YOUR INBOX, EXPLAINED

Privacy at ayy.

Updated September 5, 2026. This page describes the current development version of ayy and its self-hosted service.

What the app stores

ayy keeps your sign-in session or personal access key in your iPhone’s Keychain. It caches inbox content on your device so you can read recent conversations offline. Appearance preferences and your server URL are saved locally. Signing out removes the saved credential and local inbox cache.

What your server stores

The service stores your email address when you use email sign-in, display name, hashed access keys and sessions, agent names, alert content, replies, decisions, notification preferences, and device push tokens. The hosted backend uses Vercel and Neon Postgres. Your server operator controls the database, backups, retention, and access to that infrastructure.

Email sign-in

When you request a sign-in code, the service sends your email address and code to Resend for delivery. Codes expire after 10 minutes; the database stores a keyed hash of each code. Short-lived sign-in records also include a hashed IP address to limit abuse. Records older than two days are removed by scheduled maintenance or when the next code is requested. Sessions expire after 90 days. Signing out revokes that session and removes its device registrations.

Notifications

If you enable push notifications, the service sends notifications through Apple Push Notification service. Message previews may include an alert’s title and a short excerpt. Turn previews off to receive a generic heads-up instead.

Agent access

Each agent key is scoped to that agent’s conversations. Revoking a key stops future access. Revocation does not erase conversation history. Personal access keys provide access to your inbox and should never be shared with agents.

No advertising SDKs

The current app includes no advertising or third-party analytics SDKs. The marketing site does not set advertising cookies. Hosting providers may process standard request and security logs.

Deletion and support

Signing out keeps your conversations on the server. To erase your account, open You → Delete account in the app and confirm deletion. This removes your account, conversations, replies, agent connections, sessions, preferences, and device registrations from the active database. Backups follow your server operator’s retention policy; contact the operator about backups or exports. For questions about ayy, contact support@ayy.fyi.