Privacy Policy
Last updated October 1, 2026
- We collect what's needed to run Archreactor: your account, your diagrams and prompts, usage and payment status.
- We never sell your data or use it for ads, and your content isn't used to train AI models.
- Prompts go to AI providers whose terms don't allow training on them.
- Payments go through Razorpay; we never see your card details.
- Ask us any time to see, fix or delete your data.
The full text below is what applies; the summary is a guide.
01Who we are
Archreactor is operated by registered business name, registered address. We decide how your personal data is used for the Service (under India's Digital Personal Data Protection Act, 2023 we are the “data fiduciary”; under the GDPR, the “controller”). Questions: privacy@archreactor.app.
02What we collect
- Account details: your name, email address and profile picture, from the sign-in method you choose (email, Google, GitHub or Microsoft).
- Your content: diagrams, the prompts and chat messages you send to the AI, walkthrough captions, share links and the files you export.
- Usage and technical data: how many AI credits you've used, and server logs (IP address, browser, the requests made, errors) that keep the Service running and secure.
- Payment details: payments go through Razorpay. We receive the payment's status, amount, date and reference, never your full card number, bank login or UPI PIN.
- Messages you send us, such as support or refund requests.
03How we use it
- to run the Service: sign you in, store and draw your diagrams, generate diagrams and walkthroughs with AI, create exports and share links;
- to bill paid plans and keep count of AI credits;
- to keep the Service secure and fair, including detecting abuse such as several accounts used to collect free credits;
- to answer your messages and send service emails (receipts, notices of changes to plans or these policies);
- to understand and improve the product from aggregated usage (for example, how often exports fail), and to meet legal obligations.
We don't sell your data, don't use it for advertising, and don't use your content to train AI models. We process it because you asked for the Service (our contract with you), with your consent where that's needed, and for the legitimate uses the law allows (such as security and preventing fraud).
04AI processing
When you use an AI feature, we send your prompt and the parts of the current diagram it needs (names, types, connections, descriptions) to one of these providers, which return the result. We send them as little as the task needs and never your account details.
| Provider | Used for | Training on your data |
|---|---|---|
| Google (Gemini API, paid tier) | Generating and editing diagrams | Not allowed under its paid-service terms |
| Groq | Generating and editing diagrams | Not allowed under its services agreement |
| Anthropic (Claude API) | Generating and editing diagrams | Not used for training by default under its commercial terms |
These providers may keep requests for a limited time to operate their service and prevent abuse, under their own terms.
07How long we keep it
- Account details and your content: while your account is open. When you ask us to delete your account, we delete them within 30 days.
- Exported files: deleted automatically 30 days after they're created.
- Payment records: as long as tax and accounting law requires (in India, generally 8 years).
- Server logs: kept briefly for security and troubleshooting, then deleted.
08Where it's processed
Some of our providers, including the AI providers, process data outside India (mainly in the United States). We use providers that protect it under contract, and transfer data only as the law allows.
09Security
Data travels over encrypted connections (HTTPS), access to it is limited to what's needed to run the Service, and payment details never reach our servers. No system is perfectly secure; if a breach affects your personal data, we'll tell you and the authorities as the law requires.
10Your rights
You can ask us to: access or get a copy of your personal data; correct it; delete it or your account; withdraw consent you've given (this doesn't affect what we did before); and, under the DPDP Act, nominate someone to exercise these rights for you. If you're in the EU or UK you also have the GDPR rights to object, restrict processing, data portability, and to complain to your data protection authority.
Write to privacy@archreactor.app from your account's email address. We reply within 30 days. If you're not satisfied, contact our Grievance Officer (below), and you can then complain to the Data Protection Board of India.
11Children
The Service isn't for anyone under 18, and we don't knowingly collect their data. If you think a child has given us data, tell us and we'll delete it.
12Changes to this policy
If we make material changes, we'll tell you by email or in the Service before they apply. The date at the top shows the latest version.
13Contact and Grievance Officer
Privacy questions: privacy@archreactor.app. Grievance Officer: name, grievance@archreactor.app. See also our Terms of Service.