Privacy Policy
Effective 19 August 2026.
Ariava has no user accounts, email sign-in, or password. Watch and Host identities are device-local Ed25519 key pairs. Identifiers are derived from the public key. There is no owner string, login, or shared command secret.
What stays on the Watch
The Watch stores, in non-synchronizing Keychain (this device, after first unlock):
- Watch signing and encryption identity material
- pairing and Host-link state needed to talk to Relay
- a StoreKit subscription cache
- a UTC-month Premium TTS quota ledger
Resetting Watch identity replaces signing keys and pairing. Uninstalling the app or wiping the Watch removes local data we stored there.
What the Relay receives
The Watch talks to the Ariava Relay (Cloudflare Workers and D1). Relay routes and stores Host-scoped state. It does not run your coding agent.
Relay handles:
- Watch and Host enrollment (public identity, signed requests)
- pairing codes and active Watch–Host links
- session and event projections for the inbox
- opaque encrypted
replyandinterruptcommand blobs, plus opaque Host receipts - voice-reply session create, audio upload, status, and cancel when you choose Premium TTS (third-party transcription)
reply and interrupt payloads are encrypted on the Watch and decrypted only on the paired Host. Relay acknowledges storage with { commandId, receivedAt } only. Relay and D1 are not given command plaintext, decrypted bytes, terminal status text, or the content of encrypted receipts.
Signed requests include a timestamp and nonce for replay protection. They do not include your Apple ID.
Notifications
If you allow notifications, Relay delivers Apple Push Notification service (APNs) alerts to the Watch. APNs categories are agent.done and agent.need_human.
Where encrypted previews are used, Relay and APNs see recipient-specific ciphertext and low-sensitivity fallback metadata, not plaintext project names or agent preview text. After a successful local decrypt, the Watch may show that preview in Notification Center. That on-device display is intentional.
Voice input
On the Watch you can enter a reply by voice in two ways: Apple Watch system dictation, or optional Premium TTS (third-party voice transcription, for example Volcengine).
Apple Watch system dictation turns speech into text through the watchOS input surface. That text is then sent as a normal encrypted reply. This path does not upload audio through Relay for speech-to-text, and it is not counted against Ariava’s monthly Premium TTS minutes.
If you choose Premium TTS, the Watch records 16 kHz mono PCM and uploads it through Relay so a transcript can be returned. Audio and recognition requests are not end-to-end encrypted to your Host the way reply / interrupt are. Speech-to-text is performed via Relay using that third-party service (currently ByteDance Doubao / Volcengine). Do not use this path for audio you do not want processed that way. The recognized text can then be sent as a normal encrypted reply.
Monthly Premium TTS minutes are Free 10 minutes and Pro 180 minutes per UTC calendar month, counted from uploaded PCM. Text replies, the system keyboard, Apple Watch system dictation, and interrupt are not counted.
Purchases
Ariava Pro is an auto-renewable annual Apple subscription. Apple processes the purchase, tax, restore, and cancellation. We do not receive your Apple ID password or payment card number. The Watch reads StoreKit 2 entitlements (verified product and expiration) to gate additional Host pairing and the higher Premium TTS allotment.
Your Host computer
The Local Bridge on your Mac or Linux/WSL machine holds Host identity material and live agent session state. That Host data stays under your control on that machine. The pi extension talks to the Bridge on loopback only. Ariava does not require an Ariava cloud login for the Host.
Sharing
We do not sell personal information. Processors that may see technical data because you use the product:
- Cloudflare — Relay and this site
- Apple — APNs, App Store, StoreKit
- ByteDance / Volcengine — speech-to-text when you choose Premium TTS
We may disclose information if required by law.
Your choices
- Unlink a Watch–Host pair from either side.
- Reset Watch identity (replaces keys; does not clear Pro cache or Premium TTS ledger).
- Restore or manage Ariava Pro in Apple subscription settings.
- Disable notifications in watchOS settings.
- Stop using Premium TTS; continue with Apple Watch system dictation, text
reply, andinterrupt. - Delete the app or erase the Watch to remove local Ariava data.
Children
Ariava is not directed at children under 13, and we do not knowingly collect their data.
Changes
We may update this policy by posting a new version at https://ariava.noyx.io/privacy. The effective date above will change.
Questions: noyx@duck.com