Legal
Meet Arna — Privacy Policy
Meet Arna is an AI companion app. This policy explains exactly what data the app handles and where it goes. The short version: your connections and memories live on your phone; your conversation text passes through our server to AI providers to generate her replies; we don’t sell data and we don’t run ads.
What stays on your phone
- Her memory of you (facts you share in conversation, your name) — stored only on your device. You can view and delete any memory in the app (“Her memory of you”).
- Google Calendar connection tokens — after you connect, your access token stays on your device. Calendar contents are covered in full in Google user data below.
- Spotify and Philips Hue — connection tokens stay on your device; commands go directly from your phone to Spotify/Hue.
- Photos you attach and drawings she makes — processed on-device and/or via your own configured image provider key; not stored by us.
- Dialogue history and settings — on your device; deletable in-app.
Google user data
Connecting Google Calendar is optional and the rest of the app works without it. This section covers exactly what we access, where it goes, and how it is protected.
What we access
-
Scope requested:
calendar.events. With it we read the events on your primary calendar for roughly the next week — their titles, start and end times, and all-day flags — and we create or move events when you ask Arna to. - What we never touch: other calendars, calendar sharing settings, Gmail, Drive, Contacts, Photos, or your Google profile beyond the sign-in required to authorize. We never delete events.
How we use it
Only to provide the features you asked for: reading your agenda aloud, giving you a 15-minute heads-up before an event, and adding or moving events on request. We do not sell it, use it for advertising or profiling, or use it to train AI models — ours or anyone else’s.
Who we share, transfer, or disclose it to
- Google (Firebase Cloud Messaging) — when closed-app reminders are on, the event title and time appear in the notification we send you through Google’s own push service.
- Cloudflare — our hosting provider. If you turn on closed-app reminders, your Google refresh token is stored in Cloudflare’s key-value store and our scheduled job reads your upcoming events to decide when to notify you.
- Our AI provider — so Arna can answer “what’s on my calendar?”, a summary of your upcoming events is included in the context sent to the AI provider that generates her reply. If you add your own provider key in Settings → Her brain, this goes directly from your phone to the provider you chose and never reaches our servers.
- Our voice provider (ElevenLabs) — when Arna reads your agenda aloud using her premium voice, the sentence she speaks is sent to be turned into audio, exactly like every other sentence she says. If that sentence names an event, the event name is in it. Our account is configured so that content sent for synthesis is not used to train their models. Her free standard voice is generated on your device and sends nothing at all.
- No one else. Google Calendar data is not sent to our email provider, any analytics service, or any advertiser. When Arna acts as a receptionist and checks a visitor against your calendar, only a yes/no match result leaves your phone — never the event.
How it is protected
- In transit: every connection — phone to Google, phone to our server, our server to any provider — uses HTTPS/TLS. The app pins its API calls to our own domain.
- At rest: the only Google credential we store is the refresh token used for closed-app reminders, held encrypted at rest in Cloudflare’s key-value store, scoped to a random device identifier rather than your name or email. Tokens are never written to logs.
- Access: limited to the operator of Classroom Panda LLC for maintaining the service. There is no admin interface that browses your calendar, and event contents are not retained on our servers after a reminder check.
- Retention and deletion: the refresh token is deleted when you turn off reminders, disconnect Calendar in Settings, or revoke access at myaccount.google.com/permissions. Revoking at Google also immediately ends our ability to read anything.
- Limited Use: our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What passes through our server (api.meetarna.com)
To generate Arna’s replies and voice, the app sends through our Cloudflare-hosted backend:
- Your message text and her reply context — forwarded to our AI providers (DeepSeek and OpenAI) to produce her response. We do not use this content to train models. Providers process it under their own terms: DeepSeek may process and store data on servers in China and its terms permit using inputs to improve its services — please don’t tell Arna anything you wouldn’t want processed there. Prefer full control? Add your own AI provider key in Settings → Her brain and your conversations go directly from your phone to the provider you chose, bypassing our servers entirely.
- Her reply text — forwarded to ElevenLabs to synthesize her premium voice (the free standard voice is generated on your device).
- Calendar reminders that reach a closed app: if you link Google Calendar, our server stores your calendar refresh token and this device’s push token so it can send you a “coming up” notification even when the app isn’t running. The token is used only to read upcoming events for those reminders, and both are deleted when you disconnect Calendar (or revoke access in your Google Account). See Google user data for the full detail.
- We keep operational counters (rate limiting, voice-credit allowances) keyed to a device identifier — not your name or account.
- Reports: if you flag one of her replies as inappropriate, the flagged text is sent to us and kept up to 90 days solely for review and safety improvements.
What we don’t do
- No ads, no sale of personal data, no data brokers.
- No advertising or behavioural profile of you.
- No access to your contacts, location, SMS, or files beyond what you attach.
Accounts and payments
Meet Arna needs no account to use. She runs on your device, and nothing about you is registered with us to get started.
If you buy a paid plan, the purchase is handled by Google Play or the App Store under their own privacy policies. They take the payment and tell us only whether a purchase is active — we never receive your card number or billing address. Your purchase is tied to the store account you bought it with, which is also how it is restored on a new device; we do not create a separate login for you.
Permissions the app asks for
- Microphone — talking to Arna by voice; audio is transcribed on-device.
- Camera — only when you use the camera features (showing her something, scanning a pairing code).
- Notifications — calendar reminders you asked her to give.
Optional desktop connection
An early feature lets you pair the app with the upcoming Arna desktop app over your own home network. That link is device-to-device in your home; nothing about it passes through our servers.
Children
Meet Arna is not directed at children under 13 and should not be used by them.
Changes
We’ll update this page when the policy changes; material changes will be noted in the app’s release notes.
Your choices
Disconnect any service (Calendar, Spotify, Hue) in settings at any time — tokens are deleted from the device. Delete memories individually in-app, or uninstall the app to remove all on-device data. To revoke Google Calendar access account-side: myaccount.google.com/permissions. Questions or data requests: info@classroompanda.com.