What Arkon Vault processes
- Account information such as email address, display name, password hash, role, and license status.
- Work-continuity records that you or an authorized AI create, including projects, shared visions, handoffs, decisions, and audit events.
- Connection and Sync metadata such as AI platform, activity time, approved device name, installed version, and Sync health.
- Subscription and delivery status needed to provide billing. Stripe processes payment-card details; Arkon Vault does not store them.
- Support information you choose to submit, including ticket subject, category, messages, timestamps, account contact information, status, assignment, and an audit of support actions.
Optional local Sync
Arkon Sync accesses supported AI session folders only after you install and approve it on a computer you control. It sends the resulting project records to your private vault so work can continue across devices and AI tools. You can stop or uninstall Sync at any time.
How information is used
Information is used to authenticate users, isolate private vaults, connect approved AI tools, synchronize projects, run preflight and handoff workflows, detect conflicting work, provide an audit trail, maintain security, administer subscriptions, and answer customer support requests.
Where information is stored
Hosted accounts are stored on infrastructure operated for Arkon Vault and separated by tenant and workspace controls. In a self-hosted deployment, the organization operating that deployment controls its host, backups, retention, and access policies.
Sharing and model training
Arkon Vault does not sell personal information and does not use vault content to train foundation models. Information is shared only with service providers needed to operate the service—such as hosting, Stripe billing, and configured transactional email—or when legally required. AI providers receive information only when you enable their connector and invoke a Vault tool.
Support tickets are visible only to the submitting account and authorized operator support personnel. Support representatives receive ticket and account-support metadata, not vault projects, AI conversations, passwords, credential values, or payment-card data.
Privacy-preserving product health
Continuity-health measurements use tenant-scoped aggregate events. Those events do not store prompt or query text, file paths, project IDs, handoff messages, decision text, tokens, or credentials.
First-value timing is calculated from account creation, the first preflight that surfaces useful context, and the first completed handoff between named AI tools. It uses only timestamps, context booleans, and result counts already held by your vault; no prompt or project content is added to product-health events.
Clean-user acceptance readiness reuses tenant-scoped account, connector, Sync, billing, and continuity metadata. Its downloadable report omits emails, project titles and content, paths, handoff messages, workstation names, credential names and identifiers, tokens, and secrets, and it never claims that a manual test passed.
Connection recommendations use tenant-scoped source-AI, project-status, activity-time, and successful-preflight evidence. They do not inspect prompt text, project text, file paths, tokens, or credentials, and they do not create a connection until you explicitly request setup.
Security and your choices
Arkon Vault uses password hashing, purpose-bound one-time hashed password-reset and email-verification tokens, scoped credentials, encrypted credential delivery, transport encryption, and tenant isolation. Stripe Customer Portal access requires verified ownership of the signed-in account email. A password change revokes browser sessions while leaving separately scoped AI and Sync connections intact. From the signed-in Account view, you can download a tenant-scoped JSON copy of your continuity records and account metadata; credential secrets, password hashes, sessions, one-time account-action records, workspace push keys, and billing secrets are excluded. You can also revoke AI credentials, remove team access, and uninstall Sync. No internet service can guarantee absolute security.
Retention and contact
Continuity and account records are retained while needed to provide the vault or meet operational and legal requirements. A signed-in user can submit or cancel a deletion request from Account. Submitting a request does not delete data immediately. After a request is verified and approved, active data is deleted or irreversibly de-identified within 30 days, and recovery copies age out within 30 additional days, subject to the limited records described in the Deletion Policy. Self-hosted operators set their own retention. Arkon Vault is published by Zachary Hammons, an independent developer in Ohio. For privacy questions, email support@arkoncybersecurity.com.