Privacy Policy
Last updated:
1. Who we are
This policy describes how Arikano, Inc. (“Arikano”, “we”, “us”) handles personal and business information when you use the Arikano platform at arikano.com and its related APIs (the “Service”). Arikano is provided to businesses. When you use the Service on behalf of a company, that company is our customer and this policy applies to the data it entrusts to us.
2. Information we collect
2.1 Information you give us
- Account details: your name, work email address, password (stored only as a hash by our authentication provider), company name, industry, and state.
- Team members: names and email addresses of people you invite to your workspace, and the role you assign them.
- Portal credentials: usernames and passwords for third-party contractor-management platforms you connect (see Section 4).
- Compliance content: documents you upload or ask Arikano to draft, training and certification records, incident reports, insurance policies and certificates, corrective actions, deadlines, notes, and anything you type into the Arikano conversation.
- Billing details: handled by Stripe. We store your plan tier, subscription status, and Stripe customer identifiers; we never see or store full card numbers.
2.2 Information Arikano collects on your behalf
- Portal data: when a connected portal is scanned, Arikano reads your grades and scores, open requirements, document statuses, and expiration dates and stores a snapshot in your workspace so it can track changes over time.
- Regulatory context: public regulatory text (federal and state OSHA standards, platform requirements) is stored in our knowledge base and is not personal to you.
2.3 Information collected automatically
- Usage and audit logs: the actions taken in your workspace by people and by Arikano, with timestamps and the acting user, so you have an audit trail.
- Technical data: IP address, browser type, device information, and error reports needed to keep the Service secure and working.
- Cookies: we use strictly necessary cookies for sign-in sessions. We do not use advertising cookies or third-party tracking pixels.
3. How we use information
- To provide the Service: monitoring your connected portals, drafting documents, tracking deadlines, sending the alerts you configure, and answering your questions through the Arikano agent.
- To act on your behalf inside a connected portal, only for actions you or your plan have authorized (Section 4).
- To operate, secure, and improve the Service, including debugging and preventing abuse.
- To bill you and communicate about your account (invoices, security notices, service changes).
- To comply with law and enforce our Terms of Service.
We do not sell personal information, and we do not use your compliance content or conversations to train general-purpose AI models. Our model providers are contractually restricted from using API inputs to train their models.
4. Portal credentials
Connecting a portal gives Arikano the same access you have. Because of that, credentials are handled differently from every other kind of data:
- Encrypted at rest. Passwords are encrypted with AES-256-GCM before they are written to the database. The encryption key is held in application configuration, separate from the database, so a database export alone cannot reveal a credential.
- Decrypted only in use. A credential is decrypted in memory for the duration of a portal session (a scheduled scan, a verification you request, or a submission you approve) and is discarded when the session ends. It is never written to logs, error reports, or model prompts.
- Used only for your instructions. Read-only scans run on the schedule you set. Actions that change anything on a portal — uploading a document, updating a questionnaire answer — run only when your plan includes that capability and a member of your workspace with the right role has approved the action. Every action is recorded in your audit trail.
- Never shown back. Once saved, a password is not displayed in the interface or returned by any API. You can replace it or delete it at any time from Settings.
- Your responsibility. You confirm you are authorized to give us access to each portal account you connect, and you should use a dedicated portal user for Arikano where the platform allows it.
5. Who we share information with
We share information only with the service providers below (our “subprocessors”), who process it under contract and only to provide their service to us; with your own team members according to the roles you set; with professional advisers where necessary; and with authorities when the law requires it. We will notify customers before adding a subprocessor that handles customer content.
| Provider | Purpose | Data involved | Location |
|---|---|---|---|
| Supabase | Postgres database, authentication, and file storage | All account and workspace data; portal credentials only in AES-256-GCM ciphertext | United States |
| Vercel | Application hosting, edge network, scheduled jobs | Request logs, IP address, application data in transit | United States |
| DeepSeek | Primary language model for routing and drafting | Conversation and document text; never credentials or payment data | See provider terms |
| Anthropic | Language model for the Arikano agent | Conversation text, document excerpts, scanned portal content | United States |
| OpenAI | Text embeddings for the compliance knowledge base | Document and knowledge-base text for embedding | United States |
| Stripe | Subscription billing | Billing contact and payment method (held by Stripe, never by Arikano) | United States |
| Resend | Transactional email (alerts, invitations, digests) | Recipient email address and alert contents | United States |
| Browserless | Hosted browser automation for portal scans and submissions | Portal session traffic; decrypted credentials in memory only for the session | United States |
| Sentry | Error and performance monitoring, cron check-ins | Error traces and request metadata; credentials are scrubbed | United States |
| GitHub | Source control, CI, dependency alerts | Source code and CI logs only; no customer data | United States |
Language-model providers receive the text needed to answer a request: your message, relevant document excerpts, and the content Arikano read from a portal. They do not receive portal passwords, payment details, or your team's account credentials.
6. Retention
The windows below are what the system enforces today. A workspace owner can request deletion of the whole workspace from Settings; the request takes effect after a 7-day grace period during which it can be cancelled, and then every record, file, and login for the workspace is removed. We keep limited billing records (such as invoices) where tax and accounting law requires it.
| Data | Kept for | How it is removed |
|---|---|---|
| Account and workspace records | Life of the account | Deleted with the workspace (7-day grace period, then hard delete) |
| Arikano chat history | Life of the account, or until you delete the conversation | Conversation delete removes messages immediately |
| Audit logs | Life of the account (400-day pruning is opt-in) | Weekly retention sweep, per-tenant setting |
| Vault document versions | Newest 30 versions kept; older superseded versions removed after 90 days | Weekly retention sweep |
| Soft-deleted files | 30 days, then hard-deleted with the stored object | Weekly retention sweep |
| LLM usage ledger | 400 days | Weekly retention sweep |
| Portal credentials | Until you disconnect the portal or delete the workspace | Immediate hard delete |
| Database backups | Supabase point-in-time recovery window (currently 7 days) | Provider-managed; rolls off automatically |
7. Your choices and rights
- Access and correction: most information can be viewed and edited in Settings. Ask us for anything you cannot reach yourself.
- Deletion: a workspace owner can delete the whole workspace from Settings (7-day grace period, then permanent). You can also email us from the address on your account and we will handle it for you. Workspace owners can remove individual team members and connections at any time.
- Export: a full JSON export of your workspace, with download links for every file, is available from Settings and Reports at any time.
- Marketing: we send transactional email only. If we ever send marketing email, every message will include an unsubscribe link.
- Regional rights: depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR, including the right to complain to a supervisory authority. We honor those rights on request.
8. Security
We protect information with encryption in transit (TLS) and at rest, tenant isolation enforced at the database layer, role-based access within each workspace, rate limiting, security headers, and audit logging. The controls are described in detail on our Trust Center. No system is perfectly secure; if we learn of a breach affecting your data we will notify you without undue delay, targeting 72 hours from confirmation, and as required by law.
9. International transfers
Arikano is operated from the United States and our subprocessors are located there unless noted above. If you use the Service from elsewhere, your information will be transferred to and processed in the United States.
10. Children
The Service is for businesses and is not directed to anyone under 18. We do not knowingly collect information from children.
11. Changes to this policy
When we make material changes we will update the date at the top of this page and, for changes that affect how we handle customer content or credentials, notify workspace owners by email before the change takes effect.
12. Contact
Questions, access requests, and deletion requests: privacy@arikano.com. Security reports: security@arikano.com. Please write from the email address on your account so we can verify the request.