Privacy Policy
Last updated June 22, 2026
ARIA OS ("ARIA OS", "we", "us", or "our") is a private AI desktop, operated by Anshul Raman from Ohio, United States. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. ARIA OS is built to be local-first and bring-your-own-key: wherever possible, your data stays on your device or in storage you control.
Information we collect
Account information
When you create an account we collect your email address and an encrypted (hashed) password, managed by our authentication provider. If you sign in with a third-party identity provider, we receive your email and a unique identifier from that provider.
Content you create
ARIA OS stores the content you create so it is available across your devices: your chats with Aria, memory entries, notes, tasks, reminders, calendar entries, people entries, and app settings. This content is scoped to your workspace and protected by per-user database access rules.
Your model keys and integration credentials
If you bring your own model key (for Claude, OpenAI, OpenRouter, or another provider) or connect an integration (such as email, Telegram, Slack, or Discord), those credentials are encrypted at rest and are never returned to the browser or shared. They are used only to perform the actions you ask for.
Files on your device
On the desktop app, your files stay on your machine. ARIA OS reads or writes files only for the actions you request (for example, when the Forge agent builds something or you attach a file). We do not upload your file system to our servers.
Usage and plan data
We keep counters of your monthly messages and tool actions to enforce plan limits, along with basic records of activity (such as task runs) so features like Tasks and Activity work.
Payment information
Payments are processed by Stripe. We do not collect or store your full card number. We receive limited billing details from Stripe (such as your subscription status, plan, and a customer identifier) to manage your subscription.
Technical data and cookies
We use essential cookies to keep you signed in. We may process basic technical data (such as IP address and request logs) for security, abuse prevention, and to operate the service.
How we use your information
- To provide, maintain, and improve ARIA OS and its features.
- To sync your content across the desktop app, the web, and connected surfaces like Telegram.
- To run the actions you request, including AI requests through your chosen model provider and agent tasks via Forge.
- To enforce plan limits and process your subscription and payments.
- To keep the service secure, prevent abuse, and comply with our legal obligations.
- To respond to your support requests.
Bring your own key and AI providers
ARIA OS runs on the AI model you choose. When you send a message or run a task, the relevant content is sent to your selected model provider (such as Anthropic, OpenAI, or OpenRouter) — or to your local Claude Code / Codex CLI — to generate a response. That provider processes the request under its own terms and privacy policy. We do not add a markup to your model usage, and we do not use your content to train our own models.
Local-first and your GitHub backup
ARIA OS is designed so your most sensitive data stays with you. On the desktop, your files remain local. If you enable backup, your memory and chat history are mirrored to a private GitHub repository that you own and control — not to a vendor black box. You can read, export, or delete that repository at any time.
How we share information
We do not sell your personal information. We share data only with service providers ("subprocessors") that help us operate ARIA OS, and only as needed to provide the service:
- Supabase — database, authentication, and storage.
- Vercel — hosting of the web application and cloud functions.
- Stripe — payment and subscription processing.
- Your chosen AI model provider (e.g. Anthropic, OpenAI, OpenRouter) — to generate responses to your requests.
- GitHub — only if you enable backup, to store your data in a private repository you own.
- Optional integrations you connect (e.g. Telegram, your email provider, Slack, Discord) — to deliver the features you turn on.
We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a business transfer.
Data retention
We keep your account and content for as long as your account is active. When you delete content, it is removed from our active systems. When you delete your account, we delete or anonymize your personal data within a reasonable period, except where we must retain certain records (for example, billing records) to meet legal obligations. Backups you stored in your own GitHub repository remain under your control.
Security
We protect your data with encryption in transit and at rest, encrypted storage of secrets (your model keys and integration credentials are never returned to the client), and strict per-user database access rules that isolate each account. No method of transmission or storage is perfectly secure, but we work to protect your information and to respond quickly to any issue. You can report a security concern to ar.dev@anshulraman.com.
Your rights and choices
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can:
- Access and edit most of your content directly in the app.
- Export your memory and chat history (these are backed up to your own GitHub repository when backup is enabled).
- Cancel your subscription at any time from Settings or the Stripe customer portal.
- Request deletion of your account and associated data by contacting ar.dev@anshulraman.com.
We will respond to verified requests as required by applicable law.
International users
ARIA OS is operated from the United States and our service providers may process data in the United States and other countries. By using ARIA OS, you understand that your information may be transferred to and processed in countries that may have different data-protection laws than your own.
Children's privacy
ARIA OS is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of ARIA OS after changes take effect means you accept the updated policy.
Contact us
If you have questions about this Privacy Policy or your data, contact us at ar.dev@anshulraman.com.