Privacy policy

Last updated 24 September 2026

Arlo AI is a customer-service and sales assistant operated by AutoBricks AI ("we", "us"). A business connects its knowledge and its messaging channels, and Arlo answers its customers from what the business already knows. This page explains what we handle, why, and what you can do about it.

Who this covers

Customers of Arlo — the businesses and their team members who sign in at arlo.autobricks.ai. Their contacts — the people who message those businesses through a channel the business has connected. For contacts, the business is responsible for its own customer relationship, and we process their messages on its behalf.

What we collect

How we use it

We do not sell personal data, use it for advertising, or use it to train generalised AI models. Each workspace's data is separated from every other workspace's at the database level.

Who we share it with

Only the providers needed to run Arlo, and only what each one needs:

We may also disclose data where the law requires it.

Google user data (Gmail)

When you connect a Gmail inbox, Arlo requests exactly two scopes:

Arlo does not change, label, archive or delete anything in your Gmail account. Messages it reads are stored in your workspace so your team can see and answer them, and the relevant text is sent to your workspace's AI model provider to draft a reply.

Arlo AI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular:

Outlook works the same way through Microsoft Graph, with Mail.Read, Mail.Send, User.Read and offline_access.

Meta (Facebook, Instagram, WhatsApp)

When you connect a Facebook Page, an Instagram professional account or a WhatsApp Business number, Arlo receives the messages sent to it and sends replies through Meta's APIs. It uses this only to answer those conversations. Meta can also send us a data-deletion request through its callback; we delete what we hold under the account id Meta gives us. To have a Page's or a customer's conversations deleted, disconnect the channel or email us (see data deletion).

How long we keep it

Your choices and rights

Security

Data is encrypted in transit, channel tokens are encrypted at rest, and access inside the product is limited to members of your workspace. No system is perfectly secure; if we learn of a breach affecting your data we will tell you.

Changes

If this policy changes in a way that matters, we will update the date above and tell account holders by email.

Contact

AutoBricks AI · [email protected]