Privacy Policy

ARIA — Voice AI Assistant · Last updated: 4 August 2026

ARIA is a personal project built by Nihhar K Sonee that lets you read, search, summarize and send email using your voice. This policy explains exactly what data ARIA touches, where it goes, and what it is never used for.

The short version: ARIA stores as little as possible. Your email content is never sold, never used to train any AI model, never read by a human, and never shared with anyone beyond the specific services needed to answer the request you made.

1. What ARIA accesses

DataWhyStored?
Google account email, name, profile pictureTo sign you in and show who is logged inYes — until you sign out or delete
Google OAuth tokensTo access the mailbox you explicitly connectedYes — encrypted at rest
Email metadata (sender, subject, date)To list and rank your emailsNo — fetched live per request
Email body contentOnly when you ask for a summary or replyNo — processed in memory, then discarded
Your chat messages with ARIATo keep conversation history across devicesYes — until you delete them
Voice audioSpeech recognition runs in your browserNo — audio never leaves your device

2. Google user data — Limited Use

ARIA's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Specifically, ARIA:

3. Third parties that process your data

ARIA is a thin client over a small number of providers. Data reaches them only when a request requires it:

ProviderReceivesWhen
Groq (AI inference)Your message, and email content when you ask for a summary or replyOnly on requests that need AI
ElevenLabs (speech)The text ARIA speaks back to youOnly when voice replies are on
GoogleAPI calls against your own mailboxOnly for the mailbox you connected
Cloudflare (hosting)Requests transit their networkAlways
Supabase (database)Session, profile, chat history, encrypted tokensAlways
Please note: when you ask ARIA to summarize an email or draft a reply, the content of that email is sent to Groq to generate the response. Groq does not train on API data. If you would rather no email content ever leave Google's systems, do not use the summarize or reply features.

4. What ARIA never does

5. Your controls

6. Retention

Chat history and connected-account records persist until you delete them or ask for deletion. Email content is never written to disk — it exists only in memory for the seconds it takes to answer your request.

7. Security

All traffic uses HTTPS. API keys live server-side in Cloudflare Workers and are never exposed to the browser. OAuth tokens are stored encrypted and are never returned to the client. Rate limiting is in place to protect against abuse.

8. Beta status

ARIA is a personal project under active development, currently in limited beta. It is provided as-is, without warranty. Please do not use it for anything mission-critical.

9. Children

ARIA is not directed at children under 13 and does not knowingly collect their data.

10. Changes

Material changes will be reflected in the "last updated" date above. Continued use after a change constitutes acceptance.

11. Contact

Questions, access requests, or deletion requests:
Nihhar K Soneegithub.com/NKS-Coder/ARIA-voice-agent
Open an issue on the repository, or contact via the email listed on the GitHub profile.

← Back to ARIA · Terms of Service