Arkheia · Privacy

Privacy policy

This policy describes how Arkheia handles data for hosted detection, MCP provisioning, account administration, and subscription billing.

Effective date: April 1, 2026

1. What We Collect

We collect the minimum information required to provision and operate the Arkheia platform.

  • Email address when you request a free API key or contact Arkheia for support.
  • API usage metrics needed for rate limiting, billing, service health, and abuse prevention.
  • Operational metadata such as timestamps, subscription status, and audit references required to administer customer accounts.

2. What We Do Not Collect

Arkheia is designed to minimize content exposure.

  • We do not store prompt text as part of standard hosted detection operations.
  • We do not store response text or model outputs as part of standard hosted detection operations.
  • We do not use customer prompts or model outputs to train foundation models.
  • Detection is based on statistical and governance features rather than retaining user content by default.

3. Storage and Retention

Service data is stored in PostgreSQL on Railway in the United States region.

Usage logs are retained for 90 days unless a shorter period is required for legal or operational reasons.

Audit logs are retained according to the customer retention setting or contract terms where applicable.

4. Third Parties

Arkheia uses a small set of subprocessors to operate the service.

  • Stripe for payment processing and subscription billing.
  • Google OAuth for admin login only, where enabled.
  • Railway for hosted application and database infrastructure.

5. Security and Access

We apply access controls, auditability, and least-privilege principles to protect customer accounts and service data.

Where a customer deploys Arkheia in a private or on-premise environment, that customer controls the retention and access boundaries for that deployment.

6. Contact

For privacy requests, data questions, or support, contact support@arkheia.ai.