1. Introduction
aryyo ("aryyo", "we", "us", or "our") provides an AI agent platform that helps businesses ("Organizations") deploy conversational AI agents across channels such as WhatsApp, Telegram, SMS, and web chat. This Privacy Policy explains how we collect, use, share, and protect information when you use our website, dashboard, and chatbot services (collectively, the "Services").
By using the Services, you agree to the collection and use of information as described in this policy. If you are an end user messaging an AI agent built on aryyo, please also refer to the privacy policy of the specific Organization you are messaging — they are the data controller for those conversations, and aryyo acts as their data processor.
2. Information We Collect
Account and Organization data. When an Organization signs up, we collect names, email addresses, phone numbers, billing details, and information about the Organization's business, API endpoints, and configuration.
Conversation data. When an end user messages a chatbot built on aryyo, we process the content of those messages, attached media, platform identifiers (such as WhatsApp or Telegram user IDs), timestamps, and any information the end user voluntarily shares during the conversation (for example, account numbers or booking references) in order to fulfil their request.
Usage and device data. We automatically collect log data such as IP address, browser type, pages visited, and timestamps when you use our website or dashboard.
Payment data. Payment card details are collected and processed directly by Stripe, our payment processor. For mobile money payments (such as M-Pesa, Flutterwave, or Paystack), we receive transaction references and status updates from the relevant payment provider but do not store full payment credentials.
3. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Services, including running the AI agent pipeline that plans, executes, and responds to conversations
- Authenticate users and Organizations, and manage subscriptions and billing
- Connect to an Organization's own systems (via API tools) on their behalf, subject to the SSRF and authentication safeguards described below
- Monitor, debug, and improve the reliability and quality of our AI pipeline
- Send transactional emails such as verification, billing, and account notifications
- Comply with legal obligations and enforce our Terms & Conditions
4. Messaging Channels (WhatsApp, Telegram, SMS, Web)
When an Organization connects a messaging channel to aryyo, messages sent by their end users are received by aryyo, processed by the AI agent pipeline, and a response is delivered back through the same channel. We retain conversation history for the period configured by the Organization (subject to the session retention settings described below) so that the AI agent can maintain context across a conversation.
Session and thread metadata is retained for up to 90 days by default, after which it is automatically deleted, unless the Organization has configured a different retention period or is required to retain it for compliance purposes.
5. How We Share Information
We do not sell personal information. We share information only in the following circumstances:
- With the Organization you are messaging. Conversation data is visible to the Organization operating the chatbot, as they are the data controller for that relationship.
- With service providers. We use infrastructure and service providers — including cloud hosting, database, payment processing (Stripe, M-Pesa/Daraja, Flutterwave, Paystack), email delivery, and observability providers (such as Langfuse) — to operate the Services. These providers are bound by confidentiality and data protection obligations.
- For legal reasons. We may disclose information if required by law, regulation, legal process, or to protect the rights, property, or safety of aryyo, our users, or others.
- Business transfers. If aryyo is involved in a merger, acquisition, or asset sale, information may be transferred as part of that transaction, subject to this policy.
6. Data Security
We apply technical and organizational measures to protect information, including:
- Encrypted storage of sensitive credentials (AES-256-GCM) for API tool authentication
- JWT-based authentication and role-based access control for the platform and admin dashboards
- SSRF protections that block requests to private networks, localhost, and cloud metadata endpoints before any API tool call is made on an Organization's behalf
- Encryption of data in transit via TLS
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
7. Data Retention
We retain personal information for as long as necessary to provide the Services, comply with legal obligations, resolve disputes, and enforce our agreements. Conversation sessions are subject to a default 90-day retention window. Organizations may request deletion of their data and their end users' conversation data, subject to legal retention requirements (for example, financial records related to payments).
8. Your Rights
Depending on your location, you may have rights under applicable data protection laws — including the Kenya Data Protection Act, 2019 — to access, correct, delete, or restrict the processing of your personal information, and to object to certain processing or request a copy of your data in a portable format.
To exercise these rights, contact us using the details in Section 12. If your request relates to a conversation with a specific chatbot, we may direct you to the Organization operating that chatbot, as they are responsible for that data as the data controller.
9. Cookies
Our website uses essential cookies required for core functionality (such as keeping you signed in) and may use analytics cookies to help us understand how the site is used. You can control cookies through your browser settings, though disabling essential cookies may affect how the site functions.
10. Children's Privacy
The Services are not directed at children under the age of 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will indicate the date of the latest revision at the top of this page, and material changes will be communicated to Organizations via email or through the dashboard.
12. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
- Email: info@aryyo.com
- Phone: +254 710 127 370
- Address: 90 JGO Plaza, Lavington, Kenya