Privacy

What Arke knows, and what it does with it.

Arke reads your email and calendar, so this page is specific about exactly what that means. No hedging, no defined terms you have to decode.

Last updated 1 September 2026

Who we are

Arke is operated by Untitled Product, LLC, a Delaware limited liability company. When this policy says we or us, it means that company. When it says you, it means the person using Arke, and the workspace they own or belong to.

For data protection purposes we are the controller of the data described here. Our registered address is Untitled Product, LLC, 1111B S Governors Ave, STE 25972, Dover, DE 19904, United States.

You can reach a human at support@usearke.com about anything on this page.

What we collect

Account details you give us: your name, email address, and the workspaces you create. Payment is handled by Stripe, so card numbers never reach our servers.

When you connect Gmail, we read message metadata only. That means senders and recipients, subject lines, timestamps, thread identifiers, the List-Unsubscribe header we use to filter automated mail, and the short preview snippet Google returns alongside it. We do not read, request, or store the body of your emails, and we never send mail on your behalf.

When you connect Google Calendar, we read events in a window around today: roughly twelve months back and two months forward. We store titles, times, and attendees. Events with no other attendee, and very large events, are skipped.

Everything you type into Arke yourself, including notes, deals, and questions you ask the agent, is stored in your workspace.

We also keep ordinary operational logs, such as request timing and errors, to keep the service running and to debug failures.

How your data is used

Your data is used to build and maintain your relationship graph, to answer the questions you ask, and to run your account. That is the whole list.

We do not sell your data. We do not share it with advertisers. We do not use it to build profiles of people outside your workspace, and we do not combine data across customers.

Google user data, and the Limited Use rule

Arke's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

In plain terms: Google data is used only to provide and improve the features you connected it for. It is never sold, never used for advertising, and never used to train generalized artificial intelligence models. Humans do not read it, except with your explicit permission, to resolve a support issue you raised, or where the law requires it.

You can disconnect Google at any time from Settings, or revoke Arke's access directly from your Google account. When you disconnect, the data we synced from that account is deleted.

AI processing

When you ask the agent a question, the relevant parts of your workspace are sent to Anthropic to generate an answer. Anthropic processes it to return that answer and does not train models on it.

The agent reads your workspace at the moment you ask. It does not retain a separate copy of your data outside the workspace it read from.

How it is protected

All traffic runs over TLS 1.2 or better, and everything stored is encrypted at rest with AES-256.

Arke asks for read-only OAuth scopes on mail and calendar. It cannot send email on your behalf, and you can revoke its access from your Google account at any moment without asking us.

Every query is scoped to your workspace at the database layer. There are no shared caches across customers and no cross-workspace reads. A workspace is a wall, not a filter.

Who else touches your data

We use a small number of vendors to run the service. Each is here for a specific job. We do not add a vendor that touches customer data without a reason we would be comfortable explaining to you.

This list changes rarely and deliberately, and it is updated here before a new vendor starts processing anything.

VendorPurposeRegion
NeonDatabase hostingUS
CloudflareApplication hosting and CDNGlobal
AnthropicAI processing, no training on your dataUS
StripePayments; card details never reach ArkeUS

Compliance

SOC 2 Type II is not yet complete. We will publish the report here when it is, and we would rather say that plainly than display a badge nothing backs.

Arke is built to be GDPR-ready: data processing agreements are available on request, exports are self-serve, and deletion requests are honoured without a support ticket.

Where it is stored, and for how long

Your data is stored in the United States on managed infrastructure, encrypted in transit and at rest.

We keep your data for as long as your account is open. Delete a connected account and its synced data goes with it. Delete a workspace or your account and the contents are removed from production within 30 days, with backups ageing out on their own cycle after that.

Export before you delete. Notes, deals, and people leave as Markdown, CSV, or JSON from Settings.

Your rights

You can access, export, correct, or delete your data at any time, mostly without asking us. If you are in the EU, the UK, or California, you also have the right to object to processing, to request a copy of your data in a portable form, and to complain to your local regulator.

We honour deletion requests without requiring a support ticket, but if you would rather ask a person, write to support@usearke.com. We answer within a few days.

Cookies

Arke sets a session cookie so you stay signed in. That one is required for the product to work at all.

Anything optional, such as product analytics that would tell us which features get used, is off unless you accept it in the cookie notice. You can change your mind by clearing the choice in your browser.

Reporting a security problem

If you find a vulnerability, write to support@usearke.com. We acknowledge within 48 hours, keep you updated while we fix it, and credit researchers who report responsibly.

Please do not test against other customers' data. Ask us and we will set you up with a trial workspace to work in.

Children

Arke is a business tool and is not intended for anyone under 16. We do not knowingly collect data from children.

Changes to this policy

If we change how data is handled in a way that affects you, we will update this page and say so in the product before the change takes effect. The date at the top always reflects the current version.