Legal
Privacy Policy
Draft — under review. Not yet in effect. This text is published for review. It applies to no one until it is final and dated.
Last updated: [DATE]
1. About this policy
This policy explains what personal information Angry Pixie Electronics LLC, a [STATE] limited liability company (“we”, “us”), collects through the Holarch website at holarch.app and the Holarch application at app.holarch.app (together, the “Service”), and what we do with it. It does not cover copies of Holarch that an organization runs in its own environment; that organization is responsible for them.
2. Summary
- We collect what we need to run your account and your projects, and to keep the Service secure.
- We do not sell your information, show ads, or use advertising trackers or analytics.
- The Service uses one cookie: the sign-in session cookie.
- We do not use your content to train AI models. AI requests go only to the provider of the key in use: your own key, your organization's key, or on paid plans the key that provides the included AI allowance.
- Payments are handled by Paddle. We never receive your card number.
- You can export your projects, correct your account details, and delete your projects and your account.
3. What we collect
Account information
- Your name and email address.
- Your password, stored only as a one-way hash (argon2id). We cannot read your password.
- The time and version of your acknowledgement that you will not store regulated information (CUI, ITAR/EAR or classified).
- Invitations you send or receive: the email address invited, who invited it, and the project and role.
Sign-in sessions
- A random session identifier in a cookie. We store only a hash of it.
- For each session: when it started, when it was last used, the IP address and the browser’s user agent. The account page shows your sessions so you can end them.
Your content
- Projects, models, documents, diagrams, whiteboards, comments and settings you create, their earlier versions, and who changed what.
- Files you upload, such as attachments, images and clipart.
- Project membership and roles.
AI keys and AI usage
- API keys you add for an AI provider, stored encrypted. Only the last four characters are shown after you add a key.
- For each AI request: the time, account, project, provider, model, type of task, token counts, duration, result status and an estimated cost. We do not log the text of your prompts or the AI’s answers.
Logs
- Web server logs: IP address, time, requested address, response status and user agent for each request. Sign-in tokens are removed from logged addresses, and cookies are not logged.
- Application logs: request path, status and timing, without IP addresses, used to find errors.
- Security and audit log: security-relevant actions, such as sign-ins, sharing changes, AI key changes and project exports, with the account, time and IP address. It never contains prompt text or key material.
Contact form
- Your name, email address, organization (optional), topic and message. The form sends them to us by email; they are not stored in the application database. Your IP address is used briefly to limit how many messages can be sent.
Billing information
- When you start a paid plan, Paddle collects your payment and billing details (card or other payment method, billing address, tax ID if you give one) as Merchant of Record, under its own privacy notice.
- We receive from Paddle your subscription status, plan, number of seats, billing period, country, email address and Paddle customer and subscription identifiers. We do not receive card numbers.
Emails we send
- We send only service emails, such as invitations, email verification, password reset and account notices. We do not send marketing email without your consent.
4. How we use it
- To create and run your account, sign you in, and keep you signed in.
- To store, sync, share and back up your projects, and to run the features you use.
- To make AI requests you start, with the key you chose, and to show you your AI usage.
- To keep the Service secure: detect and stop abuse, enforce rate limits, investigate incidents and show you your sign-in history.
- To answer your messages and support requests.
- To send service emails and notices about changes to the Service, these policies or a security incident.
- To meet legal obligations.
We do not use your content for advertising, profiling or training AI models. We look at a project’s content only when you ask for support and allow it, when needed to investigate abuse, a security problem or a breach of the Terms of Use, or when the law requires it.
5. Cookies and browser storage
- The application sets one cookie,
__Host-holarch_session, to keep you signed in. It is strictly necessary, cannot be read by scripts, is sent only over HTTPS, and expires after 14 days without use or 90 days at most. Signing out ends it. - The application keeps your preferences and a copy of the projects you open in your browser’s local storage, so it loads faster and can work offline. Signing out removes the project copies.
- The holarch.app website sets no cookies and runs no scripts.
- We use no analytics, advertising or third-party tracking cookies, scripts, fonts or pixels.
6. AI providers
AI features use an API key: one that you or your organization add, or on paid plans and trials Holarch’s own key for the included AI allowance ([INCLUDED AI PROVIDER]). When you start an AI request, the content needed for it (for example, the selected requirements or part of a model) is sent to the provider of that key: Anthropic, OpenAI, Google or Microsoft Azure OpenAI. The provider processes it under its own terms and privacy policy and your agreement with it. Check those terms, including whether the provider keeps or trains on API data. No content is sent to any AI provider unless you start an AI feature, and projects marked as regulated information are blocked from AI.
7. Who we share information with
We share personal information only:
- with the service providers below, which process it for us to run the Service;
- with the AI provider you choose, when you start an AI request;
- with people you share a project with, who see its content and the names and email addresses of its members;
- when the law requires it, or to protect the rights, safety or security of users, the public or us; and
- with a successor if the Service is sold or merged, under this policy.
We do not sell personal information and do not share it for advertising.
| Provider | Purpose | Data | Location |
|---|---|---|---|
| DigitalOcean, LLC | Hosting: application server, managed database, file storage and backups | All data described in section 3, except contact-form messages | United States |
| Resend | Sending service emails and contact-form messages | Recipient email address, name, email content; contact-form fields | United States |
| Paddle.com Market Limited (Paddle) | Merchant of Record for paid plans: checkout, payment processing, tax, invoicing and refunds | Payment and billing details you give Paddle; your email address and plan | United Kingdom and the processors Paddle uses |
| AI provider you choose: Anthropic, OpenAI, Google or Microsoft (Azure OpenAI) | AI features, only when you start them, under your own key | Content you send in the AI request | Per the provider and, for Azure, the region you configure |
8. How long we keep it
| Data | Kept |
|---|---|
| Account information | Until you delete your account |
| Projects | Until you delete them. Deleted projects stay in the Trash for 30 days, then are deleted. Deleting your account deletes the projects only you belong to at once. |
| Earlier project versions | The 20 newest, plus one a day for 30 days |
| Uploaded files | Until no project uses them, then 30 days |
| Backups | Expire within 30 days |
| Sign-in sessions (with IP and user agent) | Until you sign out or the session expires (at most 90 days) |
| Web server logs | 30 days |
| Security and audit log | 1 year |
| Subscription records (plan, status, billing country, Paddle identifiers) | While you have an account, and longer where tax or accounting law requires: [BILLING RETENTION] |
| AI usage records | [AI USAGE RETENTION] |
| Contact-form messages | [CONTACT RETENTION], or sooner on request |
We may keep information longer when the law requires it or to resolve a dispute or investigate abuse.
9. Your choices and rights
- Access and export: export any project you can open as a project file (JSON). Ask us for a copy of other personal information we hold about you.
- Correct: change your name, email address and password on the account page.
- Delete: delete projects, or delete your account on the account page. You can also ask us to delete your information.
- Sessions: see your sign-in sessions and end them on the account page.
- AI: remove your AI keys at any time. Without a key, nothing is sent to an AI provider.
Send requests through the contact form (topic “Support”). We may need to confirm your identity first. We answer within 30 days. We do not treat you differently for using these rights.
10. Visitors from the EEA, UK and Switzerland
If data protection laws such as the GDPR apply to you, we are the controller of your personal information, and we rely on these legal bases:
- Contract: to provide the account and the features you use.
- Legitimate interests: to keep the Service secure, prevent abuse, and answer messages.
- Legal obligation: where the law requires us to keep or disclose information.
- Consent: where we ask for it. You can withdraw consent at any time.
You have the right to access, correct, delete, restrict or object to the processing of your personal information, and to data portability. You can also complain to your local data protection authority.
11. Where your information is stored
We are based in the United States, and the Service is hosted in the United States. If you use the Service from another country, your information is transferred to, stored and processed in the United States, where data protection laws may differ from those where you live. Where the law requires it, we use appropriate safeguards for these transfers.
12. Students and schools
When a school or instructor uses the Service for a class, student work in the Service can be an education record under the U.S. Family Educational Rights and Privacy Act (FERPA). We then act as a service provider to the school: we use student records only to provide the Service, under the school’s direction, and do not use them for advertising or sell them. The school remains responsible for its FERPA obligations. Students and parents should send requests about education records to the school; we help the school answer them.
13. Children
The Service is not for children under 13, and we do not knowingly collect personal information from them. If we learn that a child under 13 has an account, we delete the account and its information. If you believe this has happened, contact us.
14. Security
We protect your information with measures that include:
- HTTPS for every connection, and encrypted, certificate-verified connections to the database;
- passwords stored only as argon2id hashes;
- AI keys encrypted, never shown again after you add them, and never written to logs;
- roles for each project, sessions you can end on every device, invite-only sign-up and rate limits;
- nightly database backups, with restores tested automatically every week.
The Service does not hold security certifications or government authorizations such as SOC 2, ISO 27001 or FedRAMP. No online service is completely secure. If we learn of a security incident that affects your personal information, we will notify you by email without undue delay and as the law requires. See the Security page for more.
15. Changes to this policy
We may update this policy. For material changes, we will notify you by email or in the app before they take effect. The “Last updated” date shows when this page last changed.
16. Contact
Angry Pixie Electronics LLC
[ADDRESS]
Send privacy questions and requests through the contact form.