Our commitment
Privacy isn’t an afterthought — it’s central to how we built Ara. Every architectural decision, from private containers to encrypted credentials, is designed to minimize data collection and keep you in control.Key principles
Your data stays yours
We don’t sell, share, or use your conversations to train AI models. Ever.
Encrypted everywhere
All communication uses TLS. API keys are encrypted at rest.
Isolated containers
Each user runs in a private container with full isolation.
Transparent practices
We tell you exactly what data flows where, with no hidden tracking.
Where your data lives
| Data | Location | Who can access it |
|---|---|---|
| Conversations | Your container only | You and your AI |
| AI memory | Your container filesystem | You and your AI |
| Files | Your container filesystem | You and your AI |
| API keys | Database (encrypted) | Decrypted only for your container |
| Channel credentials | Your container filesystem | Your messaging bridges |
| Account info | Database | You and Ara |
What about the AI providers?
When you chat with your AI, messages are sent to your chosen provider (Anthropic, OpenAI, or Google) to generate responses. Each provider has their own privacy policy.When you use the API (which Ara does), major AI providers like Anthropic and OpenAI do not use your conversations to train their models by default. This is different from their free consumer chatbots.
Data deletion
You have full control over your data:- Clear memory — wipe your AI’s conversation history and memory from the settings page
- Delete container — destroy your container and all associated data
- Delete account — remove everything, including your account, credentials, and usage history
Connected Google services
If you connect Google Calendar or Gmail, Ara requests only the OAuth scopes you approve.- Calendar data access — Ara may access calendar data in the approved scopes (for example calendars, events, and free/busy availability) to execute your requested actions.
- Storage and retention — Ara is designed to minimize Google data handling outside your active session, but data can be processed and may appear in session workspace files, chat history, and backups according to this policy’s retention terms.
- Revocation — You can disconnect integrations in Ara settings at any time, or revoke access directly in Google Account permissions.
Best practices
Be mindful of sensitive info
Avoid sharing credit card numbers, social security numbers, or passwords with any AI.
Security deep dive
Technical details on encryption, isolation, and infrastructure security.
