Privacy Policy

Last updated: July, 2026

1. Introduction

This Privacy Policy describes how ARCY AI, a product operated by Campus Arc, Inc., a Delaware corporation ("Campus Arc," "we," "us," or "the Company"), collects, uses, and protects information when Operators embed the ARCY AI SDK in their products and when End Users interact with that embedded experience.

Data subjects in Türkiye are additionally processed under the KVKK compliance program operated by our Turkish affiliate, Campus Arc Teknoloji Limited Şirketi, described in our KVKK disclosure.

2. Information We Collect

We collect account information provided during registration, workspace and application configuration data, and data generated through use of the ARCY AI platform and SDK, described in the sections below. See our Cookie Policy for details on cookies and similar tracking technologies used on our own website.

3. SDK Session and Behavioral Data

The ARCY AI SDK streams session and behavioral signals from the Operator's product, including navigation patterns, feature usage, session depth, and interaction timing. This data is used to detect struggle and churn risk in real time and is not sold to third parties.

The same session and behavioral signals are also aggregated across an Operator's End Users and analyzed on a plan-tiered schedule to produce dashboard-side product intelligence for the Operator, including activation and churn insights, revenue-at-risk and recoverable-revenue estimates, and suggested product or process improvements. This aggregate analysis is distinct from the real-time, End User-facing widget described above and is provided to the Operator for internal use.

4. Authentication Data

Account access to the ARCY AI dashboard is managed through Clerk. Clerk processes authentication data such as email address and login credentials on our behalf, under its own privacy policy and security practices. Clerk is SOC 2 Type II certified and GDPR compliant, and we chose it in part for that posture.

5. AI Processing

ARCY AI uses two distinct AI processing paths, both running within AWS infrastructure and scoped to the Operator's own application data:

  • Widget interactions — Chat, Teach, and autonomous Agent mode responses shown to End Users are generated using AWS Bedrock.
  • Dashboard-side product intelligence — the activation and churn insights, revenue-at-risk estimates, and suggested improvements described in Section 3 are generated by AWS Strands Agents running on AWS-hosted agent infrastructure, not AWS Bedrock.

Neither AWS Bedrock nor AWS Strands Agents uses Operator or End User data submitted through the platform to train underlying foundation models. Both run on AWS's global infrastructure, which holds SOC 1, SOC 2, SOC 3, ISO 27001, ISO 27017, ISO 27018, and PCI DSS Level 1 certifications, and is GDPR-ready under AWS's GDPR compliance program. We chose AWS as our infrastructure provider in part because of this certification baseline, and Operator data never leaves AWS infrastructure to reach a third-party model provider.

AI-generated output, including autonomous actions taken in Agent mode and dashboard-side insights, is produced automatically and may not always be accurate. It is not a substitute for the Operator's own review and judgment.

6. Billing Data

Where applicable, subscription and payment data is processed by Stripe, under its own privacy policy and security practices. ARCY AI does not store full payment card details. Stripe is a certified PCI Service Provider Level 1, the most stringent level of certification available in the payments industry.

7. How We Use Information

We use collected information to operate and improve the ARCY AI platform, detect and respond to churn risk on behalf of Operators, process billing, and communicate with account holders about the service.

8. Data Sharing and Subprocessors

We share data with infrastructure and processing subprocessors described in this policy, solely to deliver the service. We do not sell personal information. Our current subprocessors include:

  • Clerk — authentication and account management
  • Amazon Web Services — hosting and infrastructure, AI processing via AWS Bedrock (widget interactions) and AWS Strands Agents (dashboard-side product intelligence)
  • Stripe — payment and subscription processing
  • Resend — transactional email delivery

9. International Data Transfers

Our core infrastructure, including AI processing via AWS Bedrock and AWS Strands Agents, is hosted on Amazon Web Services in the European Union. Some of our subprocessors, including Clerk, Stripe, and Resend, are US-based. Where data originating in the European Economic Area or other jurisdictions with data transfer restrictions is processed by these subprocessors, we rely on their standard contractual clauses and other lawful transfer mechanisms to safeguard that data.

10. Data Retention

We retain data for as long as an account remains active and as needed to comply with legal obligations. Operators may request deletion of their application data by contacting us.

11. GDPR (European Economic Area)

For Operators and End Users in the European Economic Area, we process personal data on the basis of contractual necessity (to deliver the platform to Operators), legitimate interest (to detect churn risk and improve the service), and consent where required. If you require a Data Processing Agreement (DPA), one is available on request for qualifying customers by contacting us at the address below.

12. KVKK (Türkiye)

Personal data of data subjects in Türkiye is processed in compliance with Türkiye's Law on the Protection of Personal Data No. 6698 (KVKK) by our Turkish affiliate, Campus Arc Teknoloji Limited Şirketi. See our dedicated KVKK Aydınlatma Metni for the full disclosure.

13. Your Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, or port your personal information, and to object to certain processing. EEA data subjects have these rights under GDPR; Turkish data subjects have corresponding rights under KVKK Article 11. Contact us to exercise these rights.

14. Children's Privacy

The ARCY AI platform is a business tool intended for use by organizations and their authorized personnel. It is not directed at, and we do not knowingly collect personal information from, individuals under the age of 18 acting in a personal capacity.

15. Security

We implement reasonable technical and organizational measures to protect data processed through the platform. No system is entirely secure, and we cannot guarantee absolute security. See our Security page for more detail, including how to report a vulnerability.

16. Contact

If you have questions about this Privacy Policy, please contact us through our contact page.