Skip to content
arnict

Legal · privacy

Privacy Policy

A precise account of what Arnict collects, what it never stores, why retained data exists, and when it is deleted.

Effective August 11, 2026 · Version 1.1

Prompts and completions: zero retention.

View the plain-language ZDR summary →

1. Scope

This policy explains how Arnict, Inc. (“Arnict”, “we”) handles information across the website, account system, dashboard, support channels, and API. It applies to visitors, account holders, and API users.

Production inference is not live as of this policy date. The API-content commitments below govern production requests when inference becomes available.

2. Zero Data Retention for API content

Arnict does not retain API prompts or completions. Request content is held only in transient memory for the time needed to produce and return a response. When a request ends—whether by success, error, timeout, or disconnect—the prompt and completion content are discarded.

Prompt and completion content is not written to application logs, databases, usage records, or backups. It is not available for later retrieval by Arnict or the customer.

Arnict does not use API content for model training, fine-tuning, evaluation, human review, advertising, or sale. Arnict does not forward API content to a third-party inference provider.

3. Operational API metadata

Arnict records the minimum operational metadata needed to authenticate requests, administer allowances, show usage, investigate reliability or abuse, and calculate billing: account and API-key identifiers, model identifier, input, cached-input and output token counts, latency, request status, timestamp, and equivalent cost.

Operational metadata does not contain prompt text, completion text, uploaded content, or a derived copy of that content.

4. Account and support data

Account records include your email address, authentication records, plan intent, referral attribution, API-key hashes and prefixes, allowance records, and timestamps. Password handling and sessions are provided through the account infrastructure; Arnict does not store plaintext passwords.

Support messages may include your name, email address, message, and any information you choose to send. Do not include API keys, passwords, prompts, completions, or other secrets in support messages.

5. Website and analytics

Arnict uses essential cookies for authentication and session security. The public website does not use customer API content for analytics and does not build advertising profiles from website activity.

If first-party product analytics are introduced, this policy will be updated before they are used to describe the event data collected and its retention period.

6. Payments

The payment gateway and paid-balance top-ups are not connected as of this policy date. Arnict does not currently collect card numbers or bank credentials. Before paid billing begins, this policy will identify the payment processor and the data it handles. Arnict will not store full payment-card details.

7. Service providers and hosting

Supabase provides account authentication and database infrastructure and may process account, support, key, and operational metadata on Arnict's behalf. API prompt and completion content is excluded from those records.

Kimi K3 production inference is planned for Arnict-operated US-based servers. Arnict does not use a third-party inference API to serve the model. Any new provider that materially changes these boundaries will be disclosed before use.

8. Retention schedule

API prompts and completions: zero retention; discarded when the request ends.

Account records: retained while the account is active, then deleted or anonymized within 30 days after a verified deletion request, except records that must be kept for security, fraud prevention, dispute resolution, or law.

Operational API metadata: retained for up to 24 months, then deleted or aggregated so it no longer identifies an account, unless a longer period is legally required for a transaction or dispute.

Support messages: retained for up to 12 months after the last interaction. Authentication and security-event logs, excluding API content, are retained for up to 90 days unless needed to investigate an active incident.

9. Security

API-key secrets are stored as hashes and the full key is shown only at creation. Sessions use httpOnly cookies. Access to account data is restricted by authentication and database access controls; administrative access is limited to operational need.

No system is perfectly secure. If Arnict identifies a security incident affecting personal information, it will investigate and provide legally required notice. Because API content is not retained, stored prompt and completion archives are not part of Arnict's data inventory.

10. Your choices and rights

You may access account information in the dashboard, revoke API keys, and request access, correction, deletion, or a copy of personal information associated with your account. Arnict will verify the request and respond as required by applicable law.

Send privacy requests to support@arnict.com. Arnict may retain limited information needed to document and complete the request or meet legal obligations.

11. Changes and contact

Material changes will be dated and presented before they take effect where required. A change to the Zero Data Retention boundary will not be applied retroactively to content that was already processed under this policy.

Questions about privacy, security review, or this policy: support@arnict.com.