Privacy Policy
Effective Date: July 2, 2026 · Last Updated: July 2, 2026
This Privacy Policy explains how Arkova Technologies, Inc. ("Arkova," "we," "us") collects, uses, shares, and protects information when you use our website, application, and verification API (together, the "Service"). Arkova provides verification infrastructure: we create a permanent, independently verifiable proof of a document or credential by anchoring a tamper-evident fingerprint of it to a public network.
1. Our Foundational Guarantee
For documents you upload directly, the file never leaves your device. This is not a feature — it is the architecture. A SHA-256 fingerprint of the file is computed entirely in your browser using the Web Crypto API, and only that fingerprint (plus PII-stripped metadata) is transmitted. We never receive, store, or have access to your original files.
One narrow exception — connector-sourced documents. If you connect a third-party source you already control and authorize (for example, DocuSign or Google Drive), a document you select there is fetched and fingerprinted in memory on our servers, because there is no browser on your device in that flow to compute the fingerprint. In that case the raw file bytes are used only to compute the fingerprint and are then immediately discarded: they are never written to our database, our logs, our error-monitoring, or any temporary storage, and only the resulting fingerprint and PII-stripped metadata are retained. Documents you upload directly are always fingerprinted client-side and never transmitted at all.
2. Information We Collect
Document fingerprints: A one-way SHA-256 fingerprint of your file. It cannot be reversed to reconstruct the original document and reveals nothing about its contents.
Account information: Email address, name, and organization name when you create an account.
Record metadata: Issuer name, credential type, issue/expiry dates, jurisdiction, and field labels — never raw document text or personal information extracted from a document.
Billing information: Subscription tier and payment status. Card details are handled by our payment processor (Stripe) and are never stored on Arkova's servers.
Usage and diagnostic data: Page views, feature usage, API call counts, and error diagnostics used to operate and improve the Service.
Marketing submissions: If you join the waitlist or contact us, the email address and interest you provide.
3. What We Never Collect
- Original documents, PDFs, images, or file contents (beyond the in-memory fingerprinting described in Section 1)
- Raw OCR text extracted from your documents
- Social Security numbers, student IDs, or other personal identifiers from within documents
- Your browsing history outside of Arkova
- Payment card numbers (held only by our PCI-compliant payment processor)
4. AI Metadata Processing
When AI-assisted extraction is enabled, only PII-stripped structured metadata (credential type, issuer, dates, field labels) may be sent to our AI processor for structuring. Client-side PII stripping removes personal information before anything leaves your browser. Raw OCR text and document bytes are never transmitted to the AI processor.
5. How We Use Information
- To provide verification, anchoring, and API services you request.
- To authenticate you and secure your account.
- To process payments and manage subscriptions.
- To operate, maintain, monitor, and improve the Service.
- To communicate with you about the Service and, where you have opted in, product updates.
- To comply with legal obligations and enforce our Terms.
Under the GDPR, our legal bases are: performance of a contract (providing the Service), legitimate interests (securing and improving the Service), consent (marketing email), and legal obligation. We do not sell your personal information, and we do not use it for cross-context behavioral advertising.
6. Service Providers & Sub-Processors
We share the minimum data necessary with vetted providers who process it only on our instructions:
| Provider | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication | Account info, fingerprints, metadata |
| Stripe | Payments | Billing status (card data held by Stripe) |
| Google Cloud / Vertex (Gemini) | AI metadata structuring | PII-stripped metadata only |
| Cloudflare | Edge network, secure ingress | Request routing (no document contents) |
| Vercel | Website hosting, privacy-friendly analytics | Aggregate, cookieless usage metrics |
| Sentry | Error monitoring | Diagnostics (PII-scrubbed) |
| Formspree | Waitlist / contact form | Email + interest you submit |
The public network your fingerprints are anchored to is operated by independent infrastructure outside Arkova's control; it receives only the anchored fingerprint, which is public and contains no personal information.
7. Data Retention
We retain account and record metadata for as long as your account is active and as needed to provide the Service. When you delete your account, we delete or anonymize the personal information associated with it within approximately 30 days, except where longer retention is required by law.
Anchored fingerprints are permanent and public by design. A fingerprint committed to the public network cannot be deleted, recalled, or altered by Arkova or by you — permanence is what makes the proof trustworthy. Because the fingerprint reveals nothing about the document's contents and is not personal information, deleting your account does not, and cannot, remove a fingerprint that has already been anchored.
8. Cookies & Analytics
The marketing website uses privacy-friendly, cookieless analytics (Vercel Speed Insights) that measure aggregate performance and usage without tracking you across sites. The application uses a session cookie or local storage strictly to keep you signed in. We do not use advertising or cross-site tracking cookies.
9. Data Security
Data is encrypted in transit (TLS) and at rest. Database access is enforced through Row Level Security, so every table has mandatory tenant isolation. API keys are stored only as HMAC-SHA256 fingerprints, never in raw form. Audit events are written to an append-only, PII-scrubbed trail. Our security controls are published as a CSA STAR Level 1 self-assessment (a public disclosure of our controls, not a third-party audit or certification).
10. Your Rights
Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing.
GDPR / UK GDPR (EEA & UK): access, rectification, erasure, portability, restriction, and objection, and the right to lodge a complaint with your supervisory authority.
CCPA / CPRA (California): the right to know, delete, and correct your personal information, and to opt out of its sale or sharing. We do not sell or share personal information as those terms are defined by law, and we will not discriminate against you for exercising your rights.
To exercise any right, email hello@arkova.ai. We will respond within the timeframe required by applicable law.
11. International Data Transfers
Arkova is based in the United States and processes data there. Where we transfer personal information from the EEA, UK, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.
12. Public Verification
Verification is public by design. Anyone with a record's public ID can confirm its status, issuer, and timing — no account required. Only the public ID and non-sensitive metadata are exposed; never the document itself, its contents, or the holder's personal information.
13. Children's Privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us information, contact us and we will delete it.
14. Changes to This Policy
We may update this Policy. If we make material changes, we will update the "Last Updated" date and, where appropriate, notify you by email or in-app notice.
15. Contact
For privacy inquiries: hello@arkova.ai
Arkova Technologies, Inc.