# Privacy Policy

> Draft — not yet reviewed by a lawyer. Not in force.

Draft of 2026-09-29 · Contact: hello@arettic.com

This policy says what [Company legal name] ("Arettic", "we"), [registered address], collects when you use arettic.com, the API, the MCP server and the dashboard, why, who sees it and how long we keep it. It covers customers, their team members and people who join the waitlist.

## 1. What we collect

- Waitlist: your email and, if you give them, your name, company and use case, plus the page or link you joined from.
- Account: your email, verified by a one-time link or by Google (which also gives us your name and a Google account ID); your phone number, verified by SMS code and used only so trial credits are granted once per person; your org's name, your agents' names and the emails of people you invite.
- Billing: billing name, address, country and tax ID or GSTIN. From the payment provider: a card fingerprint, brand, country, risk score and whether 3-D Secure was used, never the card number.
- Purchases: the inputs your agents send and the results they buy, kept encrypted with a key unique to your org for 7 days. Receipts keep hashes of inputs and results, the tool, price, outcome and refunds, not the data.
- Private benchmarks: the test sets you upload, sealed with your org's key.
- Provider claims: if you claim a provider listing, the evidence you give us.
- Webhooks: endpoint URLs and their signing secrets (encrypted).
- Connection data: the IP address and browser of each sign-in session; the IP addresses each API key is used from (to enforce your allowlist and to spot a leaked key); rate-limit counters per IP, key or session, cleared after a day.
- Logs: an API request log (route, status, timing, org and agent IDs, error code; never inputs); product events tied to your user, org or agent ID (waitlist events use a hash of your email); daily usage counters (people lookups per company are keyed by a hash of the domain, so we don't keep which companies you look up); and a log of every action our staff takes on your account, including every time stored data is opened and why.
- Website traffic: daily counts per page group, split into people, crawlers and agents by user agent. No IP addresses, no cookies, no fingerprinting.
- Messages: the emails and SMS we send you are kept in an outbox.

## 2. Cookies

Three cookies, all needed to sign in or use the dashboard, none for tracking: arettic_session, set when you sign in (HttpOnly, SameSite=Lax, 30 days or until you sign out); arettic_google, for 10 minutes during Google sign-in; and arettic_once, for 2 minutes on the dashboard page that shows a new key or secret once. There are no analytics, advertising or tracking cookies, and the site works without JavaScript.

## 3. How we use it

- To run the service: recommend, execute, check and settle purchases; receipts, approvals, disputes, budgets and alerts.
- To keep scores honest: stored inputs and results are re-checked when a pass rule or formula changes, reviewed when you dispute a charge, and sampled for the weekly audit. Every look is logged with who and why.
- To prevent abuse: one trial per email domain (or address, for free email) and per card; the blocklist; leaked-key and spending alerts; acceptable-use incidents.
- To bill you and meet tax law: invoices, credit notes and the ledger.
- To email you about your account (balance, budgets, approvals, disputes, price changes, trial expiry) and, on the waitlist, the first benchmark report and your launch invite.

We never sell your data, share it between customers, cache one customer's results for another or use them to train models. Public scores and reports are aggregates with no customer data in them.

## 4. Who we share it with

- Railway: hosts the site, API, worker and database. [Region to fill in.]
- Stripe: payments, when enabled. Stripe gets your billing details; we get the card fingerprint, brand, country and risk score.
- The data providers we resell: only the provider of the tool your agent runs receives that request's input (with fallback on, the provider of the substitute tool). A private benchmark sends your test-set inputs to the providers you pick. To check a found email we may send it to our email verifier (ZeroBounce, NeverBounce or Hunter). A provider receives nothing until one of its tools is switched on. Providers with resale terms in place today: none yet.
- Anthropic: the weekly audit reviewer, only when it is switched on. It receives the sampled input and result of a charged purchase and nothing else. [Confirm the DPA and this list cover it before switching it on.]
- Google: only if you sign in with Google.
- [Email and SMS delivery provider: to be chosen.]

We disclose data when the law requires it. [Counsel to confirm the wording.]

## 5. Where your data is stored

[To fill in: the Railway region for the database and the apps, and whether backups leave it.] Providers process each request wherever they operate.

## 6. How long we keep it

| Data | Kept for |
|---|---|
| Inputs and results of purchases | 7 days; under dispute until it's decided (at most 48 hours more); deleted within 24 hours of a deletion request |
| Private benchmark test sets | Until you delete them or ask for deletion |
| Receipts, ledger, invoices, credit notes | As accounting records [statutory period: confirm with the CA] |
| Hashes and non-personal call signals (outcome, timing, coarse segment) | Kept for scoring; they contain no inputs or results |
| Sign-in sessions | Valid 30 days, or until you sign out [expired records: purge period to decide] |
| Sign-in links and SMS codes | Valid 15 and 10 minutes, stored as hashes [expired records: purge period to decide] |
| API request log | 14 days |
| Rate-limit counters | 1 day |
| Product events, staff action and data-access logs, traffic counts, the IPs each key was used from | Kept [period: to decide] |
| Emails and SMS we sent you (outbox) | Kept [period: to decide] |
| Waitlist entry | Until you ask to be removed |
| Account and org details | While you have an account [and after: to decide] |

## 7. Your rights and controls

- Access and export: everything in the dashboard is also in the API, and receipts export as CSV and JSON.
- Deletion: an owner files a deletion request from the Team page (or the API, signed in). Within 24 hours we delete your org's stored inputs and results, its private test sets and its storage key, and email the person who asked. Receipts and billing records stay: they hold no inputs or results and we need them for accounting.
- Keys and sessions: revoke a key or sign out at any time; both take effect at once.
- Correction: change billing details on the Billing page; for anything else, email us.
- [Rights under the DPDP Act 2023 and the GDPR, the grievance officer for India and response times: to be drafted by counsel.]

## 8. Security

Inputs and results are encrypted per org (AES-256-GCM) with a key wrapped by a master key held in the host's secret store; a deletion request destroys the org's key. API keys, session tokens, sign-in links and SMS codes are stored only as hashes. Every access to stored data and every staff action is logged. The admin console is separate from the site and needs a password and an authenticator app. Provider API keys live in the host's secret store and are never logged.

## 9. Changes and contact

We may update this policy; the date at the top changes and account owners are emailed [notice period: to be decided]. Questions and requests: hello@arettic.com.

This page as HTML: https://arettic.com/privacy · Markdown: https://arettic.com/privacy.md · JSON: https://arettic.com/privacy.json
