Legal

Privacy Policy

How Ariso collects, uses, and protects your personal information.

Privacy Policy at a glance

Summary reviewed August 2026

Ariso builds Ari, an AI management system for teams. Using it means Ari processes the work you point it at, so this page starts with the short version: what we collect, what we never do with it, who can see it, and how to get it deleted. The full policy below is the authoritative document.

What we process

  • From you: chat messages, notes, tasks, file uploads, and feedback you choose to give.
  • From integrations you connect: calendar metadata, meeting transcripts, and email context.
  • From your administrators: user provisioning, organization configuration, and role assignments.

What we don't do

  • No model training on your data. We may use anonymized data to improve the service, and that data is never sent to third parties.
  • We don't share your conversations with your employer. Organization-level data (like company information) is shared across your workspace, but your individual conversations, notes, and reflections stay yours. Organizational insights are only ever shared anonymized and aggregated, and feedback about colleagues is anonymous unless you ask for it to be attributed.
  • Ariso staff can't read your data. Employees — including production system and database administrators — cannot view end user or organization data unless you or your organization explicitly authorize it for support.

How it's protected

Data is encrypted in transit and at rest. Every end user's data is encrypted with a key unique to that user, and company data with an organization-specific key; keys are managed in HashiCorp Vault. Ariso is SOC 2 Type I audited (Type II in progress), has completed the Google CASA assessment, and has signed the Cloud Security Alliance AI Trustworthy Pledge. The full list of subprocessors is published on the subprocessors page.

Retention and deletion

Data is retained while you remain an active customer, and you can delete conversations, messages, and personal data at any time. When an account is closed, its encryption key is deleted immediately — which renders the data cryptographically unreadable — and full deletion, including propagation through backup rotation, completes within 30–90 days. Application debug logs are deleted automatically after 90 days. You can also ask Ari to “talk off the record” for a session that is never recorded at all.

Exercising your rights

To request access, correction, export, or deletion of your personal data, email hi@ariso.ai or use the contact form. Related documents: Cookie Policy, Terms & Conditions, and Trust & Security.

This summary is provided for convenience and is not a substitute for the full document below, which governs. Questions? hi@ariso.ai · Contact us

Full Privacy Policy