What information we collect
Collected information may include your name, email address, authentication identifiers, organization membership, repository metadata, uploaded governance snapshots, architecture findings, scores, exceptions, policies, ownership/team/system mappings, usage analytics, billing metadata, and API token metadata or hashes.
If you contact us, we may also collect the information you submit through support, sales, partnership, or feedback requests.
How information is used
We use information to operate ArchPilot Cloud, authenticate users, manage organizations, support governance workflows, improve the product, respond to support requests, and communicate about your account or subscription.
We may also use aggregated operational information to understand product usage and improve reliability, onboarding, and feature quality.
Source code handling
ArchPilot Cloud does not directly scan repository source code as part of the hosted governance workflow. Cloud stores explicitly uploaded architecture metadata, findings, summaries, governance snapshots, and related workspace records instead.
Local validation continues to run in your environment through the ArchPilot CLI, VS Code extension, or CI workflows before upload.
Service providers
We use service providers to operate the product, including Clerk for authentication, Paddle for payments and billing, and Resend for email delivery.
These providers process information needed for their services, such as sign-in records, billing records, payment events, and transactional email delivery details.
Billing and payment handling
Billing and payment information for paid Cloud subscriptions is handled by Paddle.
ArchPilot stores the billing and subscription metadata needed to manage your organization plan, but full payment card details are handled by the payment provider.
Data security
We use reasonable administrative and technical measures to protect account, billing, and governance data stored in the product.
No system can be guaranteed perfectly secure, so you are also responsible for protecting your own accounts, tokens, and repository access.
Data deletion requests
You may request deletion of your account or organization data by contacting [email protected].
We may retain limited records where needed for billing, fraud prevention, legal compliance, or operational safety.
Contact information
Questions about this privacy policy can be sent to [email protected].
That same address can be used for support requests and privacy-related inquiries.