Privacy

What PAVONA does with your data

Plain language on purpose. This covers the desktop app and the website at pavona.locker. The full legal terms are on the Terms page; this page explains the same facts in one place, in plainer words.

Who publishes this

PAVONA is published by BEM Bio-Engineered Mechanics. Business and privacy questions, including anything on this page, go to outreach@priest.locker. Product support stays separate, at support@priest.locker and the Support page.

What stays on your computer

Local inference runs on the computer hosting the model. A conversation with a local model is stored on your own disk, in a file you hold. That does not protect it from other people or software that already has access to your computer.

Code: dashboard/convo_store.py

What leaves it, and when

Cloud models and connected tools you choose

Picking a cloud model or a tool with network access sends your prompt and conversation context to that provider, under its own terms and using your own account and key. PAVONA does not add a provider you did not choose.

Code: priest_core/gateway/routing.py, priest_core/privacy/destinations.py

Setup, models and update checks

Installing, downloading a model, refreshing the model catalogue and checking for a release use the network. While the app is open it reads the release list every six hours for version, size and checksum information. Installing an update needs your confirmation.

Code: dashboard/version.py, dashboard/priest-panels.js

A problem report

In the app, News → Report a problem drafts a report on your screen. It goes nowhere until you review it and send it yourself.

Code: dashboard/priest.html

Signing in to a shared panel

The app works without signing in. Someone who shares their PAVONA with other people can turn on sign-in with Google. Google then handles the sign-in under its own terms and sees that it happened. The list of people allowed in is a file on the computer that runs PAVONA. It is not sent to us.

Code: dashboard/auth_providers.py

The website's support chat

DevAd Support and the handbook assistant run on the website, not in the app. When you ask a question, its text, relevant recent conversation and public article excerpts may be processed by Netlify and the AI provider behind the chat. They cannot see your installation. The page keeps the chat in its own memory only; it is not written to application storage or logs. Leave out passwords, API keys and private files.

Code: site/support-chat.js, netlify/functions/support-chat.mjs

The Spotify player

The home page names a track before anything loads. Pressing Play connects to Spotify to play it; Spotify can then see your IP address and connection details, the same as any embedded player. Closing the player is remembered on your browser, and nothing loads again until you press Play.

Code: site/music-dock.js

Visiting the website itself

Like any website, pavona.locker's host sees the ordinary connection details of a page request, for example your IP address. No separate tracking script sits on top of that.

Code: site/_headers

What the website collects

pavona.locker runs no analytics and sets no tracking cookie. Its security policy allows scripts and styles from the site itself only, plus the Spotify player you choose to open. The site keeps a few small settings in your own browser's local storage, on your device only, never sent to us:

Clearing your browser's site data for pavona.locker removes all of it.

Code: site/_headers, site/themes.js, site/music-dock.js, site/glass.js

Children

PAVONA is for everyone aged 6 and up. If you are under 13, use it with a parent, guardian or teacher. The installed app sends us nothing about who is using it. Do not give the website's support chat a child's personal details. If a problem report needs to go out from the app, an adult should read it before it is sent. Cloud model providers and some models carry their own age terms; a parent, guardian or teacher should check those before a child under 13 uses a cloud model or a paid seat. Questions about a child's use of PAVONA can go to outreach@priest.locker.

Asking for deletion or a copy

We hold no account for you. A local conversation is a file on your own disk, so you already hold that copy, and deleting the file deletes it. If a shared panel has sign-in turned on, its list of people is a file on that computer, kept by whoever runs it. The website's support chat is not kept once you close the page. The only records PAVONA holds are what you send by email, to outreach@priest.locker or support@priest.locker. Write to either address to ask what is on file for you, to ask for a copy, or to ask for it to be deleted. Both are ordinary mailboxes read by the people who build PAVONA, and they will act on it.

Changes to this policy

This page can change as the product changes. The date below is the last time it did.

Last updated: 2026-09-19.