Privacy Policy

Effective date: March 1, 2026  ·  Last updated: March 10, 2026  ·  Contact: privacy@arctyx.io

Summary: Arctyx reads your repository metadata to generate architecture analysis. We do not store your source code. We use your data only to provide and improve the service. You can delete your data at any time.

1. Who We Are

Arctyx ("we", "us", or "our") operates the Architecture Visibility Engine available at arctyx.io. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our service.

Data controller: Arctyx, Inc. For privacy-related inquiries, contact privacy@arctyx.io.

2. Information We Collect

2.1 Account Information

When you register, we collect your name, email address, organization name, and a hashed password. We do not store your plain-text password.

2.2 Repository and Code Analysis Data

To perform architecture analysis, Arctyx connects to your source control provider (GitHub, GitLab, Bitbucket, Azure DevOps) using OAuth tokens or personal access tokens you provide. Arctyx reads file content in memory to extract structural signals such as:

We do not persist your raw source code. Only derived, structured data — service names, detected dependencies, issue counts, and diagram graphs — are stored in our database.

2.3 Usage and Billing Data

We track feature usage (AI runs, snapshot counts, project counts) to enforce plan limits and calculate overage charges. Billing is handled by Stripe; we do not store full payment card numbers. We store only the Stripe customer ID and subscription ID.

2.4 Cookies and Session Data

We use a single session JWT stored in your browser's localStorage for authentication. We do not use third-party tracking cookies or advertising cookies.

2.5 Log and Diagnostic Data

Server logs may include IP addresses, request paths, timestamps, and error messages. Logs are retained for up to 90 days for security and debugging purposes.

3. How We Use Your Information

4. Third-Party Services

Arctyx uses the following third-party services. Each has its own privacy policy:

Enterprise customers running Arctyx on-premise with Ollama do not send any code or content outside their own network.

5. Data Retention and Deletion

We retain your account data and analysis snapshots for as long as your account is active. You may delete your account and all associated data at any time by contacting privacy@arctyx.io — we will process the request within 30 days.

Enterprise customers may configure a custom data retention window (30, 60, 90, 180 days, or 1 year). Snapshots older than this window are automatically and permanently deleted.

Stripe billing records are retained as required by financial regulations (typically 7 years) regardless of account deletion.

6. Data Security

All data is transmitted over TLS. Passwords are hashed before storage. Access tokens for source control providers are stored encrypted. We perform regular security reviews and limit employee access to production data to the minimum necessary.

Despite these measures, no internet service is completely secure. We encourage you to use strong passwords and revoke access tokens you are no longer using.

7. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

To exercise any of these rights, email privacy@arctyx.io. We will respond within 30 days.

8. Children's Privacy

Arctyx is not directed at children under 16 years of age. We do not knowingly collect personal information from children. If we become aware that a child has provided us personal information, we will delete it promptly.

9. International Transfers

Arctyx operates primarily from the United States. If you access the service from outside the United States, your data may be transferred to and processed in the United States. We use standard contractual clauses where required by applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you by posting the new policy on this page and updating the "Last updated" date above. For material changes, we will send an email notification to registered users.

11. Contact Us

If you have any questions about this Privacy Policy, please contact us at: