Privacy
What AssemblyWright AI stores, where it lives, how long it is kept, who else processes it, and how each data-protection right maps to something you can actually do. This notice describes the product as it runs today and claims only what is built. The security half of the picture is at Security & trust.
Who we are. AssemblyWright AI is a product of Evadaroo & Company, LLC, a Pennsylvania limited liability company. Privacy questions and rights requests: legal@evadaroo.com.
The full legal documents, drafts for attorney review: Terms · Privacy Policy · DPA · Acceptable Use · Refund Policy
Last reviewed: 2026-09-29.
What we store, where, and for how long
| Data | Where it lives | How long |
|---|---|---|
| Deliverables and Build records, with each one's version history | Our PostgreSQL database on Google Cloud, us-central1 | Until you delete them. Deleted items go to a trash and stay there until permanently deleted with a type-to-confirm step; nothing is purged automatically. |
| Knowledge Base, Lore and imported org context — the objects, fields, automation and history read from a CRM org you connect | Same | Until you delete them, or disconnect and remove them |
| Bench memory — what the product's agents have learned across Builds in your Workspace | Same | Until deleted |
| Connection credentials — for a CRM org, and for a Workspace's own Paddle account if it connects one | Same database, encrypted at rest as a whole; never returned by any screen or API | Until you disconnect and delete the connection |
| Content Desk posting tokens — only if you switch the Content Desk on and connect a social account | Same database, encrypted at rest; never returned by any screen or API | Until you disconnect the account |
| Paddle signals — only if a Workspace connects its own Paddle account: one record per event Paddle sends it, including the buyer's name and email and a few purchase facts, never the raw message. That Workspace's owner controls this data; we process it for them. | Our database | 180 days, then deleted |
| Accounts — email, name, sign-in details, role | Clerk, our identity provider, plus the membership record in our database | While the account belongs to a Workspace |
| iPhone app devices — only if you install the app: a push token per device, the platform, and when it last registered | Our database | Until the app is removed from the device, or the device is removed in the product |
| Admin audit trail — who changed a setting, connected an org or restored a snapshot; field names, never values | Our database | The newest 2,000 records |
| Usage and cost records | Our database | Kept — they are the billing history |
| Request logs — for each request to the app: method, path, status, timing, and the signed-in account and Workspace where there is one; never request bodies or passwords | The server's own log files, on the same Google Cloud machine | No fixed limit yet — kept until the log files are cleared |
| Crash reports — errors the app reports from your browser or phone | Our database | The newest 500 records |
| Rollback payloads — the prior record values captured before a bulk update | Our database, or a file in your own CRM org — your choice per Workspace | 30 days by default, configurable per Workspace |
| Backups | Daily database dumps to Google Cloud Storage, and daily disk snapshots | Disk snapshots 7 days; dumps expire on their storage schedule |
| Billing records | Paddle, our reseller; with us, only the subscription's package, status, renewal date and Paddle's reference numbers | As long as tax and accounting law requires |
The application database and its backups are stored in the United States (Google Cloud, us-central1). Accounts sit with Clerk and billing records with Paddle, as below.
Who else processes it
- Google Cloud (
us-central1) — hosts the application, the database and the backups. - Google Cloud Vertex AI (
us-central1) — the AI that drafts and reviews Deliverables. It is sent the prompt for a stage, which can include your Build request, org context and Knowledge Base material. Under Google Cloud's enterprise terms it does not train on customer inputs. - Clerk — sign-in and accounts, including invitation email.
- Resend, only where notification email is set up — the product's own notifications: a Build finished, a review gate is waiting, your input is needed. And, only where a Workspace connects its own Paddle account, switches on an email response and a person approves each send, that Workspace's service emails (a welcome, say) to its own customers — the recipient's address and name and the email the team wrote.
- Apple Push Notification service, only if you use the iPhone app with notifications on — the same notifications, on your phone. It is sent the notification's title and detail, the Build's address in the app and the device's push token — never Deliverable content, never CRM data.
- Uiia, the Help assistant in the app, while it is switched on — another product of Evadaroo & Company, LLC, running on Cloudflare's network. It receives the questions you type into Help, and your email address if you ask to be contacted; the product never sends it Deliverables, Build content or CRM data. It currently answers with AI models on providers' free tiers, whose terms may allow them to use what they are sent to improve their models — so keep customer data out of Help.
- Paddle, when you buy a paid plan — Paddle (Paddle.com Market Limited and its affiliates) is our reseller and Merchant of Record for paid plans. It processes billing contact, payment and tax details as an independent controller under its own privacy notice (paddle.com/legal/privacy). Payment details go to Paddle, never to us.
- Let's Encrypt — TLS certificates. It sees domain names only.
- Profusia AI, only if you connect it — another product of Evadaroo & Company, LLC, which receives the Deliverables you choose to publish into your own Profusia workspace.
Your CRM vendor (Salesforce, Microsoft, HubSpot), any social account you connect through the Content Desk, and a Paddle account a Workspace connects for its own sales are your own systems, reached with credentials you supply. We run no advertising and no third-party analytics, and we do not sell personal information or share it for advertising.
Your rights, as things you can do
- Access and portability — export Deliverables from the Documents area, including as Word files; an admin can export the audit trail. Anything a screen does not cover, ask for.
- Correction — Deliverables, Knowledge Base entries and profile details are editable in the product.
- Deletion — delete items in the product, then permanently delete them from the trash. There is no one-click "delete everything" yet: ask at legal@evadaroo.com and we do it by hand and confirm in writing.
- Anything else — a restriction, an objection, a question: email legal@evadaroo.com. We check the request comes from you, usually by confirming control of the account's email address.
If your details sit inside a customer's Workspace — a name in a CRM record, say — that customer controls them, so ask them. If you ask us, we pass the request on and tell you we have.
Cookies and tracking
- This website (
assemblywright.ai) sets no cookies, runs no analytics, and loads nothing from any third party — its fonts are served from our own domain. - The app (
app.assemblywright.ai) itself sets first-party cookies only, to sign you in and keep your session, and remembers your light or dark theme on your device. There is no advertising cookie, no third-party analytics and no cross-site tracker, which is why there is no cookie banner: there is nothing a banner would be consenting to. While the Help assistant is switched on, the app loads it from Uiia.
California and other US states
We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" link — there is nothing to opt out of.
Children
AssemblyWright is a business product for people aged 18 and over. It is not directed to children, and we do not knowingly collect information from anyone under 18.
Changes and contact
This notice changes when the product does, in the same change. Privacy questions and requests: legal@evadaroo.com. Vulnerability reports: security@assemblywright.ai.