Privacy Policy
Last updated: April 26, 2026
Important
This policy explains how we handle personal data in connection with the Archivr service (archivr.cloud). It is not legal advice. Laws differ by country and sector; have qualified counsel review this document and your data flows before you rely on it for compliance.
1. Who is responsible
The service is operated as Archivr (“we,” “us”). For privacy requests, contact hello@archivr.cloud. If another legal entity formally operates the product in your region, we will identify that entity here when applicable.
2. What we process
- Account and profile: Information from your authentication provider (for example name, email address, user identifier) when you sign up or sign in.
- Service usage and configuration: Settings you create in the product (for example silos, storage connections, allowlisted email addresses, preferences).
- Content you connect or send: Files and metadata from linked cloud storage (for example Google Drive), and documents or messages you forward or route to silo email addresses, including attachments and technical message data needed to ingest and display them.
- Billing: If you subscribe to a paid plan, our payment processor receives and processes payment-related data; we typically receive limited billing metadata (for example subscription status, customer reference).
- Support and security: Information you send when you contact us, plus logs and technical data used to operate, secure, and improve the service (for example IP address, device/browser type, timestamps, error logs), subject to retention limits and minimization.
3. Purposes and legal bases (EEA/UK reference)
Where the GDPR or UK GDPR applies, we rely on appropriate legal bases such as: performance of a contract (providing the service you request); legitimate interests (for example security, fraud prevention, product improvement, and internal analytics), balanced against your rights; consent where required (for example certain cookies or optional marketing); and legal obligation where we must retain or disclose information by law.
4. Subprocessors and integrations
We use vetted service providers to run Archivr. They process data only on our instructions and under appropriate agreements, where required. Non-exhaustive examples:
- Authentication (for example Clerk) for sign-in, session security, and account management.
- Cloud infrastructure and database hosting the application and stored product data.
- Email delivery and inbound parsing (for example Mailgun or comparable providers) to receive and process messages sent to silo addresses.
- Payments (for example Stripe) for subscriptions and invoicing.
- Third-party storage APIs (for example Google Drive) when you connect a storage; their processing is also governed by your relationship with that provider and their terms.
- AI or ML providers if you use features that generate summaries or other model outputs; inputs and outputs may be processed by those systems according to our configuration and their terms.
We may update this list as vendors change. For enterprise customers, a dedicated subprocessor notice or DPA may apply.
5. International transfers
Our providers may process data in the United States, the European Economic Area, the United Kingdom, and other regions. Where required, we use appropriate safeguards (for example Standard Contractual Clauses) and assess transfer impact. You may request further information using the contact above.
6. Retention
We keep personal data only as long as needed for the purposes in this policy, unless a longer period is required by law. Account data is retained while your account is active. Content you store in the product is retained until you delete it or close your account, subject to backup and technical deletion cycles. Logs may be kept for a shorter period.
7. Security
We implement technical and organizational measures appropriate to the risk (for example access controls, encryption in transit, separation of environments). No method of storage or transmission is completely secure; we encourage strong passwords and safe handling of forwarding addresses and API credentials.
8. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. You may also withdraw consent where processing is consent-based, and lodge a complaint with a supervisory authority. To exercise rights, contact hello@archivr.cloud. We may need to verify your request.
9. Cookies and similar technologies
We and our vendors may use cookies, local storage, and similar technologies for authentication, security, preferences, and (where applicable) analytics or referral tools. You can control many cookies through your browser. Essential cookies may be required for the service to function.
10. Children
Archivr is not directed at children under the age where parental consent is required in your jurisdiction. We do not knowingly collect personal information from children.
11. Changes
We may update this policy to reflect product, legal, or operational changes. We will post the revised version with a new “Last updated” date. Where required, we will provide additional notice.