AssemblyWright
How it works The team Orchestration
Sign in Request access

Legal

Draft for attorney review — not yet in force.

AssemblyWright AI — Privacy Policy

Effective date: [DATE]

This policy explains what AssemblyWright AI stores, where it lives, how long it is kept, who else processes it, and how to exercise your rights.

Who we are. Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as AssemblyWright AI, [REGISTERED OFFICE ADDRESS], United States. Privacy questions and rights requests: legal@evadaroo.com.

Our role. For the data in your Workspace — including anything read from or written to a CRM system you connect — you are the controller (or "business") and we are the processor ("service provider"). For your own account and billing relationship with us, we are the controller. Where a data protection law applies to you as a controller, our Data Processing Addendum governs and takes precedence on the points it covers.


1. What we store, where it lives, and for how long

DataWhere it livesHow long
Deliverables and Build records — solution designs, user stories, test plans, process documentation, inputs, reviews, and the append-only version history of eachOur PostgreSQL database on a Google Cloud VM in us-central1Indefinitely, plus a trash. Deleted items go to trash and stay until permanently deleted with a type-to-confirm step. There is no automatic purge.
Knowledge Base and Lore entriesSameSame
Imported org context — objects, fields, automation, security model, and org history read from your Connected OrgSameUntil you delete it or disconnect and remove it
Wright Bench memory — what an agent has learned across Builds in your WorkspaceSameUntil deleted
Connection credentials — Salesforce private key and client id, Dynamics client secret, HubSpot private-app token, and similarSame database, encrypted at rest as a whole snapshot; values are never returned by any interfaceUntil you disconnect and delete the connection
Accounts — email, name, sign-in metadata, role, organization membershipOur identity provider (Clerk), plus the membership record in our databaseWhile the account is a member of a Workspace
Admin audit trail — who changed a setting, connected an org, restored a snapshot; actor, IP, action, and the field names touched, never the valuesOur databaseRotated to the newest 2,000 records. Export it from the admin area if you need a longer archive.
Run logs, usage and token metering, cost recordsOur databaseIndefinitely — they are the billing history
Client-side error beaconsOur databaseNewest 500 records
Rollback and snapshot payloads — the prior record values captured before a bulk update or a data snapshotEither our database (default) or a file in your own Connected Org, your choice per Workspace; where held in your org, we keep only a receipt and a checksum30 days by default, configurable per Workspace. The payload is destroyed wherever it lives; the receipt remains as the governance record.
Database backupsDaily dump to Google Cloud Storage, plus daily whole-disk snapshotsDisk snapshots: 7 days. Dumps expire on their storage schedule.
Billing recordsOur payment processor, plus invoice metadata with usAs long as tax and accounting law requires (generally 7 years)

2. What we do not do

  • We do not sell personal information, and we do not share it for cross-context behavioral advertising.
  • We do not use your content to train AI models. Our production model provider does not train on customer inputs.
  • We run no advertising network and no third-party analytics.
  • We do not read your CRM beyond what you authorize. What we can see is bounded by the credentials and permissions you grant.
  • We do not profile individuals or make automated decisions producing legal or similarly significant effects on them.

3. Subprocessors

SubprocessorPurposeWhat it can seeRegion
Google Cloud Platform (US)Hosts the application, the database, and the backupsEverything stored in the Serviceus-central1
Google Cloud Vertex AI (US)Production AI inferencePrompt and response content: Build inputs, org context, generated Deliverablesus-central1. Does not train on customer inputs.
Clerk (US)Authentication and identity, including organization invitation emailEmail addresses, sign-in metadata, session tokensUS
Stripe, Inc. (US)Payment processingBilling contact and payment details (card data goes to Stripe, never to us)US
Let's EncryptTLS certificatesDomain names only—
Profusia AI (Evadaroo & Company, LLC) — only if you connect itPublishing your Deliverables into your own Profusia workspaceThe Deliverables you publishCloudflare's network
Your CRM vendor (Salesforce / Microsoft / HubSpot)The system the Service acts onData your own org holdsYour vendor relationship, not ours

Google AI Studio's free tier is development-only by policy — its terms permit use of inputs for model improvement, so production never points at it and real customer data is never sent to it.

AssemblyWright does not send product email. Account and invitation email comes from our identity provider. If we add a sending provider, this policy will name it before it carries your data.

We will give 30 days' notice of a new or replacement subprocessor, as set out in the DPA.

4. AI processing

4.1 The Service is AI-powered throughout: Deliverables, reviews, Guide answers, and proposals are generated by third-party models.

4.2 What is sent. The prompt for a stage — which may include your Build request, the org context imported from your Connected Org, Knowledge Base material, and prior Deliverables — is sent to the model provider that answers. Responses come back and are stored as Deliverables and run records.

4.3 Production runs on Google Vertex AI in us-central1, under Google Cloud's enterprise terms, which provide that customer inputs are not used to train Google's models.

4.4 Outputs may be wrong. They can be inaccurate, incomplete, or confidently mistaken about your org. Review gates and human checkpoints exist so a person decides; you are responsible for reviewing a Deliverable before relying on it or deploying anything derived from it.

4.5 The models do not act on your CRM by themselves. Every write to a Connected Org is a separate, role-gated action taken on an instruction from one of your authorized users.

5. Cookies and tracking

We set first-party cookies only, and only to make the product work — signing you in and keeping your session, and remembering your light/dark theme choice. There is no advertising cookie, no third-party analytics beacon, and no cross-site tracker, which is why there is no cookie banner: there is nothing a banner would be consenting to. We record server-side request logs (method, path, status, latency) and client-side crash reports for reliability, both bounded as in Section 1.

6. Your rights

RightHow it works here
Access & portabilityDeliverables export from the Documents area; the admin audit trail exports as a file; ask us for anything a screen does not cover.
DeletionDelete items in-app, then permanently delete from trash. There is no one-click "delete everything" flow today — on request we do it manually and confirm completion in writing. We say so rather than implying a self-service path that does not exist.
CorrectionDeliverables, KB entries, and profile details are editable in the product.
Restriction / objectionEmail legal@evadaroo.com.
ComplainYou may lodge a complaint with your supervisory authority. We would rather hear from you first.

How to ask. Email legal@evadaroo.com. We verify identity — usually by confirming control of the account email — and respond within 30 days (extendable once by 60 days where the request is complex, with notice). We do not charge, except for a manifestly unfounded or excessive request.

If you are an individual whose data appears inside a customer's Workspace — for example a name in a CRM record or a Deliverable — send your request to that customer, who controls the data. If you send it to us, we will forward it and tell you we have.

7. Legal bases (GDPR / UK GDPR)

Where the GDPR applies to our own processing: performance of a contract (providing the Service, accounts, billing, support); legitimate interests (securing the Service, preventing abuse, keeping the audit trail, reliability); consent (where we ask for it); and legal obligation (tax, accounting, lawful requests). For data processed on your instructions, your legal basis governs; ours is the contract with you.

8. US state privacy laws

We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" link, because there is nothing to opt out of. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comparable laws have rights to know, access, correct, delete, and appeal, and we do not discriminate for exercising them. Use legal@evadaroo.com, including for an appeal, which we answer within 45 days with our reasons.

Where we process personal data on a customer's behalf, we act as a service provider / processor on the terms in the DPA, and do not retain, use, or disclose it for any purpose other than performing the Service.

9. International transfers

We are a US company and the Service runs in the United States (us-central1). All Customer Data is stored in the United States. For transfers of personal data out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, incorporated into the DPA, with the UK International Data Transfer Addendum where the UK GDPR applies.

10. Security

Workspace isolation is enforced at the data layer in one place — reads outside a workspace scope return nothing, writes outside one are refused. Credential-shaped values are encrypted at rest; the connections vault encrypts the whole credential snapshot and returns field names only. TLS with HSTS on every hostname. Destructive, cost-bearing, and org-touching routes require an elevated role. Privileged actions are recorded in an admin audit trail that logs field names, never values. Per-IP rate limiting, a per-Build spend ceiling that pauses for approval, and a Workspace budget brake. Dependencies are pinned and scanned against the public advisory database. Daily database dumps and disk snapshots with a rehearsed restore runbook.

What we do not claim: no SOC 2 report, no ISO 27001, no HIPAA attestation, no third-party penetration test — none in progress. Isolation is logical, not physical. There is no dedicated security officer, and the encryption key for stored credentials lives in the deployment environment rather than a managed key service. We record that here rather than omitting it.

Vulnerability reports: security@assemblywright.ai. We do not run a paid bounty and we will not pursue researchers who report in good faith.

11. Breach notification

If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data we process for you, we will notify you without undue delay and in any event within 72 hours, with what we know and updates as we learn more.

12. Children

The Service is for people aged 18 and over, is not directed to children, and we do not knowingly collect personal information from anyone under 18. Write to legal@evadaroo.com if you believe we have.

13. Changes

Changes are posted here with a new effective date. Material changes get 30 days' notice to Workspace owners by email and in the product.

14. Contact

legal@evadaroo.com — privacy questions, rights requests, appeals. security@assemblywright.ai — vulnerability reports.

Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA

← Back to AssemblyWright

AssemblyWright

A delivery department that works on day one.

How it works Workflows Orchestration Terms Privacy DPA Acceptable use Sign in hello@assemblywright.ai
© 2026 AssemblyWright