ARIIA / ALMFC LLC

Privacy

How ARIIA and ALMFC LLC access, use, protect, retain, and delete information for the website and ARIIA Email Operations.

Effective July 18, 2026 · Version 1.0
Plain-language promise. ARIIA asks for the least access needed for the feature a client has approved. Email access begins read-only, important changes remain permission-gated, and a client can pause or revoke access.

Who this notice covers

ARIIA is an ALMFC LLC product. This notice covers ariiaops.com, connect.ariiaops.com, and the ARIIA Email Operations pilot and service. It supplements any signed service, pilot, consent, or data-processing agreement. Contact: support@ariiaops.com.

Information we collect

Website and support information

We may receive information a person chooses to submit, such as a name, business email, service request, consent choices, support messages, and scheduling preferences. Hosting and security providers may process ordinary network and security metadata.

Google account and Gmail information

ARIIA Email Operations currently proposes only openid, email, and https://www.googleapis.com/auth/gmail.readonly. These let Google confirm the selected account and permit read-only access to Gmail messages and settings. The Gmail scope can technically expose headers, labels, bodies, settings, and attachment data. ARIIA applies the narrower permissions chosen by the client; attachment contents remain excluded unless separately approved.

Read-only access does not permit ARIIA to send mail, create drafts, add or remove labels, archive, delete, forward, unsubscribe, create filters, or change Gmail settings. Contacts, Calendar, Drive, and account-security settings are not included in this scope.

How information is used

  • Provide the user-facing email assessment and other services the client requested.
  • Identify priority messages, risks, workflow opportunities, and proposed organization rules within the approved scope.
  • Maintain consent, security, test, incident, and service-quality records.
  • Respond to support, access, correction, export, deletion, and revocation requests.

Google user data is not sold, used for advertising, or used to build a general advertising profile. It is not used for general-purpose model training. ARIIA's use and transfer of information received from Google APIs will follow the Google API Services User Data Policy, including its Limited Use requirements.

Human access and service providers

Access is limited to authorized ALMFC LLC personnel and service components needed to provide the approved feature. A person may review specific email data only with the client's affirmative agreement, when necessary to provide the visible service, investigate a security or service incident, comply with law, or produce aggregated internal measurements that do not reveal unnecessary message content.

Google processes authorization and Gmail API traffic. Cloudflare hosts the connection boundary and encrypted service records. Other processors will be disclosed before they receive Google user data. We do not transfer Google user data to data brokers or advertising platforms.

Storage and security

OAuth credentials are stored in an encrypted credential store and are not placed in Google Drive, email, documents, source code, or ordinary application logs. Connections use HTTPS. Invitations are short-lived and single-use, granted scopes are checked exactly, and token access is separated from client-facing records. No internet service can promise absolute security.

ARIIA prefers counts, categories, message identifiers, and short findings over retaining raw message bodies. Raw bodies and attachment contents are not retained by default. Sanitized consent, audit, test, incident, and approved summary records may be retained in the restricted pilot or service workspace.

Retention and deletion

Retention follows the client's approved schedule and applicable contractual or legal requirements. The Ben Heske pilot currently uses a 90-day post-pilot schedule, or less where operationally and legally possible. OAuth access ends when the client pauses, revokes, or leaves the service. Temporary content should be removed after its test or verification window. Minimal audit, transaction, security, or legal records may be retained longer when required, without unnecessary email content.

Your choices and controls

  • Pause new ARIIA email work by emailing support@ariiaops.com.
  • Remove ARIIA from the third-party connections page in your Google Account to stop future Gmail API access.
  • Request access, correction, export, restriction, or deletion of retained ARIIA service records.
  • Decline a permission or withdraw consent without sending a password or authentication code.

We will explain what was deleted, retained, returned, unavailable, or pending. Provider backup and deletion delays will be disclosed where they apply.

Changes and contact

Material changes will be dated and presented before new or expanded Google access is requested. Questions and privacy requests may be sent to support@ariiaops.com. Do not send passwords, one-time codes, recovery phrases, private keys, payment numbers, government identifiers, health information, or another person's confidential information.