Contents
- Summary
- Definitions
- Controller and contact
- Scope and application
- Data we collect
- Purposes and legal bases
- Automated decision-making
- Sharing and subprocessors
- International transfers
- Security measures
- Data retention
- Your rights
- Children
- Regional privacy rights
- Cookies and similar technologies
- Data breach notification
- Changes
- Complaints
Summary
Local-first by default. The Arcana terminal application runs on your machine. Your source code, prompts, API keys, session transcripts, and memory database are stored locally unless you explicitly enable a cloud feature. OTNEL does not have access to data that remains on your device.
Hosted services we operate. When you create an account, use the web console, enable cloud memory sync, purchase proxy credits, subscribe to Pro or Enterprise, or contact support, we process the personal data necessary to deliver those services. This policy describes what we collect, why we collect it, and your rights.
What we do not do. We do not train AI models on your data, sell your personal information, broker your personal data to third parties for advertising, or intercept the content of requests sent directly from the Arcana terminal to your chosen LLM provider. We process hosted data only as described in this policy and in our Terms of Service.
Our commitment to transparency. We believe that you should understand how your data is handled without needing a law degree. This policy is organized to distinguish between data that stays on your device, data that passes through our infrastructure, and data that we hold as part of your account. We have also included clear tables that identify the legal basis for each category of processing and the third parties that assist us.
Who this policy applies to. This Privacy Policy applies to anyone who visits the Arcana website, registers for an account, uses the Arcana web console, purchases credits or subscriptions, enables cloud synchronization, or otherwise interacts with the hosted Services. If you are using only the open-source Arcana CLI on your own machine and have not enabled any hosted feature, this policy does not apply to your local use.
Your rights are important. Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to the processing of your personal data. We provide mechanisms to exercise these rights through the console and through direct contact with our support team.
How to contact us. If you have questions about this policy or wish to exercise your privacy rights, please contact us at support@otnelhq.com. We will respond to substantive requests as promptly as possible and in accordance with applicable legal deadlines.
Changes over time. The Services will evolve, and this policy may be updated to reflect new features, processors, or legal requirements. Material changes will be announced through the console or by email, and the effective date at the top of this page will always indicate the most recent revision.
Definitions
For the purposes of this Privacy Policy, the following terms have the meanings set out below:
- "Arcana" means the terminal-native AI operations platform, including the open-source terminal application, the website at https://arcana.otnelhq.com, the web console, the proxy relay, the license server, and related cloud services.
- "Controller" means OTNEL, which determines the purposes and means of processing personal data.
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, including collection, storage, use, disclosure, and deletion.
- "Processor" means a third party that processes Personal Data on behalf of the Controller.
- "Services" means the products, features, websites, and hosted infrastructure provided by OTNEL under this policy.
- "User" or "you" means any natural person who accesses or uses Arcana.
- "LLM Provider" means a third-party provider of large language model services that you configure Arcana to use with your own API key or through the Arcana proxy.
Identifiability. Information is considered to relate to an identifiable natural person if it can be linked, directly or indirectly, to that person. This includes common identifiers such as a name, email address, or online identifier, as well as less obvious data points that, when combined, could single out an individual.
Controller and processor distinction. A controller decides why and how personal data is processed. A processor processes data only on the controller's instructions. OTNEL acts as the controller for data collected through the Services, and as a processor only where we have expressly agreed to process data on behalf of an Enterprise customer under a separate Data Processing Agreement.
Scope of Personal Data. This policy uses "Personal Data" broadly to cover any information that could identify you, alone or in combination with other information, whether or not you are named. Anonymous or aggregated data that cannot reasonably be linked to you is not Personal Data under this policy.
Meaning of "processing." Processing includes any automated or manual operation on data, from initial collection and recording through organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure, dissemination, erasure, or destruction. Almost anything we do with data that identifies you is processing.
Local data. "Local data" refers to information stored only on your own device by the Arcana CLI, including memory databases, configuration files, session transcripts, API keys, and workspace metadata, unless you explicitly upload or sync it to our hosted Services.
Cloud data. "Cloud data" refers to information that you choose to transmit to or store on Arcana-hosted infrastructure, such as account details, cloud-synced memory facts, proxy relay metadata, and support communications.
Consent. Where this policy refers to consent, it means a freely given, specific, informed, and unambiguous indication of your wishes, signified by a clear affirmative action. You may withdraw consent at any time, although withdrawal does not affect processing that occurred before withdrawal where the processing was lawful.
Third-party terms. References to third-party terms, such as those of Supabase, PayPal, Cloudflare, or LLM Providers, are included for your convenience. Those third parties remain responsible for their own privacy practices, and you should review their policies directly.
Controller and contact
The data controller responsible for the processing described in this policy is:
OTNEL
Costa Rica
Email: support@otnelhq.com
Website: https://arcana.otnelhq.com
For all privacy-related inquiries, including requests to exercise your rights, please contact us at support@otnelhq.com. We will respond to substantive requests in accordance with applicable law and, where required, within the timeframes prescribed by the jurisdiction in which you reside.
Role and responsibility. As the controller, OTNEL is responsible for ensuring that processing of your Personal Data complies with applicable data protection law, including this Privacy Policy. We designate the contact above as the primary point of contact for privacy matters, including questions, complaints, and data subject requests.
Requests from any jurisdiction. Whether you are located in the European Economic Area, the United Kingdom, Switzerland, the United States, Latin America, or elsewhere, you may direct privacy requests to the same email address. Where a request invokes rights under a specific statute, we will handle it in accordance with that statute's requirements, including any identity-verification or timing obligations.
Response timeframes. We aim to acknowledge receipt of a privacy request within five business days and to provide a substantive response within the period required by applicable law, typically not later than one month for requests under the GDPR, subject to extension for complex or numerous requests. If we cannot meet a deadline, we will inform you of the reason and the expected completion date.
Identity verification. To protect your privacy and prevent unauthorized disclosure, we may need to verify your identity before fulfilling a request. Verification may require you to sign in to your Arcana account, confirm control of the email address associated with the account, or provide additional documentation where legally required or where the request involves sensitive data.
Authorized agents. If you use an authorized agent to submit a request on your behalf, we may require the agent to provide signed written permission from you and may require you to verify your identity directly with us. This protects against fraudulent requests and ensures that you retain control over your data.
No dedicated data protection officer. OTNEL is not currently required to appoint a statutory data protection officer under applicable law. The contact above serves as our privacy lead. If regulatory requirements change and a formal officer becomes necessary, we will update this section and provide the appropriate contact details.
Record of correspondence. We retain a record of privacy-related correspondence for as long as necessary to demonstrate compliance, resolve disputes, and maintain an accurate history of our interactions with you. Such records are treated as confidential and are accessed only by personnel with a legitimate need.
Escalation. If you are dissatisfied with our response, you may escalate your complaint to a supervisory authority in your jurisdiction, as described in the Complaints section. We encourage you to contact us first so that we can attempt to resolve the matter directly.
Scope and application
This Privacy Policy applies to all processing of Personal Data carried out by OTNEL in connection with the Services. It applies to visitors of the Arcana website, registered users of the web console, subscribers to Pro or Enterprise plans, purchasers of proxy credits, and individuals who contact support.
Website visitors. If you browse the Arcana website without creating an account, we process limited data, such as your IP address, browser type, pages visited, and cookie or localStorage data. This processing is described in this policy and in our Cookie Policy.
Registered users. When you create an account, we process identity, authentication, billing, and usage data as necessary to provide the Services you have requested. The scope of processing grows with the features you use; for example, enabling cloud memory sync causes memory data to be processed on our servers.
Paid subscribers and credit purchasers. Pro and Enterprise subscribers, as well as purchasers of proxy credits, provide billing and payment information that we process through PayPal. Transaction records and subscription status are retained in accordance with this policy and applicable accounting and tax laws.
Support correspondents. If you contact support, we process your email address and the content of your message, including any files or logs you attach. This processing is necessary to respond to your inquiry and to maintain records of our relationship.
What this policy does not apply to. This policy does not apply to data that is processed entirely locally by the open-source Arcana CLI on your own machine, unless you explicitly enable a cloud-sync feature or upload such data to our hosted Services. It also does not apply to the independent privacy practices of LLM Providers or other third parties that you choose to use with Arcana.
Separate agreements control where applicable. Data processed by OTNEL pursuant to a separate written agreement, such as an Enterprise Order Form or Data Processing Agreement, is governed by that agreement to the extent it conflicts with this policy. In all other respects, this policy supplements such agreements.
Third-party integrations. When you connect Arcana to an LLM Provider or other third-party service, data is transmitted directly between your client and that provider, or through the Arcana proxy as a relay. OTNEL does not control the provider's processing, and this policy does not describe it. You should review the provider's privacy policy before sending data.
Changes to scope. As we add features, the scope of this policy may expand to cover new categories of data. We will notify you of material changes through the console or by email, and we will update the policy's effective date accordingly.
Age restriction. The Services are not intended for individuals under the age of 16, and we do not knowingly collect Personal Data from children. If you are under 16, do not use the Services or provide any Personal Data to us.
Data we collect
We collect Personal Data that you provide to us, that is generated automatically when you use the Services, and that we receive from third-party service providers. The categories of data we collect are described below.
1. Identity and registration data
When you create an Arcana account, we collect your email address, a unique account identifier, and, if you sign in through a social or identity provider, the authentication provider identifier and any profile information that provider makes available to us. Passwords and credential hashes for authentication are managed by our authentication provider, Supabase, in accordance with industry-standard security practices. OTNEL does not store your plain-text password.
Your email address serves as the primary identifier for your account and is used for authentication, billing notifications, security alerts, support correspondence, and policy updates. We may also collect a display name or username if you choose to provide one.
We may collect additional verification information if required to investigate suspicious account activity, process a billing dispute, or comply with a legal obligation. Such information is collected only to the extent necessary for the specific purpose and is retained in accordance with this policy.
Social sign-in data is limited to the information that the identity provider shares with us. We do not request access to your contacts, social graph, or other data beyond what is needed to create and secure your account.
2. Authentication and session data
We maintain records necessary to authenticate your sessions and secure your account, including session tokens, refresh tokens, IP addresses used at login, device and browser type, and timestamps of access. This data is used for access control, fraud prevention, and security monitoring.
Each time you sign in or perform a sensitive action, we log the event, including the time, the type of action, and a truncated or hashed representation of the IP address. These logs help us detect unauthorized access, brute-force attempts, and anomalous patterns.
Session identifiers are stored in cookies or localStorage and are transmitted with requests to authenticate you. They are rotated periodically and invalidated when you sign out or when a session expires. You can terminate active sessions from the console.
Device information, such as operating system and browser version, is used to ensure compatibility, diagnose login issues, and identify potentially compromised devices. We do not use this information to track you across unrelated websites.
3. Billing and payment data
When you purchase a Pro or Enterprise subscription or buy proxy credits, we collect billing contact information, transaction identifiers, subscription status, plan tier, seat count (if applicable), and payment history. Payment card numbers and bank account details are processed by PayPal. We do not collect or store full payment card numbers on OTNEL servers. We retain the transaction records required to manage your account, provide receipts, process refunds where applicable, and comply with tax and accounting obligations.
Billing records include the dates and amounts of each transaction, the payment method type, the currency, and the status of each payment or refund. These records are associated with your account so that you can review your billing history in the console.
We may receive payment confirmations and dispute notifications from PayPal. These notifications include limited information necessary to update your account status, such as whether a payment succeeded, failed, or was reversed.
Invoices and receipts are generated in accordance with the billing address or tax jurisdiction you provide. You are responsible for ensuring that your billing information is accurate and current to avoid failed payments or tax discrepancies.
Where required by law, we collect and retain tax-related information, such as your country of residence or tax identification number. This information is used solely for tax compliance and is not shared for marketing purposes.
4. Service usage and log data
When you use the hosted Services, including the web console, proxy relay, and license server, we collect server logs, request metadata, feature usage, error logs, and IP addresses. This data is used to operate, maintain, secure, and improve the Services. We do not read or store the substantive content of your local terminal sessions, prompts, or project files unless you explicitly upload them or route them through the Arcana proxy or cloud sync.
Server logs typically include the timestamp of a request, the HTTP method and path, the response status, the duration, a truncated or hashed IP address, and a user-agent string. These logs are retained for a limited period for operational and security purposes.
We may aggregate usage data to understand which features are popular, how the console is navigated, and where users encounter errors. Aggregated data does not identify individual users and is used to prioritize development and reliability improvements.
Error logs may capture technical details about a failure, such as a stack trace or request identifier. We make reasonable efforts to exclude sensitive Personal Data from error logs, but if such data is inadvertently included, it is retained only as long as necessary for debugging and is then deleted or anonymized.
License validation requests include your account identifier and entitlement information. These requests are logged to detect unauthorized use, enforce subscription limits, and ensure that licensed features are available to paying subscribers.
5. Optional cloud sync and memory data
If you enable cloud memory sync, encrypted memory facts, extracted entities, session summaries, and related context may be transmitted from your local machine to Arcana infrastructure. This data is encrypted in transit using TLS and encrypted at rest. You can disable cloud sync, export your cloud memory data, or delete it from the console at any time. We process this data solely to provide the sync service and do not use it for advertising, profiling, or model training.
Cloud memory data is stored in your personal encrypted vault on our servers. The encryption keys are managed in a manner that prevents unauthorized access, including by OTNEL personnel, except as required to provide the service or comply with law.
When you use cloud sync across multiple devices, our servers reconcile changes between your devices, merge updates, and resolve conflicts according to the rules implemented in the Arcana CLI. We do not inspect the semantic content of your memory facts during this process.
You remain the owner of your cloud memory data. You can request an export of your data at any time, and you can delete individual facts, entire memory namespaces, or your entire cloud sync dataset. Deletion is generally effective immediately, although residual copies may exist in backups for a short technical retention period.
If you share a memory namespace or team vault under an Enterprise Plan, the data is accessible to the users you authorize. You control sharing permissions and can revoke access at any time. OTNEL does not share cloud memory data with unauthorized users.
6. Proxy relay data
When you route requests through the Arcana proxy, we process request metadata necessary to deliver the request to your selected LLM Provider, enforce rate limits, track credit usage, and maintain service reliability. The substantive prompts and model outputs pass through the relay but are not retained for longer than the transient processing period necessary to fulfill the request, except where required for billing dispute resolution, abuse investigation, or legal compliance.
Proxy metadata includes the destination provider, the model identifier, the number of tokens consumed, the request timestamp, the response latency, and any error codes. This information is used to calculate credit consumption, generate usage dashboards, and detect abuse or anomalies.
We do not intentionally log the full text of prompts or completions. In rare cases, such as investigating a reported abuse incident or a billing dispute, we may retain a limited sample of request content for the duration of the investigation. Any such retention is conducted under strict access controls and in accordance with this policy.
You choose which LLM Provider to use through the proxy, and you are responsible for complying with that provider's terms and privacy policy. OTNEL acts as a relay and billing facilitator, not as the provider of the AI model.
Enterprise customers may configure gateway rules, audit logging, or data loss prevention policies that affect what proxy metadata is retained. Such configurations are governed by the applicable Enterprise agreement.
7. Communication and support data
When you contact support, submit feedback, or communicate with us, we collect your email address, the content of your message, and any attachments or files you provide. We retain this information for as long as necessary to resolve your request, improve support quality, and maintain records of our interactions.
Support data may include screenshots, logs, configuration excerpts, or other files that you voluntarily provide to help us diagnose an issue. Before sending any file, you should remove or redact any sensitive information that you do not wish to disclose.
We may use support interactions to identify recurring issues, improve documentation, and train support staff. Personal Data contained in support messages is not used for marketing or sold to third parties.
If you report a security vulnerability, we will handle your report confidentially and will not publicly disclose your identity without your permission, except where required by law or to prevent imminent harm.
Feedback that you submit through the console or website may be retained indefinitely as part of our product improvement process. Feedback provided in a clearly confidential context is treated in accordance with the confidentiality commitments in our Terms of Service.
8. Technical and device data
We collect information about the device and browser you use to access the Services, including browser type, operating system, screen resolution, language preference, and approximate geolocation derived from your IP address. This data is used for security, analytics, and compatibility purposes.
Approximate geolocation derived from IP addresses is used to detect anomalous login locations, enforce regional feature restrictions, and optimize content delivery. It is not precise enough to identify your street address or exact location.
We may collect information about the performance of the Services on your device, such as page load times, JavaScript errors, and network latency. This information is used to diagnose technical issues and improve performance.
We do not collect device identifiers such as serial numbers or MAC addresses through the website or console. The Arcana CLI may read local system information for operational purposes, but such information remains on your device unless explicitly transmitted to us.
Technical data may be aggregated with similar data from other users to produce analytics reports. These reports do not identify individual users and are used solely for operational improvement.
9. Local data we do not collect
Data stored only on your local device, including local memory databases (such as ~/.arcana/data/memory.db), API keys in your environment or system keychain, local session transcripts, workspace trust fingerprints, skill caches, and project files, is not transmitted to OTNEL unless you explicitly choose to upload or sync it. You are solely responsible for the security, backup, and management of data stored on your own machine.
The Arcana CLI is designed to operate locally by default. Your prompts, completions, and project context are sent directly to the LLM Provider you configure, or they are processed entirely on your machine if you use a local model. OTNEL does not receive this data unless you opt in to hosted features.
You should secure your local device with strong passwords, full-disk encryption, and regular backups. OTNEL cannot protect data that is stored exclusively on your machine, nor can we recover it if your device is lost, damaged, or compromised.
API keys that you configure in the Arcana CLI are stored according to the CLI's design, typically in your system keychain or environment variables. OTNEL does not have access to these keys unless you choose to store them in the cloud vault associated with your account.
If you use a third-party plugin or integration with the Arcana CLI, that plugin may handle data according to its own terms. OTNEL is not responsible for plugins that are not provided or reviewed by us.
10. Cookies and similar technologies
We use cookies, localStorage, sessionStorage, and similar browser technologies to operate the Services and remember your preferences. For detailed information, including the categories and specific technologies used, please see our Cookie Policy.
Cookies and storage technologies are classified as essential, functional, or analytics, depending on their purpose. Essential technologies are necessary for the Services to function and cannot be disabled without preventing access. Functional technologies improve your experience by remembering preferences. Analytics technologies help us understand website usage.
Your consent to non-essential technologies is recorded in localStorage and can be changed by clearing site data or adjusting your browser settings. We do not use advertising cookies or trackers that follow you across the web.
Some cookies are set by Cloudflare, our hosting and security provider, for purposes such as bot management, DDoS mitigation, and request routing. These cookies are essential for protecting the Services.
The Cookie Policy contains a complete inventory of the technologies we use, their durations, and their categories. We encourage you to review it in conjunction with this Privacy Policy.
Purposes and legal bases for processing
We process Personal Data only for lawful purposes and in accordance with the legal bases set out below. For users located in the European Economic Area, United Kingdom, Switzerland, and other jurisdictions requiring a legal basis, the table below identifies the applicable basis under the General Data Protection Regulation or equivalent local law.
| Purpose of processing | Legal basis | Description |
|---|---|---|
| Providing and maintaining the Services, including authentication, account management, subscriptions, and cloud sync | Performance of a contract | Processing necessary to fulfill our contractual obligations to you. |
| Security, fraud prevention, abuse detection, and integrity of the Services | Legitimate interest | Protecting our Services, users, and infrastructure from unauthorized access, abuse, and harm. |
| Customer support, responding to inquiries, and resolving disputes | Performance of a contract / Legitimate interest | Providing assistance and maintaining records of our relationship. |
| Product development, analytics, and reliability monitoring | Legitimate interest | Improving functionality, performance, and user experience using aggregated or de-identified data where possible. |
| Marketing communications, newsletters, and product updates | Consent | Sent only where you have opted in; you may withdraw consent at any time. |
| Compliance with legal, regulatory, and tax obligations | Legal obligation | Responding to lawful requests, maintaining tax records, and enforcing our terms. |
Where we rely on legitimate interests, we have balanced those interests against your privacy rights and have implemented measures to minimize the impact on your privacy. You may object to processing based on legitimate interests as described in the Your rights section.
Performance of a contract. Much of the processing described in this policy is necessary to perform our contract with you, namely the Terms of Service. Without processing your account data, authentication credentials, billing information, and cloud sync data, we could not provide the Services you have requested.
Legitimate interests. We rely on legitimate interests for activities such as maintaining security, preventing fraud, improving our products, and communicating with you about service-related matters. We have assessed that these interests are not overridden by your fundamental rights and freedoms, given the limited nature of the data involved and the safeguards we apply.
Consent. We rely on consent only for processing that is not strictly necessary for the Services and is not otherwise justified by a contract, legal obligation, or legitimate interest. This includes marketing emails and, where required by law, certain non-essential cookies or analytics. You can withdraw consent at any time without penalty.
Legal obligation. In some cases, we are required by law to process or retain Personal Data. Examples include tax and accounting record-keeping, responding to lawful government requests, and preserving evidence for litigation. When we process data on this basis, we limit the processing to what is strictly required by the applicable law.
Vital interests. We may process Personal Data where necessary to protect your vital interests or those of another person, such as in an emergency involving a threat to life or physical safety. This basis is rarely invoked but is available where appropriate.
Balancing test. For each processing activity based on legitimate interests, we maintain an internal record of the purpose, the data involved, the expected benefits, the potential impact on privacy, and the measures taken to mitigate risk. You may request a summary of this balancing test for processing that affects you.
Change of purpose. We will not use your Personal Data for purposes that are incompatible with the purposes for which it was originally collected, unless permitted by law or with your consent. If we wish to use your data for a new purpose, we will inform you and, where required, obtain your consent.
Aggregated and anonymized data. We may convert Personal Data into aggregated or anonymized form so that it no longer identifies you. Such data may be used for any lawful purpose, including research, benchmarking, and product development, without restriction under this policy.
Automated decision-making
We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing, including profiling. Automated systems may be used for technical purposes such as rate limiting, fraud detection, and abuse prevention, but these systems do not result in decisions that affect your legal rights or eligibility for significant benefits without human review.
Rate limiting and abuse prevention. Our systems may automatically enforce rate limits, block suspicious IP addresses, or require additional verification when anomalous activity is detected. These decisions are based on technical indicators, such as request frequency or known patterns of abuse, rather than on sensitive personal characteristics.
No profiling for marketing. We do not build profiles of your behavior, preferences, or characteristics for the purpose of targeted advertising, scoring, or automated decision-making. Our analytics are aggregated and focused on service performance rather than individual user profiling.
Human review. If an automated system flags an account or transaction for further scrutiny, a human reviewer examines the case before any action is taken that would materially affect your access or rights. You may appeal automated decisions by contacting support.
Transparency obligation. Where required by applicable law, we will inform you if we ever deploy automated decision-making that produces legal or similarly significant effects. At present, no such systems are in use.
Third-party automated systems. Some of our subprocessors, such as Cloudflare, use automated systems to detect and mitigate security threats. These systems operate on technical traffic data and are governed by the subprocessor's terms and this policy.
Algorithmic fairness. We design and review our automated systems to avoid unjustified discrimination or bias. If you believe an automated system has treated you unfairly, you may contact us to request a review.
Future changes. If we introduce automated decision-making that produces legal or similarly significant effects in the future, we will update this policy, notify affected users, and provide a mechanism for human intervention and appeal before the system goes live.
Exclusion of AI output. Outputs generated by LLM Providers through the Arcana CLI or proxy are not automated decisions about you made by OTNEL. Those outputs are generated by third-party models based on your prompts, and you are responsible for reviewing and validating them.
Sharing and subprocessors
We do not sell your Personal Data. We share Personal Data only with trusted service providers (processors) who assist us in operating the Services, and only to the extent necessary for them to perform their functions on our behalf. Each processor is contractually obligated to process Personal Data in accordance with this policy and applicable law, to implement appropriate security measures, and to use the data only for the specific purposes we authorize.
| Processor | Role | Data involved | Location |
|---|---|---|---|
| Supabase, Inc. | Authentication, user account database, and authorization | Email address, account identifier, authentication metadata, session data | United States |
| PayPal Holdings, Inc. | Payment processing, subscription management, and invoicing | Billing email, transaction identifiers, subscription status, payment history | United States / Global |
| Cloudflare, Inc. | Content delivery, security, DDoS protection, and analytics | IP address, request metadata, browser characteristics, security events | Global |
| LLM Providers chosen by you | AI inference and model serving | Prompts, files, and other content you choose to send | As determined by the provider |
Supabase. We use Supabase for authentication, user account management, and authorization. Supabase processes your email address, password hashes, session tokens, and account metadata. Supabase is contractually bound to handle this data securely and to process it only for the purposes we specify.
PayPal. We use PayPal to process payments for subscriptions and proxy credits. PayPal collects payment card or bank account information directly from you and provides us with confirmation of payment, transaction identifiers, and subscription status. We do not receive or store your full payment card details.
Cloudflare. We use Cloudflare as a content delivery network, security provider, and analytics platform. Cloudflare processes request metadata, IP addresses, and browser characteristics for purposes such as caching, DDoS mitigation, bot management, and performance analytics. Cloudflare's privacy practices are described in its own policy.
LLM Providers. When you use the Arcana proxy or configure the CLI to send requests to a third-party model provider, that provider receives the prompts and files you choose to send. OTNEL does not control the provider's processing and is not responsible for its privacy practices. You should review the provider's privacy policy before sending sensitive data.
Other disclosures. We may also disclose Personal Data: to comply with applicable law, legal process, or governmental request; to enforce our Terms of Service or other contractual rights; to protect the rights, property, or safety of OTNEL, our users, or the public; and in connection with a business transfer, such as a merger, acquisition, or sale of assets, in which case Personal Data would be transferred subject to confidentiality and data-protection obligations consistent with this policy.
Business transfers. In the event of a merger, acquisition, reorganization, or sale of all or part of our assets, your Personal Data may be transferred to the successor entity. We will ensure that the successor agrees to use your Personal Data in a manner consistent with this policy or provides you with notice of any material changes.
Legal requests. If we receive a legal request for your Personal Data, such as a subpoena, court order, or government request, we will review it carefully to ensure it is lawful and narrowly tailored. We will notify you unless prohibited by law or where notification would create a risk of harm.
Aggregated disclosures. We may share aggregated or anonymized data with third parties for research, marketing, or benchmarking purposes. Because this data does not identify you, it is not Personal Data and is not subject to the sharing restrictions in this policy.
International transfers
OTNEL is based in Costa Rica, and the processors we use may process data in other countries, including the United States, the European Union, and other global locations. By using the Services, you acknowledge and consent to the transfer of your Personal Data to countries other than your country of residence, which may have different data protection laws than those in your jurisdiction.
Transfers to the United States. Some of our processors, including Supabase, PayPal, and Cloudflare, are headquartered or operate data centers in the United States. The United States may not be regarded by some jurisdictions as providing an adequate level of data protection. Where required by applicable law, we implement safeguards for these transfers.
Safeguards. Where required by applicable law, we implement appropriate safeguards for international transfers, including Standard Contractual Clauses approved by the European Commission or equivalent mechanisms, and processor agreements that require the recipient to protect your data in accordance with this policy and applicable law.
Standard Contractual Clauses. For transfers from the European Economic Area, United Kingdom, or Switzerland to countries not recognized as adequate, we rely on Standard Contractual Clauses, supplemented by technical and organizational measures such as encryption and access controls, to ensure that your data receives a level of protection comparable to that in your home jurisdiction.
Processor locations. Cloudflare operates a global network and may route or cache data in various jurisdictions. Supabase and PayPal may process data in the United States and other locations where they maintain infrastructure. We select processors that demonstrate compliance with applicable data protection standards.
Your choices. If you do not wish your data to be transferred internationally, you should not use the hosted Services. The open-source Arcana CLI can be used locally without transferring data to OTNEL or our processors, although data sent to an LLM Provider will still be processed by that provider.
Changes in transfer mechanisms. International data transfer mechanisms are subject to regulatory and judicial developments. If a mechanism we rely on is invalidated or modified, we will promptly assess the impact and implement alternative safeguards that comply with applicable law.
Adequacy decisions. For transfers to countries that have been recognized as adequate by the European Commission or other relevant authority, we may rely on the applicable adequacy decision. We monitor changes to adequacy designations and update our transfer practices accordingly.
Data localization. We do not currently offer data localization options that restrict processing to a specific country or region. If we introduce such options in the future, we will describe them in this policy and in applicable plan documentation.
Security measures
We implement technical and organizational security measures designed to protect Personal Data against unauthorized access, disclosure, alteration, and destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher;
- Encryption of data at rest using industry-standard algorithms;
- Access controls and authentication requirements for internal systems;
- Regular security monitoring, logging, and alerting;
- Network protection through Cloudflare, including DDoS mitigation and Web Application Firewall rules;
- Rate limiting to prevent abuse and unauthorized access; and
- Periodic review and updating of security practices.
Encryption. All data transmitted between your browser or CLI and our servers is encrypted using Transport Layer Security. Data stored on our servers is encrypted at rest using algorithms and key management practices that meet current industry standards.
Access controls. Access to production systems and Personal Data is restricted to authorized personnel who have a legitimate business need. We use role-based access controls, multi-factor authentication, and audit logging to enforce and monitor access.
Monitoring and incident response. We maintain security monitoring systems that detect suspicious activity, unauthorized access attempts, and anomalies in service usage. When an incident is detected, we follow an incident response plan to contain, investigate, and remediate the issue.
Third-party security. We evaluate the security practices of our subprocessors before engaging them and require them to maintain appropriate security measures. However, we cannot guarantee the security of third-party systems, and you should review the security commitments of each provider you use.
User responsibilities. Security is a shared responsibility. You are responsible for maintaining the confidentiality of your account credentials, using strong and unique passwords, securing your API keys, keeping your devices and software up to date, and protecting the data stored on your local machine.
Limitations. No method of electronic transmission or storage is completely secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee absolute security. You use the Services at your own risk, subject to the limitations in our Terms of Service.
Security certifications and audits. While we do not currently hold a formal security certification such as SOC 2 or ISO 27001, we follow recognized security practices and regularly review our controls. If we obtain certifications in the future, we will update this policy to reflect them.
Vulnerability disclosure. We welcome responsible disclosure of security vulnerabilities. If you discover a vulnerability, please report it to support@otnelhq.com rather than exploiting it or publicly disclosing it before we have had a reasonable opportunity to address it.
Data retention
We retain Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to comply with legal and regulatory obligations, to resolve disputes, to enforce our agreements, and to maintain business records. The following retention periods apply unless a longer or shorter period is required by law:
| Category | Retention period |
|---|---|
| Account and authentication data | Until you delete your account, plus a reasonable period for dispute resolution and backups |
| Billing and transaction records | As required by applicable tax, accounting, and legal obligations, generally up to seven years |
| Cloud memory sync data | Until you delete the data or disable sync, plus a short technical retention period |
| Server logs and usage data | Generally up to 90 days, unless retained for security, fraud, or legal purposes |
| Support communications | Until the matter is resolved, plus a reasonable period for quality assurance and legal record-keeping |
| Marketing preferences | Until you withdraw consent or we cease sending such communications |
Retention principles. We apply the principle of data minimization to retention. We keep data only as long as it serves a documented business, legal, or security purpose. Once that purpose no longer applies, we delete or anonymize the data in a secure manner.
Account deletion. Upon deletion of your account, we will delete or anonymize your Personal Data in accordance with the above schedule, except where retention is necessary for the purposes described in this policy or required by law. Some residual copies may remain in backups for a limited period before being permanently purged.
Legal holds. In some cases, we may be required to retain data beyond our normal schedule because of a legal hold, litigation, regulatory investigation, or government request. When a legal hold expires, we will delete the retained data in accordance with this policy.
Deletion procedures. When we delete data, we use secure deletion methods that render the data unreadable and unrecoverable. For data stored in cloud databases, deletion may involve cryptographic erasure, logical deletion, or physical destruction of storage media, depending on the technology used.
Anonymization. In some cases, rather than deleting data, we may anonymize it so that it can no longer be linked to you. Anonymized data may be retained indefinitely for research, analytics, and product improvement.
Your control. You can delete individual cloud memory facts, disable cloud sync, or delete your entire account through the console. These actions initiate deletion in accordance with this policy. If you need assistance with deletion, contact support.
Retention exceptions. We may retain certain records, such as transaction and billing records, even after account deletion to comply with tax, accounting, or legal obligations. Such records are retained in a manner that minimizes the Personal Data included.
Changes to retention. If we change our retention practices in a way that materially affects your privacy, we will update this policy and notify you as required by law.
Your rights
Depending on your jurisdiction, you may have the following rights regarding your Personal Data:
- Right of access. You may request confirmation of whether we process your Personal Data and obtain a copy of that data.
- Right to rectification. You may request correction of inaccurate or incomplete Personal Data.
- Right to erasure ("right to be forgotten"). You may request deletion of your Personal Data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected.
- Right to restriction of processing. You may request that we limit the processing of your Personal Data in specific situations.
- Right to data portability. You may request a copy of your Personal Data in a structured, commonly used, and machine-readable format, where technically feasible.
- Right to object. You may object to processing based on legitimate interests, including direct marketing.
- Right to withdraw consent. Where processing is based on consent, you may withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
How to exercise your rights. To exercise any of these rights, please contact us at support@otnelhq.com or use the privacy controls available in the Arcana console. We may need to verify your identity before fulfilling your request to protect your privacy and prevent unauthorized access.
Response timeframe. We will respond without undue delay and, where applicable, within the timeframes required by law. For GDPR requests, the standard response period is one month, which may be extended by two further months for complex or numerous requests. We will inform you if an extension is necessary.
No fee. We do not charge a fee for exercising your rights unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request. We will explain our reasoning if we decline a request.
Scope of rights. The rights available to you depend on the jurisdiction in which you are located and the legal basis for processing. Not all rights apply in all circumstances. For example, the right to erasure does not apply where retention is necessary for legal compliance or the establishment, exercise, or defense of legal claims.
Portability. Where technically feasible, we can provide your data in a structured, commonly used, and machine-readable format, such as JSON or CSV. You may then transmit that data to another controller. We are not required to adopt systems that are technically incompatible with our own architecture.
Objection to marketing. You have the right to object at any time to the processing of your Personal Data for direct marketing purposes. If you object, we will cease sending marketing communications to you. Service-related communications, such as security alerts and billing notices, are not marketing and will continue.
Automated decision-making. You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects, except where authorized by law. As described in the Automated decision-making section, we do not currently engage in such decision-making.
Complaints. If you are dissatisfied with our response, you have the right to lodge a complaint with a supervisory authority in your jurisdiction, as described in the Complaints section.
Children's privacy
The Services are not directed to individuals under the age of 16, and we do not knowingly collect Personal Data from children. If you are a parent or guardian and believe that your child has provided Personal Data to us, please contact us at support@otnelhq.com. If we learn that we have collected Personal Data from a child under 16 without verification of parental consent, we will take steps to delete that information promptly.
Age gate. Account creation requires the user to represent that they are at least 16 years of age or the age of legal majority in their jurisdiction, whichever is greater. We do not separately verify age for ordinary account creation, but we reserve the right to request verification if we become aware that a user may be underage.
Parental consent. In jurisdictions where a higher age threshold applies or where parental consent is required for processing a child's data, we will obtain appropriate consent before collecting Personal Data from a minor. If you believe a child has registered without proper consent, please contact us.
Education and awareness. We encourage parents and guardians to supervise their children's online activities and to educate them about the risks of sharing personal information online. Children should not use AI tools or command-line applications without appropriate guidance.
Deletion upon discovery. If we discover that we have inadvertently collected Personal Data from a child under the applicable age threshold, we will promptly delete or anonymize that data, close the associated account if any, and notify the parent or guardian where required by law.
No child-directed features. The Arcana Services are designed for software developers, operators, and technically sophisticated users. We do not market to children, create child-directed content, or knowingly collect age-related data for the purpose of targeting minors.
Reporting. If you have reason to believe that a minor is using the Services, you may report it to us at support@otnelhq.com. We will investigate and take appropriate action, which may include suspending the account and deleting associated data.
Legal compliance. We comply with applicable children's privacy laws, including the Children's Online Privacy Protection Act in the United States and equivalent laws in other jurisdictions, to the extent that they apply to our Services.
Regional privacy rights
California Consumer Privacy Act ("CCPA") / California Privacy Rights Act ("CPRA")
If you are a California resident, you have the right to: (i) know what categories of Personal Data we collect and the purposes for which it is used; (ii) request deletion of your Personal Data, subject to certain exceptions; (iii) opt out of the sale or sharing of Personal Data; and (iv) non-discrimination for exercising your privacy rights. We do not sell or share Personal Data for cross-context behavioral advertising. To exercise your rights, contact support@otnelhq.com.
Categories collected. In the preceding twelve months, we may have collected the following categories of Personal Data: identifiers (such as email address and account ID); commercial information (such as billing and transaction records); internet or other electronic network activity information; geolocation data derived from IP addresses; and professional or employment-related information provided by Enterprise customers.
Sources. We collect Personal Data directly from you, automatically through your use of the Services, and from our subprocessors, such as payment and authentication providers. We do not purchase Personal Data from third-party data brokers.
Business or commercial purpose. We collect and use Personal Data for the purposes described in the Purposes and legal bases section, including providing the Services, maintaining security, processing payments, providing support, and complying with legal obligations.
Third parties. We disclose Personal Data to the subprocessors listed in the Sharing and subprocessors section and to law enforcement or other parties when required by law or to protect our rights. We do not sell or share Personal Data for cross-context behavioral advertising.
Retention. We retain Personal Data in accordance with the Data retention section. We do not retain Personal Data longer than is reasonably necessary for the disclosed purpose, except as required by law.
Virginia Consumer Data Protection Act ("VCDPA") and Colorado Privacy Act ("CPA")
If you are a resident of Virginia or Colorado, you may have rights to access, correct, delete, obtain a portable copy of, and opt out of the processing of your Personal Data for targeted advertising, sale, or profiling. We do not sell Personal Data or process it for targeted advertising or profiling in furtherance of decisions that produce legal or similarly significant effects. To exercise your rights, contact support@otnelhq.com.
Opt-out rights. Because we do not engage in targeted advertising, sale, or profiling as those terms are used in the VCDPA and CPA, no opt-out action is required to stop such processing. If our practices change, we will provide a clear opt-out mechanism and update this policy.
Appeals. If you submit a request and we decline to act on it, you have the right to appeal our decision. We will respond to your appeal within the timeframe required by applicable law and provide information about how to contact the relevant attorney general if your appeal is denied.
Sensitive data. The VCDPA and CPA define certain categories of sensitive Personal Data. We do not knowingly collect sensitive Personal Data as defined by those laws, except where you voluntarily provide it in support communications or cloud memory data. Where we process such data, we rely on the applicable lawful basis, such as consent or the necessity of providing the Services.
Universal opt-out mechanisms. We respect universal opt-out signals, such as the Global Privacy Control, to the extent required by applicable law. Because we do not sell or share Personal Data for targeted advertising, such signals do not change our current practices, but we will honor them if our practices change.
European Economic Area, United Kingdom, and Switzerland
If you are located in the EEA, UK, or Switzerland, you have the rights described in the Your rights section above. You also have the right to lodge a complaint with your local supervisory authority if you believe our processing violates applicable data protection law.
Legal bases. For processing in these regions, we rely on the legal bases set out in the Purposes and legal bases section, including performance of a contract, legitimate interests, consent, and legal obligation. We have documented the legal basis for each category of processing.
International transfers. Transfers of Personal Data from the EEA, UK, or Switzerland to countries outside those regions are safeguarded by Standard Contractual Clauses and additional technical and organizational measures, as described in the International transfers section.
Supervisory authorities. You have the right to lodge a complaint with the supervisory authority in the country where you live, work, or where the alleged infringement occurred. A list of EU supervisory authorities is available from the European Data Protection Board.
UK GDPR. Following the United Kingdom's departure from the European Union, the UK GDPR and the Data Protection Act 2018 apply to processing in the UK. We treat UK data subjects' rights as equivalent to those under the EU GDPR, subject to local variations.
Cookies and similar technologies
We use cookies, localStorage, sessionStorage, and similar browser technologies to operate and secure the Services and to remember your preferences. For a detailed description of the technologies we use, their purposes, and how you can control them, please see our Cookie Policy.
Essential technologies. Essential cookies and storage items are necessary for the website and console to function. They include authentication cookies, session tokens, CSRF protection tokens, and consent records. These cannot be disabled without preventing access to the Services.
Functional technologies. Functional cookies and storage remember your preferences, such as your chosen theme, console layout, and display settings. They improve your experience but are not strictly necessary for core functionality.
Analytics technologies. We use privacy-preserving analytics to understand how visitors use the website and to diagnose issues. We do not use advertising cookies, behavioral trackers, or cross-site tracking pixels for marketing purposes.
Consent. Where required by law, we obtain your consent before setting non-essential cookies or analytics technologies. Your consent is recorded in localStorage and can be withdrawn at any time by clearing site data or adjusting your browser settings.
Browser control. You can manage or delete cookies and localStorage through your browser settings. Please note that disabling essential technologies will prevent you from signing in to the console or using hosted features.
Third-party cookies. The only third-party cookies we use are set by Cloudflare for security and performance purposes. We do not allow advertising networks or social media platforms to set tracking cookies on our website.
Cookie Policy relationship. The Cookie Policy is an integral part of this Privacy Policy and provides the detailed inventory of technologies, their durations, and their categories. We encourage you to review it regularly.
Updates. As technologies and regulations evolve, we may update the cookies and storage mechanisms we use. Material changes will be described in an updated Cookie Policy and, where appropriate, in this Privacy Policy.
Data breach notification
In the event of a data breach affecting your Personal Data, we will notify you and the relevant supervisory authorities in accordance with applicable law. Notification will include, at a minimum, the nature of the breach, the categories of data likely affected, the likely consequences, and the measures taken or proposed to address the breach.
Breach response plan. We maintain an incident response plan that governs how we detect, assess, contain, and recover from security incidents. The plan includes procedures for identifying affected data, notifying affected individuals, and cooperating with law enforcement and regulators.
Detection and assessment. When we become aware of a potential breach, we promptly investigate to determine whether Personal Data has been accessed, disclosed, altered, or destroyed without authorization. We assess the severity of the breach, the categories of data affected, and the number of individuals likely impacted.
Notification timing. Where required by law, such as under the GDPR, we will notify supervisory authorities without undue delay and, where feasible, within 72 hours of becoming aware of a reportable breach. We will notify affected individuals as soon as reasonably practicable, unless law enforcement or a regulator directs us to delay notification.
Content of notifications. Notifications will describe, to the extent known: the nature of the breach; the categories and approximate number of affected individuals; the categories and approximate volume of affected Personal Data; the likely consequences; and the measures taken or proposed to mitigate harm and prevent recurrence.
Communication channels. We will use the most reliable contact information we have for you, typically the email address associated with your account. For large-scale breaches, we may also post a notice on the website or console.
Mitigation measures. Upon discovering a breach, we take steps to contain it, eradicate the cause, recover affected systems, and restore normal operations. We also review and, if necessary, strengthen our security controls to reduce the risk of recurrence.
No fault admission. A breach notification does not constitute an admission of fault or liability. We provide notifications as a transparency and compliance measure, and we reserve all rights and defenses under applicable law.
Cooperation. We will cooperate with supervisory authorities, law enforcement, and affected users to investigate and resolve breaches. We will provide reasonable assistance to users who are affected by a breach, including guidance on steps they can take to protect themselves.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the Services. If we make material changes, we will notify you by posting the revised policy on this page with a new "Last updated" date and, where appropriate, by email or through the web console. Your continued use of the Services after the effective date of the revised policy constitutes acceptance of the changes. We encourage you to review this policy periodically.
Material changes. A material change is one that significantly affects your privacy rights or the way we process your Personal Data. Examples include adding new categories of Personal Data collection, introducing new subprocessors in a materially different jurisdiction, or changing the legal basis for a significant processing activity.
Notice methods. We may notify you of material changes by email to the address associated with your account, by a prominent notice in the console, by a banner on the website, or by a combination of these methods. We will also update the effective date at the top of this policy.
Advance notice. Where practicable and required by law, we will provide advance notice of material changes before they take effect. If you do not agree to a material change, you may close your account and stop using the Services.
Non-material changes. Minor changes, such as clarifications, formatting updates, or the addition of non-substantive examples, may be made without advance notice. Such changes will be posted on this page with an updated effective date.
Historical versions. We do not currently maintain a public archive of prior versions of this policy. If you need a prior version for legal or compliance purposes, please contact us and we will provide it if reasonably available.
Compliance with local law. If a local law requires a specific form of notice or a longer advance period, we will comply with that requirement for users in the affected jurisdiction, even if our general policy would otherwise permit earlier implementation.
Your responsibility. It is your responsibility to review this policy periodically and to ensure that the email address associated with your account is current. We are not liable if you miss a notice because your contact information is outdated.
Complaints
If you believe our processing of your Personal Data infringes applicable data protection law, you have the right to lodge a complaint with a supervisory authority in your jurisdiction. We encourage you to contact us first at support@otnelhq.com so that we may address your concerns directly.
Internal resolution. We take privacy complaints seriously. When you contact us with a complaint, we will acknowledge receipt, investigate the matter, and provide a response. We aim to resolve complaints informally and promptly.
Information to include. To help us investigate your complaint, please include: your name and contact information; the nature of the complaint; the relevant Arcana account or email address; the approximate date of the issue; and any supporting documentation. The more detail you provide, the faster we can respond.
External recourse. If you are not satisfied with our response, you may contact the supervisory authority in the country where you live, work, or where the alleged infringement occurred. For EU residents, a list of national supervisory authorities is maintained by the European Data Protection Board.
UK residents. In the United Kingdom, the Information Commissioner's Office is the relevant supervisory authority. You can find contact details at ico.org.uk.
California residents. If you are a California resident and believe a business has violated the CCPA/CPRA, you may also contact the California Attorney General's Office. We will not discriminate against you for exercising your privacy rights.
Good-faith engagement. We commit to engaging in good faith with supervisory authorities and affected individuals to resolve privacy disputes. We will provide truthful and complete information in response to lawful investigations.
No waiver. Our willingness to address complaints internally does not waive any rights or defenses we may have under applicable law. A complaint to a supervisory authority remains your right at any time.