Documentation
Compliance

Regulatory Compliance

How ARKA-AI complies with privacy regulations including GDPR, CCPA, and other data protection laws.

GDPR Compliance

The General Data Protection Regulation (GDPR) applies to users in the European Union. ARKA-AI is designed to comply with GDPR requirements:

Lawful Basis

We process personal data based on contractual necessity (providing the service you signed up for) and legitimate interest (improving the service).

Data Subject Rights

You can access, correct, delete, or export your data at any time. Contact support to exercise these rights.

Data Minimization

We collect only the data necessary to provide the service. We don't ask for information we don't need.

Data Protection by Design

Privacy considerations are built into our architecture from the start, not added as an afterthought.

CCPA Compliance

The California Consumer Privacy Act (CCPA) provides privacy rights to California residents. Here's how we comply:

  • Right to Know - You can request what data we collect about you
  • Right to Delete - You can request deletion of your personal information
  • Right to Opt-Out - We don't sell personal information, so no opt-out needed
  • Non-Discrimination - We don't discriminate against you for exercising your rights

No Data Sales

ARKA-AI does not sell your personal information to third parties. We never have, and we never will. This means CCPA's "Do Not Sell" requirements don't apply to us, but we support the spirit of the regulation.

Data Processing Agreements

When using third-party services, we have appropriate agreements in place:

ServicePurposeDPA Status
ClerkAuthenticationDPA in place
StripePayment processingDPA in place
VercelHostingDPA in place
Database ProviderData storageDPA in place

Data Location

Understanding where your data is stored and processed:

Data Centers

ARKA-AI infrastructure is hosted in the United States with our hosting provider. Your data may be processed in regions where our providers operate.

Primary Location

United States (US-East)

Provider Regions

Varies by AI provider

AI Provider Compliance

When you use ARKA-AI, your requests are forwarded to your configured AI providers. Each provider has their own privacy policies:

OpenAI

OpenAI API requests are not used for training. Data retention policies depend on your OpenAI account settings.

View OpenAI Privacy Policy →

OpenRouter

OpenRouter routes to various model providers. Each underlying provider has their own policies. OpenRouter does not train on API data.

View OpenRouter Privacy Policy →

Your Responsibility

By using ARKA-AI with your own API keys, you agree to the terms and privacy policies of your chosen AI providers. We recommend reviewing their policies to understand how they handle your data.

Privacy Inquiries

For privacy-related questions or to exercise your data rights:

Contact Us

Email: privacy@arka-ai.com

We aim to respond to all privacy inquiries within 30 days.