Arkheia · Privacy
Privacy policy
This policy describes how Arkheia handles data for hosted detection, MCP provisioning, account administration, and subscription billing.
Effective date: April 1, 2026
1. What We Collect
We collect the minimum information required to provision and operate the Arkheia platform.
- Email address when you request a free API key or contact Arkheia for support.
- API usage metrics needed for rate limiting, billing, service health, and abuse prevention.
- Operational metadata such as timestamps, subscription status, and audit references required to administer customer accounts.
2. What We Do Not Collect
Arkheia is designed to minimize content exposure.
- We do not store prompt text as part of standard hosted detection operations.
- We do not store response text or model outputs as part of standard hosted detection operations.
- We do not use customer prompts or model outputs to train foundation models.
- Detection is based on statistical and governance features rather than retaining user content by default.
3. Storage and Retention
Service data is stored in PostgreSQL on Railway in the United States region.
Usage logs are retained for 90 days unless a shorter period is required for legal or operational reasons.
Audit logs are retained according to the customer retention setting or contract terms where applicable.
4. Third Parties
Arkheia uses a small set of subprocessors to operate the service.
- Stripe for payment processing and subscription billing.
- Google OAuth for admin login only, where enabled.
- Railway for hosted application and database infrastructure.
5. Security and Access
We apply access controls, auditability, and least-privilege principles to protect customer accounts and service data.
Where a customer deploys Arkheia in a private or on-premise environment, that customer controls the retention and access boundaries for that deployment.
6. Contact
For privacy requests, data questions, or support, contact support@arkheia.ai.