Draft for attorney review — not yet in force.
AssemblyWright AI — Privacy Policy
Effective date: [DATE]
This policy explains what AssemblyWright AI stores, where it lives, how long it is kept, who else processes it, and how to exercise your rights.
Who we are. Evadaroo & Company, LLC, a Pennsylvania limited liability company trading as AssemblyWright AI, [REGISTERED OFFICE ADDRESS], United States. Privacy questions and rights requests: legal@evadaroo.com.
Our role. For the data in your Workspace — including anything read from or written to a CRM system you connect — you are the controller (or "business") and we are the processor ("service provider"). For your own account and billing relationship with us, we are the controller. Where a data protection law applies to you as a controller, our Data Processing Addendum governs and takes precedence on the points it covers.
1. What we store, where it lives, and for how long
| Data | Where it lives | How long |
|---|---|---|
| Deliverables and Build records — solution designs, user stories, test plans, process documentation, inputs, reviews, and the append-only version history of each | Our PostgreSQL database on a Google Cloud VM in us-central1 | Indefinitely, plus a trash. Deleted items go to trash and stay until permanently deleted with a type-to-confirm step. There is no automatic purge. |
| Knowledge Base and Lore entries | Same | Same |
| Imported org context — objects, fields, automation, security model, and org history read from your Connected Org | Same | Until you delete it or disconnect and remove it |
| Wright Bench memory — what an agent has learned across Builds in your Workspace | Same | Until deleted |
| Connection credentials — Salesforce private key and client id, Dynamics client secret, HubSpot private-app token, and similar | Same database, encrypted at rest as a whole snapshot; values are never returned by any interface | Until you disconnect and delete the connection |
| Accounts — email, name, sign-in metadata, role, organization membership | Our identity provider (Clerk), plus the membership record in our database | While the account is a member of a Workspace |
| Admin audit trail — who changed a setting, connected an org, restored a snapshot; actor, IP, action, and the field names touched, never the values | Our database | Rotated to the newest 2,000 records. Export it from the admin area if you need a longer archive. |
| Run logs, usage and token metering, cost records | Our database | Indefinitely — they are the billing history |
| Client-side error beacons | Our database | Newest 500 records |
| Rollback and snapshot payloads — the prior record values captured before a bulk update or a data snapshot | Either our database (default) or a file in your own Connected Org, your choice per Workspace; where held in your org, we keep only a receipt and a checksum | 30 days by default, configurable per Workspace. The payload is destroyed wherever it lives; the receipt remains as the governance record. |
| Database backups | Daily dump to Google Cloud Storage, plus daily whole-disk snapshots | Disk snapshots: 7 days. Dumps expire on their storage schedule. |
| Billing records | Our payment processor, plus invoice metadata with us | As long as tax and accounting law requires (generally 7 years) |
2. What we do not do
- We do not sell personal information, and we do not share it for cross-context behavioral advertising.
- We do not use your content to train AI models. Our production model provider does not train on customer inputs.
- We run no advertising network and no third-party analytics.
- We do not read your CRM beyond what you authorize. What we can see is bounded by the credentials and permissions you grant.
- We do not profile individuals or make automated decisions producing legal or similarly significant effects on them.
3. Subprocessors
| Subprocessor | Purpose | What it can see | Region |
|---|---|---|---|
| Google Cloud Platform (US) | Hosts the application, the database, and the backups | Everything stored in the Service | us-central1 |
| Google Cloud Vertex AI (US) | Production AI inference | Prompt and response content: Build inputs, org context, generated Deliverables | us-central1. Does not train on customer inputs. |
| Clerk (US) | Authentication and identity, including organization invitation email | Email addresses, sign-in metadata, session tokens | US |
| Stripe, Inc. (US) | Payment processing | Billing contact and payment details (card data goes to Stripe, never to us) | US |
| Let's Encrypt | TLS certificates | Domain names only | — |
| Profusia AI (Evadaroo & Company, LLC) — only if you connect it | Publishing your Deliverables into your own Profusia workspace | The Deliverables you publish | Cloudflare's network |
| Your CRM vendor (Salesforce / Microsoft / HubSpot) | The system the Service acts on | Data your own org holds | Your vendor relationship, not ours |
Google AI Studio's free tier is development-only by policy — its terms permit use of inputs for model improvement, so production never points at it and real customer data is never sent to it.
AssemblyWright does not send product email. Account and invitation email comes from our identity provider. If we add a sending provider, this policy will name it before it carries your data.
We will give 30 days' notice of a new or replacement subprocessor, as set out in the DPA.
4. AI processing
4.1 The Service is AI-powered throughout: Deliverables, reviews, Guide answers, and proposals are generated by third-party models.
4.2 What is sent. The prompt for a stage — which may include your Build request, the org context imported from your Connected Org, Knowledge Base material, and prior Deliverables — is sent to the model provider that answers. Responses come back and are stored as Deliverables and run records.
4.3 Production runs on Google Vertex AI in us-central1, under Google Cloud's enterprise terms, which provide that customer inputs are not used to train Google's models.
4.4 Outputs may be wrong. They can be inaccurate, incomplete, or confidently mistaken about your org. Review gates and human checkpoints exist so a person decides; you are responsible for reviewing a Deliverable before relying on it or deploying anything derived from it.
4.5 The models do not act on your CRM by themselves. Every write to a Connected Org is a separate, role-gated action taken on an instruction from one of your authorized users.
5. Cookies and tracking
We set first-party cookies only, and only to make the product work — signing you in and keeping your session, and remembering your light/dark theme choice. There is no advertising cookie, no third-party analytics beacon, and no cross-site tracker, which is why there is no cookie banner: there is nothing a banner would be consenting to. We record server-side request logs (method, path, status, latency) and client-side crash reports for reliability, both bounded as in Section 1.
6. Your rights
| Right | How it works here |
|---|---|
| Access & portability | Deliverables export from the Documents area; the admin audit trail exports as a file; ask us for anything a screen does not cover. |
| Deletion | Delete items in-app, then permanently delete from trash. There is no one-click "delete everything" flow today — on request we do it manually and confirm completion in writing. We say so rather than implying a self-service path that does not exist. |
| Correction | Deliverables, KB entries, and profile details are editable in the product. |
| Restriction / objection | Email legal@evadaroo.com. |
| Complain | You may lodge a complaint with your supervisory authority. We would rather hear from you first. |
How to ask. Email legal@evadaroo.com. We verify identity — usually by confirming control of the account email — and respond within 30 days (extendable once by 60 days where the request is complex, with notice). We do not charge, except for a manifestly unfounded or excessive request.
If you are an individual whose data appears inside a customer's Workspace — for example a name in a CRM record or a Deliverable — send your request to that customer, who controls the data. If you send it to us, we will forward it and tell you we have.
7. Legal bases (GDPR / UK GDPR)
Where the GDPR applies to our own processing: performance of a contract (providing the Service, accounts, billing, support); legitimate interests (securing the Service, preventing abuse, keeping the audit trail, reliability); consent (where we ask for it); and legal obligation (tax, accounting, lawful requests). For data processed on your instructions, your legal basis governs; ours is the contract with you.
8. US state privacy laws
We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" link, because there is nothing to opt out of. Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comparable laws have rights to know, access, correct, delete, and appeal, and we do not discriminate for exercising them. Use legal@evadaroo.com, including for an appeal, which we answer within 45 days with our reasons.
Where we process personal data on a customer's behalf, we act as a service provider / processor on the terms in the DPA, and do not retain, use, or disclose it for any purpose other than performing the Service.
9. International transfers
We are a US company and the Service runs in the United States (us-central1). All Customer Data is stored in the United States. For transfers of personal data out of the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses, incorporated into the DPA, with the UK International Data Transfer Addendum where the UK GDPR applies.
10. Security
Workspace isolation is enforced at the data layer in one place — reads outside a workspace scope return nothing, writes outside one are refused. Credential-shaped values are encrypted at rest; the connections vault encrypts the whole credential snapshot and returns field names only. TLS with HSTS on every hostname. Destructive, cost-bearing, and org-touching routes require an elevated role. Privileged actions are recorded in an admin audit trail that logs field names, never values. Per-IP rate limiting, a per-Build spend ceiling that pauses for approval, and a Workspace budget brake. Dependencies are pinned and scanned against the public advisory database. Daily database dumps and disk snapshots with a rehearsed restore runbook.
What we do not claim: no SOC 2 report, no ISO 27001, no HIPAA attestation, no third-party penetration test — none in progress. Isolation is logical, not physical. There is no dedicated security officer, and the encryption key for stored credentials lives in the deployment environment rather than a managed key service. We record that here rather than omitting it.
Vulnerability reports: security@assemblywright.ai. We do not run a paid bounty and we will not pursue researchers who report in good faith.
11. Breach notification
If we become aware of a breach of security leading to the accidental or unlawful destruction, loss, alteration, or unauthorized disclosure of personal data we process for you, we will notify you without undue delay and in any event within 72 hours, with what we know and updates as we learn more.
12. Children
The Service is for people aged 18 and over, is not directed to children, and we do not knowingly collect personal information from anyone under 18. Write to legal@evadaroo.com if you believe we have.
13. Changes
Changes are posted here with a new effective date. Material changes get 30 days' notice to Workspace owners by email and in the product.
14. Contact
legal@evadaroo.com — privacy questions, rights requests, appeals. security@assemblywright.ai — vulnerability reports.
Evadaroo & Company, LLC · [REGISTERED OFFICE ADDRESS] · Pennsylvania, USA