Privacy Policy
Privacy Policy
1. Introduction
Arche ("Arche," "we," "us," or "our") is operated by Stone Sargent, a sole proprietor based in the United States, doing business as Arche at thearche.ai (the "Service"). This Privacy Policy explains what information we collect, how we use it, how our AI agents use it to act on your behalf, and the choices you have. By using Arche, you agree to the practices described here. If you do not agree, do not use the Service.
2. What Arche Is (and why it matters for your data)
Arche is an AI cofounder and an autonomous agent workforce. Its agents — a strategist, an engineer, a marketer, and an operator — plan your company, write and ship code to your own GitHub repositories, draft and send communications, publish marketing, and monitor your deployed applications. To do this, agents read the context you give them, the contents of your connected accounts, and memory we maintain about your projects. Understanding this data flow is central to understanding this policy.
3. Information We Collect
3.1 Information you provide
- Account information: your email address and password when you create an account.
- Project and business information: company ideas, plans, goals, and any details you share with your agents.
- Instructions and content: the messages, prompts, briefs, documents, and approvals you give agents.
- Connected-service credentials: access tokens for third-party services you choose to connect (for example, GitHub, or a publishing/API key), which we store encrypted.
- Communications: messages you send to support.
3.2 Information collected automatically
- Usage data: features used, actions taken, agent activity, and approvals.
- Device and log data: browser type, operating system, IP address, and timestamps.
- Billing and usage metering: records of metered resource consumption (for example, API calls and sandbox runtime) used to account for usage against your plan.
3.3 Information from connected third parties
- GitHub: when you connect GitHub, we access repository data within the scope you grant (see Section 8).
- Other connected services: data returned by services you connect so that agents can act on your behalf.
4. How Your Agents Use Your Data and Connected Accounts
When you use Arche, you are directing an autonomous system. Your agents:
- read your project context, conversation history, and stored memory to make decisions;
- read and write to your connected GitHub repositories, including creating commits;
- draft and, upon your approval, send emails and publish social/marketing content;
- provision temporary cloud sandboxes (via E2B) that execute your project's code; and
- record the actions they take for your review and for audit.
Every action that affects the outside world is presented to you for approval before it runs (and, if you enable autonomous operation, runs on a schedule you can pause or disable at any time). We describe the responsibility this creates in our Terms of Service.
5. How We Use Your Information
We use the information we collect to:
- provide, operate, and improve the Service and its agents;
- carry out the actions you and your agents authorize;
- authenticate you and secure your account;
- meter and account for usage against your plan;
- send transactional messages (confirmations, security notices);
- detect, prevent, and respond to fraud, abuse, and security incidents; and
- comply with legal obligations.
We do not sell your personal information. We do not use your data to train third-party AI models, and we do not permit our AI provider to train its models on your data through our use of its API.
6. AI Processing and Agent Memory
Arche uses Anthropic's API to power its agents. Your instructions and relevant project context are sent to Anthropic to generate agent responses and actions. We also maintain agent memory — scoped to you and your projects — so agents can remember your goals, decisions, and context across sessions. We keep an audit log of memory writes. You can request that we clear your agent memory (see Section 11).
7. Service Providers and Subprocessors
We share data with the following providers only as needed to run the Service. Each processes data on our behalf under its own terms:
| Provider | Role |
|---|---|
| Anthropic | AI model provider that powers the agents |
| Supabase | Database, authentication, and encrypted secret storage |
| Vercel | Application hosting and deployment |
| GitHub | Source-code hosting; agents read/write your repositories |
| E2B | Ephemeral cloud sandboxes that execute your project's code |
| Resend | Transactional and outbound email delivery |
| PostHog | Product analytics — enabled only after you accept via our consent banner |
We do not use Replicate or Plausible.
8. GitHub and Your Repositories
When you connect GitHub, you grant Arche access to your repositories within the OAuth scope you approve, including the ability to read, write, and commit code to repositories associated with your projects. Your projects are your own GitHub repositories, owned by you. Agents act within the access you grant; you can review their commits and revoke GitHub access at any time through your GitHub account settings, which stops further repository access.
9. Data Sharing and Disclosure
Beyond the providers above, we disclose information only: (a) to comply with law, legal process, or governmental request; (b) to protect the rights, safety, and property of Arche, our users, or the public; or (c) in connection with a business transfer (merger, acquisition, or sale of assets), with notice to you.
10. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. You may request deletion of your account and associated data at any time by contacting privacy@thearche.ai. We will delete your data within 30 days of a verified request, except where retention is required by law or for legitimate security and fraud-prevention purposes. Note that code committed to your own GitHub repositories remains in your GitHub account and is governed by GitHub, not Arche.
11. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, delete, or export your personal information, to object to or restrict certain processing, and to withdraw consent. You can also request that we clear your agent memory or disconnect a linked service. To exercise any of these, contact privacy@thearche.ai; we will respond within 30 days. Where laws such as the GDPR or CCPA apply to you, we honor the rights they provide.
12. Cookies
Arche uses strictly necessary cookies: an authentication/session cookie (stored as an httpOnly cookie) keeps you signed in, and a short-lived cookie carries your "what are you building?" input from the landing page into signup. These are required for the Service to work.
We use optional analytics (PostHog), enabled only after you accept via the consent banner; declining disables analytics entirely. Our only analytics-related cookie is the one that records your consent choice. If we introduce additional non-essential cookies in the future, we will update this policy and provide a consent choice before loading them.
13. Security
We protect your data with encryption in transit (TLS), encryption of stored credentials and secrets, row-level security on our database with default-deny access, and audited third-party libraries for authentication and payments. No method of transmission or storage is completely secure, but we work to protect your information and to respond quickly to incidents.
14. Children's Privacy
Arche is not directed to anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact privacy@thearche.ai and we will delete it.
15. International Users and Data Location
Arche is operated from the United States and uses providers located in the United States and elsewhere. If you access the Service from outside the United States, you understand that your information will be processed in the United States, where data-protection laws may differ from those in your country.
16. Changes to This Policy
We may update this Privacy Policy from time to time. For material changes, we will notify you by email or in-app at least 14 days before they take effect. Continued use after the effective date constitutes acceptance.
17. Contact
Arche — Stone Sargent, sole proprietor
Privacy: privacy@thearche.ai · General: support@thearche.ai · thearche.ai