HowTo / Aria  ·  Terms of Service

HowTo / Aria Privacy Policy

Effective Date: July 4, 2026

Last Updated: July 4, 2026

This Policy is incorporated into our Terms of Service, version-dated July 4, 2026.

HowTo / Aria ("Aria," "we," "us," or "our") is operated by Open Corp, located in Wichita, Kansas, USA. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have. It applies to howtoaria.com, our desktop and mobile applications, the Aria assistant (chat, voice, and assist mode), our hosted lead-capture and payment pages, and all business tools we provide (together, the "Service").

We wrote this to be readable. Every section starts with a one-line plain-English summary. The summaries are part of this Policy, not marketing. The summaries are binding descriptions of our data practices; if a summary and the full text conflict about how we collect, use, share, or retain information, the reading more protective of you governs. Allocations of liability, responsibility, and dispute resolution are governed solely by the Terms of Service.

This Policy works together with our Terms of Service and, for business users, our Data Processing Addendum (Section 3.1); capitalized terms not defined here have the meanings given in the Terms. Creating an account requires you to take an affirmative action (a separate, unbundled checkbox) agreeing to this Policy; certain data uses — such as AI training on the Free plan — require their own separate, affirmative consent and are never bundled into general account acceptance.


1. What We Collect

In plain English: We collect what you give us at signup, the business data you put into the app, your conversations with Aria, usage and device data (including IP address and device identifiers), and — only during assist sessions — what's on your screen. Stripe handles card and bank numbers; we never store them.

We collect the following categories of information:

1.1 Account Information

When you sign up, we collect your name and email address, and you create a password. We never store your password in readable form — only a cryptographic hash (see Section 10). We collect your date of birth to determine your account tier — under 13 (not permitted), 13-17 (restricted account), or 18+ — and to enforce the under-18 restrictions (see Section 9). We retain only the date of birth and derived age tier needed for that enforcement; it is used for no other purpose and never for training or marketing.

1.2 Business Data You Input

If you use Aria's business tools, we store the data you enter or generate through the Service, including jobs, leads, estimates, invoices, schedules, and the contact information of your own customers (names, phone numbers, email addresses, job addresses, and notes). Your customers' data is treated specially — see Section 3. Business data you input is never used to train AI models on any plan (see Section 2.6).

1.3 Conversations with Aria

We collect the content of your text conversations with Aria and, when you use voice features, your voice audio and the transcripts generated from it.

Be aware of two things we want stated plainly:

If you enable owner-notification or owner-texting features, your owner-channel text conversations with Aria are stored as part of your conversation history.

How long we keep conversations, and whether they may be used for AI training, depends on your plan and your training-consent setting (see Sections 2 and 7).

1.4 Usage, Device, and Telemetry Data

We collect information about how you use the Service: features used, actions taken, timestamps, session length, error and crash logs, approximate usage costs (for metering and billing), IP address, browser/app type and version, operating system, and device identifiers. We use this to run, secure, meter, bill, and improve the Service.

1.5 Device and Screen Data — Assist Mode Only

If you start an assist mode session (where Aria guides you on your computer or, on paid plans, operates it with your permission), we process screenshots or screen content (including text and interface structure read through operating-system accessibility interfaces), cursor position, commands executed, and information about applications visible on screen — only during the active assist session and only to perform the assistance you asked for. We do not capture your screen outside of an active assist session. Assist sessions always begin with your explicit action, and control-level actions require your permission.

Activity context (awareness feed). During an active assist session we also log your own interactions — mouse clicks, keystrokes, which applications you use, and commands executed — so Aria has context for what you are doing. Password and other secure input fields are masked on your device before any of this data is transmitted to us. Activity logs are retained for [OWNER TO CONFIRM: retention period], are excluded from AI training on every plan, and collection stops when the assist session ends.

No PHI. The Service is not designed for, and must not be used to create, receive, store, or transmit protected health information (PHI) under HIPAA. We are not a business associate and do not sign Business Associate Agreements. Do not enable Assist or Computer Control while PHI or other medical information is displayed or accessible.

Additional commitments for assist mode, on every plan:

Assist mode operates software on your computer at your direction. The allocation of responsibility for actions taken in assist mode — including unintended changes to files, settings, or third-party accounts — is governed by the Terms of Service, which you should read.

1.6 Payment Information

Payments (cards and ACH bank debits) are processed by Stripe, Inc. Your full card number and full bank account number go directly to Stripe — we never receive or store them. We store only what we need to run your account: billing status, plan, transaction records, the last four digits and card brand/bank name (as provided by Stripe for display), and Stripe's tokens/identifiers. Stripe's handling of your payment data is governed by Stripe's own privacy policy. Payments made to you by your customers through hosted payment pages are covered in Section 3.4.

1.6a Business Registration Information (EIN)

To register your business for A2P text messaging, we ask for your federal Employer Identification Number (EIN) on a secure page and transmit it directly to Twilio's Trust Hub for required carrier registration. We do not store your EIN: it is not written to our databases or logs and is not retained by us after transmission. Twilio retains it under its own privacy policy as required for carrier registration (see the Twilio bullet in Section 5.1).

1.7 Photos, Documents, and Uploaded Files

We store photos and documents you upload — for example, receipts, job photos, quotes, contracts, and files saved to your proof vault — so you can access them and so Aria can help you work with them (e.g., receipt scanning, estimates). Uploaded files can contain highly sensitive information (Social Security numbers, EINs, financial account details, signatures). For that reason, uploaded files and documents are excluded from AI training on every plan, including Free (see Section 2.6), and are included in your data export (Section 6.1).

1.8 Consent and Rights Records

We keep timestamped records of your plan choices, consents (including the separate training-consent action recorded at signup and at every plan switch or toggle change), and any privacy rights requests you make. We keep these because the law requires us to be able to prove them (retention period in Section 7).

1.9 Information from Third Parties

If you connect third-party services (for example, Google Calendar, or a business profile lookup during business discovery), we receive the data those services provide under the permissions you grant. You can disconnect these services at any time in settings.

Google user data — Limited Use. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is used only to provide the calendar and connected-service features you enable, is never used for advertising, and is never used to train AI models.

We do not collect precise GPS location in the background. Location-related features (like mileage tracking, if you enable it on mobile) operate only when you turn them on.


2. How We Use Your Information — By Plan

In plain English: On the Free plan, your conversations may be used to train Aria — but only if you separately opt in, only after automated scrubbing of names, phone numbers, and addresses, and you can opt out anytime, for free, in settings. On paid plans, your data is never used for training — not even in "de-identified" form. Humans may review a limited amount of training-eligible content under strict controls, and we tell you that here.

2.1 Uses That Apply to Every Plan (Operational Uses)

Regardless of plan, we use your information to:

2.2 Free Plan — Training, With Your Separate Consent

If you are on the Free plan and you have given separate, affirmative, unbundled consent (a standalone checkbox or toggle — never pre-checked, never buried in general terms), the following data may be used to train and improve Aria's AI models:

That consent is recorded server-side with a timestamp. This data exchange helps fund the Free plan; it is described in our Notice of Financial Incentive (Section 6.4). The training-consent toggle is not shown to under-18 accounts, and the Notice of Financial Incentive program is not offered to users under 18.

You can withdraw training consent at any time, for free, without upgrading: a settings toggle (or an email to the address in Section 13) stops all training use going forward, and you keep the Free plan. Withdrawing is as easy as consenting.

2.3 What Is Never Used for Training — On Any Plan, Including Free

The following are excluded from AI training under all circumstances:

2.4 Paid Plans (Pro and Pay-As-You-Go) — Private

If you are on Pro or Pay-As-You-Go, your conversations and business data are private: we do not use them to train AI models — including in de-identified, aggregated, or derived form (see Section 2.8). We process them only for the operational uses in Section 2.1, and we retain only what we are legally or operationally required to keep (Section 7). This commitment binds any successor to our business (Section 5.3).

2.5 Redaction Before Training; Protection Against Model Leakage

Before any Free-plan conversation enters a training dataset, it passes through an automated redaction pipeline that removes or masks personal identifiers — names, phone numbers, email addresses, street addresses, and payment-card-like and SSN-like number patterns — belonging to you, your customers, and third parties mentioned in the conversation. No automated system is perfect; we test the pipeline, and if you find personal information that slipped through into a model's output, report it to the address in Section 13 and we will remove it from the dataset and remediate.

We also apply output filtering and testing designed to prevent trained models from reproducing one user's specific business details (pricing, customer information, addresses) in another user's outputs.

2.6 Human Review — Disclosed

A limited number of trained Open Corp personnel (or contractors under written confidentiality obligations) may read training-eligible, redacted Free-plan conversations for labeling, quality assurance, and safety review, and may review any user's content where reasonably necessary to investigate abuse, a security incident, a legal obligation, or a support request you make. Humans do not browse conversations for curiosity or marketing, do not listen to voice audio except for debugging a voice failure you report, and access is logged. If you have not consented to training, no human reviews your content except for the security/abuse/support/legal purposes just listed.

2.7 Plan Switches and Consent Changes

When you switch plans or change your training-consent setting, the change is re-recorded with a new timestamp and applies going forward:

2.8 De-identified and Aggregated Data

We may create and use de-identified or aggregated data (data that can no longer reasonably be linked to you or your customers) for analytics and service improvement, subject to these limits:

2.9 Aria's Outputs Are Not Professional Advice

Aria generates estimates, prices, schedules, drafts, expense categorizations, and suggestions using AI. AI outputs can be wrong. They are informational tools, not legal, tax, accounting, or other professional advice, and you are responsible for reviewing them before relying on them — especially estimates you send to customers and tax categorizations. The Terms of Service contain the governing disclaimers and limitations for AI outputs, including outputs affected by attempted manipulation of the AI (e.g., prompt injection from content on a webpage during an assist session). We monitor for and filter manipulated or unsafe outputs; report problems to the abuse contact in Section 13.

2.10 Guest Use (No Account)

In plain English: You can try Aria without an account, with a small daily usage grant. Guest conversations are tied to a device identifier, not your name — and they are never used to train our AI.

If you use the Service without creating an account, we associate your usage with a device or session identifier rather than a registered identity. Guest conversations are NOT used to train our AI models. Guest data is used only to operate the session, for security, and for abuse prevention. Guest access requires an affirmative tap-through acceptance of the Terms and this Policy before first use, recorded against the device/session identifier, after a neutral age screen; data from any guest session we know or learn belongs to a user under 18 is excluded from any training dataset and purged. Guest data is retained on the same schedule as Free Plan data. You hold the Section 6 rights as a guest, subject to reasonable verification that the device or session was yours.


3. Your Customers' Data (Data You Input About Other People)

In plain English: Your customers' data is processed only to serve you, is never used to train AI on any plan, and is deleted when you delete it — with three narrow exceptions we name here: opt-out (STOP) records, payment-authorization proof, and records under a legal hold. Your customers also get their own short privacy notice on any page of ours they use directly.

Business owners using Aria enter personal information about their own customers and leads — names, phone numbers, email addresses, service addresses, job details, and communications. For this data:

3.1 Our Role; Data Processing Addendum

We act as a service provider / data processor on your behalf. Our Data Processing Addendum (DPA) — available at https://howtoaria.com/privacy and incorporated into the Terms of Service for all business users — contains the written contractual terms required by the CCPA/CPRA (Cal. Civ. Code § 1798.140(ag)), the Virginia CDPA, the Colorado Privacy Act, and similar laws, including our commitments not to sell, retain, use, or disclose your customers' data for any purpose other than providing the Service. You (the business owner) are the controller of your customers' data and are responsible for:

3.2 What We Do (and Don't Do) With It

We process your customers' data only to provide the Service to you: storing it, displaying it in your pipeline, sending the messages you direct or configure, generating the invoices you request, and related support, security, and legal-compliance functions. We do not:

3.3 Deletion, Rights Requests, and the Records We Must Keep

When you delete a customer record, a job, or your account, your customers' associated data is deleted under the flows and timelines in Sections 6 and 7, except for three categories we intentionally retain, because deleting them would hurt you and your customers:

1. Opt-out and suppression records. If one of your customers texted STOP, revoked consent, or asked not to be contacted, we keep a minimal suppression record (the phone number/email and its opt-out status — nothing else) even after you delete the contact or your account. This prevents an opted-out person from being re-contacted if the contact is re-imported, and preserves your proof of compliance.

2. Payment and authorization proof. ACH authorization records for customer payments are retained for at least two years after revocation or termination as NACHA rules require, and transaction/dispute evidence is retained per Section 7.

3. Legal holds. Data subject to a litigation hold, an active dispute (including payment chargebacks), or a legal preservation obligation is retained until the hold ends, then deleted.

If one of your customers contacts us directly with a privacy request, we will refer them to you (as the controller) and/or assist you in fulfilling the request, as the law requires of a service provider.

3.4 When Your Customers Use Our Hosted Pages Directly

Some of your customers interact with surfaces we host: public lead-capture pages (e.g., howtoaria.com/l/…), hosted payment pages, and text-message conversations with your business number. For those people:

3.5 Employees and Other Authorized Users of Your Account

If you allow employees, family members, or others to use your account, you are responsible for telling them that their conversations, voice audio, and usage are processed under this Policy (including any training consent you control — training consent for an account applies only to data generated under that account's setting). Rights requests (deletion, export) for an account are exercised by the account owner. You are responsible for keeping credentials secure; responsibility for actions taken under valid credentials, including compromised ones, is allocated in the Terms of Service, and you should report suspected compromise to us immediately (Section 10).


4. Messages, Calls, and Marketing Sent Through the Service

In plain English: Aria can compose and send texts and emails for your business — so we build in the compliance rails: consent attestation before first contact, automatic STOP handling, a permanent suppression list, quiet hours, bot disclosure, and unsubscribe links. Aria never places AI-voice calls to your customers without the recipient's prior express written consent — today, we don't offer outbound AI calling at all.

Because Aria can autonomously compose, time, and send messages on your behalf (for example, speed-to-lead responses and follow-ups), compliance is shared — we do not simply hand you the legal risk:

4.1 Platform Compliance Controls (What We Do)

4.2 Your Responsibilities (What You Do)

You remain responsible for the truthfulness of your consent attestations, the lawfulness of your contact lists, the content choices you configure, and honoring commitments you make to your customers. The platform controls above help you comply; they do not replace your judgment.

4.3 Email and Unsubscribe (CAN-SPAM)

4.4 Calls, Voicemail, and Inbound Messages Involving Your Customers

If you enable features that record, transcribe, or AI-analyze calls or voicemails with your customers (for example, pulling job details from a call), understand and disclose the following:

4.5 Subscriptions and Cancellation (Cross-Reference)

Auto-renewal terms, pricing, and renewal consent for paid plans are disclosed at checkout and in the Terms of Service. Cancelling a paid plan is online, self-serve, and at least as easy as signing up — and is different from deleting your account (Section 6.1). Cancelling stops billing; deleting removes your data.


5. How We Share Information

In plain English: We share data with the vendors that make the Service work — all barred from using your content for their own purposes, including their own AI training — with authorities under narrow legal circumstances, and with a buyer of the company only if the buyer is bound by every promise in this Policy. We do not sell your personal information, and we will never start without your prior opt-in — and your customers' data and paid-plan content can never be sold, period.

We do not share your personal information except as described here:

5.1 Service Providers

We share information with vendors who process it on our behalf, under written contracts that restrict their use of it to providing services to us and that include the service-provider terms required by applicable privacy laws. Depending on the features you use, these include:

We share only what each provider needs to perform its function. A current list of subprocessors is available at [OWNER TO CONFIRM: subprocessor list URL].

5.2 Legal Compliance and Safety

We may disclose information where required by law, subpoena, court order, or other valid legal process, or where reasonably necessary to prevent imminent harm to a person, to investigate fraud or a security incident affecting the Service, or to establish or defend legal claims in a proceeding to which we are a party. We interpret these grounds narrowly — especially for conversation content, voice data, and screen data — we require legal process where the law allows us to insist on it, and where lawful and practicable we will notify you before disclosing your information so you can object.

5.3 Business Transfers

If Open Corp is involved in a merger, acquisition, reorganization, bankruptcy, or sale of all or part of its assets, your information may be transferred as part of that transaction, subject to all of the following:

5.4 No Sale of Personal Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as defined under the California Consumer Privacy Act and similar state laws), and we honor the Global Privacy Control and similar opt-out preference signals as confirmation of that status.

If we ever proposed to begin selling or sharing personal information in the future:

1. It would apply only to data collected after you gave prior, affirmative, opt-in consent — never to data already collected under this Policy, and never by mere notice, continued use, or an opt-out default;

2. Your customers' personal information (Section 3) and paid-plan conversations and business data (Section 2.4) would remain excluded permanently and unconditionally — no consent mechanism will be offered for them;

3. We would update this Policy, provide prominent advance notice in-app and by email, provide a "Do Not Sell or Share" mechanism, honor opt-out preference signals, and honor all state-law protections, including opt-in requirements for consumers under applicable age thresholds.

5.5 With Your Direction or Consent

We share information when you direct us to (for example, texting your customer, emailing an invoice, publishing a lead-capture page, or connecting your Google Calendar) or when you otherwise consent.


6. Your Rights and Choices

In plain English: You can see, fix, export (including your uploaded files), and delete your data. Deletion is self-serve with email confirmation. You can turn off AI training with a free settings toggle — no payment, no negotiation, no penalty. We don't punish anyone for using their rights.

6.1 Rights Available to Everyone

Regardless of where you live, we offer every user:

6.2 How to Exercise Rights

Use the in-app settings where available, or email [email protected] [ATTORNEY NOTE: CCPA requires a second request method — e.g., a toll-free number — unless the business operates exclusively online with a direct consumer relationship]. We will verify your identity (typically via your account email) before acting on a request, respond within the time required by applicable law (generally 45 days, extendable where permitted), and will not require you to create anything new to exercise a right. You may use an authorized agent where the law allows, subject to verification.

6.3 No Discrimination

We will not deny you the Service, charge you different prices, or degrade quality because you exercised a privacy right — including the free training opt-out, which carries no penalty and no feature loss. The Free plan's optional training exchange is a disclosed financial incentive program, described next.

6.4 Notice of Financial Incentive (Free Plan Training Consent)

Under California law (Cal. Civ. Code § 1798.125 and its regulations), the Free plan's optional data-for-service exchange is a financial incentive program, and we disclose its material terms:

6.5 California Residents (CCPA/CPRA)

California residents have the rights to know/access, correct, delete, port, limit use of sensitive personal information, opt out of sale/sharing, and non-discrimination. In the last 12 months, we have collected the following categories of personal information (sources: you directly, your devices, services you connect; purposes: Section 2; disclosed to: the service-provider categories in Section 5.1):

CCPA CategoryExamples We CollectSold or Shared?Retention
IdentifiersName, email, IP address, account IDsNoLife of account + deletion window (Sec. 7)
Personal records (Cal. Civ. Code § 1798.80)Name, contact info, billing status (payment card/bank numbers held by Stripe, not us)NoLife of account; billing records 7 years
Age informationDate of birth / age tier used to enforce the 13+ minimum and the 13-17 restricted modeNoDate of birth and derived age tier, life of the account
Commercial informationPlan, transactions, jobs, invoices, estimatesNoLife of account; transaction records 7 years
Internet/network activityUsage logs, telemetry, feature interactionsNo24 months (security logs, Sec. 7)
Audio/visual informationVoice recordings (raw audio ≤ 30 days) and transcripts; uploaded photos/documents; screen content during assist sessions only (not retained post-session)NoSec. 7 per type
Biometric informationNone. We do not create voiceprints or use voice/face data to identify anyone (Sec. 8)NoN/A
GeolocationApproximate location from IP; feature-specific location only if you enable itNoWith the log it appears in (Sec. 7)
Professional/employment informationYour business details (trade, business name)NoLife of account + deletion window
InferencesCommunication-style and usage-pattern preferences (including voice pitch/pace/energy signals, if enabled) used to tailor Aria's responses; Free-plan usage patterns also feed training if you consented (Sec. 2.2)NoLife of account + deletion window
Sensitive personal informationAccount credentials (stored hashed); contents of your messages/conversations with Aria; precise geolocation only if you enable a feature requiring it; and information that may incidentally appear in uploads or assist-session screens (e.g., SSNs, financial account numbers, health information in a receipt or on-screen document)NoPer type above; assist screens not retained

We do not sell or share personal information as defined by the CCPA/CPRA. We use and disclose sensitive personal information only to provide the Service you request, for security, and as otherwise permitted by § 7027(m) of the CCPA regulations without a right-to-limit obligation — but we will honor any "Limit the Use of My Sensitive Personal Information" request you submit regardless. We have no actual knowledge of selling or sharing personal information of consumers under 16 (we do not sell or share anyone's).

6.6 Other State Privacy Laws (Virginia, Colorado, Connecticut, Utah, Texas, and Others)

If you live in a state with a comprehensive privacy law, you have substantially similar rights: access, correction, deletion, portability, opt-out of targeted advertising, sale, and certain profiling. We honor these rights for all users through the mechanisms in Section 6.1. If we deny a request, you may appeal by replying to our decision or emailing the address in Section 13 with "Appeal" in the subject line; if your appeal is denied, you may contact your state Attorney General.


7. Data Retention

In plain English: We keep data while your account is active. When you delete your account, live data is removed within 14 days and backups purge within 30 — except the narrow, named records the law or your own protection requires us to keep, each with a stated period.

DataRetention
Account and business dataLife of account; deleted within 14 days of confirmed account deletion (backups purge below)
Conversations with Aria (text and transcripts)Life of account; deleted on account deletion. Consented Free-plan copies in training datasets are purged within 30 days of deletion or consent withdrawal (Sec. 2.7)
Raw voice audioDeleted within 30 days of transcription (kept that long only for quality/debugging); never retained for training (Sec. 2.3)
Assist-mode screen contentNot retained after the session; scrubbed error logs up to 30 days; action logs (no screen imagery) 24 months (Sec. 1.5)
Billing and transaction records7 years (tax, accounting, and financial regulations). Survives account deletion. Customer personal information inside retained financial records is minimized to what the record legally requires
Security and access logs24 months. Survives account deletion
Consent and rights-request records5 years after account deletion (to demonstrate compliance), then deleted
Suppression / opt-out records (Sec. 3.3)Retained as long as needed to prevent re-contacting opted-out people — minimal fields only (number/email + status)
ACH authorization and payment-dispute evidenceAt least 2 years after revocation/termination (NACHA), or until the dispute closes, whichever is later
Legal holdsUntil the hold or proceeding ends, then deleted
Deleted accounts — backupsPurged from encrypted backups within 30 days of confirmed deletion

Where a period above is stated as a maximum, we may delete sooner. De-identified data (Section 2.8) is not subject to these periods because it is no longer personal information, but it remains subject to the no-training and no-re-identification limits in Section 2.8.


8. Voice Analysis and Biometric Information

In plain English: We analyze how you sound (pitch, pace, energy) only to adjust Aria's responses, only if you leave the feature on — and we do NOT create voiceprints or identify people by voice. If we ever build voice identification, it will launch only with your prior express written consent and a published retention-and-destruction schedule, never by policy update alone.


9. Age Requirements and Minors

In plain English: You must be at least 13 to use Aria. Users 13-17 get a restricted account — strict age-appropriate content filtering, and no paid plans, payment/ACH features, outbound customer messaging, or computer control. A parent or legal guardian must agree to the Terms for anyone 13-17. We never use the data of anyone under 18 to train our AI. We don't allow anyone under 13, and if we learn of an under-13 account we close it and delete the data.

Minimum age 13. We do not knowingly collect personal information from children under 13, consistent with COPPA. Our signup flow collects date of birth to determine your account tier — under 13 (not permitted), 13-17 (restricted), or 18+ — enforces the 13-minimum, discards information from a failed age check, and is designed to resist simple retry. If we learn an account holder is under 13, we promptly close the account and delete its personal information as COPPA requires.

Users 13-17 (restricted). If you are between 13 and 17: (a) a parent or legal guardian must review and agree to the Terms on your behalf, recorded at signup with a timestamp; (b) your account runs in a restricted mode with age-appropriate content filtering; and (c) you may not use paid plans, payment or ACH features, outbound customer messaging, or computer-control features — those are offered only to users 18 and older with capacity to contract. If we discover a 13-17 user accessed adult-only features, we disable those features and delete the data they collected.

Teen data protections. Data of any user we know to be under 18 is never used to train our AI and is purged from any training dataset regardless of any recorded toggle. Teen accounts default to the most protective settings: voice-characteristics analysis off, no marketing emails, no financial-incentive program, and processing limited to what is strictly necessary for the restricted service. Teen conversations are subject to automated safety filtering whose signals are used only for safety enforcement — never for training or marketing. Providing a false date of birth is grounds to refuse, restrict, or terminate the account. If you believe a child under 13 has an account, contact us at the address in Section 13.


10. Security and Breach Notification

In plain English: We encrypt data in transit and at rest, hash passwords with scrypt, restrict internal access, and log who touches what. If a breach affects you, we'll notify you as the law requires — and if it affects your customers' data, we'll tell you fast enough and in enough detail for YOU to meet your own legal deadlines to them.

We use administrative, technical, and physical safeguards designed to protect your information, including:

No system is perfectly secure, and we cannot guarantee absolute security. If a data breach occurs affecting your personal information:

Security researchers can report vulnerabilities to [SECURITY EMAIL, e.g., [email protected]]; we commit to acknowledge good-faith reports and not pursue them legally. Please use a strong, unique password and notify us immediately of any suspected unauthorized access.


11. Cookies, Local Storage, and Opt-Out Preference Signals

In plain English: We use cookies/local storage to keep you logged in and remember your settings — no third-party ad tracking — and we honor the Global Privacy Control.

We use cookies and browser local storage for:

We do not use third-party advertising cookies or cross-site tracking. You can clear or block cookies in your browser, but the Service will not function without session cookies (you won't be able to stay logged in).

Opt-out preference signals: We honor the Global Privacy Control (GPC) and similar legally recognized signals. Because we do not sell or share personal information (Section 5.4), a GPC signal changes nothing in practice — but we treat it as a valid opt-out on record. We do not track users across third-party websites and therefore have no separate response to the older "Do Not Track" header.


12. International Users

In plain English: We're a US company serving US businesses; data is processed in the United States.

The Service is operated from the United States, is designed for US-based businesses, and is not currently marketed to or intended for users in the European Economic Area, the United Kingdom, or other jurisdictions with data-localization or representative requirements we have not yet implemented. Your information is stored and processed in the United States (and, where our service providers operate infrastructure elsewhere, in the locations they use under contract).

If the GDPR or UK GDPR nonetheless applies to particular processing: our legal bases are performance of a contract (providing the Service), legitimate interests (security, fraud prevention, service improvement), legal obligation (retained records in Section 7), and consent (AI training, Section 2.2 — withdrawable at any time); international transfers rely on Standard Contractual Clauses or another valid mechanism where required; you have the rights in Section 6 plus the rights to object, to restrict processing, and to lodge a complaint with your supervisory authority. [ATTORNEY/OPERATIONAL NOTE: policy language alone cannot create GDPR compliance — before accepting EEA/UK signups, the company must either geo-restrict registration or implement the operational apparatus: Art. 27 EU/UK representative, executed SCCs with subprocessors, records of processing, and a DPO analysis.]


13. Changes to This Policy; Contact

In plain English: If we want to change how we actually use data you've already given us, we'll ask first — silence or continued use is never treated as a yes for material changes. And here's how to reach us.

13.1 Changes

We may update this Privacy Policy from time to time.

All prior versions are posted in a public archive at [VERSION ARCHIVE URL], so you can always see which terms applied when your data was collected.

Mobile Information and Text Messaging Consent

In plain English: your phone number and your texting consent are never sold or handed to anyone else for their marketing. Period.

We do not share, sell, or otherwise provide your mobile phone number or messaging consent information to any third parties or affiliates for marketing or promotional purposes. By signing up for text messages, you agree to receive recurring service messages from Open Corp Junk Removal; message frequency varies and message and data rates may apply.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. All the sharing categories described in this Policy exclude text messaging originator opt-in data and consent; this information will not be shared with, sold to, or transferred to any third parties for any purpose other than delivering the messages you consented to receive (for example, our SMS carrier partner transmitting the message itself).

This applies to every text messaging program we operate, including the Open Corp Junk Removal quote and appointment program: when you check the SMS consent box on a quote form or otherwise opt in, your number and consent record are used solely to send you the service messages you requested (quote follow-ups, appointment confirmations, and arrival updates — typically 2–5 messages per job). Message and data rates may apply. Reply STOP to opt out at any time or HELP for help.

13.2 Contact Us

Questions, requests, complaints, abuse reports, or privacy-rights appeals:

Open Corp (HowTo / Aria)

Wichita, Kansas, USA

Privacy: [email protected]

Security/vulnerabilities: [email protected]

Abuse/AI-output reports: [email protected]

Web: howtoaria.com

[OWNER TO CONFIRM: mailing address]

If you are unsatisfied with our response, you may contact your state Attorney General or, where applicable, your local data-protection authority.