Privacy Policy
1. Introduction
[COMPANY LEGAL NAME] (“we,” “us,” “our,” or “the Company”) operates Aria, an AI companion application (“the Service”). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use the Service.
We are committed to protecting your privacy, particularly given the personal and sensitive nature of conversations you may have with Aria. We encourage you to read this Privacy Policy carefully and contact us at [SUPPORT EMAIL] if you have any questions.
By creating an account or using the Service, you consent to the collection and use of your information as described in this Privacy Policy.
2. Information We Collect
2A. Information You Provide Directly
- Account Information: Name, email address, password, and date of birth (for age verification).
- Onboarding Data: Information you provide during initial setup, such as your communication preferences, what motivated you to use Aria, current mood or emotional state, and topics of interest.
- Conversation Content: The text of all messages you send to Aria and all responses Aria generates.
- Voice Data: If you use voice features, audio may be processed by our text-to-speech provider to generate Aria’s spoken responses. We do not store recordings of your voice.
- Payment Information: If you subscribe to a paid plan, payment details are collected and processed by our payment processor (Stripe). We do not store your full credit card number.
- Support Communications: Information you provide when contacting our support team.
2B. Information Generated Through Your Use
- Memory Data: Key facts, preferences, personal details, and contextual information extracted from your conversations by our memory system. This enables Aria to remember and reference your previous interactions.
- Pattern Data: Behavioral, emotional, temporal, topical, and communication patterns detected across your interactions. These patterns are used to personalize Aria’s responses.
- Usage Data: Session timestamps, session duration, features used, conversation frequency, and interaction metadata.
- Device Information: Device type, operating system, browser type, screen resolution, and app version.
- Log Data: IP address, access times, pages viewed, and error logs.
2C. Sensitive Information
In your conversations with Aria, you may choose to share information about your health, mental health, emotional state, relationships, religious or political views, sexual orientation, financial situation, or other sensitive personal matters.
We want to be transparent about how this information is handled:
- Sensitive information shared in conversations is processed by our AI systems and memory infrastructure to provide personalized responses and maintain conversational continuity.
- We do not categorize, label, or separately index your sensitive information for any purpose other than enabling Aria’s conversational memory.
- We do not use sensitive information from your conversations for advertising, marketing, profiling for commercial purposes, or any purpose unrelated to providing the Service.
- Our crisis detection systems may process conversation content to identify expressions of self-harm or danger, as described in our Terms of Service.
By sharing sensitive information with Aria, you consent to its processing as described in this Privacy Policy. You are never required to share sensitive information to use the Service.
3. How We Use Your Information
We use your information for the following purposes:
Providing the Service
- Operating Aria and enabling personalized conversations
- Maintaining conversational memory so Aria can reference previous interactions
- Detecting patterns to improve relevance and quality of responses
- Generating proactive messages based on context from previous conversations
- Processing voice features through our text-to-speech provider
Safety and Security
- Operating automated crisis detection and safety systems
- Detecting and preventing abuse, fraud, and violations of our Terms of Service
- Protecting the security and integrity of the Service
Improvement and Development
- Analyzing aggregate, de-identified usage patterns to improve the Service
- Identifying and fixing bugs, errors, and performance issues
- Developing new features and capabilities
Communications
- Sending account-related notifications (password resets, billing, Terms updates)
- Responding to your support inquiries
Legal Compliance
- Complying with applicable laws, regulations, and legal processes
- Responding to lawful requests from government authorities
4. How We Store Your Information
4A. Data Storage Infrastructure
Your data is stored using the following systems:
- Primary Database: Account information, conversation metadata, and subscription data are stored in our PostgreSQL database hosted on [HOSTING PROVIDER].
- Memory System: Conversational memory data (facts, preferences, and contextual details extracted from your conversations) is stored in our memory infrastructure, which uses a combination of graph and vector databases to enable rich, contextual recall.
- Cache: Temporary session data may be cached in Redis for performance purposes and is not retained beyond your active session.
- Payment Data: Payment information is processed and stored by Stripe in accordance with PCI DSS standards. We do not store full payment card details on our systems.
4B. Data Retention
- Active Accounts: Your data is retained for as long as your account is active and you continue to use the Service.
- Deleted Conversations: When you delete a conversation through the app, the conversation content is removed from our active systems within thirty (30) days. Residual data in backups may persist for up to ninety (90) days before being overwritten.
- Deleted Memories: When you delete specific memories through the app, they are removed from our memory system within thirty (30) days.
- Account Deletion: Upon account deletion, we will delete your personal data within thirty (30) days, except where retention is required by law or necessary for legitimate purposes such as resolving disputes. Backup copies may persist for up to ninety (90) days.
- Anonymized Data: We may retain aggregated, de-identified data that cannot reasonably be used to identify you for analytical and improvement purposes indefinitely.
4C. Data Security
We implement commercially reasonable technical and organizational measures to protect your data, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Access controls limiting who can access user data
- Regular security assessments and monitoring
- Secure authentication practices
No system is perfectly secure. While we strive to protect your data, we cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.
6. Your Rights and Choices
Depending on your jurisdiction, you may have the following rights regarding your personal information:
6A. Access and Portability
You have the right to request a copy of the personal information we hold about you. Where technically feasible, we will provide this information in a commonly used, machine-readable format.
6B. Correction
You have the right to request that we correct inaccurate or incomplete personal information.
6C. Deletion
You have the right to request deletion of your personal information, subject to certain exceptions (such as data we are required to retain by law). You can delete specific conversations and memories through the app, or request full account deletion by contacting us.
6D. Restriction and Objection
You may have the right to request that we restrict the processing of your data or to object to certain types of processing.
6E. Withdraw Consent
Where we rely on your consent to process personal information, you may withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of processing conducted before the withdrawal.
6F. How to Exercise Your Rights
To exercise any of these rights, please contact us at [SUPPORT EMAIL]. We may ask you to verify your identity before processing your request. We will respond to your request within thirty (30) days, or as required by applicable law.
7. Children’s Privacy
The Service is not directed to or intended for individuals under the age of eighteen (18). We do not knowingly collect personal information from anyone under 18. If we become aware that we have collected personal information from a person under 18, we will take steps to delete that information promptly.
If you believe a child under 18 has provided us with personal information, please contact us at [SUPPORT EMAIL].
8. International Data Transfers
Your information may be transferred to and processed in countries other than the country in which you reside. These countries may have data protection laws that differ from the laws of your country. By using the Service, you consent to the transfer of your information to these countries.
Where required by applicable law, we will implement appropriate safeguards for international data transfers, such as Standard Contractual Clauses approved by the European Commission.
9. California Privacy Rights
If you are a California resident, you may have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), including:
- The right to know what personal information we collect, use, and disclose
- The right to request deletion of your personal information
- The right to opt out of the sale or sharing of your personal information (we do not sell your personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights, contact us at [SUPPORT EMAIL].
10. European Economic Area, UK, and Switzerland
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contractual Necessity: Processing necessary to provide the Service to you
- Legitimate Interest: Processing for our legitimate interests (such as improving the Service and ensuring security), where those interests are not overridden by your rights
- Consent: Processing based on your explicit consent (such as processing sensitive information shared in conversations)
- Legal Obligation: Processing necessary to comply with legal requirements
You have the rights described in Section 6 above, as well as the right to lodge a complaint with your local data protection authority.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least thirty (30) days before the changes take effect. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
Email: [SUPPORT EMAIL]
Website: meetaria.ai
Mailing Address: [COMPANY ADDRESS]
If you are located in the EEA, UK, or Switzerland and wish to exercise your data protection rights or file a complaint, you may also contact your local data protection authority.