AriseAriseAiSign in

Draft. This document is a placeholder while AriseAi is in closed beta. Final language will be reviewed by counsel before general availability. For questions in the meantime, get in touch.

Legal

Privacy Policy

Last updated: July 22, 2026

What we collect, how we use it, and what we don't do with it. Written in plain language so you can actually read it.

1. Who we are

AriseAi is a product of Arise Technology Company. This policy covers data processed through the AriseAi platform.

2. What we collect

From you, the customer (the company on the contract):

  • Account data: company name, billing contact, billing address, payment method.
  • Configuration data: ICP definition, message library, campaign settings, BYOK API keys (encrypted at rest).
  • Customer data you bring: prospect lists, account targets, CRM-linked records.

From end users on your tenant:

  • Identity data: name, work email, hashed password (managed by Clerk, our auth provider).
  • Activity logs: which features were used, when, by whom — for auditability.

3. How we use it

  • To run the agents you configured.
  • To bill you, support you, and fix things when they break.
  • To improve the platform — but only with aggregated, de-identified data, never with content from your tenant.

4. What we don't do

  • We don't sell your data. Ever.
  • We don't train third-party models on your data. Anthropic (our LLM provider) does not train on API traffic by default, and we use the API in that mode.
  • We don't share your data with another customer. Multi- tenant isolation is enforced at the database layer (RLS) plus application layer.

5. Where data lives

Customer data is stored in Supabase (Postgres) hosted in United States regions. LLM inference runs through Anthropic's US-based API. If you need a different data-residency posture for procurement reasons, talk to us about Dedicated Cloud.

6. Subprocessors

We use the following subprocessors to deliver the service. All process data in United States regions unless noted.

  • Clerk — authentication and session management
  • Supabase — Postgres database and Realtime
  • Anthropic — Claude API (LLM inference)
  • Tavily — web search grounding
  • Apify — public-web data collection for AriseRep monitoring
  • Firecrawl — web page extraction for AriseRep monitoring
  • DataForSEO — search-results data for AriseRep monitoring
  • Resend — transactional and digest email delivery
  • Stripe — billing and payment processing
  • GoHighLevel — invoicing and CRM for Enterprise customers, and marketing forms on our public site
  • Sentry — application error monitoring
  • PostHog — product analytics, loaded only if you accept analytics cookies (see Cookies below)
  • Cloudflare — DNS and content delivery (global)
  • Vercel — application hosting
  • Railway — agent runtime hosting

We'll notify customers of material subprocessor changes before they take effect.

7. Your rights

You can access, export, correct, or delete your data, and you can object to or restrict certain processing. To make a request, email privacy@ariseai.ai. We verify the requester, then respond within 30 days (GDPR) or 45 days (CCPA/CPRA); we'll tell you if we need a permitted extension. Customer-data deletion happens within 30 days of a verified request, except records we're legally required to retain (for example, billing records under tax law), which are deleted when those holds expire. Exercising a right never affects the price or level of service you receive.

8. Security

  • Data in transit: TLS 1.2+ everywhere.
  • Data at rest: encrypted by our database provider.
  • BYOK API keys: encrypted at rest, never logged.
  • 2FA: required for every user.
  • Cross-tenant isolation: verified by an automated test suite that runs against our test environment.

SOC 2 readiness work begins once a paying enterprise prospect requires it. We'll publish progress when underway.

9. Data retention

We keep customer data for as long as your contract is active. On cancellation we freeze the workspace, give you 30 days to export, then delete what's left — except records we're legally required to retain.

10. Cookies

Essential cookies keep you signed in (set by Clerk) and are always on, because the app can't work without them.

Optional analytics cookies (PostHog) help us understand how the product is used so we can improve it. These load only after you accept them in the consent banner. If you decline, no analytics cookies are set and PostHog never loads. You can change your choice at any time by clearing cookies for this site. We don't run advertising trackers, and we don't sell or share analytics data.

11. Changes

We may update this policy. Material changes are announced in-app or by email at least 30 days in advance.

12. Contact

Privacy questions, data subject requests, or a copy of our Data Processing Addendum (DPA) — email privacy@ariseai.ai. Arise Technology Company is the data controller for account data and a processor for the customer data you bring into the platform.