Last updated: 10 September 2026
Arcus AI ("Arcus", "we", "us") is an AI workspace that gives you access to frontier language models. This policy explains what we collect, why, and the choices you have. We keep it plain because your data deserves plain answers.
When you create an account we collect your email address and authentication credentials. Authentication is handled through our identity provider (Supabase); passwords are salted and hashed and never stored in plaintext.
We process the messages, prompts, files, and documents you submit so the service can generate responses, run tools, and build artifacts (charts, diagrams, documents, code). Files you upload for retrieval are indexed to power search and citations within your own projects.
If you use the memory feature, facts and preferences you explicitly save are stored so Arcus can recall context across sessions. Memories are editable and deletable by you at any time.
We record operational metadata — request timestamps, model routing, token counts, rate-limit counters, error traces, and coarse device/browser information — to run, secure, and improve the service.
We do not sell your personal data, and we do not use the content of your conversations to train our own foundation models.
Arcus routes prompts to third-party model providers (which may include OpenAI, Anthropic, Google, DeepSeek, xAI, Meta, and others) to generate responses. Your prompt content is transmitted to the selected provider solely to produce your response, subject to that provider's terms. Web-grounding features fetch public pages through our own private search and crawling infrastructure.
We rely on the following categories of subprocessors: cloud hosting (Vultr), authentication (Supabase), model routing, and content-delivery/edge security (Cloudflare). Each processes data only as needed to deliver the service.
Your data is stored on dedicated infrastructure we operate. We apply industry-standard safeguards: encrypted transport (TLS), short-lived access tokens with rotating refresh tokens, per-user access controls with ownership checks, server-side request forgery protection on outbound fetches, and secret redaction in logs. No system is perfectly secure, but we work to protect your data proportionate to its sensitivity.
Conversations, projects, files, and memories are retained until you delete them or delete your account. Operational logs and traces are retained for a limited period for security and reliability, then aged out.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. Contact us to exercise them.
Arcus is not directed to children under 13 (or the minimum age of digital consent in your jurisdiction), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will delete it.
Your data may be processed in regions where we or our subprocessors operate. By using Arcus you consent to such transfers, carried out with appropriate safeguards.
We may update this policy as the service evolves. Material changes will be reflected in the "Last updated" date above, and where appropriate we will notify you in-app.
Questions or requests about this policy or your data: [email protected].