Skip to content
ARCAVISION
Arca Vision

LEGAL

Privacy Policy

Architectural privacy-first principles for ARCA, this website, and commercial engagements.

Effective Date:
August 28, 2026
Entity:
ARCA VISION LABS LLC

1. Architectural Privacy First Principle

ARCA VISION LABS LLC ("Company," "we," "us," or "our") builds software, artificial intelligence systems, and engineering infrastructure under zero-trust, privacy-first principles. We believe the most effective way to safeguard sensitive user data is to avoid collecting, storing, or centralizing it in the first place.

2. Standalone Software Tools (ARCA Secrets Manager)

For users of our offline, local-first utilities (including ARCA at /artifacts/arca):

  • Zero Cloud Storage: ARCA operates entirely on your local machine. We do not maintain vault servers, backend databases, or cloud sync infrastructure.
  • Zero Telemetry or Analytics: The core binary contains zero network dependencies and does not collect usage analytics, crash reports, IP addresses, or telemetry.
  • Zero Knowledge of Credentials: We have no technical means to see, capture, log, or decrypt your master passwords, secrets, recovery shares, or vault contents.

3. Information We Collect Through Our Website & Commercial Services

We limit data collection to the operational minimum required to communicate, fulfill commercial transactions, and deliver professional engineering engagements:

  • Direct Communications: If you contact us directly via email (e.g., observer@arca.vision), we retain your email address, message contents, and relevant metadata to respond to your inquiry.
  • Billing & Purchases: If you purchase commercial licenses or pay consulting invoices through our payment processors (e.g., Stripe), your payment details and billing address are processed directly by the payment processor under their respective security and privacy standards. We do not store full credit card numbers on our servers.
  • Basic Server Logs: When accessing arca.vision, our hosting infrastructure may record standard, temporary HTTP logs (e.g., IP address, browser user-agent, timestamp) strictly for routing integrity, DDoS defense, and infrastructure security.

4. Sector-Specific Engagements (Healthcare, Government & Commercial)

  • Healthcare (HIPAA): Any consulting, model deployment, or custom development involving Protected Health Information (PHI) is isolated and handled strictly under executed Business Associate Agreements (BAAs).
  • Government & Defense (DoD / SAM.gov): Work performed for defense or civilian agencies adheres strictly to the data safeguarding, non-disclosure, and FAR/DFARS compliance mandates established in the applicable prime contract or grant award.
  • Private Clients: Proprietary algorithms, customer data, and development artifacts shared under enterprise consulting agreements remain governed by the confidentiality clauses in our bilateral contracts.

5. How We Share Information

We do not sell, rent, monetize, or trade personal data or customer records. We only disclose information under the following narrow circumstances:

  • Service Providers: Essential infrastructure providers (e.g., payment processing and transactional email) bound by strict confidentiality obligations.
  • Legal Compliance: When strictly required by applicable federal law, court order, or binding government subpoena.

6. Data Retention & Security

We retain direct communication and billing records only as long as necessary to fulfill business operations, warranty obligations, and statutory tax/accounting requirements. We employ industry-standard technical controls to prevent unauthorized access or disclosure.

7. Your Rights

Depending on your jurisdiction, you may request access to, correction of, or deletion of any personal contact information we hold about you. Direct all requests to observer@arca.vision.

8. Contact Information

ARCA VISION LABS LLC

Email: observer@arca.vision

Austin, TX, United States

Software for missions
that matter.

Get in touch