Privacy Notice
This staging notice explains the categories of information the ARIA platform may handle and the privacy principles Random Target AI is building around. Final production legal language must be reviewed before launch.
DRAFT FOR STAGING REVIEW · UPDATED AUGUST 2026
01Scope
Random Target AI builds and operates the ARIA platform and related customer deployments. Depending on the products and integrations enabled for an organization, ARIA may process account information, business knowledge, customer conversations, leads, bookings, files, project information, usage events and operational logs.
02Information the platform may process
- Account information such as name, business or organization name, email, authentication/session records and role.
- Customer and lead information supplied through website forms, voice conversations or configured business workflows.
- Conversation and call records including channel, messages/transcripts, summaries, outcomes and related customer context where the deployment stores them.
- Knowledge and files uploaded or connected by an authorized organization.
- Development project information exposed to an ARIA IDE workspace through an approved connector.
- Usage, security and audit information required to operate, protect and improve the service.
03How information is used
Information may be used to authenticate users, provide the requested ARIA product, maintain conversation or workflow context, create customer/lead/booking records, perform authorized tool actions, support the customer, secure the service, troubleshoot failures and measure service usage.
Random Target AI should not use a customer's private organization data to provide another customer with that organization's records.
04Service providers and integrations
ARIA deployments can use third-party model, speech, telephony, hosting, communications, workflow and infrastructure providers. The specific providers can vary by product and customer configuration. Data shared with a provider should be limited to what is required for the connected function and governed by the applicable service relationship.
The current platform can include server-side conversation, customer, lead, call and related operational records when those features are part of the deployment; users should not assume all ARIA data exists only in temporary browser storage.
05Security and organization boundaries
The application is designed around authenticated sessions, role checks and organization-scoped data. Customer-facing records should be queried and changed within the signed-in user's organization. Sensitive connectors should use least privilege, protect secrets from browser/client exposure and require approval for actions that the deployment classifies as sensitive.
06Retention
Retention can differ by record type, customer agreement, operational need and applicable legal requirement. The final production privacy policy must define approved retention/deletion rules before launch rather than publishing an unverified universal retention period.
07Privacy questions and requests
For access, correction, deletion or other privacy questions, use the Random Target AI contact page. The response available for a particular request may depend on the relationship with the organization that controls the relevant data and applicable law.
08Legal review required before production
This is an interim staging notice, not the final production policy. Before production launch, Random Target AI should complete formal legal review covering Trinidad and Tobago requirements, international customers where applicable, voice/telephone disclosures, processor terms, retention/deletion, customer-controller responsibilities and any product-specific sensitive-data obligations.