Security & data

Updated 19 August 2026 · Aria, Dubai, United Arab Emirates

Brokerages ask us the same sensible questions before they let a tool near their client book: where does the data live, who can see it, is it used to train AI, and how do we get it out. This page answers them plainly. For the legal version, see the Privacy Policy, and ask us for the Data Processing Addendum.

In one paragraph. Your client data sits in an encrypted PostgreSQL database in Frankfurt, Germany, partitioned per broker with row-level security. Your AI agent runs on its own machine with its own disk in Singapore — one per broker, nothing shared. WhatsApp is connected through Meta's official Cloud API on your own WhatsApp Business Account and number. AI processing happens at OpenAI at request time only; nothing is kept there and nothing is used for training. You can export or delete everything yourself; deletion completes within 30 days.

Where your data lives

YOUR SIDE · DUBAI You and your team Browser, desktop app or phone. Everything travels over TLS (HTTPS). WhatsApp · Meta Cloud API Your own WhatsApp Business Account and number. Official API only — no unofficial clients. ARIA · SINGAPORE Aria control plane Three machines on Fly.io. Handles sign-in, routing and the web app. Your private AI agent Its own machine and its own disk — one per broker. Memory and chat sessions live here. Nothing shared. STORAGE · FRANKFURT, GERMANY Database Supabase PostgreSQL on AWS. Encrypted at rest; row-level security. Backups Nightly to Supabase storage in Frankfurt, plus an off-site copy held with Cloudflare R2. OpenAI API · USA Processing at request time only. Not stored there by Aria. Not used to train models. TLS TLS per request, in and out

Data types, locations and access

DataWhere it is heldEncryptionWho can access it
Client book — names, phone numbers, notes, labels, stagesDatabase, Frankfurt, Germany (Supabase PostgreSQL, AWS eu-central-1)TLS in transit; encrypted at rest; row-level security per tenant, verified by cross-tenant probingYou and your team. Aria support only when you ask for help — and it is logged.
WhatsApp messages and metadataDatabase, Frankfurt. Meta also holds message content for up to 30 days for deliveryAs above; Meta Cloud API over TLSYou and your team; Aria support on request, logged.
AI agent memory and chat sessionsYour private agent machine, Singapore — its own machine and its own disk, one per brokerTLS in transit; an isolated disk no other broker's agent can reachYou; Aria support on request, logged.
Connected credentials — Gmail app password, Calendly token, calendar addressDatabase, FrankfurtAES-256-GCM application-level encryption on top of encryption at restUsed by the system only, not read by people. Deleted the moment you press Disconnect.
Emails, calendar events, YouTube (only if you connect them)Read live from Google over IMAP and iCal; only what Aria needs is kept in FrankfurtTLS in transit; encrypted at restYou; Aria support on request, logged.
Documents and filesSupabase storage, FrankfurtTLS in transit; encrypted at restYou and your team; Aria support on request, logged.
BackupsNightly to Supabase storage in Frankfurt, plus an off-site copy in Cloudflare R2Encrypted at restAria operators only, for restore. Rotate out within the 30-day deletion window.
AI requests in flightOpenAI API, USA — at request time onlyTLS; not stored by Aria at OpenAI; not used for trainingNot read by people at Aria; processing is automated.

Secrets are encrypted with AES-256-GCM. TLS is used everywhere. Privileged credentials are never stored on the machines that run individual brokers' agents; those machines hold only a scoped token and reach privileged services through a controlled gateway.

The questions brokerages ask

Who owns the data?

You do. Your brokerage is the data controller; Aria is the processor and acts only on your instructions. We never sell it, never share it across customers, and never reuse it for anything else.

Which law applies?

UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). GDPR applies only where you process EU residents' data. DIFC and ADGM have their own data-protection regimes — tell us if you are based in one.

Can our data be hosted only in the UAE?

The standard service runs in Frankfurt and Singapore under PDPL-compliant transfer safeguards. UAE-only hosting is available as an enterprise option — ask us.

Can we export it?

Yes, self-serve, at any time. Your client book, conversations and documents can be exported from inside Aria without asking us.

Can we delete it?

Yes, self-serve. Connections → Delete my data disconnects WhatsApp immediately; everything is deleted within 30 days, backups included, and we confirm it to you. It is free. Steps on the Data Deletion page.

Who at Aria can see our data?

Nobody by default. Support staff access a workspace only when you ask for help, every privileged access is logged, and the log is visible to you in the app at any time. Aria staff do not browse customer data.

Is AI trained on our data?

No. Aria does not train models on your data, and OpenAI does not use API data for training. Each request is processed and the answer returned — nothing is kept at OpenAI.

Backups and uptime?

Backups run nightly to Frankfurt with an off-site copy held with Cloudflare, so a single provider failing cannot lose your data. The platform is monitored continuously with on-call alerting.

Sub-processors

These are the providers that process data on our behalf under contract. We give at least 30 days' notice before adding or replacing one.

Supabase — database, storage, backups · Frankfurt Fly.io — compute · Singapore Cloudflare — DNS, off-site backups, email routing OpenAI — AI processing · USA Meta — WhatsApp Business Platform Google — only if you connect Gmail, Calendar or YouTube Calendly — only if you connect it Resend — transactional email, if used

Paperwork for your compliance team

We have a short, plain-English Data Processing Addendum (controller–processor terms, security measures, sub-processors, 72-hour breach notice, 30-day deletion, annual audit answers) and a one-page “Where your data lives” handout. Email support@aria-app.dev and we will send both.