Privacy policy

Last updated: 6 September 2026

Draft prepared for legal review. The company details in brackets are completed before launch.

1. Controller

[COMPANY LEGAL NAME], [ADDRESS], Switzerland. Contact: privacy@araldo.ai. We process personal data under the Swiss Federal Act on Data Protection (FADP) and, where it applies, the GDPR.

2. What we collect

Account data (name, email, password hash, language); the product information and brief you provide; access tokens of the platform accounts you connect (stored encrypted); content drafts and their approval history; events sent by your tracked links, pixel and payment webhooks (visit, signup, sale, amount, a hashed email when provided); billing data handled by Stripe; technical logs (IP address, user agent, timestamps) kept for security.

3. Why and on what basis

To run the agent for you (contract); to attribute results and produce reports (contract); to send transactional emails such as the weekly report and drafts waiting (contract, with opt-out in Settings); to bill you (contract, legal obligation); to keep the service secure and prevent abuse (legitimate interest); to improve the service using aggregated, non-identifying statistics (legitimate interest).

4. Your customers' data

Your pixel and webhooks may send us data about your visitors and customers. You are the controller of that data and we process it as your processor under our data processing terms: only to attribute results to you, never to build profiles across tenants, never for our own marketing. Emails are stored hashed; you can export and delete everything from Settings.

5. AI processing

Drafts, briefs and reports are generated with Anthropic's Claude models. We send the model your product information, brief, rules and aggregated results, never your customers' identities. Anthropic processes this data as our processor and does not train on it.

6. Sharing and processors

Stripe (payments), Anthropic (language model), the platforms you connect (publishing through their APIs, under your own account), our hosting provider [HOSTING PROVIDER, COUNTRY] and our email provider [EMAIL PROVIDER]. No data is sold. Transfers outside Switzerland/EEA rely on adequacy decisions or standard contractual clauses.

7. Retention

Account and product data for the life of the account and 30 days after deletion; events and reports for the life of the account; billing records 10 years as required by law; security logs 90 days.

8. Your rights

Access, rectification, deletion, restriction, portability and objection, and the right to complain to the Swiss FDPIC or your local authority. Use Settings → Account to export or delete your data, or write to the address above. We answer within 30 days.

9. Cookies

We use only strictly necessary cookies: session, CSRF protection and your language choice. No advertising or analytics cookies are set on this site.

10. Security

TLS everywhere, encrypted tokens, hashed passwords, access limited to people who need it, nightly backups, audit log of every action the agent takes.

11. Changes

We may update this policy; material changes are announced by email and on this page with the date above.