Skip to main content

Privacy Policy

Last updated:

This policy explains what personal data aiArch processes, why, the legal basis for each use, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).

Who we are

aiArch is an early, in-development education product operated from the European Union (the Netherlands). The data controller responsible for your personal data is:

What data we process, why, and the legal basis

We keep data collection to the minimum needed to provide the service. Accounts and billing are handled by our authentication provider (Clerk); we do not store payment card details ourselves.

Who we share data with (subprocessors)

We do not sell your personal data. We share it only with the service providers needed to operate the platform. The full list, with region and transfer safeguard for each, is on our Subprocessors page; the ones most relevant to what we process are:

International transfers

Several of our processors are based in the United States: Clerk (authentication) and Stripe (payments); OpenRouter and Anthropic, which handle the AI coach feature (messages may also pass through Amazon Web Services/Bedrock; coach messages are additionally sent to the automated safety check when it runs, currently served by Groq); and Microsoft and Google, for analytics and advertising measurement (only after you consent). Learner coach messages leave the European Economic Area on this path. Each transfer outside the European Economic Area relies on an appropriate safeguard under the GDPR: the European Commission's Standard Contractual Clauses agreed with the processor, certification under the EU-US Data Privacy Framework, or both. Our Subprocessors page lists the region and the specific safeguard for each processor.

How long we keep it

Your rights under the GDPR

You have the right to:

Access, rectification, restriction, and objection can be requested by emailing privacy@aiarch.dev; erasure and data portability are also available immediately, self-serve, from your Profile page (see above), with email as a fallback. We respond within one month, as the GDPR requires; if a request is unusually complex we may take up to two further months, and will tell you within the first month if so.

Complaints

If you believe we have mishandled your personal data, you have the right to lodge a complaint with the supervisory authority. In the Netherlands this is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. We'd appreciate the chance to resolve it directly first — please contact us at privacy@aiarch.dev.

Changes to this policy

This is an early product and this policy may change as it grows — for example, when new features are added. We will update the "Last updated" date above when we make material changes. Related reading: our Cookie Policy and Terms of Service.