법적 고지
Privacy Policy
최종 업데이트 · 5 September 2026
Ara is an AI employee that works in your Slack and your dashboard. To do its job it reads the tasks you give it, the tools you connect and the work it produces for you. This policy says what Ara ("we") collects when you use Ara ("the Service"), why, who else processes it, how long it is kept, and what you can do about it. It is written to be read, not skimmed: every section is short.
1.Who is responsible
Ara operates the Service at https://arator.rinda.ai and is the controller of the personal data described here, except for the data your workspace puts into the Service, where the company that owns the workspace decides what Ara is asked to do and we process it on their behalf.
2.What we collect
Account data. Your email address, your name (if you give one or sign in with Google), a password hash if you set a password (we never store the password itself), your language preference, and the workspaces you belong to.
Work you give the agent. Tasks and messages you send in the dashboard, in Slack or through the API; files you attach; the answers, documents, spreadsheets, images and other artifacts it produces; and the memory it writes about how your company works — skills and facts that you can read, edit and delete.
Connected services. When you add Ara to Slack it can read the channels it is invited to and the direct messages sent to it, and the names and email addresses of the people it talks to, so that it knows who asked. When you connect an app (for example Gmail, Google Calendar, GitHub or Notion) it reads or changes only what a task needs, and only through the tools you left switched on for that app — a workspace admin can additionally require a person's approval for every change in an app, or block the app entirely.
Technical data. Server logs, the record of every run (which tools it called, with what, and whether they worked), your IP address for abuse protection and rate limiting, and — only if you accept the analytics banner — how the site and dashboard are used.
Payments. Card details are entered on our payment provider's page and never reach us; we keep the transaction reference and the credits it bought.
3.Why we use it
- To do the work you ask for and deliver it back to you, in Slack, in the dashboard, or to the caller of the API.
- To remember how your company works between tasks, so the next one starts informed.
- To keep the Service safe: authentication, session management, rate limits, abuse detection and an audit trail of what the agent did.
- To bill credits for completed work and to send the receipts and notices that go with an account, such as sign-in links and password resets.
- To understand which parts of the product are used, in aggregate, so we can improve them — only with your consent to analytics.
We do not sell personal data, and we do not send marketing email you have not asked for.
4.AI models and your data
To produce an answer, the relevant parts of a task — your message, the context the agent retrieved, and the output of the tools it ran — are sent to a large language model provider for processing. We do not train AI models on your data, and we route requests to providers under terms that do not allow them to use API traffic to train theirs. The agent runs its code in an isolated sandbox created for your workspace; another customer's workspace cannot reach it.
5.Who else processes data
We use a small number of providers to run the Service. Each receives only what its job needs:
- Language model providers, reached through OpenRouter, to generate the agent's reasoning and replies.
- Sandbox compute (E2B, or AWS Bedrock AgentCore) to run the agent's code and hold your workspace's files.
- Slack, when you install Ara there.
- Composio, to hold the authorizations for the apps you connect and to call them on your behalf.
- Creem, for payments and invoices.
- Resend, to deliver transactional email such as sign-in links.
- PostHog, for product analytics and error reporting — analytics only with your consent.
- Our cloud hosting provider, for the servers and the database.
We may add or replace a provider; the current list lives on this page.
6.It only uses the tools you switch on
With nothing connected the agent has no access to your apps at all. Each person connects their own accounts and decides, tool by tool, what it may do with them — a tool switched off cannot be used, by anyone, for any reason. On top of that a workspace admin can put an app under review, so every change in it is shown to a person and runs only when they approve it, or block an app outright. Review is a setting rather than a default, because a queue of routine approvals stops being read. Every run, approval and refusal is kept in the workspace's log either way, so an administrator can see who asked for what, when, and what happened.
7.How long we keep it
Your account, workspaces, memory, run history and artifacts are kept while the account exists. Slack conversations are not copied into the Service: the agent reads them live when it needs them. Server logs are kept for a limited period for security and troubleshooting and then deleted. Backups roll off on a fixed schedule.
Deleting your account from Settings removes your sessions, API keys, the workspaces you own and their run history. Data that must be kept by law — such as invoices — is kept for as long as that law requires.
8.Security
Data travels over TLS. Passwords are stored as argon2id hashes. Tokens for Slack and connected apps are encrypted at rest (AES-256-GCM). Each workspace's sandbox is isolated from every other. Sign-in links are one-time and expire. Sessions are revoked when a password is reset. No system is perfectly secure; if we learn of a breach affecting your data we will tell you without undue delay.
10.Where data is processed
The Service runs on cloud infrastructure in the United States, and the providers above process data where they operate. If you use the Service from the European Economic Area, the United Kingdom or Switzerland, your data may therefore leave that area; where the law requires it we rely on standard contractual clauses or an equivalent safeguard with the provider concerned.
11.Your rights
You can see and change your name in Settings, edit or delete what the agent remembers in Memory and Skills, and delete your account and its data in Settings at any time. You can also ask us for a copy of your personal data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent (analytics) you can withdraw it at any time. If you are in the EEA or the UK you also have the right to complain to your data protection authority.
To exercise a right, write to us using the contact details at the end of this page. We answer within a month.
12.Children
The Service is for businesses and the people who work in them. It is not directed at anyone under 16, and we do not knowingly collect their data. If you believe a child has given us data, tell us and we will delete it.
13.Changes to this policy
We will post any change here and update the date at the top. If a change materially reduces your rights or changes how we use your data, we will tell you in the dashboard or by email before it takes effect.
함께 보기 이용약관.