Privacy Policy
In force since 2026-08-06
The other half of this agreement is the Terms of Use, which govern using Arroway.
What Arroway is, in one sentence
Arroway is a shared working memory: a team's decisions and rules, written by people and by the AIs they use, kept somewhere that belongs to no AI vendor. This policy says exactly what is kept, where, for how long, and who can reach it.
Who is responsible
Arroway is operated by Alexandre Viola. For anything in this policy — a question, a correction, a copy of your data, or deletion — write to hello@arroway.app.
What we keep about you
Your account: name, e-mail address and profile picture, from the identity provider when you sign in with an existing account, or just the e-mail when you sign in with a link. We also keep your chosen language and the date of your last sign-in.
Your AI connections: a label you write yourself, which assistant it is, and when it was last used. The secret connection address is NEVER stored — we keep only a cryptographic digest (SHA-256) of it, which recognises the right address and cannot rebuild it. The same applies to invitations and to OAuth credentials.
Your work: the projects you create, with name and scope; the memories (decisions, rules, facts, preferences, references) and the daily log. That content is written by you in the panel or by your AI through the connection — we do not generate it and we do not edit it.
What your AI sends, and what we record of it
When your AI reads the commons, it may send a short sentence saying what it is about to do, to improve the relevance of what it gets back. We do NOT store that sentence. We store up to six words extracted from it and mark them as declared context. They count as observed-use evidence only when a matching completion residue arrives from the same session.
When your AI logs what it did or proposes a memory, the text it writes is stored — that is the product's function, and it is what you read and approve in the panel. It writes the residue of a task, not the conversation: we do not receive or store your chat history, your files, or the assistant's memory.
We also record every tool call and every curation action: who, through which connection, in which project, which tool and when. That is what the audit screen rests on — the answer to 'where did this come from and who decided it'. Without that record the product could not prove anything it shows.
We keep a session identifier that some AI clients send in a header, only to group calls from the same conversation. It is opaque to us and does not identify you.
What we never keep
Passwords — Arroway has none; authentication is the identity provider you choose, or the link sent to your e-mail.
Credentials, tokens and API keys: the instruction handed to every connected AI forbids writing them into the commons, with no exception and no opt-out. If one slips through, delete it in the panel and tell us.
Your conversation with the AI, your files, and the assistant's own memory. Arroway cannot reach any of it, and the instruction given to the AI expressly forbids extracting from there.
Who sees what
Team project: members of that project see what is in it. That is what it exists for.
Personal project: only you. Your personal rules travel to the reads of YOUR connections, in any project — that is what lets your AI know how you work without the team seeing it.
We do not sell, rent or share your content with third parties. We do not use what you write to train any AI model.
Where the data lives, and who else touches it
Data is kept in a managed PostgreSQL database and the application runs on a cloud hosting platform, both with servers in the United States. This means your data is transferred internationally.
Categories of providers that process data so Arroway can work: managed database, application hosting, identity provider (when you choose to sign in with an existing account), e-mail delivery, and error monitoring. None of them receives your content for their own use, and all process only on our instructions. We describe them by category rather than by name because the list changes with the infrastructure and the policy should not go stale for that reason — if you want the current named list, ask at hello@arroway.app and we will send it.
Your AI — Claude, ChatGPT or another — receives what the commons returns, because it is the one doing the reading. What that vendor does with what it receives is governed by THEIR policy, not this one. That is precisely why Arroway exists outside them.
What leaves by E-MAIL, and this changed on 2026-08-06: besides the sign-in link, you receive a summary of what is in your projects. It carries memory TITLES, counts, the name of whoever wrote them, and how full each project is — and it does NOT carry the content of a memory or the text of a daily log entry. The distinction matters because e-mail crosses servers that are not ours and rests in a mailbox we do not control: a title says a decision about pricing exists, the content would say what it is. Every summary carries a link to stop receiving it, which works without signing in and in one click.
How long we keep it
As long as your account exists. Arroway does not delete as a side effect: archiving a memory or closing a project hides it from AI reads and preserves the history, because knowing that something was decided and later reversed is part of the value.
Daily-log entries older than 14 days stop being sent to AIs, but stay visible to you in the panel.
Your rights, and how to exercise them
On your own, at any time, you can: revoke an AI connection under Connections (access dies immediately), correct or archive any memory, and close a project.
You can DELETE your account yourself, from the menu under your photo. The screen shows exactly what goes and what stays before you confirm. What goes: your access, your AI connections, your e-mail and picture, and your entire personal project. What STAYS is what you wrote in a TEAM project, under your name — because it is that team's record and it is your signature on a document you wrote for them. Leaving does not unsign what you did, and erasing authorship would leave the audit trail of the people who stayed with no answer to "who decided this".
To get a copy of your data, or to correct something you cannot correct in the panel, write to hello@arroway.app. We answer within 15 days.
If you are in Brazil, these are your rights under the LGPD (Law 13.709/2018). In the European Union, under the GDPR.
Security
All traffic is over HTTPS. Connection addresses, invitations and OAuth credentials are stored only as cryptographic digests. An AI's access is limited to the projects you belong to, and is always derived from your identity — never from anything the AI tells us.
No system is immune. If an incident affects your data, we notify you and the competent authority as the applicable law requires.
Changes to this policy
Last updated: 2026-08-06. A material change is announced by e-mail before it takes effect, and the date above always says when this version started to apply.