AssemblyWright AI
How it works The team Orchestration
Sign in Request access

Privacy

Privacy

What AssemblyWright AI stores, where it lives, how long it is kept, who else processes it, and how each data-protection right maps to something you can actually do. This notice describes the product as it runs today and claims only what is built. The security half of the picture is at Security & trust.

Who we are. AssemblyWright AI is a product of Evadaroo & Company, LLC, a Pennsylvania limited liability company. Privacy questions and rights requests: legal@evadaroo.com.

The full legal documents, drafts for attorney review: Terms · Privacy Policy · DPA · Acceptable Use · Refund Policy

Last reviewed: 2026-09-29.

What we store, where, and for how long

DataWhere it livesHow long
Deliverables and Build records, with each one's version historyOur PostgreSQL database on Google Cloud, us-central1Until you delete them. Deleted items go to a trash and stay there until permanently deleted with a type-to-confirm step; nothing is purged automatically.
Knowledge Base, Lore and imported org context — the objects, fields, automation and history read from a CRM org you connectSameUntil you delete them, or disconnect and remove them
Bench memory — what the product's agents have learned across Builds in your WorkspaceSameUntil deleted
Connection credentials — for a CRM org, and for a Workspace's own Paddle account if it connects oneSame database, encrypted at rest as a whole; never returned by any screen or APIUntil you disconnect and delete the connection
Content Desk posting tokens — only if you switch the Content Desk on and connect a social accountSame database, encrypted at rest; never returned by any screen or APIUntil you disconnect the account
Paddle signals — only if a Workspace connects its own Paddle account: one record per event Paddle sends it, including the buyer's name and email and a few purchase facts, never the raw message. That Workspace's owner controls this data; we process it for them.Our database180 days, then deleted
Accounts — email, name, sign-in details, roleClerk, our identity provider, plus the membership record in our databaseWhile the account belongs to a Workspace
iPhone app devices — only if you install the app: a push token per device, the platform, and when it last registeredOur databaseUntil the app is removed from the device, or the device is removed in the product
Admin audit trail — who changed a setting, connected an org or restored a snapshot; field names, never valuesOur databaseThe newest 2,000 records
Usage and cost recordsOur databaseKept — they are the billing history
Request logs — for each request to the app: method, path, status, timing, and the signed-in account and Workspace where there is one; never request bodies or passwordsThe server's own log files, on the same Google Cloud machineNo fixed limit yet — kept until the log files are cleared
Crash reports — errors the app reports from your browser or phoneOur databaseThe newest 500 records
Rollback payloads — the prior record values captured before a bulk updateOur database, or a file in your own CRM org — your choice per Workspace30 days by default, configurable per Workspace
BackupsDaily database dumps to Google Cloud Storage, and daily disk snapshotsDisk snapshots 7 days; dumps expire on their storage schedule
Billing recordsPaddle, our reseller; with us, only the subscription's package, status, renewal date and Paddle's reference numbersAs long as tax and accounting law requires

The application database and its backups are stored in the United States (Google Cloud, us-central1). Accounts sit with Clerk and billing records with Paddle, as below.

Who else processes it

  • Google Cloud (us-central1) — hosts the application, the database and the backups.
  • Google Cloud Vertex AI (us-central1) — the AI that drafts and reviews Deliverables. It is sent the prompt for a stage, which can include your Build request, org context and Knowledge Base material. Under Google Cloud's enterprise terms it does not train on customer inputs.
  • Clerk — sign-in and accounts, including invitation email.
  • Resend, only where notification email is set up — the product's own notifications: a Build finished, a review gate is waiting, your input is needed. And, only where a Workspace connects its own Paddle account, switches on an email response and a person approves each send, that Workspace's service emails (a welcome, say) to its own customers — the recipient's address and name and the email the team wrote.
  • Apple Push Notification service, only if you use the iPhone app with notifications on — the same notifications, on your phone. It is sent the notification's title and detail, the Build's address in the app and the device's push token — never Deliverable content, never CRM data.
  • Uiia, the Help assistant in the app, while it is switched on — another product of Evadaroo & Company, LLC, running on Cloudflare's network. It receives the questions you type into Help, and your email address if you ask to be contacted; the product never sends it Deliverables, Build content or CRM data. It currently answers with AI models on providers' free tiers, whose terms may allow them to use what they are sent to improve their models — so keep customer data out of Help.
  • Paddle, when you buy a paid plan — Paddle (Paddle.com Market Limited and its affiliates) is our reseller and Merchant of Record for paid plans. It processes billing contact, payment and tax details as an independent controller under its own privacy notice (paddle.com/legal/privacy). Payment details go to Paddle, never to us.
  • Let's Encrypt — TLS certificates. It sees domain names only.
  • Profusia AI, only if you connect it — another product of Evadaroo & Company, LLC, which receives the Deliverables you choose to publish into your own Profusia workspace.

Your CRM vendor (Salesforce, Microsoft, HubSpot), any social account you connect through the Content Desk, and a Paddle account a Workspace connects for its own sales are your own systems, reached with credentials you supply. We run no advertising and no third-party analytics, and we do not sell personal information or share it for advertising.

Your rights, as things you can do

  • Access and portability — export Deliverables from the Documents area, including as Word files; an admin can export the audit trail. Anything a screen does not cover, ask for.
  • Correction — Deliverables, Knowledge Base entries and profile details are editable in the product.
  • Deletion — delete items in the product, then permanently delete them from the trash. There is no one-click "delete everything" yet: ask at legal@evadaroo.com and we do it by hand and confirm in writing.
  • Anything else — a restriction, an objection, a question: email legal@evadaroo.com. We check the request comes from you, usually by confirming control of the account's email address.

If your details sit inside a customer's Workspace — a name in a CRM record, say — that customer controls them, so ask them. If you ask us, we pass the request on and tell you we have.

Cookies and tracking

  • This website (assemblywright.ai) sets no cookies, runs no analytics, and loads nothing from any third party — its fonts are served from our own domain.
  • The app (app.assemblywright.ai) itself sets first-party cookies only, to sign you in and keep your session, and remembers your light or dark theme on your device. There is no advertising cookie, no third-party analytics and no cross-site tracker, which is why there is no cookie banner: there is nothing a banner would be consenting to. While the Help assistant is switched on, the app loads it from Uiia.

California and other US states

We do not sell personal information and do not share it for cross-context behavioral advertising, so there is no "Do Not Sell or Share" link — there is nothing to opt out of.

Children

AssemblyWright is a business product for people aged 18 and over. It is not directed to children, and we do not knowingly collect information from anyone under 18.

Changes and contact

This notice changes when the product does, in the same change. Privacy questions and requests: legal@evadaroo.com. Vulnerability reports: security@assemblywright.ai.

← Back to AssemblyWright

AssemblyWright AI

The intelligent engine for builders.

How it works Workflows Orchestration Security & trust Terms Privacy Refunds DPA Acceptable use Sign in hello@assemblywright.ai
© 2026 Evadaroo & Company, LLC · AssemblyWright AI From the makers of Profusia AI