Reference
Data and Security
Holarch on the web keeps projects on the Holarch server. Only members of a project can open it, each with a role.
Where data lives
- Projects: in the server's database, saved about half a second after each edit. Every request needs a signed-in account; a project you are not a member of answers as if it did not exist.
- Deleted projects stay in the server's Trash for 30 days, then they are deleted for good. Only owners delete projects.
- In this browser: interface settings, saved My Queries, AI reference files, Ask AI history and a cached copy of the projects you open. Signing out removes the cached projects.
- Not for regulated data: see Data You Must Not Store Here.
Backups and earlier versions
- Earlier versions: the last 20 saves and one save per day for 30 days are kept automatically. Choose Restore Earlier Version… in the project menu of the top bar or in the project's row menu in Manage Projects.
- Your own copy: export a project (Export this project… in the project's row menu in Manage Projects).
- Changed on the server: when another member saves the open project first, Holarch asks whether to load the version on the server or keep this window's version. The version you do not keep stays under Restore Earlier Version.
- Save status in the top bar: Saved, Saving… or Not saved — retrying. When neither the server nor the browser can be written, a notice says “Changes are not saved. Do not close this page.” with Retry and Download a copy.
Access
- Accounts, sessions and passwords: Signing In and Your Account.
- Members and roles: Sharing and Roles.
Imports
- Imported files are validated and sanitized: SVG pictures lose scripts, event handlers and external references; rich text loses scripts and unsafe links.
- CSV exports neutralize spreadsheet formulas.
What is sent to AI providers
- Only when you use an AI feature, and only to the provider of the AI key in use (yours or your organization's): Anthropic, OpenAI, Google or an Azure OpenAI resource. The request goes from the Holarch server to that provider.
- The text the feature needs: for a requirement tool, that requirement and its context; for Ask AI, the question, help topics, the project's entities and relationships (names, numbers, descriptions, attributes), the current page and recent conversation; plus the active AI reference files.
- Holarch stores no prompts or replies; it records time, key, token counts and result for usage and limits. AI keys are encrypted on the server and never sent to the browser.
- AI is blocked for projects marked CUI, ITAR, EXPORT CONTROLLED, SECRET or similar. See Which AI Key Is Used and How AI Handles Untrusted Content.