← Dashboard Plans & billing
Arkon Vault

Private by default

Arkon Vault privacy policy

Applies to the hosted Arkon Vault dashboard, MCP connectors, and Arkon Sync.

Last updated: August 2, 2026

What Arkon Vault processes

  • Account information such as email address, display name, password hash, role, and license status.
  • Work-continuity records that you or an authorized AI create, including projects, shared visions, handoffs, decisions, and audit events.
  • Connection and Sync metadata such as AI platform, activity time, approved device name, installed version, and Sync health.
  • When you separately install and approve Arkon Sync, session-derived project records that can include a project title, a brief summary derived from session metadata or the first user message, AI platform, last-active time, message count, working directory, deep link, and external session identifier.
  • Subscription and delivery status needed to provide billing. Stripe processes payment-card details; Arkon Vault does not store them.
  • Support information you choose to submit, including ticket subject, category, messages, timestamps, account contact information, status, assignment, and an audit of support actions.

Optional local Sync

Arkon Sync is separate Windows software. It accesses supported local AI session folders only after you install it and approve a private-vault connection on a computer you control. It sends the limited session-derived project records described above to Arkon Vault's servers, where they are stored in your tenant-isolated private vault so work can continue across devices and AI tools. Arkon Sync does not upload complete raw transcripts or full assistant responses. You can stop or uninstall Sync at any time.

The MCP connector itself receives only content deliberately supplied to a Vault tool. It does not automatically ingest the surrounding Claude, ChatGPT, or other AI conversation, cannot read local files, and cannot start Arkon Sync. The MCP vault_sync action refreshes Arkon Vault's server-side continuity index and any configured Notion mirror.

How information is used

Information is used to authenticate users, isolate private vaults, connect approved AI tools, synchronize projects, run preflight and handoff workflows, detect conflicting work, provide an audit trail, maintain security, administer subscriptions, and answer customer support requests.

Where information is stored

Hosted accounts are stored on infrastructure operated for Arkon Vault and separated by tenant and workspace controls. In a self-hosted deployment, the organization operating that deployment controls its host, backups, retention, and access policies.

Sharing and model training

Arkon Vault does not sell personal information and does not use vault content to train foundation models. Information is shared only with service providers needed to operate the service—such as hosting, Stripe billing, and configured transactional email—or when legally required. AI providers receive information only when you enable their connector and invoke a Vault tool.

Support tickets are visible only to the submitting account and authorized operator support personnel. Support representatives receive ticket and account-support metadata, not vault projects, AI conversations, passwords, credential values, or payment-card data.

Privacy-preserving product health

Continuity-health measurements use tenant-scoped aggregate events. Those events do not store prompt or query text, file paths, project IDs, handoff messages, decision text, tokens, or credentials.

First-value timing is calculated from account creation, the first preflight that surfaces useful context, and the first completed handoff between named AI tools. It uses only timestamps, context booleans, and result counts already held by your vault; no prompt or project content is added to product-health events.

Clean-user acceptance readiness reuses tenant-scoped account, connector, Sync, billing, and continuity metadata. Its downloadable report omits emails, project titles and content, paths, handoff messages, workstation names, credential names and identifiers, tokens, and secrets, and it never claims that a manual test passed.

Connection recommendations use tenant-scoped source-AI, project-status, activity-time, and successful-preflight evidence. They do not inspect prompt text, project text, file paths, tokens, or credentials, and they do not create a connection until you explicitly request setup.

Public-site action counts

The public Arkon website records a daily aggregate count only when someone deliberately selects one of five actions: open Vault, review plans, open the ChatGPT plugin, open the Claude connector, or start a design-partner email. Arkon does not store a raw event, unique visitor identifier, IP address, user agent, referrer, cookie, fingerprint, advertising identifier, project content, or session content with these counts.

The server keeps only the action name, calendar date, and aggregate count for up to 400 days. Short-lived IP processing is used in memory at the website proxy solely to rate-limit abuse; the action endpoint disables access logging and strips forwarded network and browser headers before the count reaches Arkon Vault. These totals are directional product signals, not individual tracking or marketing attribution. Because no person or account is attached to a count, an individual count cannot be viewed, exported, or deleted as a personal record.

Security and your choices

Arkon Vault uses password hashing, purpose-bound one-time hashed password-reset and email-verification tokens, scoped credentials, encrypted credential delivery, transport encryption, and tenant isolation. Stripe Customer Portal access requires verified ownership of the signed-in account email. A password change revokes browser sessions while leaving separately scoped AI and Sync connections intact. From Account → Your data, you can download a tenant-scoped JSON copy of your continuity and Sync-derived project records; credential secrets, password hashes, browser sessions, one-time account-action records, workspace push keys, and billing secrets are excluded. The same area lets you submit or cancel a verified deletion request. You can also revoke AI credentials, remove team access, and uninstall Sync. Uninstalling Sync stops future uploads but does not delete records already stored in Arkon Vault. No internet service can guarantee absolute security.

Retention and contact

Continuity and account records are retained while needed to provide the vault or meet operational and legal requirements. A signed-in user can submit or cancel a deletion request from Account. Submitting a request does not delete data immediately. After a request is verified and approved, active data is deleted or irreversibly de-identified within 30 days, and recovery copies age out within 30 additional days, subject to the limited records described in the Deletion Policy. Self-hosted operators set their own retention. Arkon Vault is published by Zachary Hammons, an independent developer. For privacy questions, email support@arkoncybersecurity.com.

Arkon Vault · AI Work Continuity Platform Terms Deletion Dashboard Plans & billing Support