AriaBack to home

Aria · Flying Pixel

Privacy policy

Version dated 14 July 2026 · Local processing and online services are explained separately.

With local models, dictation content, meeting recordings and processing results can stay on your Mac. Data leaves the device only for online features you choose and for essential account, licensing and payment operations.

1. Data controller

Flying Pixel Sebastian Urbaniak

ul. Serbska 15/119, 61-696 Poznań, Polska

VAT ID: PL7811875368

REGON: 362220474

kontakt@appfly.pl

+48 570 800 060

For privacy matters contact kontakt@appfly.pl.

2. Data stored locally

Aria stores dictation history, meeting recordings and transcripts, speaker assignments, dictionary items, actions, settings and downloaded local models on your Mac. When both transcription and processing are local, audio and text are not sent to our cloud.

Uninstalling the app may not remove every user file or Keychain item. Histories, recordings and models can be removed in Aria or by following support instructions.

3. Account and sign-in

When you sign in we process the account identifier, email address, selected identity provider, session information and basic account security data. Sign-in is provided by Supabase Auth and, depending on your choice, Apple or Google.

The legal basis is contract performance or steps requested before a contract, and our legitimate interest in protecting accounts and preventing abuse.

4. Anonymous installation and Free limits

Without an account, Aria creates a random pseudonymous installation and device identifier. It sends this with information required to enforce Free limits, provide the one trial meeting and count installations. Dictation content and recordings are not sent for this purpose.

After sign-in, the installation may be associated with your account to keep limits and conversion data consistent. The basis is providing Free and our legitimate interest in licensing security and aggregate installation analysis.

5. License and devices

We process device identifiers and names, license type and status, validity and verification dates, recent activity and occupied seats. This supports activation, periodic verification, device disconnection, refunds and prevention of license circumvention.

6. Payments

Stripe processes checkout and the Customer Portal. We receive customer and transaction identifiers, plan, amount, currency, payment status, refund information and limited billing data. We do not receive the full card number. Stripe also acts as an independent controller where required to process and secure payments.

The bases are contract performance, accounting and tax obligations, and legitimate fraud prevention interests.

7. Aria Cloud and your API keys

If you choose Aria Cloud, the relevant audio file or text, language settings and request diagnostics are sent through our infrastructure to the model provider needed for that feature. The initial cloud transcription provider is Groq. We meter usage time to enforce the Pro allowance.

With your own API key, Aria may send data directly to your selected provider. That processing is also governed by the provider's terms and privacy policy. API keys are stored locally in macOS Keychain and are not sent to us for storage.

8. Telemetry and diagnostics

With consent, Aria may send product events to PostHog EU, such as feature use, plan type, general settings and error information. Telemetry should not contain dictation content, transcripts or recordings. Consent can be changed in Privacy settings.

Optional telemetry relies on consent. Essential security, licensing and online service logs rely on contract performance or legitimate interest.

9. Founding Beta feedback

A Founding Beta participant may send a title, description, email and up to three image or video attachments. The report is passed by a protected function to a dedicated Discord channel for support and product development. Do not attach passwords, API keys or third-party data you may not share.

10. Providers and international transfers

Depending on the feature, recipients may include Supabase (database, Auth, Storage and functions), Stripe (payments), Vercel (website), PostHog EU (consented telemetry), Groq (Aria Cloud), Discord (Founding Beta feedback), Apple and Google (sign-in), and a BYOK provider selected by you.

Some providers may process data outside the European Economic Area. Appropriate safeguards are used where required, including adequacy decisions or standard contractual clauses. Contact us for more detail.

11. Retention

  • account and active license data — for the service period plus accounting and claims periods;
  • transaction data — for the period required by accounting and tax law;
  • pseudonymous installations and license logs — while needed for limits, security and abuse analysis, then deleted or aggregated;
  • telemetry — under the configured PostHog retention, no longer than needed for product analysis;
  • feedback and attachments — until the report and beta analysis are complete, unless a valid earlier deletion request applies;
  • local content — until removed by the user.

12. Your rights

Depending on the basis and circumstances, you may request access, correction, deletion, restriction and portability, object to processing, or withdraw consent without affecting earlier lawful processing. You may complain to the Polish Data Protection Authority or your competent supervisory authority.

Send requests to kontakt@appfly.pl. We may verify identity to avoid disclosing data to the wrong person.

13. Security and policy changes

We use access controls, encrypted transport, restricted service keys, signed webhooks and license revocation. No system can provide an absolute security guarantee.

This policy may change with the product or law. Material changes will be communicated in the app, on this site or by email where required.