Privacy Policy

Last updated: April 6, 2026

1. Introduction

AIARCO Inc ("we," "our," or "us"), a Delaware corporation, operates the AIARVA platform at aiarva.com and mobile applications for iOS and Android (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the practices described in this policy. For data processing on behalf of business customers, see our Data Processing Agreement.

2. Information We Collect

2.1 Information You Provide

  • Account information: name, email address, and password (or OAuth credentials via Google, SAML/OIDC) when you register
  • Payment information: processed securely through Stripe; we do not store credit card numbers on our servers
  • Content: search queries, conversations, uploaded files (CSV, XLSX, JSON, images), and generated content
  • Health & fitness data: weight, caloric intake, exercise logs, nutrition entries (if you use AIARVA Life health/fitness features)
  • Financial data: bank account information linked via Plaid, transaction summaries (if you use AIARVA Life finance features)
  • Smart home data: device names, states, and command history (if you use AIARVA Life smart home features via Google Home)
  • Integration data: Notion pages, Obsidian vault content (if you connect third-party integrations)
  • Feedback: ratings, comments, and support inquiries

2.2 Information Collected Automatically

  • Usage data: pages visited, features used, search frequency, session duration, and model preferences
  • Device information: browser type, operating system, device identifiers, and push notification tokens
  • Log data: IP address, access times, referring URLs, and error logs
  • Location data: approximate location derived from IP address; precise latitude/longitude only when explicitly provided for weather or fitness features

2.3 Biometric Data Clarification

AIARVA's vision and image analysis features process images you upload but do not collect, extract, or store biometric identifiers (e.g., facial geometry, fingerprints). Images are processed transiently by our AI model providers and are not used for biometric identification.

3. Legal Basis for Processing (GDPR Article 6)

If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

Processing ActivityLegal Basis
Providing the Service (search, conversations, AI responses)Contract performance (Art. 6(1)(b))
Account creation and authenticationContract performance (Art. 6(1)(b))
Payment processing and billingContract performance (Art. 6(1)(b))
Health and fitness data processingExplicit consent (Art. 6(1)(a), Art. 9(2)(a))
Financial data processing (Plaid)Explicit consent (Art. 6(1)(a))
Smart home device controlExplicit consent (Art. 6(1)(a))
AI model improvement (Free tier, anonymized)Legitimate interest (Art. 6(1)(f))
Analytics and service improvementLegitimate interest (Art. 6(1)(f))
Contextual advertising (Free tier)Legitimate interest (Art. 6(1)(f))
Fraud prevention and securityLegitimate interest (Art. 6(1)(f))
Legal compliance (tax records, law enforcement)Legal obligation (Art. 6(1)(c))

4. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process transactions and manage subscriptions
  • Personalize your experience and search results
  • Improve AI model quality using anonymized query patterns and feedback (Free tier only; paid users may opt out in account settings)
  • Send transactional emails (password resets, billing, security alerts)
  • Display contextual advertisements (Free tier only)
  • Detect and prevent fraud, abuse, and security threats
  • Comply with legal obligations
  • Generate audit logs for Teams/Enterprise accounts
  • Process referral and affiliate program conversions

Data minimization: We collect only the information necessary to provide the features you use. We do not collect data from features you have not activated (e.g., health, finance, smart home data is only collected if you opt in to those features).

5. Data Sharing and Sub-Processors

We do not sell your personal information. We share data with the following categories of third-party service providers (sub-processors), each bound by data processing agreements:

CategoryProvider(s)Data Processed
Cloud InfrastructureAmazon Web Services (AWS)All service data (hosting, storage, compute)
Frontend HostingVercelWeb traffic, access logs
AI Model ProvidersOpenRouter (gateway), OpenAI, Anthropic, Google, xAI, Meta, Mistral, DeepSeek, PerplexityQueries, conversation context (providers are contractually prohibited from using data for training)
Image GenerationStability AIImage prompts
Web SearchTavily, Brave Search, Serper, PerplexitySearch queries
PaymentsStripeBilling info, subscription status
Financial ServicesPlaidBank account links, transaction data (handled by Plaid; credentials never stored on AIARVA servers)
Smart HomeGoogle Home / Smart Device Management (SDM)Device states, command history
Identity & SSOWorkOSSAML/OIDC tokens, directory sync data
AnalyticsPostHogAnonymized usage events, feature flags
Error TrackingSentryError logs, stack traces (no PII)
EmailAmazon SESEmail addresses, transactional email content
NutritionFatSecretFood search queries
WeatherOpenWeatherLocation coordinates (when provided)
TravelAmadeusFlight search queries
Delivery TrackingShip24Tracking numbers
ShoppingPricesAPI.ioProduct search queries
NewsNewsData.ioNews search queries
IntegrationsNotionPage content (with your OAuth authorization)
Social Media (Marketing)Twitter/X, Reddit, LinkedIn, Facebook, Instagram, TikTok, TelegramScheduled posts, analytics (with your OAuth authorization)

We may also disclose your information when required by law, subpoena, court order, or to protect our rights, property, or safety.

6. Health Data

If you use AIARVA Life health and fitness features, we collect health-related data (weight, caloric intake, exercise logs, nutrition entries) that you voluntarily provide. This data is classified as special category data under GDPR Article 9 and is processed only with your explicit consent.

  • AIARCO Inc is not a HIPAA-covered entity. Health features are for personal wellness tracking only and do not constitute medical advice, diagnosis, or treatment
  • Health data is stored in encrypted form on AWS infrastructure in the US
  • Health data is retained for 36 months or until you delete it, whichever comes first
  • You may delete all health data at any time from your account settings

7. Financial Data

If you use AIARVA Life finance features, you may link bank accounts via Plaid. Financial data is subject to the following protections:

  • Bank credentials are handled exclusively by Plaid and are never transmitted to or stored on AIARVA servers
  • Plaid access tokens stored by AIARVA are encrypted at rest using Fernet symmetric encryption
  • Multi-factor authentication (MFA) is required to access linked financial accounts
  • We comply with the Gramm-Leach-Bliley Act (GLBA) safeguards applicable to the financial data we process
  • Financial transaction data is retained for 7 years to comply with tax and regulatory requirements, after which it is deleted
  • AIARVA does not provide financial advice, investment recommendations, or tax guidance

8. Smart Home Data

If you connect smart home devices via Google Home integration, we collect device names, states, and command history. Due to the sensitivity of smart home data (lifestyle patterns, physical security):

  • Device credentials and OAuth tokens are encrypted at rest
  • Security-critical commands (locks, cameras) require MFA verification
  • Smart home command history is retained for 12 months
  • You may disconnect devices and delete smart home data at any time

9. Data Retention

We retain your data for the minimum period necessary. Specific retention periods:

Data TypeRetention Period
Account dataUntil account deletion + 30 days
Search history & conversations12 months (auto-deleted)
Generated images12 months (auto-deleted)
Health & fitness data36 months or until deleted
Financial data7 years (regulatory requirement)
Smart home command history12 months
Audit logs (Teams/Enterprise)3 years
Anonymized analyticsIndefinite

You may delete your data at any time from your account settings, except where retention is required by law.

10. Data Security

We implement industry-standard security measures including:

  • Encryption at rest (AES-256) and in transit (TLS 1.3)
  • Secure password hashing (bcrypt)
  • Fernet symmetric encryption for sensitive tokens (Plaid, integrations)
  • AWS WAF (Web Application Firewall) for threat protection
  • Regular security audits and vulnerability scanning
  • Multi-factor authentication support (email OTP)
  • SSL certificate pinning on mobile applications

No method of electronic transmission or storage is 100% secure. If you discover a security vulnerability, please report it to security@aiarva.com.

11. Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms:

  • We will notify the relevant supervisory authority within 72 hours of becoming aware of the breach (GDPR Article 33)
  • We will notify affected users without undue delay via email and in-app notification, including a description of the breach, the data affected, and remedial steps (GDPR Article 34)
  • We will comply with applicable US state breach notification laws (including California, Delaware, and other state requirements)

12. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access your personal data (GDPR Art. 15)
  • Rectify inaccurate personal data (GDPR Art. 16)
  • Erase your personal data ("right to be forgotten") (GDPR Art. 17)
  • Restrict processing of your personal data (GDPR Art. 18)
  • Data portability — export your data in a structured, machine-readable format (GDPR Art. 20)
  • Object to processing based on legitimate interests (GDPR Art. 21)
  • Withdraw consent at any time without affecting the lawfulness of prior processing
  • Opt out of data collection for AI training (paid plans, in account settings)
  • Opt out of targeted advertising
  • Lodge a complaint with a supervisory authority

To exercise these rights, contact our Data Protection Officer at privacy@aiarva.com. We will respond to verified requests within 30 days (45 days for complex requests, with notice).

13. Automated Decision-Making (GDPR Article 22)

We use automated processing in the following contexts:

  • Content moderation: automated detection of prohibited content and policy violations
  • Model selection: automatic routing of queries to appropriate AI models based on content and plan
  • Ad targeting: contextual advertisement selection based on search queries (Free tier only; no behavioral profiling)
  • Fraud detection: automated analysis of usage patterns to detect abuse

You have the right to obtain human intervention, express your point of view, and contest decisions that significantly affect you. Contact privacy@aiarva.com to request a review of any automated decision.

14. Cookies and Tracking Technologies

We use the following cookies and similar technologies:

Cookie / TechnologyTypePurposeDuration
Session cookieEssential (1st party)Authentication and session managementSession / 30 days
CSRF tokenEssential (1st party)Cross-site request forgery protectionSession
PostHog analyticsAnalytics (1st party)Usage analytics and feature flags1 year
Theme preferenceFunctional (1st party)Light/dark mode preference1 year

You may disable non-essential cookies through your browser settings. Disabling essential cookies may prevent you from using the Service.

Do Not Track: We currently do not respond to Do Not Track (DNT) browser signals, as there is no industry-standard protocol for compliance. However, you can opt out of analytics tracking in your account settings.

15. International Data Transfers

Your data is primarily processed in the United States. For transfers from the EEA, UK, or Switzerland to the US, we rely on:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Supplementary technical measures (encryption, access controls) as needed
  • Data processing agreements with all sub-processors

For details, see our Data Processing Agreement.

16. Children's Privacy

The Service is not intended for children under 13 (or under 16 in EU/EEA member states where applicable). We do not knowingly collect personal information from children under these ages. If we learn that we have collected such data, we will promptly delete it. If you believe a child has provided us with personal information, contact us at privacy@aiarva.com.

17. California Privacy Rights (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act and California Privacy Rights Act provide you with specific rights:

17.1 Categories of Personal Information Collected

  • Identifiers (name, email, IP address)
  • Commercial information (subscription plan, billing history)
  • Internet activity (search queries, browsing history within the Service)
  • Geolocation data (approximate, from IP; precise only when provided)
  • Professional or employment information (if provided in conversations)
  • Health information (if you use health features)
  • Financial information (if you link bank accounts)
  • Inferences drawn from the above for personalization

17.2 Your CCPA Rights

  • Right to know: request categories and specific pieces of personal information collected
  • Right to delete: request deletion of your personal information
  • Right to correct: request correction of inaccurate personal information
  • Right to opt out of sale: we do not sell personal information
  • Right to limit sensitive PI use: you may limit use of sensitive personal information to what is necessary
  • Non-discrimination: we will not discriminate against you for exercising your CCPA rights

17.3 Do Not Sell or Share My Personal Information

We do not sell personal information. We do not share personal information for cross-context behavioral advertising. Free tier advertising is contextual only (based on the current query, not behavioral profiles).

17.4 Authorized Agents

You may designate an authorized agent to make CCPA requests on your behalf. We may require verification of the agent's authority and your identity before processing such requests.

17.5 Financial Incentives

Our referral program provides account credits for successful referrals. This constitutes a financial incentive under CCPA. You may opt in to the referral program and withdraw at any time without penalty. The value of the incentive is reasonably related to the value of the data provided.

18. Additional US State Privacy Laws

If you are a resident of the following states, you may have additional rights under state privacy laws:

  • Virginia (VCDPA): rights to access, correct, delete, obtain a copy, and opt out of targeted advertising, sale, or profiling
  • Colorado (CPA): similar rights to VCDPA, plus the right to opt out of automated profiling in furtherance of decisions that produce legal or similarly significant effects
  • Connecticut (CTDPA): rights to access, correct, delete, data portability, and opt out of sale, targeted advertising, and profiling

To exercise these rights, contact privacy@aiarva.com. We will respond within the timeframes required by each applicable law.

19. Australian Privacy Act

If you are an Australian resident, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We comply with applicable APPs regarding the collection, use, disclosure, and storage of your personal information. You may request access to and correction of your personal information, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.

20. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service at least 30 days before they take effect. Continued use after changes constitutes acceptance. We recommend reviewing this policy periodically.

21. Data Protection Officer

Our Data Protection Officer can be contacted at:

  • Email: privacy@aiarva.com
  • Mail: AIARCO Inc, Attn: Data Protection Officer, Wilmington, Delaware, United States

22. Contact Us

For questions about this Privacy Policy:

AIARCO Inc
Wilmington, Delaware, United States

← Back to AIARVATerms of Service →