Legal

Privacy Policy

What Arci collects, why it needs it, and what it will never do with it.

Effective date:

Overview

Arci (“Arci”, “we”, “our”), a product of Artha operated by Flare Technologies, is an AI-native marketing operating system operated by Flare Technologies. This Privacy Policy explains how we collect, use, disclose, and protect information when you use our platform at getarci.com.

1. Information we collect

1.1 Information you provide

  • Account data — name, email address, company name when you create an account.
  • Workspace data — your website URL, brand documents, product descriptions, and marketing content you enter or generate inside Arci.
  • Payment data — billing details processed by Stripe (US) or Razorpay (India). We store only a masked card identifier and subscription status; we never see your full card number.
  • Communications — messages you send via in-app chat or email to our team.

1.2 Data from connected Google services

When you voluntarily connect a Google account, Arci requests limited, read-only OAuth scopes. We access only the data described below and only for the purpose of displaying analytics inside your Arci workspace:

  • Google Analytics 4 (analytics.readonly) — session counts, active users, top pages, top channels, and top countries. Used solely to populate the Traffic tab in your workspace analytics panel.
  • Google Search Console (webmasters.readonly) — search queries, click counts, impressions, CTR, and average positions. Used solely to populate the SEO tab in your workspace analytics panel.

We do not store raw GA4 or Search Console rows in our database. Metric values are fetched on demand and displayed in your UI. OAuth access tokens are encrypted at rest with AES-256-GCM and are never shared with third parties. You can disconnect Google services at any time from Settings → Connectors, which permanently deletes the stored token.

1.3 Usage and technical data

  • Log data — IP address, browser type, pages visited, timestamps, referring URLs.
  • Product analytics — aggregate feature usage via PostHog. No data is sold or shared with advertisers.
  • Error reports — crash traces via Sentry; these never include the content of your workspace documents.

2. How we use your information

  • Provide, operate, and improve the Arci platform.
  • Display analytics and insights inside your workspace.
  • Power AI-generated content and recommendations (with your explicit direction).
  • Send transactional emails (signup confirmation, billing receipts, onboarding tips).
  • Respond to support requests.
  • Detect, prevent, and address security incidents or abuse.
  • Comply with legal obligations.

We do not train AI models on your data. Your workspace content and connected Google data are never used as training data for any model, including models operated by Anthropic, OpenAI, or Google.

3. Data sharing

We do not sell your personal information. We share data only as follows:

  • Infrastructure providers — Supabase (database, EU/US), Vercel (hosting, US), Inngest (job queue), Resend (transactional email), Upstash (cache), Sentry (errors), PostHog (analytics), Stripe / Razorpay (billing). Each provider processes only what is necessary for their service.
  • AI inference — when generating content, prompts are sent to Anthropic, OpenAI, or Google. These providers are bound by data-processing agreements and may not train on API inputs.
  • Legal requirements — if required by applicable law, court order, or governmental authority.
  • Business transfers — if Arci is acquired or merged, data may transfer as part of that transaction with the same privacy commitments.

4. Data retention and deletion

We retain account data for as long as your account is active. If you delete your account, personal data is deleted within 30 days except where retention is required by law (e.g. billing records). Workspace content and encrypted connector tokens are deleted immediately upon account deletion or when you disconnect a connector.

To request deletion of your data at any time, email privacy@flares.in or use the account deletion flow in Settings → Account.

5. Security

  • All data is encrypted in transit via TLS 1.2+.
  • OAuth tokens are encrypted at rest (AES-256-GCM).
  • Row-Level Security (RLS) in Postgres ensures one organisation cannot read another’s data at the database level.
  • We conduct periodic security reviews and penetration tests.

6. Your rights

Depending on your jurisdiction you may have the right to:

  • Access the personal data we hold about you.
  • Request correction of inaccurate data.
  • Request deletion (“right to be forgotten”).
  • Object to or restrict certain processing.
  • Data portability — export your workspace from Settings → Export.

To exercise any right, email privacy@flares.in. We respond within 30 days.

7. Cookies

We use essential cookies only — for authentication sessions. No advertising or cross-site tracking cookies are used. Disabling cookies will prevent sign-in.

8. Children

Arci is not directed to children under 16. If we learn we have collected data from a child under 16 without parental consent, we will delete it promptly.

9. International transfers

Our infrastructure is primarily hosted in the United States. If you are located outside the US, your data may be processed there. We rely on Standard Contractual Clauses where required by applicable law.

10. Changes to this policy

We may update this policy. We will notify you by email or in-app banner at least 14 days before material changes take effect.

11. Contact