arcodash
PlatformConnectorsPricingSecurityDocs
Sign inStart free trial
PlatformConnectorsPricingSecurityDocs
Sign inStart free trial
legal

Privacy Policy

Effective as of the date this policy is published.

This Privacy Policy explains how arcodash ("arcodash", "we", "us"), a service operated by an individual sole proprietor based in Israel, handles information in connection with the arcodash platform. Please read it together with our Terms of Service.

1. Scope

This policy covers arcodash Cloud — the hosted service we operate — and describes what we collect, store, and process when you use it, along with any account or website interactions you have directly with us.

Unless stated otherwise, the sections below describe arcodash Cloud.

2. Information We Collect

Account information. When you register, we collect your name, email address, and authentication credentials (stored in hashed form), along with basic account and organization settings.

Customer business data. When you connect a data source and run a query, the query result rows returned by your query — your own business data — are stored in arcodash's hosted database (as JSON) to enable caching and to display your dashboards and monitors. This is not merely pass-through: the result data is persisted until it is overwritten or deleted as described in Section 6. This data may itself contain personal data belonging to your own users or contacts; that content is determined and controlled by you, not by arcodash.

Data source connection credentials. The credentials you provide to connect a data source (such as database passwords or API keys) are storedencrypted at rest using AES-256-GCM.

AI feature inputs. If you use the optional AI-assisted query feature, we process your database schema (table and column names only) and the natural-language question or SQL text you provide. See Section 4.

Technical and operational data. We process the minimal technical data needed to operate the service securely, such as authentication session data.

3. How We Use Information

We use the information above to:

  • provide, operate, and maintain the dashboarding, visualization, and data-observability monitoring service;
  • authenticate you and secure your account;
  • run the queries and monitors you configure and cache their results for display;
  • power the optional AI SQL-generation feature (Section 4); and
  • communicate with you about the service and respond to your requests.

4. The AI-Assisted Query Feature

The AI feature is optional and administrator-configurable. When it is enabled and used, arcodash sends your database schema (table and column names only)and the question or SQL text you provide to the large-language-model provider your organization configures — Google Gemini, OpenAI, or Anthropic — to generate SQL. You choose the provider and supply your own API key for it; arcodash does not select this vendor on your behalf.

Your actual data rows and query results are never sent to the LLM provider — only schema metadata and your own question text. The provider processes this input under its own terms and privacy policy. If you do not wish to use this feature, it can be left disabled.

5. Legal Basis for Processing (GDPR)

For users in the EU, UK, and similar jurisdictions, we rely on the following legal bases:

  • Performance of a contract — to provide the service you have signed up for, including storing account data, running queries, and caching results.
  • Legitimate interests — to secure, maintain, and improve the service, prevent abuse, and communicate with you, where those interests are not overridden by your rights.
  • Consent — where specifically requested, and which you may withdraw at any time.

With respect to the business data you push through connected data sources, arcodash acts as a data processor and you act as thedata controller; you are responsible for having a lawful basis to process that data and to make it available to arcodash.

6. Data Retention

We retain your account information for as long as your account remains open. We retain cached query result data and connection credentials for as long as your account and the relevant data source, dashboard, or query remain active.

There is currently no fixed, time-based automatic purge of cached query result data. Cached result data is overwritten when the corresponding query is re-run (by default when it is older than roughly 24 hours), and is deleted when you delete the corresponding data source, dashboard, query, or your account/organization. In other words, we retain your data for as long as your account and the relevant connection remain active, and delete it when you delete the corresponding resource or close your account.

Closing your account today disables it — sign-in stops working and the account is no longer billed — but does not yet trigger an automatic export or deletion of the underlying data. If you need your organization's data deleted or exported on account closure, contact [email protected] and we will handle it manually. We are building an automated retention and deletion process for account closure; this section will be updated with specifics once it ships.

7. Data Sharing and Subprocessors

We do not sell your personal data, and we share it only as needed to run the service:

  • Google Cloud — hosts the application database, cached query results, and uploaded files, in the europe-west4 (Netherlands) region.
  • PostHog (EU) — product analytics on this website and in the dashboard app, used only if you accept the analytics consent banner. See Section 12.
  • AI/LLM provider (Google Gemini, OpenAI, or Anthropic) — only if your organization enables and configures the AI feature, and only schema metadata and your question text, as described in Section 4. You choose this vendor; arcodash does not.
  • Email delivery — the service may send transactional email via an SMTP server configured by the operator; a specific named email subprocessor is not fixed at this time.

This website (not the dashboard app) also uses Google Analytics, subject to the same consent banner described in Section 12 — see Section 12 for how to decline it. Analytics never runs before you accept.

This subprocessor list reflects what arcodash actually uses today and may be updated as the service evolves. Where required, we will make an updated list available on request at [email protected] or publish it, and will provide notice of material changes.

8. International Data Transfers

arcodash is operated from Israel and may store or process data in the United States, the European Union, Israel, or other countries where arcodash or its infrastructure providers operate. This means your data may be transferred to and processed in countries other than your own. Where such transfers involve personal data subject to GDPR, we rely on appropriate safeguards (such as adequacy decisions or standard contractual clauses) where required by law.

9. Security

We protect your data using technical and organizational measures, includingencryption at rest of connection credentials (AES-256-GCM), encrypted transport, hashed authentication credentials, and server-side access controls that enforce tenant isolation so that each account can access only its own data. No system is perfectly secure, and we cannot guarantee absolute security, but we work to protect your information using reasonable measures.

10. Your Rights

GDPR (EU/UK) rights. Subject to applicable law, you have the right to access your personal data, to rectify inaccurate data, to erase data, to receive your data in a portable format, to object to certain processing, and to restrict processing. You may exercise these rights by contacting[email protected]. You also have the right to lodge a complaint with your local data protection authority. For business data you process as a controller, requests from your own users should be directed to you, and we will assist you as your processor.

California (CCPA) rights. If you are a California resident, you have the right to know what personal information we collect and how we use it, to request deletion, to opt out of the sale of personal information, and to non-discrimination for exercising your rights. arcodash does not sell personal information.

11. Children's Privacy

arcodash is not directed to children and is not intended for anyone under the age of 16 (or under 18 where required by local law). We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact us and we will delete it.

12. Cookies

arcodash uses essential cookies necessary for authentication and session management — these run without asking, since the service can't function without them.

This website and the dashboard app also use analytics cookies (PostHog, and Google Analytics on this website) — never advertising or tracking-for-marketing cookies. A consent banner is shown before either analytics vendor runs anything: no analytics cookie is set, and no analytics request is made, until you accept it. Declining keeps both off; you can change your choice at any time by clearing your browser's storage for this site and reloading.

13. Data Processing Addendum

If you require a Data Processing Addendum (DPA) under GDPR Article 28 for the business data you process through arcodash, one is available on request. Please contact[email protected].

14. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will provide reasonable advance notice by email or through an in-app or website notice. Your continued use of the service after the changes take effect constitutes acceptance of the updated policy.

15. Contact

For any privacy questions or to exercise your rights, contact us at[email protected].

arcodash

Full-Scale BI & Data Observability — query your data, and trust it.

Product

  • Platform
  • Connectors
  • Pricing
  • Security

Developers

  • Docs
  • REST API

Company

  • About
  • Contact
© 2026 arcodashconnect · query · visualize · dashboard · alert · monitorTerms · Privacy

We use privacy-friendly analytics to improve arcodash. No analytics run until you accept.