Privacy Policy
Last updated September 7, 2026·Version 1.2
1. Roles
This Privacy Policy explains how Arya Labs, Inc. (“Arya Labs,” “Samva,” “we,” “us,” or “our”) handles personal information relating to Samva websites, dashboards, APIs, email Services, and related communications.
Arya Labs is generally a controller for account, identity, billing, website, security, abuse-prevention, service-improvement, and direct-support information.
When a customer submits contacts, message content, templates, events, or related recipient information to use the Services, the customer generally determines the purposes and means of processing and Arya Labs acts as a processor or service provider. The customer is responsible for providing notices, obtaining permissions, responding to recipient requests, and giving lawful instructions. The Data Processing Addendum governs that processing.
2. Information We Collect
We may collect:
- account names, email addresses, organization details, authentication records, and support communications;
- billing, subscription, invoice, tax, payment-status, and usage information; payment-card details are handled by payment providers rather than stored by Samva as the card number;
- domains, sender identities, API keys, contacts, templates, message content, attachments, campaigns, and other Customer Content;
- delivery, bounce, complaint, unsubscribe, suppression, open, click, timestamp, IP-address, user-agent, clicked-URL, and provider-webhook information;
- security, authentication, audit, quota, abuse, reputation, and operational telemetry;
- website, device, browser, cookie, analytics, and session-replay information as described in the Cookie and Analytics Notice; and
- information provided when you contact us, request support, report abuse, or exercise a privacy right.
Do not submit payment-card data, protected health information, special-category personal data, children’s data, or other regulated data through the Services unless Arya Labs has approved that use in a separate written agreement.
3. How We Use Information
We use information to:
- provide, authenticate, maintain, and support the Services;
- process messages and delivery events;
- manage billing, limits, subscriptions, and invoices;
- operate unsubscribe, suppression, bounce, complaint, and anti-abuse controls;
- secure accounts, investigate misuse, and protect recipients and infrastructure;
- communicate about accounts, changes, incidents, support, and product operations;
- measure and improve the Services, including analytics and session replay where permitted and configured;
- comply with law, respond to lawful requests, resolve disputes, and enforce agreements; and
- create aggregated or de-identified information that does not reasonably identify a person.
4. Engagement Tracking
Samva may process email opens and clicks, including timestamps, IP addresses, user agents, clicked URLs, and link metadata, when engagement tracking is enabled for the relevant message or organization. Tracking may be enabled by default in some contexts and will be disabled or require consent where applicable law requires prior consent.
Customers are responsible for providing recipients with required notices and obtaining required permissions. A recipient’s engagement preference is separate from an unsubscribe or suppression record. Suppression data may be retained to prevent future contact even after other data is deleted.
5. Cookies, Analytics, and Session Replay
Essential cookies and similar technologies support authentication, security, routing, preferences, and core functionality.
The public Samva website is measured by default without cookies and without any identifier stored in your browser: PostHog groups visits under a daily identifier it computes on its servers and that we cannot reverse, and the Google Analytics tag runs with every storage permission denied, so it writes no cookie and reads none. Accepting analytics cookies adds a first-party identifier stored in your browser for each processor, grants Google its advertising storage permissions in the same answer, and turns on session replay for public marketing and documentation pages, with typed input masked. Rejecting them returns both processors to the cookieless measurement and deletes the Google Analytics cookies from your browser. The Cookie and Analytics Notice describes both modes, what each one collects, and how to change your choice at any time.
When you create an account you accept the Terms of Service, and that acceptance permits us to link what you do inside the Services to your account for product analytics, through an opaque account identifier and never your name or email address. You can withdraw it at any time in Settings → Profile → Privacy, under Product analytics; withdrawing stops the linking and ends the identity we hold for you in our analytics provider. The Samva dashboard and mailbox send no automatic page views and run no session replay.
PostHog, Inc. processes this analytics and replay data on our behalf on infrastructure in the United States. Google LLC processes website analytics on our behalf through Google Analytics. We connect no advertising product to that measurement: Google Signals and ad-personalization signals are turned off, and no advertising or remarketing audience is built from your visit.
Withdrawing consent does not affect processing already completed and does not disable essential functionality.
6. Sharing
We may share information with:
- infrastructure and service providers that process information for us, including AWS, Cloudflare, PlanetScale, Upstash, Autumn, Stripe, Axiom, PostHog, Google, and Cloudflare Turnstile;
- customer-authorized recipients, providers, or integrations necessary to deliver a customer’s messages;
- professional advisers, auditors, insurers, financing parties, and transaction counterparties subject to appropriate confidentiality;
- authorities, courts, or other parties when required by law or necessary to protect rights, safety, the Services, or recipients; and
- a successor in a merger, acquisition, financing, reorganization, or sale of assets.
Our current subprocessor list and notice process are available at /legal/subprocessors.
7. International Processing
Samva uses providers and infrastructure that may process information in the United States and other countries. Provider location and transfer mechanisms vary by service. Where data-protection law requires a transfer safeguard, Arya Labs will use an applicable lawful mechanism, such as an adequacy decision, contractual safeguard, or other legally recognized measure.
8. Retention and Deletion
We do not promise one uniform retention period for all information. Retention varies by data type, operational purpose, customer configuration, legal obligation, security need, billing requirement, backup lifecycle, and provider behavior.
Website analytics events and session recordings are retained according to the configuration of our analytics provider. Specific retention periods for those categories are under review and will be stated here once fixed.
You may request account deletion through available controls or by contacting us. Organization deletion may not immediately remove every copy and may not remove data that must remain for billing, legal compliance, security, abuse prevention, audit, backups, or suppression. Suppression data may be retained specifically to prevent re-contact.
Customers must handle deletion and correction requests for recipient data and may ask Samva for reasonable assistance where technically available.
9. Security
We use technical and organizational measures appropriate to the nature of the information and the Services. These include encryption in transit, access controls, tenant isolation, credential protection, key-management controls, logging, operational monitoring, and provider security controls. No system or transmission is completely secure, and we do not promise that unauthorized access will never occur.
If we determine that a security incident requires notice, we will provide prompt notice through an appropriate channel, subject to law, investigation, security, and provider constraints.
10. Rights and Requests
Depending on location and applicable law, individuals may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information, and to withdraw consent.
We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California law. We do not use analytics data to build advertising profiles or to target you on other services.
For account and website information, contact privacy@samva.dev. For recipient and Customer Content held on behalf of a customer, contact the relevant customer first. We will assist customers with legally required requests where appropriate and technically possible. We may verify identity and authority before responding.
11. Children
The Services are not directed to children. Do not use Samva to collect or process children’s data without a separate written agreement and all required protections.
12. Changes
We may update this Policy by posting a new version and effective date. For material changes, we will provide reasonable notice through the Services or email where required.
13. Contact
Privacy requests: privacy@samva.dev
Legal notices: legal@samva.dev
Arya Labs, Inc.
1111B S Governors Ave #29161
Dover, DE 19904