Privacy Policy

In force since 2026-09-18

The other half of this agreement is the Terms of Use, which govern using Arroway.

What Arroway is, in one sentence

Arroway is a shared working memory: a team's decisions and rules, written by people and by the AIs they use, kept somewhere that belongs to no AI vendor. This policy says exactly what is kept, where, for how long, and who can reach it.

Who is responsible

Arroway is operated by Alexandre Viola. For anything in this policy — a question, a correction, a copy of your data, or deletion — write to hello@arroway.app.

What we keep about you

Your account: name, e-mail address and profile picture, from the identity provider when you sign in with an existing account, or just the e-mail when you sign in with a link. We also keep your chosen language and the date of your last sign-in.

Your AI connections: a label you write yourself, which assistant it is, and when it was last used. The secret connection address is NEVER stored — we keep only a cryptographic digest (SHA-256) of it, which recognises the right address and cannot rebuild it. The same applies to invitations and to OAuth credentials.

Your work: the projects you create, with name and scope; the memories (decisions, rules, facts, preferences, references) and the daily log. That content is written by you in the panel or by your AI through the connection — we do not generate it and we do not edit it.

What your AI sends, and what we record of it

When your AI reads the commons, it may send a short sentence saying what it is about to do, to improve the relevance of what it gets back. We do NOT store that sentence. We store up to six words extracted from it and mark them as declared context. They count as observed-use evidence only when a matching completion residue arrives from the same session.

When your AI logs what it did or proposes a memory, the text it writes is stored — that is the product's function, and it is what you read and approve in the panel. It writes the residue of a task, not the conversation: we do not receive or store your chat history, your files, or the assistant's memory.

We also record every tool call and every curation action: who, through which connection, in which project, which tool and when. That is what the audit screen rests on — the answer to 'where did this come from and who decided it'. Without that record the product could not prove anything it shows.

When a connection asks for the tool list, we keep only the first time it received it. We do not keep every listing, the list delivered, the conversation, prompt, memory, or a browsing sequence.

We keep a session identifier that some AI clients send in a header, only to group calls from the same conversation. It is opaque to us and does not identify you.

What stays in your browser

Your session cookie, which is what keeps you signed in. The panel does not work without it.

An origin cookie, introduced on 2026-08-24 and written only when you ask to install something of ours — the connector or a starter pack — having arrived from one of our public pages. It holds ONE word from a fixed list: which page brought you. It is not an identifier, it does not tell apart two people who came through the same page, and it does not follow you to any other site. It exists so we can tell which question brings people who actually go on to use the product — today we see the visit and the click, and lose the person at sign-in. It is erased on your first signed-in visit, and expires on its own after 30 days if that visit never comes.

An acquisition cookie, introduced on 2026-08-26 and written when you reach any of our public pages from outside — a link we published, a search, another site. It holds three short labels and the time you arrived: where you came from (say, `linkedin`), what kind of channel that was (say, `organic-social`) and, when the link says so, which piece brought you. It is not an identifier, it does not tell apart two people who came from the same place, it does not record where you browsed, and it does not follow you to any other site. When we do not recognise where you came from we store the word `other` rather than the address; when there is no sign of origin at all, we store no cookie. It exists so we can tell which channel brings people who actually go on to use the product. It is erased on your first signed-in visit, and expires on its own after 30 days if that visit never comes.

On the start screen, a visit identifier held in the tab's own storage, so one arrival is not counted twice. It disappears when you close the tab.

We measure traffic on the public pages with Google Analytics, since 2026-09-18. It sets a cookie with a visitor identifier, used to tell returning visitors from first-time ones, and records which public pages were viewed and where the visit came from. That cookie is not set in the panel — only on the public pages — and Google processes this data under its own terms, as an audience-measurement provider. On the installation page we also count when someone copies an install command, with two short labels from a fixed list: which installation route (for example, `claude`) and whether it was the command or the connection address. It is a count, not identification — it does not tell apart two people who copied the same command, and it does not record where you browsed.

What we never keep

Passwords — Arroway has none; authentication is the identity provider you choose, or the link sent to your e-mail.

Credentials, tokens and API keys: the instruction handed to every connected AI forbids writing them into the commons, with no exception and no opt-out. If one slips through, delete it in the panel and tell us.

Your conversation with the AI, your files, and the assistant's own memory. Arroway cannot reach any of it, and the instruction given to the AI expressly forbids extracting from there.

Who sees what

Team project: members of that project see what is in it. That is what it exists for. Since 2026-09-02, the project's People tab also shows every member which AI assistant each person has connected (by the tool's icon, never the connection's address) and when their last activity in that project was — it is what lets a team see who reads the project with an AI and who has not connected one yet.

Personal project: only you. Your personal rules travel to the reads of YOUR connections, in any project — that is what lets your AI know how you work without the team seeing it.

We do not sell, rent or share your content with third parties. We do not use what you write to train any AI model.

Where the data lives, and who else touches it

Data is kept in a managed PostgreSQL database and the application runs on a cloud hosting platform, both with servers in the United States. This means your data is transferred internationally.

Categories of providers that process data so Arroway can work: managed database, application hosting, identity provider (when you choose to sign in with an existing account), e-mail delivery, error monitoring, and audience measurement on the public pages. None of them receives your content for their own use, and all process only on our instructions. We describe them by category rather than by name because the list changes with the infrastructure and the policy should not go stale for that reason — if you want the current named list, ask at hello@arroway.app and we will send it.

Your AI — Claude, ChatGPT or another — receives what the commons returns, because it is the one doing the reading. What that vendor does with what it receives is governed by THEIR policy, not this one. That is precisely why Arroway exists outside them.

What leaves by E-MAIL, and this changed on 2026-08-06 and again on 2026-09-02: besides the sign-in link, you receive a summary of what is in your projects. It carries memory TITLES and types, counts, the name of whoever wrote them, the one-line summary of a daily log entry and of a handed-off piece of work (the single sentence its author left as a summary, plus the work's next step), how full each project is and, if you run a team project, how many memories and log entries each member saved and which assistant each one uses — and it does NOT carry the content of a memory or the text of a daily log entry. The distinction matters because e-mail crosses servers that are not ours and rests in a mailbox we do not control: a title says a decision about pricing exists, the content would say what it is. Every summary carries a link to stop receiving it, which works without signing in and in one click.

How long we keep it

As long as your account exists. Arroway does not delete as a side effect: archiving a memory or closing a project hides it from AI reads and preserves the history, because knowing that something was decided and later reversed is part of the value.

Daily-log entries older than 14 days stop being sent to AIs, but stay visible to you in the panel.

Your rights, and how to exercise them

On your own, at any time, you can: revoke an AI connection under Connections (access dies immediately), correct or archive any memory, and close a project.

You can DELETE your account yourself, from the menu under your photo. The screen shows exactly what goes and what stays before you confirm. What goes: your access, your AI connections, your e-mail and picture, and your entire personal project. What STAYS is what you wrote in a TEAM project, under your name — because it is that team's record and it is your signature on a document you wrote for them. Leaving does not unsign what you did, and erasing authorship would leave the audit trail of the people who stayed with no answer to "who decided this".

To get a copy of your data, or to correct something you cannot correct in the panel, write to hello@arroway.app. We answer within 15 days.

If you are in Brazil, these are your rights under the LGPD (Law 13.709/2018). In the European Union, under the GDPR.

Security

All traffic is over HTTPS. Connection addresses, invitations and OAuth credentials are stored only as cryptographic digests. An AI's access is limited to the projects you belong to, and is always derived from your identity — never from anything the AI tells us.

No system is immune. If an incident affects your data, we notify you and the competent authority as the applicable law requires.

Changes to this policy

Last updated: 2026-09-18. A material change is announced by e-mail before it takes effect, and the date above always says when this version started to apply.