Last Updated: 09/11/2026
Effective Date: 09/11/2026
This Privacy Policy describes how Arkimedes Inc (“Arkimedes,” “we,” “our,” or “us”) collects, uses, stores, and shares your personal and company data when you access or use our platform.
1. Information We Collect
We may collect the following categories of information:
1.1 Personal Information
- Name, email address, job title, and company name.
- Login credentials (through company OAuth 2.0).
1.2 Company and Usage Data
- Uploaded files, documents, and inputs.
- AI-generated outputs linked to your company use.
- Usage logs, preferences, and feature interactions.
1.3 Technical Data
- Device type, browser type, IP address, and location (inferred).
- Cookies and similar technologies for functionality and analytics.
1.4 Sensitive and Financial Information
- Financial information, such as billing details and payment-related information necessary to process payments and manage your account. We may also collect other categories of sensitive personal information only where you choose to provide it.
- Where we process sensitive personal information, we will obtain your consent (opt-in) where required by applicable law, and we will use and disclose it only for the purposes permitted by law or as reasonably necessary to provide the Platform.
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve our services.
- Authenticate users and ensure platform security.
- Respond to support inquiries and customer needs.
- Monitor usage trends to improve performance.
- Prevent fraud, misuse, or unauthorized access.
- Protect the rights, safety, security, and legitimate interests of Arkimedes, our users, and third parties.
- Meet legal, governmental and institutional policy obligations.
- Enforce our agreements, policies, and terms.
3. Legal Bases for Processing
We process personal data on one or more of the following legal bases:
- Consent by User.
- Performance of a contract or steps taken at the request of the data subject before entering into a contract.
- Compliance with legal obligations.
- Legitimate interests pursued by Arkimedes, including maintaining, securing, improving, and administering the Platform, preventing fraud, enforcing agreements, and managing business operations.
The table below summarizes the purposes for which we process personal data, the categories of personal data involved, and the legal basis we rely upon for each processing activity.
4. Data Sharing & Third Parties
We may share data with:
- Subprocessors and Vendors for cloud hosting, analytics, support, and payment processing, and related operational services.
- Potential buyers, investors, lenders, successors, affiliates, or other parties involved in a merger, acquisition, financing, asset sale, restructuring, bankruptcy, or similar transaction.
- Courts, regulators, governmental authorities, law enforcement agencies, or other parties where disclosure is required or reasonably necessary to: comply with applicable laws or regulations; respond to lawful requests; protect rights, property, safety, or security; investigate fraud, abuse, or security incidents.
- Third parties with whom you choose to interact through integrations or other Platform functionality.
- We do not sell your personal or company data.
5. Data Retention
We retain your data for as long as reasonably necessary to provide the Platform, fulfill the purposes described in this Privacy Policy, comply with legal obligations, resolve disputes, enforce agreements, maintain security, and protect legitimate business interests.
Account-related information is retained while an account remains active.
Upon account termination, we retain your data for 30 days before secure deletion, unless otherwise required by law or necessary for security purposes, dispute resolution, legal compliance, enforcement of agreements, backup systems, or other legitimate business purposes.
6. Security
We maintain reasonable technical and physical safeguards designed to protect the confidentiality, integrity, and availability of personal data against unauthorized access, disclosure, alteration, loss, or destruction.
Our security measures include, among other things:
- Encryption of data at rest and in transit.
- Regular vulnerability assessments.
- Restricted access to sensitive systems.
While we strive to use commercially reasonable safeguards, no method of transmission over the internet or method of electronic storage is 100% secure. Accordingly, we cannot guarantee absolute security of any information transmitted to or stored on our systems. In addition, we are not responsible for circumvention of any privacy settings or security measures contained on the Service, or third-party websites.
7. International Use & Applicable Privacy Rights
Arkimedes Inc is based in Delaware, USA. Personal data collected through the Platform may be transferred to, stored, accessed, or processed in the United States and other jurisdictions in which Arkimedes, its affiliates, service providers, subprocessors, or business partners operate.
Where personal data originating from the European Economic Area (“EEA”), the United Kingdom, or Switzerland is transferred to a country that has not been recognized as providing an adequate level of data protection under applicable law, we will implement appropriate safeguards designed to protect such personal data, including, where appropriate, the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, EU–US Data Privacy Framework, or other lawful transfer mechanisms.
8. AI Services and User Content
The Platform uses artificial intelligence and machine learning technologies provided by Arkimedes and third-party service providers to generate, analyze, process, or assist in generating outputs requested by users.
Content submitted to the Platform, including prompts, documents, files, messages, and other inputs (“User Content”), may be processed as necessary to provide, maintain, secure, support, and improve the functionality of the Platform.
We may engage third-party service providers to process User Content on our behalf in connection with the provision of Platform services. Such processing is subject to contractual, technical, and organizational measures designed to protect the confidentiality and security of the information processed.
Users are responsible for ensuring that they have all rights, permissions, and legal bases necessary to submit User Content to the Platform.
8.1 Google User Data and Limited Use
When you connect a Google account to Arkimedes (Google Drive or Google Calendar), we access only the data needed to provide the features you enable: the folders you select for synchronization, their file names and contents, and the calendar events of the calendars you connect.
Arkimedes' use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In particular:
- We use Google user data only to provide and improve the user-facing features you have enabled, such as syncing your selected documents and preparing board meetings.
- We do not use Google user data, in raw, aggregated or derived form, to develop, train or improve generalized artificial intelligence or machine learning models, whether our own or those of third parties.
- We do not transfer Google user data to third parties except as necessary to provide these features (for example, document parsing, embeddings and AI model providers that process the data under enterprise agreements with zero data retention and no training on customer data), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- We do not sell Google user data, and we do not use it for advertising.
- Our employees do not read your Google user data unless you give us explicit permission for support purposes, it is necessary for security purposes such as investigating abuse, or it is required to comply with applicable law.
You can revoke Arkimedes' access to your Google account at any time from https://myaccount.google.com/connections. Disconnecting a Google integration in Arkimedes deletes the documents and derived data synchronized through that connection.
9. Cookies and Similar Technologies
Arkimedes uses cookies, pixels, local storage objects, and similar technologies (“Cookies”) to operate, secure, maintain, and improve the Platform, such as:
- Strictly Necessary Cookies: necessary for the operation, security, and functionality of the Platform and cannot be disabled through our cookie preference tools.
- Analytics and Performance Cookies: help us understand how users interact with the Platform, measure performance, diagnose technical issues, and improve functionality and user experience.
- Functional Cookies: enable enhanced functionality and personalization, including remembering user preferences and settings.
- Advertising and Marketing Cookies: where used, these Cookies may be used to deliver relevant advertising, measure advertising effectiveness, and understand user interactions with marketing content.
Where required by applicable law, including the GDPR and applicable ePrivacy rules, we will obtain consent before placing or accessing non-essential Cookies on a user’s device.
Users may manage or withdraw cookie consent at any time through the cookie preferences tools made available by us or through their browser settings. Disabling certain Cookies may affect the availability, functionality, or performance of portions of the Platform.
Certain Cookies and similar technologies may be provided by third-party service providers, including analytics, authentication, hosting, security, and infrastructure providers. For more information regarding our use of Cookies, users may contact us at legal@arkimedes.com.
10. Your Rights and Choices
Subject to the U.S. state privacy laws that apply to you, including the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), the Delaware Personal Data Privacy Act ("DPDPA"), and other comparable U.S. state privacy laws, you may have the following rights regarding your personal data:
- Right to Access / Know: you may request confirmation as to whether we process your personal data, and information about the categories and specific pieces of personal data we have collected, the sources, the purposes, and the categories of third parties with whom we share it.
- Right to Correct: you may request that we correct inaccuracies in your personal data.
- Right to Delete: you may request deletion of personal data, subject to legal exceptions.
- Right to Data Portability: where required by applicable law and technically feasible, you may request a copy of certain personal data in a portable format.
- Right to Opt Out: you may opt out of the processing of your personal data for purposes of (i) targeted advertising, (ii) the sale or sharing of personal data, and (iii) profiling in furtherance of solely automated decisions that produce legal or similarly significant effects. We honor recognized universal opt-out preference signals, including the Global Privacy Control (GPC).
- Right to Limit Use of Sensitive Personal Information: where we use sensitive personal information (including financial account information) for purposes beyond those permitted by law, you may direct us to limit its use and disclosure to those purposes.
- Right to Non-Discrimination: we will not discriminate against you for exercising any of these rights.
Where the EU GDPR or the UK GDPR and the DPA applies, data subjects have the right to:
- Obtain access to personal data processed by us;
- Request rectification of inaccurate or incomplete personal data;
- Request erasure of personal data in circumstances provided by law;
- Request restriction of processing in circumstances provided by law;
- Object to processing based on legitimate interests or for direct marketing purposes;
- Receive personal data in a structured, commonly used, and machine-readable format and, where technically feasible, transmit such data to another controller;
- Withdraw consent at any time where processing is based on consent;
- Not be subject to a decision based solely on automated processing that produces legal effects or similarly significant effects, except where permitted by applicable law.
These rights are subject to applicable legal limitations and exceptions. If you believe that Arkimedes has processed your personal data in violation of applicable law, you may lodge a complaint with the competent supervisory authority in the Member State of your habitual residence, place of work, or alleged infringement. Where the UK GDPR or the DPA applies, you may complain to the UK Information Commissioner’s Office (“ICO”).
11. Privacy Rights Requests
Privacy rights requests may be submitted at any time by contacting us at delete@arkimedes.com or by submitting our online privacy rights request form available at our website. We provide at least two methods for submitting requests so that you may choose the one most convenient for you.
We reserve the right to take reasonable steps to verify the identity of the requesting individual and the authenticity of any request. We may deny, limit, or decline requests where permitted by applicable law, including where we are unable to verify identity, where an exemption applies, where a request is manifestly unfounded, excessive, repetitive, fraudulent, or where compliance would impose a disproportionate burden.
Users may designate an authorized agent to submit certain requests on their behalf. We may require reasonable verification of both the consumer’s identity and the agent’s authority before acting on any such request.
12. Response Times & Appeals
Where the GDPR applies, we will respond to requests without undue delay and, in any event, within one (1) month of receipt of a verifiable request. This period may be extended by up to two (2) additional months where necessary due to the complexity or number of requests.
Where the UK GDPR and the DPA applies, we will acknowledge receipt within thirty (30) days, take appropriate steps to investigate, keep you informed of progress where appropriate, and communicate the outcome without undue delay.
Where U.S. state privacy laws apply, we will respond to verifiable consumer requests within the timeframe required by the applicable law (for example, forty-five (45) days under the DPDPA and the CCPA/CPRA, extendable by an additional forty-five (45) days where reasonably necessary). Notice of any extension and the reasons for it will be provided within the initial response period.
If we decline to take action regarding your request, we will provide notice of our decision, the basis for the decision, and instructions regarding how to appeal. Appeals may be submitted by contacting legal@arkimedes.com and including the subject line “Privacy Rights Appeal.”
We will respond to appeals within sixty (60) days of receipt. If an appeal is denied, we will provide any information required by applicable law regarding available complaint mechanisms or regulatory remedies.
13. Changes to This Policy
We may update this Privacy Policy periodically. If changes are material, we will notify you via email or in-app notice.
14. Contact Us
If you have questions about this Privacy Policy, please contact:
- Email: legal@arkimedes.com
- Address: Arkimedes Inc, 169 Madison Ave STE 15173, New York, New York.
Thank you for trusting Arkimedes.