Arkyvst Privacy Policy
Last updated: July 25, 2026
This policy describes what information Arkyvst collects, how we use it, and the choices you have. It applies to the Arkyvst Chrome extension, our website, and any related services we offer (collectively, "Arkyvst" or "the service").
The data controller for Arkyvst is Tosch Roy, sole proprietor. You can reach us at info@arkyvst.com for any privacy question, request, or concern.
In plain English
We built Arkyvst to be a thin layer over your own Google Drive. We hold only the data needed to make the product work, and most importantly, we never read or store the contents of your Drive files. To make your tags searchable across your devices and shareable with teammates, the tags you create — and basic file details like each file's name and type — are stored in our database, scoped to your workspace so only you and the teammates you invite can see them. We also collect a small set of anonymous, content-free usage events (like "3 tags added") to see which features get used — with no file names, tag text, or search queries ever included, and a Settings toggle to switch it off.
The rest of this policy explains exactly what that means.
What we collect
1. Information you give us when you sign in
When you sign in with Google to enable cross-device sync, we receive (from Google) and store:
- your email address
- your display name
- a unique identifier for your account
- the avatar URL associated with your Google profile
This is stored in our database (Supabase) so we can recognize you across devices and apply your subscription tier to your account.
2. Workspace data you create
Arkyvst lets you build a library of "saved tags" and "tag categories" that appear as quick-add chips in the sidebar. These are stored in our database, scoped to your workspace (org). If you invite teammates later, they'll see the same library.
This includes:
- the text of each saved tag
- the name, color, and ordering of each category
- which tags belong to which category
- timestamps for when entries were created or modified
When you tag a file, we also store that file's tag associations in our database, scoped to your workspace:
- the file's Google Drive identifier and the tags you've applied to it (or a marker that you reviewed it without adding tags)
- basic file details — the file's name and type — kept alongside the tags so your file list and search are instant without re-querying Drive each time
- timestamps for when the tags were created or modified
If you use Collections, we also store each collection's name and a record of which Drive items (including copies or shortcuts Arkyvst created for you) belong to it, scoped to your workspace the same way.
On Free and Individual plans, your workspace is just you, so these are private to your account. On Team plans, tags on shared files are visible to the teammates in your workspace.
Teammates and invitees. If you invite a teammate to your workspace or share a collection by email, we store the email address you entered (and, once they accept, their account details as described in section 1) and pass it to our email delivery provider (Resend) to send the invite or share notification. This is the one case where we hold information about someone who hasn't signed in to Arkyvst yet; we use it only to deliver the invitation and never for marketing.
3. Subscription information (if you upgrade)
If you purchase a paid plan, our payments processor (LemonSqueezy) handles the transaction. We never see or store your card details. From LemonSqueezy we receive and store:
- your subscription's external ID, status, and current billing period
- the tier and seat count you've subscribed to
- the timestamps of subscription lifecycle events (created, renewed, cancelled, expired)
- a copy of the raw webhook payload from LemonSqueezy, for audit and debugging
LemonSqueezy's own privacy policy governs what they collect from you during checkout: https://www.lemonsqueezy.com/privacy
4. Local data on your device
The Arkyvst extension stores some information on your computer using Chrome's local storage. This data never leaves your browser unless you sign in (see "Sync" below). It includes:
- your sidebar preferences (which file types show Arkyvst, sort order, layout, etc.)
- a local index of your tagged files, used to make search instant
- the current folder you have open in Drive (used by the share feature)
- your Supabase session token (if signed in), so you don't have to sign in again every time
- your recent conversations with the in-app support assistant (see section 8), so you can pick up where you left off
- a short-lived queue of pending usage-analytics events awaiting upload (see section 7), unless you've opted out
Removing the extension or running "Clear browsing data" wipes this.
5. Information we receive from Google Drive
To make Arkyvst work, our extension uses the Google Drive API to:
- list files in your Drive so we can find files that already have Arkyvst tags
- read file metadata (name, MIME type, thumbnail link, modified time, etc.) for the file you're currently viewing or for files in your search results
- read and write a Drive-managed metadata field called
appPropertieson the folders, copies, and shortcuts Arkyvst itself creates for a Collection, to mark which items belong to it — Arkyvst never writes metadata to files you already own - create items in your Drive when you ask it to — for example the folder for a new Collection, and the copies or shortcuts that fill it
appProperties is a per-application field in Drive, readable only by Arkyvst — not by other apps, other Drive users, or Google's other services. We use it only to identify Collection folders and their items. Your tags themselves are not stored in appProperties — they live in our database, as described under "Workspace data you create" above.
To show file previews, the extension displays Drive-generated thumbnails in your browser and, for some images, downloads the image into your browser to downscale it into a preview locally. These previews exist only on your device — file contents and previews are never transmitted to or stored on our servers.
6. Diagnostic logs
Like most services, our backend (Supabase) logs technical information about requests, including timestamps, the operation performed, and the IP address the request came from. These logs are retained per our hosting provider's defaults (currently 7 days for Supabase) and are used only to investigate errors, abuse, or security incidents.
7. Usage analytics (first-party, content-free, opt-out)
To understand which features are used and catch problems, the extension records a small set of product events — things like "signed in", "tags added (count: 3)", "search run", "upgrade button clicked", or "sync error" — in our own database (Supabase). Each event carries only the event name, coarse properties such as counts and category labels, your workspace ID, the extension version, and a timestamp.
These events are deliberately content-free: they never include file names, file IDs, folder names, tag text, search queries, or any other Google Drive data — the extension strips anything of that shape before an event can be recorded. We use no third-party analytics SDK; the data goes only to our own database and is never shared or sold.
You can turn this off any time with the "Share anonymous usage analytics" toggle in the Settings tab.
8. AI support assistant
Arkyvst includes an optional in-app support assistant. It runs only when you, as a signed-in user, open the Support tab and ask it a question. When you do, we send your message to Anthropic (the maker of Claude) so it can generate an answer. When — and only when — your question is about your own account (for example, "why can't I tag more files?" or "when does my plan renew?"), we also send the relevant details of your own workspace, such as your plan tier, seat usage, tagged-file count, pending invites, and your teammates' roles, so the assistant can answer accurately.
We never send the contents of your Drive files, and the assistant can only ever access your own workspace's data — never anyone else's. Anthropic processes what we send only to return the answer to you and, under its commercial terms, does not use it to train its models. If you never open the assistant, none of your data is sent to Anthropic.
Each time you ask the assistant a question, we also record a usage-log entry in our database — your account ID, a timestamp, whether the question was answered, and how many AI tokens it consumed. This log exists to enforce fair-use limits and track our costs; it does not contain the text of your questions or the assistant's answers.
What we don't collect
- The contents or previews of any Drive file (documents, spreadsheets, images, PDFs, etc.) — our servers only ever hold metadata such as the file's name and type; previews render locally in your browser (see section 5)
- Your browsing history
- Third-party analytics SDKs, tracking pixels, or advertising identifiers — the only usage data we collect is the first-party, content-free events described in section 7, and you can switch those off
- Data about anyone other than the people in your workspace — the sole exception being the email addresses you yourself enter to invite a teammate or share a collection (see section 2)
We do not buy data about you from data brokers, and we do not sell or rent any data we collect.
How we use what we collect
We use the information described above only to:
- Operate the Arkyvst service (sign you in, sync your saved tags across devices, apply your subscription tier)
- Process payments through LemonSqueezy and keep your subscription status up to date
- Respond to support requests you send us, including through the optional in-app AI support assistant (see section 8 above)
- Send transactional emails you trigger — teammate invitations, collection-share notifications, and account notices — through our email delivery provider (Resend)
- Understand feature usage through the content-free analytics described in section 7, unless you opt out
- Investigate security incidents, debug errors, and prevent abuse
- Comply with legal obligations when required
We do not use your information for advertising, profiling, or training machine-learning models.
Google API Services User Data Policy
Arkyvst's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, with respect to the Google Workspace APIs we access (Drive file metadata and content via drive.readonly, and files Arkyvst itself creates via drive.file):
- We use the data only to provide the user-facing features of Arkyvst (tagging and searching files you own or have access to).
- We do not transfer this data to third parties except as necessary to provide or improve the user-facing features (for example, our hosting provider), to comply with applicable law, or as part of a merger, acquisition, or sale of assets with notice to you.
- We do not use this data for serving ads.
- We do not allow humans to read this data unless you give us specific consent, it is necessary for security reasons (such as investigating abuse), to comply with applicable law, or the data has been aggregated and anonymized in a way that does not personally identify you.
Where your data goes (sub-processors)
We use the following third-party services to operate Arkyvst. Each has its own privacy policy and security practices:
| Provider | What they do for us | Where data goes | Their policy |
|---|---|---|---|
| OAuth + Drive API | Google data centers | policies.google.com/privacy | |
| Supabase | Hosted database and auth | AWS US-East-2 (Ohio) | supabase.com/privacy |
| LemonSqueezy | Subscription billing + checkout | LemonSqueezy infrastructure (EU/US) | lemonsqueezy.com/privacy |
| Anthropic | AI support assistant (Claude), when you use it | Anthropic infrastructure (US) | anthropic.com/legal/privacy |
| Resend | Transactional email delivery (invites, share notifications, account notices) | Resend infrastructure (US) | resend.com/legal/privacy-policy |
If we add or remove a sub-processor we'll update this list.
How long we keep it
- Account information (email, name, workspace memberships): kept as long as your account is active. Deleted within 30 days of an account-deletion request.
- Saved tags and categories: kept as long as your workspace is active. You can delete individual entries any time from the Settings tab.
- Subscription records: kept for as long as required by tax and accounting law (typically 7 years), even after you cancel.
- Usage-analytics events and support-assistant usage logs: kept in our database until you delete your account, at which point they're removed with the rest of your account data.
- Diagnostic logs: per the retention windows set by our hosting provider (currently 7 days at Supabase).
Your rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Delete your account and the data associated with it
- Export your tagged-file list in a portable format (CSV, from the Settings tab's Import/Export section)
- Object to or restrict certain processing
To exercise any of these rights, email info@arkyvst.com from the address associated with your account. We'll respond within 30 days. We won't charge you for any of this, and we won't discriminate against you for asking.
Residents of the European Economic Area (EEA) and the United Kingdom: the legal basis we rely on to process your data is your consent (for sign-in) and the performance of our contract with you (for delivering the service you're paying for). You have the right to lodge a complaint with your local data protection authority if you believe we've mishandled your data.
Residents of California: you have the rights described above plus those granted by the California Consumer Privacy Act (CCPA), including the right to know what information we've collected and the right to opt out of "sale" of personal information. We do not sell personal information.
Cookies and local storage
The Arkyvst extension uses Chrome's local storage (a per-extension key/value store) to hold the data described in section 4 above. It does not set cookies on third-party websites and does not use tracking pixels.
The Arkyvst website (if any) may use cookies for basic functionality (such as remembering whether you're signed in to read documentation). We'll update this policy if that changes.
Children
Arkyvst is not directed at children under 13 (or under 16 in the EEA/UK). We don't knowingly collect information from anyone in that age group. If you believe a child has provided information to us, email info@arkyvst.com and we'll delete it.
International transfers
Arkyvst is operated from the United States. If you access the service from outside the US, your information will be transferred to and stored in the US. By using Arkyvst you consent to that transfer. We rely on standard contractual clauses or equivalent safeguards with our sub-processors where required by law.
Security
We use industry-standard practices to protect your data: TLS in transit, encryption at rest (handled by Supabase), Row-Level Security policies that scope every database read to your workspace, and the minimum-necessary principle for any data we store. No system is perfectly secure — if we discover a breach that affects you, we'll notify you within the timeframe required by applicable law.
Changes to this policy
If we make material changes to this policy, we'll update the "Last updated" date at the top and, when the change is significant, notify you via email or an in-app notice before it takes effect. Continued use of Arkyvst after a change means you accept the updated policy.
Contact
Questions, requests, or feedback about this policy or our privacy practices:
Tosch Roy
info@arkyvst.com