Contents
Introduction & Data Controller
This Privacy Policy describes how ARMES Labs, Inc. (“ARMES,” “we,” “us,” or “our”), a Delaware S-Corporation, collects, uses, shares, and protects information when you use the ARMES platform, website, APIs, and related services (collectively, the “Services”).
ARMES separates intelligence from memory. AI providers process your requests through Zero Data Retention infrastructure and immediately forget them. Your workspace — including personalization — is stored for you, is visible to you, and is used only to serve you. No ads. No provider profiles. No human review of inference.
For the purposes of the EU General Data Protection Regulation (“GDPR”) and similar data protection laws, ARMES Labs, Inc. is the data controller for personal data processed through the Services.
By using our Services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Services.
Data We Collect
We collect only the data necessary to operate and improve the Services. Here is a transparent inventory of what we hold and what we do not.
Information You Provide
Email address, display name, and authentication credentials (managed by Firebase).
Messages you send and receive through ARMES, saved to your private workspace.
Notes, documents, and prompt templates you create within ARMES.
Custom bot/agent settings, system prompts, and mode preferences.
Files you attach to a chat for AI processing. Stored in your private workspace and purged automatically within 10 days, or immediately when you delete the chat.
Files you save to your Notes knowledge base. Retained in your private workspace until you delete them, along with the text we extract to make them searchable and usable by your agents.
Messages and information you send when contacting support.
Identity you enter (such as preferred name, role, and style), memory facts derived from your conversations (with provenance: which chat, which agent, user-stated vs inferred), conversation summaries (episodes), and search embeddings of those objects. All of it is visible in Settings. Personalization is on by default; you can turn it off at any time.
Information Collected Automatically
Token counts, model selections, feature usage, and search-embedding usage (aggregate, non-content) for billing and system health.
Browser type, operating system, IP address, and general location (country/region).
Server logs including timestamps, request paths, and error codes for system health.
Session tokens and refresh tokens managed by Firebase Authentication.
What We Do NOT Collect
How We Use Your Data
We use your data only for the purposes described below. We do not sell your personal data. We do not use your data for advertising. We do not build advertising or hidden behavioral profiles. Personalization that lives in your workspace exists only to serve you, and you can inspect and turn it off.
Providing the Services
Processing your AI queries, storing your conversations and knowledge base, managing your agents, and delivering responses.
Personalization
Maintaining a user-owned memory layer so system agents can remember facts you have shared or approved. This includes injecting an inspectable envelope into agent conversations, searching your memories and episodes, and showing you a ledger so you can keep, edit, discard, or delete inferred facts. Personalization is on by default and can be turned off in Settings. Extraction and embedding run only through Zero Data Retention inference — no human review. We do not use this layer for advertising, training models, or profiling you for anyone else.
Account Management
Creating and maintaining your account, authenticating your identity, and managing subscriptions.
Billing & Payments
Processing subscription payments and managing usage-based billing through Stripe.
Service Improvement
Analyzing aggregate, non-content usage patterns (e.g., which models are popular, feature adoption rates) to improve the platform.
Error Diagnosis
Reviewing anonymized error logs to diagnose and fix bugs. See Section 11 for details.
Security & Fraud Prevention
Detecting, preventing, and responding to security incidents, abuse, and violations of our Terms.
Communications
Sending transactional emails (receipts, security alerts, service updates). Marketing emails only with your opt-in consent.
Legal Compliance
Meeting legal obligations, responding to lawful requests, and enforcing our Terms of Service.
Private Inference Architecture
They Process. They Forget. You Keep the Keys.
ARMES uses a three-part architecture: ephemeral AI processing, your private workspace, and a glass-box personalization layer you can see and control. Together this is private inference — the core of our privacy model. Zero Data Retention is about the inference layer. Your workspace is stored for you. Both are true at once.
Layer 1: Ephemeral AI Processing
When you send a query to ChatGPT, Claude, Gemini, or any model through ARMES:
- 1Routing: Your query travels through our gateway partner, OpenRouter, which enforces private inference endpoints.
- 2Processing: The AI provider processes your query and returns a response. Your data is not stored on their servers, not used for model training, and not used to build advertising or behavioral profiles.
- 3Deletion: Once the response is generated, the context is discarded by the AI provider. It is never written to persistent storage.
Layer 2: Your Private Workspace
ARMES stores your conversations, notes, files, agent configurations, and personalization for your benefit — not for training, advertising, or hidden profiling.
- Isolated: Your data is stored in your private workspace with row-level security isolation.
- Not mined by us: ARMES staff do not read your conversations, notes, or memories to train models, sell data, or advertise. Automated systems may derive personalization from your content solely to serve you, using the same Zero Data Retention inference path described in Layer 1. That derived layer is visible to you (Layer 3).
- Deletable: You can delete any or all of your data at any time. See Section 06.
Layer 3: Glass-Box Personalization
System agents can remember facts about you because those facts live in a user-owned memory layer — not in a hidden model profile. Anything an agent can use, you can see and manage.
- Visible: Settings shows your identity, the exact envelope injected into agents (“what agents see”), a ledger of memory facts, and conversation episodes. There is no second secret store.
- On unless you turn it off: Personalization is enabled by default so agents can serve you with continuity. A master toggle in Settings stops injection. You can keep, edit, discard, or delete individual facts and episodes without deleting your account.
- Provenance and supersession: Every memory carries where it came from. Inferred facts cannot overwrite what you asserted. Corrections supersede; they do not silently erase history you are entitled to see.
- Search embeddings: We may store numerical embeddings of your memories and episodes so you and your agents can search by meaning, not just keywords. Embeddings exist only to operate search for you. They are not a hidden dossier, are not used for advertising, and are deleted with the source object.
- Shared human conversations: Memory is off in DMs and group rooms with other people. Agents in those rooms do not build cross-session personalization from those messages.
ARMES Does Not
- Train any AI model on your data
- Build advertising or hidden behavioral profiles
- Sell or monetize your personal data
- Hide a second memory your agents can use that you cannot see
AI Providers Must Not
- Retain your query or response data
- Use your data for model improvement
- Build user profiles from ARMES queries
- Subject ARMES inference to human review queues
Data Sharing & Sub-Processors
We do not sell your personal data. We share data only with the service providers necessary to operate ARMES. Each sub-processor is bound by contractual obligations to protect your data.
We explicitly list every major sub-processor so you know exactly where your data flows.
When We May Disclose Data
- • To comply with applicable law, regulation, or valid legal process (e.g., subpoena or court order).
- • To protect the rights, safety, or property of ARMES, our users, or the public.
- • In connection with a merger, acquisition, or sale of assets (you will be notified beforehand).
- • With your explicit consent.
Data Retention & Deletion
In the digital world, “Delete” often means “Hide.” At ARMES, delete means gone.
Retention Schedule
Discarded immediately after response via private inference
Files attached to a chat are purged automatically within 10 days, or immediately when you delete the chat
Files saved to your Notes knowledge base — and the text extracted from them — remain until you delete them or your account
Stored in your workspace for as long as you choose
Visible in the personalization ledger. Deleting a source chat may orphan or purge memories that came from it. Turning the master toggle off stops injection without deleting stored facts.
Rolling summaries of threads, listed in Settings. Deleting an episode removes it from search and from agents.
Numerical search indexes of memories and episodes. Deleted with the memory or episode they belong to. Used only to search your workspace.
Preferred name, role, style, and similar fields you enter. The master toggle can stop agents from using this without wiping the fields.
Removed when you delete your account
Rotated and purged automatically for system health
Tax and financial regulations may require longer retention
How Deletion Works
Immediate Deletion
When you delete a conversation, note, memory, episode, or your entire account, the underlying data is permanently removed from the active database. Agents cannot see or search deleted objects. Your account profile is scrubbed of all personal information and retained only as an anonymous tombstone for referential integrity.
Backup Purge (7-Day Buffer)
Deleted data may persist in encrypted cold-storage backups for a maximum of 7 days as a disaster recovery safeguard. After 7 days, it is overwritten and permanently destroyed.
Security
We implement administrative, technical, and physical safeguards designed to protect your data. While no system is 100% secure, we follow industry best practices.
In Transit
TLS 1.3 encryption for all data moving between you, ARMES, and AI providers.
At Rest
AES-256 encryption at rest on all stored data, plus row-level security (RLS) policies that isolate each user's data at the database level.
Breach Notification
In the unlikely event of a data breach that affects your personal data, we will notify affected users and relevant supervisory authorities within 72 hours of becoming aware of the breach, as required by applicable law.
For a deeper technical breakdown of our encryption, key management, and subprocessors, see our Trust & Security page.
International Data Transfers
ARMES Labs, Inc. is based in the United States. If you access our Services from outside the United States, your data may be transferred to, stored in, and processed in the United States and other countries where our sub-processors operate.
Primary Data Location
Your workspace data is stored by Supabase on AWS infrastructure in the United States. Authentication data is managed by Firebase (Google Cloud Platform).
AI Processing
AI queries may be processed by providers located in various countries. Because these queries are processed ephemerally under private inference (no retention, no storage), the data exposure during transit is momentary and no persistent copy exists at the provider.
Safeguards for EU/EEA Users
Where personal data is transferred from the European Economic Area, we rely on appropriate transfer mechanisms including Standard Contractual Clauses (SCCs) and the EU-U.S. Data Privacy Framework, as applicable.
Your Rights
Depending on your jurisdiction, you may have some or all of the following rights regarding your personal data. To exercise any of these rights, contact us.
For All Users (and GDPR where applicable)
Right of Access
Request a copy of the personal data we hold about you, including personalization you can already inspect in Settings.
Right to Rectification
Request correction of inaccurate personal data.
Right to Erasure
Request deletion of your personal data, including through Settings (chats, notes, memories, episodes, or your account).
Right to Data Portability
Access and export conversations, notes, and personalization you can already see in Settings. For a broader copy of personal data we hold, contact us — we fulfill verified requests; a single bulk-account download is not yet a self-serve product.
Right to Restrict Processing
Request that we limit how we process your data in certain circumstances.
Right to Object
Object to processing based on legitimate interest, including direct marketing.
Additional Rights for California Residents (CCPA/CPRA)
Right to Know
Request disclosure of what personal data we collect, use, and share.
Right to Delete
Request deletion of personal data we have collected.
Right to Opt-Out of Sale
We do not sell personal data. This right is satisfied by default.
Right to Non-Discrimination
We will not discriminate against you for exercising your privacy rights.
Response Time: We will respond to verified rights requests within 30 days (or sooner where required by law). If we need additional time, we will notify you of the reason and extension period. If you are in the EU/EEA and believe we have not adequately addressed your concerns, you have the right to lodge a complaint with your local data protection supervisory authority.
Children’s Privacy
ARMES is not intended for use by anyone under the age of 18. We do not knowingly collect personal data from children under 18.
If we learn that we have collected personal data from a user under 18, we will take steps to delete that data promptly. If you believe a child under 18 has provided us with personal data, please contact us.
Error Diagnostics & Safety
We want to be transparent about the limited circumstances in which a person at ARMES may review data beyond aggregate metrics. Automated personalization (extraction, summarization, embedding) is not human review: it is Zero Data Retention inference, and the results are stored only in your workspace where you can see them.
When We May Review Error Data
When an error or failure occurs in the AI processing pipeline, we may review anonymized diagnostic information to identify and fix the issue. When doing so:
- We do not have access to your identity in the error log. Diagnostic data is separated from user identifiers.
- We do not review the content of your conversations unless strictly necessary to diagnose a specific failure.
- Any review is conducted by authorized personnel only, under strict access controls.
- Diagnostic data is retained only for the duration necessary to resolve the issue.
This practice is similar to how other AI platforms handle safety-flagged content, but we are committed to minimizing any access to your data. We will never use error diagnostic data for training, advertising profiles, or any purpose other than fixing the specific technical issue.
User-Submitted Feedback
You can voluntarily share specific messages with our team for quality review using the “Share Feedback” option in chat. This is entirely user-initiated and works as follows:
- Only the messages you explicitly select and preview are shared — a frozen copy taken at the moment you submit. We never open or access your chats themselves.
- Submission requires your explicit consent via a required confirmation, recorded with the submission.
- Shared messages are reviewed by authorized personnel only, solely to assess and improve response quality, and are never used for AI training or profiling.
- Feedback submissions are retained only as long as needed to review and address them, after which they are deleted. You may request deletion of a submission at any time by contacting us with its reference number.
Cookies & Similar Technologies
ARMES uses a minimal set of cookies, limited to what is strictly necessary for the Services to function. We do not use advertising, tracking, or analytics cookies.
Authentication Cookies
Strictly NecessaryManaged by Supabase and Firebase to maintain your login session securely. These are strictly functional cookies required for the service to operate.
Security Cookies
Strictly NecessaryCSRF tokens and session integrity cookies to protect against cross-site attacks.
Preference Cookies
FunctionalStore your UI preferences such as theme (light/dark mode) selection.
No Tracking: We do not use Google Analytics, Facebook Pixel, or any third-party advertising or behavioral tracking technologies.
Google Workspace API & Limited Use Disclosure
ARMES allows users to optionally connect their Google account to reference, search, create, and update documents within their private workspace. We treat the privacy, confidentiality, and security of your Google user data with the highest standard of care.
Google API Services User Data Policy Compliance
ARMES's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
How We Access and Use Google User Data
- On-Demand Contextual Retrieval: When you ask questions about your files or search your connected Google Drive, ARMES retrieves file metadata and content strictly in real time to answer your prompt.
- Document Creation & Structural Updates: When you direct the assistant to draft new reports or append notes to existing Google Docs, ARMES creates or modifies files in your Drive per your explicit instructions.
- Human-in-the-Loop Safeguards: ARMES requires explicit, in-app user confirmation before executing any destructive update or overwrite to an existing file. No background or unsolicited modifications ever occur.
Data Storage & Protection
OAuth access tokens and refresh tokens are strongly encrypted at rest using AES-256-GCM. We never store copies of your full Google Drive files on our servers, except when you explicitly choose to import a document into your private Knowledge Vault.
Sharing, Advertising, and AI Training Prohibitions
Google Workspace user data received via Google APIs is never used to train, retrain, or fine-tune generalized artificial intelligence (AI) or machine learning (ML) foundation models.
We never sell Google user data, transfer it to data brokers, or use it to serve advertisements (including retargeted or personalized ads).
ARMES personnel do not view your Google Drive documents or files, except with your prior explicit consent for specific technical support investigations, or when strictly required by law.
Google user data is only transferred to external sub-processors (such as our database hosting provider) to the extent strictly necessary to provide the user-facing workspace features.
Revoking Access & Disconnecting Google Drive
You retain full control over your Google integration at all times. You may disconnect Google Drive from ARMES at any moment in your workspace Settings (or Integrations tab). Upon disconnection, all stored OAuth credentials and tokens are permanently deleted from our database. You can also revoke access directly from your Google Account Security Settings.
Third-Party Links
The Services may contain links to third-party websites, products, or services that are not owned or controlled by ARMES. We are not responsible for the privacy practices of these third parties.
We encourage you to review the privacy policies of any third-party services you access through ARMES. Our inclusion of a link does not imply endorsement of the linked site's privacy practices.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
Material Changes
For significant changes that affect how we collect, use, or share your data, we will notify you by email (to the address associated with your account) and/or by posting a prominent notice within the Services at least 30 days before the changes take effect.
Minor Changes
For non-material changes (e.g., formatting, clarifications that don't change the substance), we will update the “Last Updated” date at the top of this page.
Your continued use of the Services after any changes become effective constitutes your acceptance of the revised policy.
Contact Us
Questions, concerns, or rights requests? We're here to help.
ARMES Labs, Inc.
Delaware, United States
We aim to respond to all privacy inquiries within 48 hours.