Privacy Policy
Effective date: June 24, 2026
Summary: We collect only what we need to operate ArmaraOS and hosted AI services at armaraos.com. We use PostHog for anonymous product analytics to improve features. We do not sell personal information. You have rights to access, correct, and delete your data where applicable law requires.
Legal notice. This Privacy Policy is a transparency notice about how we handle personal information. It is not legal advice. Have qualified counsel in your jurisdiction review entity details, subprocessors, and regulatory obligations before relying on this Policy in production.
AINativeLang Inc.
Registered business address available on request at hello@ainativelang.com.
Email: hello@ainativelang.com
Website: armaraos.com
AINativeLang Inc. (“we,” “us,” or “our”) operates ArmaraOS and related AI inference services through armaraos.com and affiliated properties. “Armara” and “ArmaraOS” are product names for our software and hosted services (collectively, the “Services”). We respect your privacy and are committed to protecting personal information we collect in connection with the Services. This Privacy Policy explains what we collect, why we collect it, how we use and share it, and the choices and rights available to you.
This Policy works together with our Terms of Service, which govern your use of the Services. By accessing or using the Services, you acknowledge this Policy. If you do not agree, do not use the Services.
1. Scope
This Policy applies to personal information we process when you:
- Visit or interact with our websites (including armaraos.com and related domains)
- Create or use an ArmaraOS account
- Use hosted chat, API, or inference features we provide
- Download, install, or run ArmaraOS when it communicates with our services
- Contact support, participate in affiliates/referrals, or otherwise interact with us
ArmaraOS local-first use. When you run ArmaraOS entirely on your own machine without connecting to our hosted services, most processing occurs locally on your device. Local-only use is governed by this Policy only when you connect to our hosted services. If ArmaraOS is configured to send anonymous telemetry or connect to hosted inference, those flows are covered by this Policy.
Bring-your-own-key inference. If you supply third-party API keys (for example, keys you configure in ArmaraOS), those providers process data under their own policies. We do not control and are not responsible for third-party model providers you choose to use directly.
2. Personal information we collect
We collect personal information in three broad categories: information you provide, information collected automatically, and information from third parties.
2a. Information you provide
- Account data — email address, display name, password (stored in hashed form via our authentication provider), and profile preferences
- Billing data — subscription tier, transaction identifiers, and billing metadata. Payment card details are collected and processed directly by Stripe; we do not store full card numbers on our servers
- Support communications — messages, attachments, and contact details you send to us
- User content — prompts, messages, files, agent configurations, and other content you submit through hosted Services (for example, web chat or API requests routed through our infrastructure)
- Referral and affiliate data — referral codes you use or share, and related attribution metadata
2b. Information collected automatically
- Device and usage data — browser type, operating system, app version, language, pages viewed, feature interactions, timestamps, and diagnostic events
- Log and security data — IP address, request metadata, rate-limit counters, authentication events, and error logs used for security, abuse prevention, and reliability
- Inference and quota data — API key identifiers (not full secrets after initial display), message counts, token or usage quotas, and service performance metrics
- Cookie and local storage data — session cookies, authentication tokens, referral cookies, and similar technologies described in Section 6
2c. Information from third parties
- Authentication providers — if you sign in with OAuth (for example, Google), we receive basic profile information permitted by your provider settings
- Payment processors — Stripe and CopperX provide transaction status, customer identifiers, and subscription lifecycle events
We do not intentionally collect sensitive categories of personal information (such as health data, government ID numbers, or financial account credentials beyond what payment processors handle) unless you voluntarily submit them in user content. Do not submit sensitive personal information or third-party confidential data through the Services unless you have a lawful basis and appropriate safeguards.
3. How we use personal information
We use personal information to:
- Provide, operate, maintain, and improve the Services
- Authenticate users, manage accounts, and enforce usage quotas
- Process subscriptions, payments, referrals, and affiliate commissions
- Route, execute, and monitor hosted AI inference requests you initiate
- Detect, prevent, and respond to fraud, abuse, security incidents, and violations of our terms
- Communicate with you about the Services, updates, billing, and support
- Analyze product performance and reliability through anonymous telemetry (see Section 5)
- Comply with legal obligations and protect the rights, safety, and property of AINativeLang Inc., our users, employees, contractors, and the public
- Develop new features, conduct internal research, and improve model routing and system quality
We do not sell personal information and we do not share personal information for cross-context behavioral advertising. Where required by law, we provide mechanisms to opt out of certain processing as described in Sections 9 and 10.
Model training. We do not use your hosted inference prompts or outputs to train third-party foundation models. We may use aggregated or de-identified telemetry and feedback to improve our own software, routing, safety filters, and reliability. If we ever introduce optional training-related uses of user content, we will provide clear notice and choice before doing so.
4. AI services and inference data
When you use hosted AI features, we process the content you submit (prompts, context, attachments, and generated outputs) to deliver the requested functionality, enforce plan limits, maintain logs for security and debugging, and improve service quality.
- AI outputs may be inaccurate, incomplete, or inappropriate. Do not rely on outputs as professional, legal, medical, financial, or safety-critical advice
- You are responsible for reviewing outputs before use and for ensuring your inputs comply with our Terms of Service and applicable law
- We may use automated systems to detect abuse, spam, malware patterns, or policy violations. Flagged content may be retained longer for investigation even if you delete an account, as permitted by law
- API keys and inference credentials are encrypted at rest. Full API keys are shown only at creation or rotation; thereafter we display masked values
5. Product analytics and telemetry (PostHog)
We use PostHog (PostHog, Inc.) to collect anonymous product analytics and telemetry across our website, ArmaraOS (when enabled), and hosted AI services. This helps us understand feature adoption, diagnose crashes, measure performance, and prioritize improvements.
PostHog data may include, for example:
- Page views, navigation paths, and UI interactions
- App version, operating system, and device class
- Feature flags, session duration, and error events
- Aggregated inference or API usage events (such as request counts or latency buckets)
We configure analytics to minimize identification of individual users. Where possible, we use pseudonymous identifiers rather than directly identifying fields. PostHog may set cookies or use local storage. PostHog processes data as our service provider under contractual data protection terms. Learn more at posthog.com/privacy.
You can limit analytics collection by adjusting browser cookie settings, using privacy tools that block analytics scripts, or — where available in ArmaraOS — disabling telemetry in product settings. If you opt out of analytics in a jurisdiction that requires consent, we will honor that preference for future collection once applied.
6. Cookies and similar technologies
We use cookies and similar technologies for:
- Essential operations — authentication sessions, security, load balancing, and checkout flows (these are necessary for the Services to function)
- Referral attribution — storing referral codes (for example,
armara_ref) for up to 30 days to attribute signups and affiliate commissions - Analytics — PostHog cookies or local identifiers for anonymous usage measurement as described above
Most browsers let you block or delete cookies. Blocking essential cookies may prevent you from signing in or completing purchases.
7. How we disclose personal information
We disclose personal information only as described below. We require service providers to process personal information on our instructions and under appropriate contractual safeguards.
7a. Service providers and subprocessors
| Provider | Purpose | Privacy / DPA |
|---|---|---|
| Supabase | Authentication, database, and account storage | supabase.com/privacy |
| Stripe | Card payments, subscriptions, and fraud prevention | stripe.com/privacy |
| CopperX | Cryptocurrency (USDC) checkout and payment status | copperx.io/privacy |
| PostHog | Anonymous product analytics and telemetry | posthog.com/privacy |
| Vercel | Website hosting and edge delivery | vercel.com/legal/privacy-policy |
| Upstash | Distributed rate limiting and abuse prevention (where configured) | upstash.com/trust/privacy |
We may update subprocessors from time to time. Material changes will be reflected in this Policy or a linked subprocessor list.
7b. Other disclosures
- Legal and safety — to comply with law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect rights, safety, security, or to detect and prevent fraud or abuse
- Business transfers — in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to standard confidentiality obligations
- With your direction — when you integrate third-party services or explicitly authorize sharing
- Aggregated or de-identified data — we may share statistics that do not reasonably identify individuals
8. Legal bases for processing (EEA, UK, Switzerland)
If you are in the European Economic Area, United Kingdom, or Switzerland, we process personal data only where we have a valid legal basis, including:
- Contract — to provide the Services you request, manage your account, and process payments
- Legitimate interests — to secure the Services, prevent abuse, improve product quality through anonymous analytics, and communicate about the Services, balanced against your rights
- Consent — where required for non-essential cookies, analytics in certain jurisdictions, or optional features
- Legal obligation — to comply with applicable law, tax, and accounting requirements
You may withdraw consent at any time where processing is consent-based, without affecting the lawfulness of processing before withdrawal.
9. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or port personal information, and to lodge a complaint with a supervisory authority.
- Access and correction — review and update account information in your account settings or by contacting us
- Deletion — request deletion of your account and associated personal information, subject to legal retention exceptions
- Opt-out of marketing — unsubscribe from promotional emails using the link in the message or by contacting us
- Analytics preferences — use browser controls or in-product settings where available
To exercise rights, email hello@ainativelang.com. We may verify your identity before fulfilling requests. We respond within timeframes required by applicable law.
10. U.S. state privacy disclosures
Residents of California, Colorado, Connecticut, Virginia, and other U.S. states with comprehensive privacy laws may have additional rights, including the right to know categories of personal information collected, to delete personal information, to correct inaccurate personal information, and to opt out of certain processing.
Categories collected (last 12 months). Identifiers (email, account ID, IP address); commercial information (subscription and transaction records); internet or network activity (logs, analytics events); and user content you submit to hosted Services.
Business purposes. Providing Services, security, analytics, billing, support, and compliance as described in this Policy.
No sale or sharing for cross-context behavioral advertising. We do not sell personal information and do not share it for cross-context behavioral advertising as those terms are defined under California law. We do not use or disclose sensitive personal information for purposes other than those permitted by CPRA.
California residents may designate an authorized agent to submit requests on their behalf. We do not discriminate against you for exercising privacy rights.
11. International data transfers
We and our service providers may process personal information in the United States and other countries where we or our vendors operate. When we transfer personal data from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or equivalent mechanisms offered by our subprocessors.
12. Security
We implement administrative, technical, and organizational measures designed to protect personal information, including encryption of API keys at rest, server-side session validation, row-level database protections, rate limiting, webhook signature verification, content security policies, and access controls for production systems. No method of transmission or storage is completely secure; we cannot guarantee absolute security.
Report suspected vulnerabilities or security issues to hello@ainativelang.com. See our repository SECURITY.md for additional hardening notes where published.
13. Data retention
We retain personal information only as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.
- Account data — retained while your account is active and for a reasonable period afterward for backup, dispute resolution, and legal compliance
- Billing records — retained as required for tax, accounting, and chargeback evidence
- Hosted inference logs — retained for operational, security, and abuse investigation purposes, then deleted or aggregated according to internal schedules
- PostHog analytics — retained according to PostHog project settings and our analytics retention configuration
- Referral cookies — up to 30 days unless cleared earlier
14. Children
The Services are not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided personal information, contact us and we will take appropriate steps to delete it.
15. Changes to this Policy
We may update this Privacy Policy from time to time. When we do, we will post the updated Policy on this page and revise the effective date above. If changes are material, we will provide additional notice where required by law (for example, by email or in-app notification). Continued use of the Services after the effective date constitutes acknowledgment of the updated Policy.
16. Contact us
Questions about this Policy or our privacy practices:
AINativeLang Inc.
Email: hello@ainativelang.com
Website: armaraos.com