller, or everyone holding a seat on the same session. They are not public.
  • Your phone number is shared with the other party only when a booking is confirmed.
  • If you block someone, you disappear from each other immediately.
  • We may read reported messages when investigating a report, in order to keep people safe.

4. How we use your data

  • To run the booking loop: request a seat, confirm it, and let the two of you meet.
  • To let you message the people you have booked with or reconnected with.
  • To show you experiences that are genuinely available, and to suggest one when you ask.
  • To generate trip itineraries on the website using AI.
  • To investigate reports and keep the platform safe.
  • To email you about your bookings and requests.
  • To improve the product from aggregate usage patterns.

We do not sell your personal data, and we do not use your messages or photos for advertising.

5. Legal basis (GDPR)

If you are in the European Economic Area, we process your data on these bases: contract performance (running the booking and messaging you asked for), legitimate interests (safety, fraud prevention, product improvement), and consent (optional profile fields, photo library access — withdrawable at any time in your device or browser settings).

6. Where your data is stored

On Cloudflare infrastructure: a D1 database (accounts, bookings, messages, profiles), KV (sessions and credentials), and R2 (uploaded images). Transport is HTTPS-only with HSTS. Passwords are hashed with PBKDF2 and never stored in plain text. No system is perfectly secure — if you think your account has been compromised, contact us immediately.

7. Third-party services

  • Cloudflare: hosting, database, image storage, and cookieless visitor analytics.
  • Resend: delivers our transactional emails (booking updates, password resets); receives your email address.
  • Cloudflare Workers AI: itinerary generation on the website, and translating a profile bio when you tap "translate". Your trip preferences, or the text being translated, are sent to the model.
  • Nominatim / OpenStreetMap: geocoding place names; no personal data sent.

8. Deleting your account

You can delete your account yourself, from inside the app: Profile → Delete my account. No email required.

Deletion removes, permanently and immediately:

  • Your login — the account can no longer be signed into.
  • Your name, profile photo, bio, city, age, nationality, interests and social handles.
  • Every photo you uploaded, including trip memories.
  • The text of every message you sent.

What remains, and why:

  • Booking and review records stay, with your name replaced by "Deleted account". A booking is a record of a meeting between two people — erasing it would delete the other person's history of their own outing.
  • Message rows stay as empty placeholders so the other side's conversation doesn't silently lose half of itself.

If you have an upcoming confirmed booking, the app will ask you to cancel or complete it first — someone is expecting you, and they would otherwise be left without a way to reach you. You can also email hello@auvatunisie.com and we will handle it for you.

9. Data retention

Account data is kept while your account is active. When you delete it, the personal data listed in section 8 is removed straight away, not on a 30-day delay. Anonymised records (a booking with no name attached, aggregate usage counts) may be kept indefinitely. Reports and blocks are kept while they are needed for safety.

10. Children

Auva is not intended for children under 13, and we do not knowingly collect their data. The app allows adults to message each other; if you believe a child has created an account, contact us and we will remove it.

11. Your rights

Under GDPR and Tunisian Law No. 2004-63, you have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Request deletion ("right to be forgotten") — see section 8.
  • Object to processing based on legitimate interests.
  • Request data portability.

To exercise any of these, email hello@auvatunisie.com. We respond within 30 days.

12. Reporting someone

If someone behaves badly, report or block them from their profile or from the conversation. Reports reach us with the reason you wrote and, where relevant, the message you reported. We review them and can suspend accounts. You can also write to hello@auvatunisie.com.

13. Changes to this policy

We may update this policy as the platform evolves. We notify registered users of material changes by email. Continued use after a change means you accept the updated policy.

14. Contact

For any privacy question or request: hello@auvatunisie.com