Last updated: 18 July 2026
MAVOS Company Limited, a company established in Vietnam, is the Publisher of Envi. This notice explains what MAVOS and its service providers process when you use the public Envi application, website, account, and support channels.
Envi source builds using developer-only provider adapters are not a public service and are outside the public account and provider routing described here.
The short version
- Envi sends selected text only after you invoke a translation action.
- MAVOS does not store Selection, Translation, Dictionary, clipboard, voice text, or audio content in its product database, application logs, analytics, crash reports, or backups.
- Translation content remains ephemeral in MAVOS systems, but a selected official provider processes it and may have its own limited retention.
- MAVOS keeps the minimum account, session, quota, security, operational, purchase, and legally required finance records needed to run the service.
- Envi has no advertising, third-party analytics, session replay, donated examples, saved translation history, or data-broker sharing.
Data you choose to send
Selected text and language settings
When you use the Translation Shortcut or an enabled selection control, Envi sends the active selected text and the source and target language settings over encrypted connections to the Envi backend. The backend authorizes the request and sends it to the provider selected for that capability and service tier.
MAVOS releases request content after completion, cancellation, replacement, timeout, or disconnection. Envi does not use selected text to build advertising profiles or train a MAVOS model.
Support messages
MAVOS receives the message and contact details you choose to include when you email support. Do not send confidential selected text, passwords, credentials, payment-card data, or identity documents unless MAVOS has provided a specific private channel and explained why the information is needed.
Provider routing
Public Envi uses official providers through the Envi backend. Routing is deterministic and does not silently retry the same text with another provider.
| Request | Recipient |
|---|---|
| Free Tier single-word or sentence translation | Google Gemini 3.1 Flash-Lite |
| Paid Tier sentence translation | Google Gemini 3.1 Flash-Lite |
| Paid Tier single word with automatic source detection | Google Gemini 3.1 Flash-Lite |
| Paid Tier single word with an explicit source language | Microsoft Azure Translator |
| Paid Tier dictionary for an eligible explicit-source single word | Microsoft Azure Translator |
| Optional Paid Voice | Google Cloud Text-to-Speech |
| System Voice | The operating system voice on your device, without a remote Envi voice request |
Provider facts relevant to your choice:
- Standard Gemini API abuse monitoring retains prompts and responses for 55 days and can allow authorized human review of flagged content. MAVOS will not launch this route unless it accepts that production condition or confirms approved zero-data-retention eligibility. See Gemini API usage policies and zero data retention.
- Microsoft states that Azure Translator does not store submitted text or translations for the synchronous text-translation service. See Azure Translator data, privacy, and security.
- Google states that Cloud Text-to-Speech does not log customer text or audio data. See Cloud Text-to-Speech data logging.
MAVOS will update this notice if the released provider, product configuration, or contract changes.
Account and authentication data
Every public plan requires an Envi Account authenticated with Google or Apple. Successful provider sign-in verifies the provider identity. Google and Apple identities create separate Envi Accounts even if they expose the same email address. Envi v1 does not link or merge them.
Google Identity Platform or Sign in with Apple processes the information needed to authenticate you. Provider-managed identity metadata can include an email address and authentication network records. The Envi product database uses an opaque account identifier, provider identifier, one-way identity fingerprint, bounded provider deletion handle, timestamps, disabled state, and current service tier. MAVOS does not copy the account email into its ordinary product records.
The desktop stores only a rotating Envi session in the operating system's secure credential store. MAVOS stores credential hashes and bounded session-family records, not the usable desktop credential itself.
Service records MAVOS stores
MAVOS limits public service storage to:
- pseudonymous account and current service-tier records;
- short-lived sign-in attempts, one-time exchange records, and rotating session families;
- current-month quota counters and short concurrency leases;
- content-free provider observations containing route kind, provider class, outcome, admitted units, and a coarse latency bucket;
- verified purchase grants, webhook idempotency records, and minimal finance records after Paid Tier launches; and
- support or security correspondence you choose to send.
Application logs do not contain request or response bodies, credentials, account emails, language values, client addresses, full user agents, provider request URLs, or stable account IDs. MAVOS does not enable product analytics, advertising identifiers, session replay, content fingerprints, saved history, or donated-example collection for v1.
Retention
| Record | Normal retention |
|---|---|
| Selection, Translation, Dictionary, voice text, and audio in MAVOS systems | Active request only, then released |
| Sign-in attempt and one-time code | Authorizes for up to 5 minutes; scheduled for database TTL cleanup within the following 24 hours |
| Envi session family | 15-minute access window, 30-day idle maximum, and 180-day absolute maximum, or earlier revocation |
| Exchange idempotency record | 24 hours |
| Current usage counters | Current quota month; deleted with the account unless separately required as a finance record |
| Content-free provider observation | 30 days |
| Support or security case | Normally 90 days after closure, unless a disclosed legal hold or dispute requires longer |
| Account tombstone after deletion | Scheduled for deletion within 30 days after deletion starts |
| Purchase and finance record | Only for the legally approved tax, refund, chargeback, accounting, or dispute period |
The production launch configuration will keep Firestore scheduled backups disabled and exclude public Cloud Run request logs from ordinary application-log storage. Cloud-provider administrative audit records that MAVOS cannot disable can remain for the provider's fixed period, currently 400 days. Envi does not put selected text or translation responses into those administrative records.
Authentication-provider deletion can take longer than deletion from live Envi product systems. Google documents that deletion from Firebase systems and backups can take up to 180 days, while some authentication IP records are retained for a limited fraud-prevention period. See Privacy and Security in Firebase.
Account deletion
You can start deletion from Account Settings in Envi. Deletion immediately disables the Envi Account, revokes all Envi session families, rejects new provider work, cancels active work on the current device, and clears the local secure session. MAVOS then initiates identity-provider deletion and schedules non-required live account data for deletion within 30 days.
Account deletion does not cancel a subscription billed by Apple or a merchant of record. You must cancel billing at its source. Financial records can remain only when law or a live tax, refund, chargeback, accounting, or dispute duty requires them. Read the complete account deletion instructions.
Website data
MAVOS does not place analytics cookies, advertising pixels, or tracking scripts on this website. The site is hosted by GitHub Pages, so GitHub can process ordinary web-request information needed to deliver and secure the pages under the GitHub Privacy Statement.
If you follow a link to a Store, identity provider, billing provider, or another website, that service's privacy notice applies to its processing.
International processing
MAVOS operates from Vietnam. The launch backend is planned for the United States, and Firebase Authentication processing is US-based. Google, Microsoft, Apple, GitHub, Stores, and a future merchant of record may process data in other countries under their contracts and privacy terms. MAVOS will publish the final vendor register and transfer disclosures required for launch after legal and contract review.
Security
Envi uses encrypted network connections, operating-system secure credential storage, restricted service identities, protected secrets, role-based production access, and content-free operational logs. No system is completely secure. Contact MAVOS promptly if you believe an Envi Account or service has been compromised.
Your choices and rights
You can:
- avoid sending selected text by not invoking Envi;
- choose System Voice instead of cloud voice;
- sign out and clear the current device session;
- delete the Envi Account from the application; and
- contact MAVOS about access, correction, deletion, objection, restriction, or another right available under applicable law.
MAVOS may need to verify the request without asking for your password or full provider credential. Some records cannot be deleted immediately when a legal duty requires retention, but they remain separated from product access and are deleted when that duty ends.
Children
Envi is a general productivity tool and is not directed to children. If you believe a child has provided personal data contrary to applicable requirements, contact MAVOS so the request can be reviewed.
Contact and changes
Until MAVOS domain mailboxes are activated, contact willnguyen.services@gmail.com with the subject Envi Privacy. Do not include passwords, session credentials, or sensitive selected text.
MAVOS will post material changes at this URL and update the date above. A change to provider routing, stored data, retention, analytics, or advertising requires a corresponding product and privacy review before it takes effect.