Aria is developed and maintained by Charles Hartmann ("we", "us", "our"). You can reach us at charles.h.hartmann1@gmail.com.
Aria is designed from the ground up to be private. The table below summarises every data type and what happens to it.
| Data type | Processed on-device? | Sent anywhere? | Stored? |
|---|---|---|---|
| Your voice / audio | Yes — on device only | Never | No (discarded after transcription) |
| Conversation text | Yes — normally on device | Only when explicitly included in a support or quality report | Local database; report provider if shared |
| Location | Yes — on device only | Never | No (used in-context, not stored) |
| Contacts / calendar | Yes — on device only | Never | No (read in-context only) |
| SMS / notifications | Yes — on device only | Never | No (read aloud then discarded) |
| Camera images | Yes — on device only | Never | No (used only when you ask) |
| Purchase / billing | Handled by Google Play | Google Play only | Google Play only |
| App analytics | Generated by the app | Firebase / Google | Firebase project |
| Crash diagnostics | Captured on device | Firebase / Google | Firebase project |
| Performance diagnostics | Measured on device | Firebase / Google | Firebase project |
| Web search query | Created from your request | Selected public search/content providers | Subject to provider policy |
| Translation text | Yes — on device only | Never after model download | No server copy by Aria |
| Issue report | You choose its contents | GitHub when submitted | GitHub issue/repository |
| AI quality report | Category and technical context | Cloudflare Worker when submitted | Aggregate fields; text only if explicitly included |
| Advertising data | Generated by free-tier ad use | Google AdMob | According to Google policies and consent choices |
Aria contains Firebase Analytics, Firebase Crashlytics, Firebase Performance Monitoring, Google AdMob, and Google's User Messaging Platform. These services may process app-instance or advertising identifiers, app interactions, consent choices, device/app metadata, stack traces, app state, timing data, ad interactions, approximate location derived from IP, and sanitized network-performance information. Aria does not intentionally attach voice audio or conversation content to Firebase events or ad requests. Premium users do not see ads.
Required for the wake word listener (OpenWakeWord) and voice transcription (Whisper STT). Audio is processed in real-time on device and immediately discarded. It is never written to disk or transmitted.
Android requires these permissions to keep Aria listening in the background while showing a persistent notification. The notification is mandatory and cannot be suppressed.
Required on Android 13+ to display the foreground service notification that keeps Aria running. Aria uses this permission only for its own status notification.
An optional Premium feature can place a phone call only after a user request and runtime permission. The Google Play release does not request restricted SEND_SMS, READ_SMS, RECEIVE_SMS, or READ_CALL_LOG permissions.
Used to look up contact names when you say "call John" or "text Sarah". Contacts are read in-context and never exported or transmitted.
Used when you ask location-based questions ("What's the weather?", "Navigate to the nearest coffee shop"). Location is never stored or sent to any server. Used only for the duration of the query.
A premium feature that lets you ask Aria to take a photo or describe what the camera sees. Camera is only activated in response to an explicit voice command.
Lets Aria create events and read your schedule when you ask. Calendar data is never transmitted.
Used to display an optional overlay showing Aria's response while you are using another app. You must explicitly grant this in Android Settings — it is not requested automatically at install.
Allows commands like "set brightness to 50%" or "turn on Wi-Fi". This requires a manual grant in Android Settings.
Lets Aria read incoming notifications when you ask "What did I just get?" This is disabled by default and requires manual activation in Android Settings → Special App Access → Notification Access.
The Google Play release does not include an AccessibilityService. Developer/debug builds may contain an optional screen-automation service for local testing; it is disabled by default and is not part of the Play-distributed artifact.
Aria may open Android's standard battery optimization settings so you can decide whether to change system behavior. The app does not request direct exemption through a restricted manifest permission.
Allows Aria to restart its listener automatically after a device reboot, so you do not have to open the app manually. No data is accessed at boot.
Used for model and translation-model downloads, web verification, Firebase analytics/crash/performance telemetry, GitHub issue reporting, and Play Billing verification.
Aria can perform multi-source web research when a request requires current or verifiable information. The verification mode in Settings controls whether it researches all factual questions, current facts only, or only explicit requests. Query text and requested public page URLs are sent to search/content providers. Aria validates public URLs, extracts relevant text, and displays sources and an expandable verification trace.
You can select an interface language during onboarding or in Settings. Google ML Kit downloads the required language model. After that download, menu text is translated locally without sending the text to a cloud translation service. Machine translations can be inaccurate, and you can switch back to English or another language at any time.
Firebase Analytics helps us understand aggregate app usage, Crashlytics reports crashes and application-not-responding events, and Performance Monitoring measures startup, screen, and network performance. These services are operated by Google and are governed by Google's Firebase terms and privacy documentation. We use them to improve reliability and do not intentionally log prompts, responses, contacts, messages, notification contents, or voice recordings.
Support & Feedback in Settings lets you create a GitHub issue and optionally include diagnostics, a screenshot, your name, or your email. Nothing is submitted until you press the report button. Submitted content is stored by GitHub and may be visible according to the repository's visibility. Do not include sensitive information.
The thumbs-down control on an assistant response sends a report to an Aria Cloudflare Worker. By default, it contains only the selected category, app version, language, and response length. The prompt and response are omitted unless you affirmatively select the content-sharing checkbox after reading its disclosure. Cloudflare D1 stores submitted reports so the developer can review aggregate trends. The app does not include an account identifier in this report.
Premium subscriptions are processed exclusively through Google Play Billing. Aria never receives, stores, or processes payment card information. The only data we receive from Google Play is an anonymised purchase token confirming that a valid subscription exists. This token is verified against Google Play's servers to enable premium features. No other personally identifiable information is shared with us by Google.
Aria is not directed at children under 13. We do not knowingly collect any information from children. If you believe a child has provided information through Aria, please contact us at charles.h.hartmann1@gmail.com and we will address it promptly.
Because Aria stores all data locally on your device, the security of your data is determined by your device's own security (screen lock, encryption). Conversation history is stored in an Android Room database that is not accessible to other apps. We strongly recommend keeping your device encrypted and updated.
Conversation history is stored locally on your device until you clear it. Uninstalling Aria removes local app data. Firebase, Google, GitHub, Cloudflare, and public web providers retain transmitted data according to their applicable policies and configured controls; deleting local app data does not automatically delete previously submitted reports or diagnostics.
You can clear conversation history inside the app or uninstall it to remove local data. For a question or request concerning Firebase diagnostics or a GitHub report, contact us using the address below and identify the relevant report where possible.
If we make material changes to this Privacy Policy, we will update the "Last updated" date at the top of this page and note the change in the app's release notes. Continued use of Aria after changes take effect constitutes acceptance of the revised policy.
Questions or concerns about this Privacy Policy? Contact us at:
charles.h.hartmann1@gmail.com
We aim to respond within 5 business days.