Running an org

Data handling and retention

What we store, for how long, encrypted with what, and how to have it deleted.

Your agents send us inputs (names, domains, emails, URLs) and buy results. This page says what we keep, how, for how long, who can see it, and how to have it deleted. The legal version is the privacy policy.

Stored inputs and results

What stays after deletion

The receipt of each purchase stays, because it is your record of what you paid: the tool, the provider, the price, the outcome, the check version, refunds, and SHA-256 hashes of the input and the result. A hash can confirm a result you still hold; it can't be turned back into the data. We also keep the outcome, timing and a coarse segment of each call (for example the task type and region) to compute scores.

Ask for deletion

An owner can ask us to delete the org's stored inputs and results, its private test sets and its storage key, on the Team page of the dashboard or with POST https://api.arettic.com/v1/orgs/{orgId}/deletion-requests (optional note). It is done within 24 hours, and we email the owner who asked when it is. Destroying the org's key makes anything encrypted with it unreadable at once. Receipts, invoices and your balance stay: they hold no inputs or results, and invoices are tax records.

curl
curl https://api.arettic.com/v1/orgs/$ORG_ID/deletion-requests \
  -H "Authorization: Bearer $ARETTIC_SESSION" \
  -H "Content-Type: application/json" \
  -d '{ "note": "End of the pilot" }'

Who sees your data

The weekly audit

Every week we sample up to 100 recently passed results per task type from the last 3 days and review them, to check that our pass rules pass the right things. The review is automated (rule-based plausibility checks today; an AI reviewer can be switched on later), and anything it is unsure about goes to a person at Arettic. It reads the stored input and result; like every other look, it is logged. Its findings feed the accuracy input of the scores; it never changes what you were charged.

Acceptable use: people lookups

To stop bulk collection of one company's staff, an org can make at most 500 people lookups (find_email, enrich_person, verify_email) per company domain per day (UTC). The request that would pass it is declined with 429 aup_limit, nothing is held or charged, and the incident is recorded for review. Counters are kept by a hash of the domain, so we don't keep a list of the companies you look up. Contact support if you have a legitimate research need.

Other data we keep

Retention
DataKept for
Stored inputs and results7 days (under dispute: until decided, at most 48 hours more); deleted within 24 hours of a deletion request
Private benchmark test setsUntil you delete them or ask for deletion
Receipts, invoices, the ledgerKept: they are your records and ours, and contain no inputs or results
API request log (route, status, timing, org and agent IDs, error code; never inputs)14 days
Rate-limit counters1 day

Where it lives

Arettic runs on Railway. The hosting region is being fixed before launch and will be named here and on the privacy policy, with the sub-processors we use. Providers process each request wherever they operate.

Updated 2026-09-30 · This page as Markdown · JSON