Trust
Privacy
Arthat Vault is built to preserve personal and business material. This is a plain account of what we hold, when another service may receive it, and which controls are live today.
1. What we keep, and why
- Account information
- Your email address, account identifier, linked sign-in methods and settings, so you can access and control your vault. Authentication is handled by Supabase. If you choose a password, the Arthat Vault application never receives its stored hash or can read the password back.
- Source evidence
- Files, photos, documents, chat exports, links and notes you choose to keep, together with details such as source, filename, type, size and capture time. As the new evidence record rolls out, the original is kept separately from later interpretation.
- Derived context
- Extracted text, descriptions, tags, embeddings and other structured results that make material useful and findable. These results may be wrong, so Arthat Vault keeps them attributable to the source and processing work that produced them as the new contract runtime lands.
- Connection and access records
- Connected-tool profiles, grants, processing status, audit entries and ordinary service logs used to operate, troubleshoot and protect Arthat Vault. The new scoped credential path stores a token prefix and one-way fingerprint, not the reusable secret token.
Arthat Vault does not sell your vault or use it for advertising. The current product does not include third-party behavioural analytics or advertising trackers inside your vault. Ordinary hosting and security logs still exist because the service cannot run safely without them.
2. Services and AIs that may receive data
- Cloudflare R2
- Stores file bytes and locally produced file derivatives.
- Supabase
- Provides account sign-in and stores records, searchable context, permissions, processing state and audit data.
- An AI you connect
- May receive an authorized, non-Private source and a limited processing contract when you use that connection. Its own privacy, retention and training terms also apply.
Private content is not eligible for dispatch to an AI provider. Provider-neutral processing, the current transition, and provider-term limits are explained on AI and your data.
3. How long we keep it
- Items you keep. An active item remains until you archive or delete it. Archived items remain yours until you delete them.
- Trash. Deleting an item removes it from ordinary search and puts it in trash. You can permanently delete it yourself. Items left in trash become eligible for permanent removal after 30 days; cleanup may occur later than day 30 because it runs as the product performs its cleanup work.
- Audit and service records. Some are kept while the account exists so access can be reviewed and the service secured. A shorter, record-specific retention schedule is still being defined.
- Closing the account. Self-serve deletion removes the account and database records after attempting to remove the account’s stored objects. Copies held in provider backups age out under those providers’ own backup schedules.
4. Your controls and requests
You can:
- See and retrieve it. Open or download individual items and use the current account export.
- Correct it. Change user-editable details or replace an AI-derived description that is wrong.
- Restrict it. Choose Private before capture, remove a grant, or pause a connected assistant.
- Delete it. Remove individual items or use the self-serve account deletion control.
- Ask for help. Contact us about access, correction, deletion, objection or another privacy right that applies where you live.
Write to privacy@arthat.org. We may need to confirm that the account is yours before acting on a request. We aim to acknowledge requests within seven days and finish them within thirty, unless the request or applicable law reasonably requires longer.
5. Contacting us
- Privacy questions and data requests: privacy@arthat.org
- Security reports: security@arthat.org — see Security for what to include.
- General support: support@arthat.org
India: grievance contact
Arthat Vault is operated by Arthat AI Technologies Pvt Ltd, Bangalore, India.
Founder to complete — to be filled in before launch
6. Changes to this page
If we materially change who receives your data or what we use it for, we will update this page and give notice in the app or by email before the change where practical. Small corrections may be published with an updated date.
This page separates current behavior from work that is landing or planned. None of it is an audited guarantee. Arthat Vault has not completed independent assurance of these claims. We hold no SOC 2, ISO 27001, or other security certification. A status box calls out an incomplete or transitional capability instead of asking you to assume it is already live.
