Privacy Policy

Last updated: September 2026

1. Introduction

This Privacy Policy describes how ARCY AI, a product operated by Campus Arc, Inc., a Delaware corporation (“Campus Arc,” “we,” “us,” or “the Company”), collects, uses, and protects information when Operators install arcy.js in their products and when End Users interact with what it shows them.

Two words carry most of this document. An Operator is the company that uses ARCY AI inside its own product. An End User is that company's own customer, who meets ARCY AI on the Operator's pages and has no account with us.

Personal data of data subjects in Türkiye is handled under the KVKK program described in our KVKK disclosure.

2. Information We Collect

We collect the account information an Operator provides when registering, the configuration they create in the dashboard, and the data described in the three sections below. See our Cookie Policy for cookies on our own website and dashboard.

3. What arcy.js Collects

arcy.js is the small script an Operator installs on their own pages. It sends us four kinds of information.

  • Behavioral signals. Navigation, feature usage, session depth, and interaction timing, used to understand where End Users get stuck.
  • Identity attributes the Operator chooses to send. When an Operator calls identify(), they pass a user identifier and may pass attributes such as first name, last name, email address, plan, and account value. The Operator decides which of these to send. We receive what they send and nothing more.
  • An anonymous visitor identifier when no user has been identified. This is a random value stored in the browser on the Operator's own site so a returning visitor keeps their conversation. It is not linked to a person by us, and it does not follow anyone across browsers or devices.
  • Autocapture. arcy.js observes interactions that are already happening, specifically clicks, form submissions, and page navigation, so ARCY AI can learn what each page does without the Operator annotating their own code.

Masking happens before anything leaves the browser. Values likely to be personal, including what is typed into form fields and text matching patterns for email addresses, government identifiers, and payment card numbers, are removed in the End User's own browser. What reaches us describes the shape of an interaction, for example that a button with a given label was clicked, rather than what the End User typed.

ARCY AI holds no standing credential to an Operator's product and never signs in to it.

4. Content You and Your End Users Give Us

  • Training sources. An Operator can point ARCY AI at their own public website pages, or upload documents, so the assistant can answer from them. We store the text of those pages and files, and a mathematical representation of them that makes search possible.
  • Conversations. Messages between an End User and the assistant are stored so the conversation can be continued later and so the Operator can review how their assistant is performing.
  • Images an End User attaches to a message. These are stored privately, are never reachable by URL alone, and are deleted on the schedule in Section 13.
  • Element confirmations. An Operator admin can open their own product and confirm or relabel what ARCY AI has detected about a page element. Access is issued through their existing signed-in dashboard session, is limited to admins and owners of that application, and is short-lived and single-use. Every confirmation is logged with who made it, what it affected, and when. To show an Operator their own page inside the dashboard, our servers fetch that page and display it with the assistant on top. This only works for domains the Operator has verified as theirs.

An Operator decides what an End User can send us. If a form or a page in their product contains personal data, and their End User describes it in a message or photographs it, that content reaches us the same way any other message does. Operators should tell their End Users that the assistant is there, which is what the paragraph we publish in our documentation is for.

5. How the Assistant Acts

An Operator can build a flow, a sequence of steps through their own product. The assistant may suggest a flow when an End User asks for something it covers, and when the End User chooses to run it, the flow carries out the steps the Operator authored inside that End User's own session.

The steps are always the Operator's. ARCY AI does not decide on its own to act inside a product. Where ARCY AI detects that a step no longer matches the page, it proposes a correction to the Operator and does not change anything in a live session.

6. Insights and ARCY Lift

Behavioral signals are also aggregated across an Operator's End Users to produce insights for that Operator, such as where users drop out of a flow, and a comparison called ARCY Lift between End Users the assistant helped and End Users who reached the same step without it. This analysis is for the Operator's own internal use and is separate from anything an End User sees.

Insights are generated from figures that have already been calculated, not from raw records of individual people.

7. Authentication Data

Access to the ARCY AI dashboard is managed through Clerk, which processes authentication data such as email address and login credentials on our behalf under its own privacy policy and security practices. Clerk is SOC 2 Type II certified and GDPR compliant, and we chose it in part for that posture.

8. AI Processing

All AI processing runs on AWS Bedrock inside our own European Union infrastructure, and is scoped to the Operator's own application data. Bedrock does not use data submitted through the platform to train foundation models, and no request content leaves AWS to reach a separate AI vendor.

AWS holds SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, and PCI DSS Level 1 certifications and is GDPR-ready under its GDPR compliance program. We chose AWS in part because of that baseline.

AI-generated output, including answers shown to End Users and insights shown to Operators, is produced automatically and may be wrong. It is not a substitute for the Operator's own review and judgment.

9. Billing Data

Subscriptions, checkout, and payment are handled through Clerk Billing, which uses Stripe as the underlying payment processor. ARCY AI does not store full payment card details. Stripe is a certified PCI Service Provider Level 1, the most stringent level available in the payments industry.

10. How We Use Information

We use the information described here to operate and improve the ARCY AI platform, to answer End User questions and run the flows an Operator has built, to produce insights for Operators, to process billing, and to communicate with account holders about the service. We do not sell personal information.

11. Data Sharing and Subprocessors

We share data with the subprocessors below, solely to deliver the service.

SubprocessorWhat it does
Amazon Web ServicesHosting, storage, database, and AI processing through AWS Bedrock
ClerkAuthentication, account management, and billing through Clerk Billing
StripePayment processing behind Clerk Billing
ResendTransactional email delivery
GoogleCalendar scheduling when someone books a call with us

12. International Data Transfers

Our core infrastructure, including AI processing, is hosted on Amazon Web Services in the European Union. Some subprocessors, including Clerk, Stripe, Resend, and Google, are US-based. Where data originating in the European Economic Area or another jurisdiction with transfer restrictions is processed by them, we rely on their standard contractual clauses and other lawful transfer mechanisms.

13. Data Retention

We keep data for as long as an account is active, except where a shorter window is stated below.

DataHow long we keep it
Account and configuration dataWhile the account is active
Behavioral and autocapture dataWhile the application is active. This history is what the Operator's own insights are built from, so we do not delete it on a rolling schedule
Conversations365 days
Images attached to a message30 days, after which the message remains and the image is gone

14. Deletion and Erasure

An Operator may ask us to delete their application data at any time. If an End User asks their Operator to erase their personal data, the Operator can pass that request to us.

We complete deletion requests within 30 days of receiving them. Contact us through our contact page to make one.

15. GDPR (European Economic Area)

For Operators and End Users in the European Economic Area, we process personal data on the basis of contractual necessity to deliver the platform to Operators, legitimate interest to understand where users get stuck and improve the service, and consent where required. A Data Processing Agreement is available on request by contacting us.

For End User data collected through arcy.js, the Operator is the data controller and ARCY AI acts as processor, or as sub-processor where the Operator is itself processing on behalf of its own customers. For an Operator's own account and dashboard data, ARCY AI is the controller.

16. KVKK (Türkiye)

Personal data of data subjects in Türkiye is processed in compliance with Türkiye's Law on the Protection of Personal Data No. 6698 (KVKK) by Campus Arc Teknoloji Limited Şirketi. See our KVKK Aydınlatma Metni for the full disclosure, including how to make an application under Article 11.

17. Your Rights

Depending on where you are, you may have rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing. EEA data subjects have these rights under GDPR, and Turkish data subjects have corresponding rights under KVKK Article 11. Contact us to exercise them.

18. Children's Privacy

The ARCY AI platform is a business tool for organizations and their authorized personnel. It is not directed at, and we do not knowingly collect personal information from, individuals under the age of 18 acting in a personal capacity.

19. Security

We apply reasonable technical and organizational measures to protect the data we process. No system is entirely secure and we cannot guarantee absolute security. See our Security page for detail, including how to report a vulnerability.

20. Contact

If you have questions about this Privacy Policy, please contact us through our contact page.