Brokerages ask us the same sensible questions before they let a tool near their client book: where does the data live, who can see it, is it used to train AI, and how do we get it out. This page answers them plainly. For the legal version, see the Privacy Policy, and ask us for the Data Processing Addendum.
| Data | Where it is held | Encryption | Who can access it |
|---|---|---|---|
| Client book — names, phone numbers, notes, labels, stages | Database, Frankfurt, Germany (Supabase PostgreSQL, AWS eu-central-1) | TLS in transit; encrypted at rest; row-level security per tenant, verified by cross-tenant probing | You and your team. Aria support only when you ask for help — and it is logged. |
| WhatsApp messages and metadata | Database, Frankfurt. Meta also holds message content for up to 30 days for delivery | As above; Meta Cloud API over TLS | You and your team; Aria support on request, logged. |
| AI agent memory and chat sessions | Your private agent machine, Singapore — its own machine and its own disk, one per broker | TLS in transit; an isolated disk no other broker's agent can reach | You; Aria support on request, logged. |
| Connected credentials — Gmail app password, Calendly token, calendar address | Database, Frankfurt | AES-256-GCM application-level encryption on top of encryption at rest | Used by the system only, not read by people. Deleted the moment you press Disconnect. |
| Emails, calendar events, YouTube (only if you connect them) | Read live from Google over IMAP and iCal; only what Aria needs is kept in Frankfurt | TLS in transit; encrypted at rest | You; Aria support on request, logged. |
| Documents and files | Supabase storage, Frankfurt | TLS in transit; encrypted at rest | You and your team; Aria support on request, logged. |
| Backups | Nightly to Supabase storage in Frankfurt, plus an off-site copy in Cloudflare R2 | Encrypted at rest | Aria operators only, for restore. Rotate out within the 30-day deletion window. |
| AI requests in flight | OpenAI API, USA — at request time only | TLS; not stored by Aria at OpenAI; not used for training | Not read by people at Aria; processing is automated. |
Secrets are encrypted with AES-256-GCM. TLS is used everywhere. Privileged credentials are never stored on the machines that run individual brokers' agents; those machines hold only a scoped token and reach privileged services through a controlled gateway.
You do. Your brokerage is the data controller; Aria is the processor and acts only on your instructions. We never sell it, never share it across customers, and never reuse it for anything else.
UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). GDPR applies only where you process EU residents' data. DIFC and ADGM have their own data-protection regimes — tell us if you are based in one.
The standard service runs in Frankfurt and Singapore under PDPL-compliant transfer safeguards. UAE-only hosting is available as an enterprise option — ask us.
Yes, self-serve, at any time. Your client book, conversations and documents can be exported from inside Aria without asking us.
Yes, self-serve. Connections → Delete my data disconnects WhatsApp immediately; everything is deleted within 30 days, backups included, and we confirm it to you. It is free. Steps on the Data Deletion page.
Nobody by default. Support staff access a workspace only when you ask for help, every privileged access is logged, and the log is visible to you in the app at any time. Aria staff do not browse customer data.
No. Aria does not train models on your data, and OpenAI does not use API data for training. Each request is processed and the answer returned — nothing is kept at OpenAI.
Backups run nightly to Frankfurt with an off-site copy held with Cloudflare, so a single provider failing cannot lose your data. The platform is monitored continuously with on-call alerting.
These are the providers that process data on our behalf under contract. We give at least 30 days' notice before adding or replacing one.
We have a short, plain-English Data Processing Addendum (controller–processor terms, security measures, sub-processors, 72-hour breach notice, 30-day deletion, annual audit answers) and a one-page “Where your data lives” handout. Email support@aria-app.dev and we will send both.