Privacy Policy
This policy explains what personal data aiArch processes, why, the legal basis for each use, who we share it with, and the rights you have under the EU General Data Protection Regulation (GDPR).
Who we are
aiArch is an early, in-development education product operated from the European Union (the Netherlands). The data controller responsible for your personal data is:
- Operator / data controller: Wibo van der Sluis, Amsterdam, Netherlands
- Business name: aiArch
- KvK (Dutch Chamber of Commerce) number: 50937782
- Contact: privacy@aiarch.dev
What data we process, why, and the legal basis
We keep data collection to the minimum needed to provide the service. Accounts and billing are handled by our authentication provider (Clerk); we do not store payment card details ourselves.
- Account and login. The email address used to log in and a signed session cookie that keeps you logged in. Legal basis: performance of a contract (providing you access to the platform) and our legitimate interest in securing that access.
- Newsletter. The email address you submit to receive the Weekly AI Engineering Brief and product updates. Legal basis: consent — you can withdraw it at any time by emailing us (see "Your rights" below).
- Learning activity. Your quiz attempts, mastery progress, and spaced-repetition (review-scheduling) state. We store this to provide the service, including tracking your progress, quiz results, mastery, and spaced-repetition schedule. Legal basis: performance of a contract and our legitimate interest in delivering a working learning product.
- Server logs. Standard request metadata (such as IP address, timestamp, and the page or endpoint requested) generated by our hosting provider. Legal basis: our legitimate interest in the security and reliable operation of the service.
- Analytics (only with your consent). If you accept in our cookie banner, Microsoft Clarity and Google Analytics record aggregated usage of the site (such as pages visited and interaction patterns) to help us improve it. Nothing is collected until you opt in, and you can withdraw consent at any time. Legal basis: consent. See our Cookie Policy.
- Advertising measurement (only with your consent). We run a small number of ads on Microsoft Bing. If you accept in our cookie banner, Microsoft Advertising's conversion tracking tells us which ads led to a waitlist request or a membership purchase. Nothing is loaded until you opt in; we show no third-party ads on this site. Legal basis: consent. See our Cookie Policy.
Who we share data with (subprocessors)
We do not sell your personal data. We share it only with the service providers needed to operate the platform. The full list, with region and transfer safeguard for each, is on our Subprocessors page; the ones most relevant to what we process are:
- Cloudflare — hosting, edge delivery, our D1 database, and outbound account email. The application and your session run on Cloudflare Workers; your account and learning data are stored in Cloudflare's D1 database, and your coach conversation history in Cloudflare's Durable Object storage.
- Clerk — authentication and account data (your email address, session state, and sign-in credentials).
- Stripe, via Clerk Billing — payment processing for paid plans. Card details are handled directly by Stripe and Clerk Billing; they never reach our own systems.
- OpenRouter — the AI coach feature. When the coach is enabled, messages you send to it are routed through Cloudflare's AI Gateway to OpenRouter, which passes them to the models that generate a response. Your recent messages are also sent, the same way, to an automated safety model that checks them for attempts to tamper with the coach before the coach replies. That check fails open: when it is unavailable, your message reaches the coach without being checked. In some of those cases the check is skipped before your message is sent to the safety model; in others your message has already been sent to the safety model and the result came back too slowly, failed, or was unusable. OpenRouter may serve these models via Amazon Web Services (Bedrock) or via other inference providers in its network (see Groq below).
- Anthropic — the underlying AI model provider for the coach's replies (see OpenRouter above for how your messages reach it).
- Amazon Web Services (Bedrock) — a possible serving path for the coach's underlying AI model, used by OpenRouter and Anthropic rather than by us directly.
- Groq — the current serving path for the automated safety model that screens coach messages when that check runs (see OpenRouter above). The safety model is open-weight (published by OpenAI as
gpt-oss-safeguard). Your messages do not go to OpenAI; they are processed by the inference provider OpenRouter routes to, currently Groq. OpenRouter may route to other providers in its network. - Microsoft (Clarity) — product analytics. Only if you accept analytics cookies, Clarity processes aggregated usage data so we can see how the site is used. Not loaded otherwise.
- Google (Analytics and Ads) — site analytics and, for our own ad campaigns, conversion measurement. Only if you accept analytics or advertising cookies. Not loaded otherwise.
- Microsoft (Advertising) — conversion measurement for our own Bing ads. Only if you accept in the cookie banner. Not loaded otherwise.
International transfers
Several of our processors are based in the United States: Clerk (authentication) and Stripe (payments); OpenRouter and Anthropic, which handle the AI coach feature (messages may also pass through Amazon Web Services/Bedrock; coach messages are additionally sent to the automated safety check when it runs, currently served by Groq); and Microsoft and Google, for analytics and advertising measurement (only after you consent). Learner coach messages leave the European Economic Area on this path. Each transfer outside the European Economic Area relies on an appropriate safeguard under the GDPR: the European Commission's Standard Contractual Clauses agreed with the processor, certification under the EU-US Data Privacy Framework, or both. Our Subprocessors page lists the region and the specific safeguard for each processor.
How long we keep it
- Account and learning data (quiz attempts, mastery progress, spaced-repetition state): kept while your account exists; deleting your account deletes all of it.
- Coach conversation history: deleted automatically after 12 months of inactivity, and also deleted immediately when you delete your account.
- Newsletter email: if you unsubscribe, the record is deleted 3 months after your unsubscribe date.
- Advertising click identifiers (the
gclid/msclkidvalues used to attribute a sign-up to an ad click): cleared 90 days after they are recorded. - Funnel analytics events (aggregate, non-cookie page/conversion events): deleted after 13 months.
- Server logs: retained only as long as needed for security and operational purposes, then discarded.
Your rights under the GDPR
You have the right to:
- Access the personal data we hold about you.
- Rectification — correct data that is inaccurate or incomplete.
- Erasure — delete your account and data ("right to be forgotten"). Use the Delete my account button on your Profile page for immediate self-serve deletion; it also removes your coach conversation history and newsletter record. Deleting your account from the Clerk account portal instead also triggers erasure, with one gap: if you subscribed to the newsletter separately, that path does not remove your newsletter record. Use the Delete my account button, or contact us, to be sure it is removed.
- Restriction — ask us to limit how we process your data.
- Data portability — receive your data in a portable, machine-readable form. Use the Export my data button on your Profile page for an immediate self-serve JSON download.
- Objection — object to processing based on our legitimate interests.
- Withdraw consent — where we rely on consent (for example, the newsletter), withdraw it at any time. Withdrawing consent does not affect processing that already took place.
Access, rectification, restriction, and objection can be requested by emailing privacy@aiarch.dev; erasure and data portability are also available immediately, self-serve, from your Profile page (see above), with email as a fallback. We respond within one month, as the GDPR requires; if a request is unusually complex we may take up to two further months, and will tell you within the first month if so.
Complaints
If you believe we have mishandled your personal data, you have the right to lodge a complaint with the supervisory authority. In the Netherlands this is the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens. We'd appreciate the chance to resolve it directly first — please contact us at privacy@aiarch.dev.
Changes to this policy
This is an early product and this policy may change as it grows — for example, when new features are added. We will update the "Last updated" date above when we make material changes. Related reading: our Cookie Policy and Terms of Service.