Documentation
Security

Data Privacy

How ARKA-AI protects your data and respects your privacy. We believe in transparency about our security practices.

Our Privacy Commitment

ARKA-AI is built with privacy as a core principle. We collect only what's necessary to provide the service, and we never sell your data. Here's what that means in practice:

Minimal Data Collection

We only store what's needed to run the service - no tracking, no profiling.

Encrypted at Rest

All data is encrypted using AES-256 when stored in our database.

Your Keys, Your Control

API keys are encrypted and never used for any purpose other than your requests.

No Data Selling

We never sell, share, or monetize your personal data or content.

What We Collect

Here's a transparent breakdown of what data we collect and why:

Account Data

  • Email address - For authentication and account recovery
  • Name (optional) - For personalization
  • Plan & billing info - Managed securely by Stripe

Usage Data

  • Tool usage counts - To enforce plan limits
  • Model routing data - Anonymized for service improvement
  • Error logs - For debugging (no content logged)

Content Data

  • Conversation history - Stored encrypted for your reference
  • API keys - Encrypted with AES-256 before storage

What We Don't Collect

No tracking pixels

We don't embed tracking pixels or third-party analytics that follow you across the web.

No behavioral profiling

We don't build profiles based on your usage patterns for advertising or other purposes.

No content training

Your inputs and outputs are not used to train AI models. They're yours alone.

API Key Security

Your API keys are critical credentials. Here's how we protect them:

  • Encrypted at rest using AES-256 encryption
  • Never logged in plain text anywhere
  • Transmitted securely over HTTPS only
  • Access restricted to your authenticated sessions
  • Deletable anytime from your settings

Your Responsibility

While we protect your keys on our end, you're responsible for keeping them secret. Never share your API keys publicly or commit them to version control. Rotate keys immediately if you suspect exposure.

Data Retention

We retain your data only as long as needed:

Data TypeRetention
Account dataUntil account deletion
Conversation historyUntil you delete it or close account
API keysUntil you remove them
Usage logs90 days (anonymized)
Error logs30 days

Your Rights

You have control over your data:

  • Access - Request a copy of all data we have about you
  • Correction - Update or correct your information
  • Deletion - Delete your account and all associated data
  • Export - Download your conversation history (Pro)
  • Portability - Receive your data in a standard format