Legal

Privacy Policy

Effective date: June 25, 2025  ·  Last updated: July 16, 2026

The short version

1. Who we are

Aria is developed and maintained by Charles Hartmann ("we", "us", "our"). You can reach us at charles.h.hartmann1@gmail.com.

2. What data Aria collects

Aria is designed from the ground up to be private. The table below summarises every data type and what happens to it.

Data typeProcessed on-device?Sent anywhere?Stored?
Your voice / audioYes — on device onlyNeverNo (discarded after transcription)
Conversation textYes — normally on deviceOnly when explicitly included in a support or quality reportLocal database; report provider if shared
LocationYes — on device onlyNeverNo (used in-context, not stored)
Contacts / calendarYes — on device onlyNeverNo (read in-context only)
SMS / notificationsYes — on device onlyNeverNo (read aloud then discarded)
Camera imagesYes — on device onlyNeverNo (used only when you ask)
Purchase / billingHandled by Google PlayGoogle Play onlyGoogle Play only
App analyticsGenerated by the appFirebase / GoogleFirebase project
Crash diagnosticsCaptured on deviceFirebase / GoogleFirebase project
Performance diagnosticsMeasured on deviceFirebase / GoogleFirebase project
Web search queryCreated from your requestSelected public search/content providersSubject to provider policy
Translation textYes — on device onlyNever after model downloadNo server copy by Aria
Issue reportYou choose its contentsGitHub when submittedGitHub issue/repository
AI quality reportCategory and technical contextCloudflare Worker when submittedAggregate fields; text only if explicitly included
Advertising dataGenerated by free-tier ad useGoogle AdMobAccording to Google policies and consent choices

Aria contains Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, Google AdMob, and Google's User Messaging Platform. These services may process app-instance or advertising identifiers, app interactions, consent choices, device/app metadata, stack traces, app state, timing data, ad interactions, approximate location derived from IP, and sanitized network-performance information. Aria does not intentionally attach voice audio or conversation content to Firebase events or ad requests. Premium users do not see ads.

3. Permissions and why they are needed

RECORD_AUDIO

Required for the wake word listener (OpenWakeWord) and voice transcription (Whisper STT). Audio is processed in real-time on device and immediately discarded. It is never written to disk or transmitted.

FOREGROUND_SERVICE / FOREGROUND_SERVICE_MICROPHONE

Android requires these permissions to keep Aria listening in the background while showing a persistent notification. The notification is mandatory and cannot be suppressed.

POST_NOTIFICATIONS

Required on Android 13+ to display the foreground service notification that keeps Aria running. Aria uses this permission only for its own status notification.

CALL_PHONE

An optional Premium feature can place a phone call only after a user request and runtime permission. The Google Play release does not request restricted SEND_SMS, READ_SMS, RECEIVE_SMS, or READ_CALL_LOG permissions.

READ_CONTACTS / WRITE_CONTACTS

Used to look up contact names when you say "call John" or "text Sarah". Contacts are read in-context and never exported or transmitted.

ACCESS_FINE_LOCATION / ACCESS_COARSE_LOCATION

Used when you ask location-based questions ("What's the weather?", "Navigate to the nearest coffee shop"). Location is never stored or sent to any server. Used only for the duration of the query.

CAMERA

A premium feature that lets you ask Aria to take a photo or describe what the camera sees. Camera is only activated in response to an explicit voice command.

READ_CALENDAR / WRITE_CALENDAR

Lets Aria create events and read your schedule when you ask. Calendar data is never transmitted.

SYSTEM_ALERT_WINDOW

Used to display an optional overlay showing Aria's response while you are using another app. You must explicitly grant this in Android Settings — it is not requested automatically at install.

WRITE_SETTINGS

Allows commands like "set brightness to 50%" or "turn on Wi-Fi". This requires a manual grant in Android Settings.

BIND_NOTIFICATION_LISTENER_SERVICE

Lets Aria read incoming notifications when you ask "What did I just get?" This is disabled by default and requires manual activation in Android Settings → Special App Access → Notification Access.

AccessibilityService

The Google Play release does not include an AccessibilityService. Developer/debug builds may contain an optional screen-automation service for local testing; it is disabled by default and is not part of the Play-distributed artifact.

Battery optimization settings

Aria may open Android's standard battery optimization settings so you can decide whether to change system behavior. The app does not request direct exemption through a restricted manifest permission.

RECEIVE_BOOT_COMPLETED

Allows Aria to restart its listener automatically after a device reboot, so you do not have to open the app manually. No data is accessed at boot.

INTERNET / ACCESS_WIFI_STATE

Used for model and translation-model downloads, web verification, Firebase analytics/crash/performance telemetry, GitHub issue reporting, and Play Billing verification.

4. Web search

Aria can perform multi-source web research when a request requires current or verifiable information. The verification mode in Settings controls whether it researches all factual questions, current facts only, or only explicit requests. Query text and requested public page URLs are sent to search/content providers. Aria validates public URLs, extracts relevant text, and displays sources and an expandable verification trace.

5. On-device translation

You can select an interface language during onboarding or in Settings. Google ML Kit downloads the required language model. After that download, menu text is translated locally without sending the text to a cloud translation service. Machine translations can be inaccurate, and you can switch back to English or another language at any time.

6. Firebase diagnostics

Firebase Analytics helps us understand aggregate app usage, Crashlytics reports crashes and application-not-responding events, and Performance Monitoring measures startup, screen, and network performance. These services are operated by Google and are governed by Google's Firebase terms and privacy documentation. We use them to improve reliability and do not intentionally log prompts, responses, contacts, messages, notification contents, or voice recordings.

7. Support, GitHub issues, and AI quality reports

Support & Feedback in Settings lets you create a GitHub issue and optionally include diagnostics, a screenshot, your name, or your email. Nothing is submitted until you press the report button. Submitted content is stored by GitHub and may be visible according to the repository's visibility. Do not include sensitive information.

The thumbs-down control on an assistant response sends a report to an Aria Cloudflare Worker. By default, it contains only the selected category, app version, language, and response length. The prompt and response are omitted unless you affirmatively select the content-sharing checkbox after reading its disclosure. Cloudflare D1 stores submitted reports so the developer can review aggregate trends. The app does not include an account identifier in this report.

8. Billing and subscriptions

Premium subscriptions are processed exclusively through Google Play Billing. Aria never receives, stores, or processes payment card information. The only data we receive from Google Play is an anonymised purchase token confirming that a valid subscription exists. This token is verified against Google Play's servers to enable premium features. No other personally identifiable information is shared with us by Google.

9. Children's privacy

Aria is not directed at children under 13. We do not knowingly collect any information from children. If you believe a child has provided information through Aria, please contact us at charles.h.hartmann1@gmail.com and we will address it promptly.

10. Data security

Because Aria stores all data locally on your device, the security of your data is determined by your device's own security (screen lock, encryption). Conversation history is stored in an Android Room database that is not accessible to other apps. We strongly recommend keeping your device encrypted and updated.

11. Data retention and deletion

Conversation history is stored locally on your device until you clear it. Uninstalling Aria removes local app data. Firebase, Google, GitHub, Cloudflare, and public web providers retain transmitted data according to their applicable policies and configured controls; deleting local app data does not automatically delete previously submitted reports or diagnostics.

12. Your rights

You can clear conversation history inside the app or uninstall it to remove local data. For a question or request concerning Firebase diagnostics or a GitHub report, contact us using the address below and identify the relevant report where possible.

13. Changes to this policy

If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and note the change in the app's release notes. Continued use of Aria after changes take effect constitutes acceptance of the revised policy.

14. Contact

Questions or concerns about this Privacy Policy? Contact us at:
charles.h.hartmann1@gmail.com

We aim to respond within 5 business days.