Privacy Policy
How We Handle Your Data
This policy explains what we collect when you build on Archie, why we hold it, how long we keep it, who it goes to, and the controls you have. It applies to the Connect API, the MCP server, the SDKs, the CLI, and the developers portal.
Effective 3 June 2026 · Hey Archie
1. What We Collect
| Category | Examples | Why |
|---|---|---|
| Account | Name, work email, organization, role, sign-in provider. | Authenticate you and scope your access. |
| Credentials | API key prefixes and metadata, OAuth grants. We never store a full sk_* value after issue. | Authorize calls and let you manage keys. |
| Request content | The inputs you send and the outputs Archie produces, including uploaded documents and ledgers. | Run the work you ask for and return the result. |
| Operational | Timestamps, endpoint, status, latency, key id, workspace, correlation and trace ids. | Run the audit log, enforce limits, and debug. |
| Device and network | IP address, user agent, coarse location derived from IP. | Security, abuse detection, and rate limiting. |
2. How We Use It
- To provide the service: authenticate, authorize, run your calls, and return outputs.
- To maintain the audit log so every call is traceable back to its inputs and citations.
- To keep the service secure: detect credential abuse and spend anomalies, and enforce limits.
- To support you when you ask, and to send service notices.
- To meet legal and regulatory obligations.
3. Who We Share It With
We do not sell your data. We share it only with the processors that run the service, each under a data-processing agreement, and only as needed:
- Identity: WorkOS, for authentication and organization management.
- Model providers: to generate outputs, under terms that bar training on your content.
- Infrastructure: hosting, database, and observability providers that operate the platform.
- Connected systems you authorize: accounting systems (for example Xero or QuickBooks) only when you connect them, and only for the actions you approve.
We may disclose data where the law requires it, or to protect the service, our users, or the public.
4. How Long We Keep It
- Account and credential metadata: for as long as your access is active, then a short wind-down window.
- Request content: retained to serve the call and your audit trail, then deleted or de-identified on the schedule for your tier.
- Audit and operational logs: kept for the period needed to investigate security and meet obligations.
When you close access, we delete or de-identify your data within a reasonable period, except where we must keep a record by law.
5. Security
- Data is encrypted in transit and at rest.
- Access is scoped per organization and workspace; a leaked key is bounded by its scope and credit cap.
- Full
sk_*key values are shown once and never stored, so they cannot be retrieved or leaked from our side. - Every call writes to an audit log keyed to the credential and workspace it ran against.
6. Your Controls
- Manage and revoke keys in
Dashboard → Keys, and OAuth connections inDashboard → Connections. - Request access to, correction of, or deletion of your personal data, subject to the law that applies to you.
- Object to or restrict certain processing where the law gives you that right.
To exercise any of these, email [email protected].
7. International Transfers
We may process data in countries other than yours. Where we do, we use recognized safeguards for the transfer so your data keeps its protection.
8. Changes and Contact
We update this policy when our practices change. Material changes are dated and announced. Questions go to [email protected].