Privacy Policy

Effective Date: July 20, 2026

Obsidian Insights LLC (“Obsidian Insights,” “we,” “us,” or “our”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and protect information when you use oistudio.ai, contact us, join a waitlist, request services, use ARIA Executive Assistant, or receive communications from us.

Information We Collect

We may collect information you provide directly, including your name, email address, phone number, company or business information, project details, appointment or scheduling details, client/contact records, notes, account settings, support requests, and messages you send to us. ARIA may also process calendar event details, route information, voice/audio input when you use voice features, and draft communication text that you ask ARIA to prepare. We may also collect basic website usage information such as pages visited, device/browser information, approximate location derived from IP address, and referral information.

How We Use Information

We use information to provide, operate, and improve our website and services; respond to inquiries; manage waitlists and onboarding; schedule appointments; send requested reminders, confirmations, customer-care messages, and service notifications; maintain security; comply with legal obligations; and understand how people use our website.

SMS and Phone Number Privacy

If you provide your mobile phone number and consent to receive SMS messages from ARIA Executive Assistant by Obsidian Insights, we may use your number to send appointment reminders, scheduling confirmations, customer-care messages, requested reminders, and service notifications. Message frequency varies based on your requests and relationship with us. You can reply STOP to opt out or HELP for help. Message and data rates may apply.

Obsidian Insights does not sell or share SMS opt-in data, consent records, or mobile phone numbers with third parties for their marketing or promotional purposes. SMS data is shared only with service providers needed to deliver ARIA messages, such as telecommunications providers, subject to their processor obligations.

For details on how ARIA Executive Assistant handles SMS consent on behalf of operators and clients, see our SMS Consent Flow.

ARIA App Data and Apple-Native Services

ARIA is designed as an approval-gated assistant. In the App Store V1 release, ARIA may use Apple-native, user-granted device services such as Calendar/EventKit and native compose handoff. If you have connected a third-party email or calendar account to Apple apps on your device, those items may appear through the Apple-native service after you grant device permission. ARIA does not use that device permission as a direct connection to the third-party provider’s separate APIs.

ARIA may prepare draft text and open a native compose surface for your review, but you decide whether to send it. ARIA does not read Apple Mail inboxes, scan system mailboxes, or send messages automatically. ARIA may read or write device calendar events only after you grant calendar permission and approve calendar changes.

Account Sync, Export, and Deletion

ARIA may provide account setup, secure sign-in, encrypted account storage, sync, data export, and account deletion controls when those features are enabled for your release tier and device. Sync and account services may store account identifiers, encrypted records, consent receipts, audit events, and operational metadata on Obsidian Insights infrastructure so ARIA can provide the requested functionality. We do not use these records for advertising or cross-app tracking.

You may request export or deletion of supported account data through in-app controls where available or by contacting us. Some records may be retained for legal, security, audit, fraud-prevention, backup, or compliance reasons.

Restricted Provider and OAuth Data

Direct restricted-provider email, mailbox scanning, provider draft-save, direct workspace calendar/task OAuth, and related CASA-dependent features are not enabled in the App Store V1 release. If those features are enabled in a future reviewed release or authorized beta, ARIA will request provider access through the provider’s consent flow and will use that data only for user-requested assistant features, such as schedule review, meeting preparation, inbox triage summaries, draft preparation after approval, calendar booking after approval, account status, export, and disconnect controls.

ARIA keeps provider actions approval-gated. ARIA does not use restricted provider permissions to send messages automatically by default. ARIA does not sell provider data, does not use provider data for advertising, and does not transfer provider data to third parties except as necessary to provide or secure the requested service, comply with law, or with your consent. ARIA's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements, whenever Google API access is enabled.

How We Share Information

We may share information with trusted service providers who help us operate our website, communications, scheduling, analytics, hosting, and business systems. We may also share information if required by law, to protect rights and safety, in connection with a business transfer, or with your consent. We do not sell personal information.

Data Retention

We retain information for as long as needed to provide services, maintain records, resolve disputes, enforce agreements, and comply with legal obligations. We may delete or de-identify information when it is no longer needed. If you disconnect a provider account or request deletion, we will delete or disable stored tokens where applicable and delete or de-identify associated provider-derived records subject to legal, security, audit, and backup-retention requirements.

Security

We use reasonable administrative, technical, and organizational safeguards to protect information. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

Your Choices

You may contact us to request access, correction, export, or deletion of personal information, subject to applicable law and operational requirements. You may also revoke provider access from the provider’s account permissions page, and ARIA will provide in-app connected-account controls where available. For SMS messages, reply STOP to opt out and HELP for help.

Children’s Privacy

Our website and services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.

Changes to This Policy

We may update this Privacy Policy from time to time. The updated policy will be posted on this page with a revised effective date.

Contact Us

For privacy questions or requests, contact Obsidian Insights through https://oistudio.ai/contact.