← Back to Arkathos

Privacy Policy

Arkathos by TheApexFrameworkLLC  |  Effective Date: July 27, 2026  |  Version 1.0

1. Introduction

TheApexFrameworkLLC ("we," "us," or "our") operates Arkathos, an AI-powered business management platform available at arkathos.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service.

By accessing or using Arkathos, you agree to this Privacy Policy. If you do not agree with the terms of this Privacy Policy, please do not access the Service.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information from Third Parties

3. How We Use Your Information

We use the information we collect to:

4. AI Data Processing

Arkathos uses artificial intelligence to power its business management agents. When you interact with our AI agents, your prompts and business data are sent to third-party AI providers for processing. We use Anthropic and Google (Gemini) for certain agent tasks; which provider handles a given task depends on the task and the agent. Important details about this processing:

4.1 De-Identified Platform Improvement (Opt-In)

To make Arkathos better for everyone, we may create de-identified and aggregated datasets from business records and agent interactions and use them to operate, secure, and improve the Service — for example:

How we protect you in all of the above:

5. How We Share Your Information

We do not sell your personal information. We share your information only in the following circumstances:

5.1 Service Providers

We share data with third-party service providers who help us operate Arkathos:

ProviderPurposeData Shared
SupabaseHosting for our managed Postgres database (with row-level security) and our secrets/key store (Supabase Vault)All application data (encrypted in transit and at rest); encrypted credentials and key references
StripePayment processingBilling info, subscription details
SignalWireSMS two-factor authentication, business communications, and the AI phone secretary that answers inbound calls (see Section 5.6)Phone numbers, message content; live call audio and conversation content for calls handled by the AI secretary
Meta Platforms, Inc. (WhatsApp Business Platform / Cloud API)WhatsApp Business message delivery for opted-in recipients (see Section 5.4)Phone numbers, message content
AnthropicAI agent task processingAgent prompts, business context
Google (Gemini)AI agent task processingAgent prompts, business context
fal.aiAI video generationVideo prompts and any source images you upload for generation
ResendTransactional email delivery (verification, notifications, service messages)Email addresses, email content
CloudflareEdge network / CDN, DDoS protection, TLS termination, and the country signal used to apply the correct regional privacy-consent defaultIP addresses, request metadata
Cloudflare TurnstileBot protection at signup and loginTurnstile token + originating IP address (no PII; no form data)

We may disclose your information if required by law, subpoena, court order, or other governmental request, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

5.3 Business Transfers

If TheApexFrameworkLLC is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent notice on our Service before your information becomes subject to a different privacy policy.

5.4 Mobile Information, SMS Text Messaging, and WhatsApp Opt-In

Text-messaging program. Mobile phone numbers and the text-messaging opt-in consent you provide at signup are used to send you: (i) account verification codes (SMS-based two-factor authentication one-time passcodes); (ii) account-related and transactional service notifications; and (iii) business-communication messages that you or your business direct us to send through the platform (for example, scheduling or dispatch notifications to your own workers or contacts). We do not currently send marketing or promotional text messages. If we ever introduce marketing text messages, we will do so only with your separate, express written consent, and opting out of marketing messages will not affect delivery of verification codes or security notifications. SMS messages are delivered by our messaging provider, SignalWire (see Section 5.1), acting as our service provider (processor) solely to transmit messages on our behalf.

How consent is captured. Text-messaging consent is captured at signup through a dedicated consent checkbox. We retain the verbatim consent language presented to you, together with a timestamped, phone-number-scoped record of your opt-in (and any subsequent opt-out), as evidence of consent. See Section 7 for the retention period applicable to these consent records.

No sharing of mobile information. No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging originator opt-in data and consent are not shared with any third parties. Stated plainly: mobile phone numbers and SMS opt-in/consent data are never shared with or sold to third parties or affiliates for their own marketing or promotional purposes. Sharing with subcontractors that support message delivery (such as SignalWire) occurs solely so those providers can deliver the messaging service on our behalf.

Opting out. You may opt out of SMS at any time by replying STOP to any message, and reply HELP for assistance. Message and data rates may apply, and message frequency varies.

WhatsApp Business channel. Some business-communication conversations may run over WhatsApp instead of SMS. Where a conversation runs over WhatsApp, message delivery is processed by Meta Platforms, Inc. through the WhatsApp Business Platform (Cloud API), acting as a service provider listed in Section 5.1, and your WhatsApp conversations are also subject to WhatsApp's and Meta's own terms of service and privacy policy. Recipients must opt in before receiving business-initiated WhatsApp messages, as required by Meta policy; where messages are sent at a business's direction, that business is responsible for obtaining the recipient's prior opt-in before enrolling the recipient's number. Opt-out (STOP) requests are recorded and honored across both SMS and WhatsApp: the phone-number-scoped opt-out/suppression record is channel-neutral, and the signup consent record described above covers the account holder's own number for both channels. Business-initiated WhatsApp messages sent outside WhatsApp's 24-hour customer-service window use Meta-approved message templates. To stop receiving WhatsApp messages, reply STOP (or request an opt-out) in the conversation, or block the sender within WhatsApp; an opt-out received on either channel is honored across both SMS and WhatsApp. The no-sharing commitments above apply equally to the WhatsApp channel: phone numbers and opt-in consent data are shared with Meta solely to deliver messages, never for Meta's or any other party's marketing or promotional purposes.

5.5 Integrations You Connect

Arkathos allows you to connect your own third-party accounts and services to the platform — for example, workspace messaging tools (such as Slack), email and calendar accounts, social media platforms, point-of-sale and payment services, sales-tax computation engines, bank-data connections, e-commerce stores, and similar business connectors. When you connect such a service using your own account or credentials, any data you direct Arkathos to send to that service (for example, a dispatch notification posted to your own Slack workspace, or content published to your connected account) is transmitted to that service and is thereafter governed by that service's own terms and privacy policy. In these cases we act on your instructions as a service provider (processor); you are the controller of the data you direct us to transmit and are responsible for ensuring you have the rights and any required consents to send it to the connected service. Credentials and tokens for connected services are stored encrypted (see Section 6) and are used only to operate the integration you configured.

Google user data. Where you connect a Google account (for example Gmail or Google Calendar), Arkathos's use and transfer to any other application of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: data received from Google APIs is used only to provide the mailbox and calendar features you configured; it is not used for advertising, is not sold, and is not transferred to third parties except as needed to provide those features, as required by law, or as part of a merger or acquisition with prior notice to you. Connections to Microsoft accounts (Outlook / Microsoft 365) and Apple calendar accounts are operated under the same internal restrictions.

5.6 AI Phone Secretary (Voice Calls)

Arkathos offers an optional AI phone secretary that answers inbound calls to a business phone number you have configured on the platform. It is off by default and answers calls only after the account owner turns it on.

Who processes the call. The AI secretary is operated by SignalWire, our telephony provider (listed in Section 5.1), using SignalWire's voice-AI service. When the secretary answers a call, the live audio of that call and the conversation itself — everything the caller says and everything the assistant says — are transmitted to and processed by SignalWire in order to hear the caller, speak back, and carry out the request. SignalWire processes this information as our service provider (processor) and under its own terms of service and privacy policy. Arkathos supplies the assistant's instructions (your business details, greeting, and any voice notes you have written for it); SignalWire supplies the speech processing.

Callers may not be you. Anyone who calls the business number reaches the assistant. Callers are frequently third parties who do not have an Arkathos account and who have no direct relationship with us — your customers, prospects, suppliers, and members of the public. Where a business enables the AI secretary on its number, that business is the controller of the call information and is responsible for any notice, disclosure, or consent that applicable law requires for AI-handled or recorded calls — including any state or national two-party/all-party consent requirement, and any requirement to disclose that the caller is speaking with an automated assistant. Arkathos acts as a service provider (processor) on the business's instructions.

What Arkathos stores. Arkathos does not store audio recordings of these calls, and does not store a transcript of the conversation. What we store is the outcome of the call, in text, in the business's own account:

These records are stored in the business's account under the same tenant isolation, security, and retention terms as the rest of the account's data (Sections 6 and 7). The account owner may edit or delete them at any time. Where the assistant takes a message or captures a lead, we also notify the account owner by message on the account's configured channel.

Call metadata. Independently of the assistant, our telephony provider processes the standard call metadata required to connect any phone call — the calling and called numbers, the time, and the duration — as described in its own privacy policy.

6. Data Security

We implement comprehensive security measures to protect your information, organized in five layers:

While we use commercially reasonable efforts to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6.1 Biometric Information

Arkathos does not collect, capture, store, transmit, sell, lease, or otherwise process biometric identifiers or biometric information. We do not use fingerprint, face-geometry, iris, voiceprint, retina, or hand-geometry recognition to identify or authenticate anyone, and we do not maintain a biometric database. Where your device offers a screen lock or a device-level unlock method, that is a function of your own device and operating system; the associated biometric data stays on your device, is matched entirely by your device's secure hardware, and is never transmitted to or accessible by Arkathos.

The following state-law disclosures are provided for clarity, regardless of whether the state law would otherwise apply to our practices:

If we ever introduce a feature that would process biometric information, we will update this Policy and obtain any consent that applicable law requires before that feature is activated.

7. Data Retention

We retain your information according to the following schedule. Where a retention window is operational and may be adjusted within reasonable bounds, we say so explicitly.

8. Your Rights

Depending on your location, you may have certain rights regarding your personal information. Time periods specified for our response apply per applicable state law; in all cases we strive to respond as promptly as practicable.

8.1 All Users

8.2 California Residents (CCPA / CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act and California Privacy Rights Act:

Right to Know: You can request details about the categories and specific pieces of personal information we collect, the sources of that information, our business purposes for collecting it, and the categories of third parties with whom we share it.

Right to Delete: You can request that we delete your personal information, subject to certain exceptions.

Right to Opt-Out of Sale: We do not sell your personal information. If this changes, we will provide a clear opt-out mechanism.

Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, contact us at [email protected]. We will respond to verified requests within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the CCPA / CPRA.

8.3 New Jersey Residents (NJDPA)

If you are a New Jersey resident, you have rights under the New Jersey Data Privacy Act ("NJDPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise NJDPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the NJDPA.

8.4 Virginia Residents (VCDPA)

If you are a Virginia resident, you have rights under the Virginia Consumer Data Protection Act ("VCDPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise VCDPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the VCDPA.

8.5 Connecticut Residents (CTDPA)

If you are a Connecticut resident, you have rights under the Connecticut Data Privacy Act ("CTDPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise CTDPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the CTDPA.

8.6 Texas Residents (TDPSA)

If you are a Texas resident, you have rights under the Texas Data Privacy and Security Act ("TDPSA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise TDPSA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the TDPSA.

8.7 Oregon Residents (OCDPA)

If you are an Oregon resident, you have rights under the Oregon Consumer Privacy Act ("OCDPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise OCDPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the OCDPA.

8.8 Colorado Residents (CPA)

If you are a Colorado resident, you have rights under the Colorado Privacy Act ("CPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise CPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the CPA.

8.9 Utah Residents (UCPA)

If you are a Utah resident, you have rights under the Utah Consumer Privacy Act ("UCPA"), including the right to access, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising and the sale of personal data. We do not sell personal data and do not engage in targeted advertising. To exercise UCPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the UCPA.

8.10 Montana Residents (MTCDPA)

If you are a Montana resident, you have rights under the Montana Consumer Data Privacy Act ("MTCDPA"), including the right to access, correct, delete, and obtain a portable copy of your personal data, and the right to opt out of targeted advertising, the sale of personal data, and certain profiling. We do not sell personal data and do not engage in targeted advertising. To exercise MTCDPA rights, contact us at [email protected]; we will respond within 45 days, with one extension of up to 45 additional days where reasonably necessary, consistent with the MTCDPA.

9. Do Not Sell My Personal Information

TheApexFrameworkLLC does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. The data shared with our service providers (listed in Section 5.1) is shared solely to operate and improve Arkathos, not for those providers' independent use.

10. Children's Privacy

Arkathos is a business management platform designed for use by adults. We do not knowingly allow children under 13 (or 16 in certain jurisdictions) to create accounts or use the Service directly, and we do not knowingly collect personal information directly from children as users of the Service.

Childcare, daycare, and education customers. Some businesses that use Arkathos — such as childcare centers, daycares, and tutoring services — keep records about the minors in their care. Where such a business enters children's records into the Service, Arkathos acts solely as a service provider (processor) handling that information on the business's behalf and under its instructions. The business is the controller of those records and is solely responsible for providing required notices to, and obtaining any required consent from, the children's parents or legal guardians, including under the Children's Online Privacy Protection Act (COPPA) and applicable state childcare, education, and privacy laws. For these records we provide additional safeguards, including encryption under a dedicated key that is separate from the keys protecting other personal information and that fails closed (if that key is unavailable the record is rejected rather than stored unprotected, see Section 6), role-based per-employee access controls, access logging, and consent tracking. Children's records are not sent to any third-party AI provider. We do not use children's records to train AI models, to generate cross-customer analytics, or for any purpose other than providing the Service to the business that entered them. Children's records are never included in any de-identified or aggregated platform dataset — including the vendor/supplier directory, creator suggestions, or AI-improvement corpus described in Section 4.1 — and are never shared with any other customer or third party.

If you believe a child has provided personal information to us directly (as opposed to a business customer entering records about a child in its care), please contact us at [email protected] and we will promptly delete it.

11. Mobile Application Data Practices

The Arkathos mobile applications (iOS and Android) provide authenticated access to your Arkathos account. The mobile applications do not perform on-device fingerprinting, do not call platform fingerprinting APIs for the purpose of uniquely identifying a device, and do not transmit derived device-identification signals from the application process. Device fingerprinting (canvas, WebGL, font, and browser-derived signals described in Section 2.2) is performed only during web-based signup, account activation, and payment flows accessed through the in-app browser surface (SFSafariViewController on iOS, Chrome Custom Tabs on Android). Subscription purchases and billing actions are handled through the same web flow; the mobile applications display billing status as read-only. The mobile applications retain your workspace session token in application storage on the device so you remain signed in between launches (see Section 6). Where you sign in to a business's client portal as a portal visitor, the portal session token is retained in browser local storage on the web and is held only in memory, for the duration of the app session, in the native applications.

Trusted-device recognition. To recognize trusted devices and help secure your account, the mobile applications compute, on-device, a hashed device identifier (derived from device and application characteristics) and transmit ONLY that hash to Arkathos's own systems when you sign in and during your session, so the device appears in your account's authorized-devices list and sign-ins from unrecognized devices can be detected. This is separate from, and does not change, the web-flow device fingerprinting described in Section 2.2 (which remains web-only): the recognition hash is used for account security, is not a fraud-grade fingerprint, is never shared with third parties, and no underlying device signals leave the device. This disclosure supersedes the statement above that the mobile applications do not transmit derived device-identification signals — to the extent of this trusted-device-recognition purpose only.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on our website and updating the "Effective Date" above. For significant changes, we will provide additional notice via email. Your continued use of Arkathos after changes become effective constitutes acceptance of the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

TheApexFrameworkLLC

For data access or deletion requests, please email us with the subject line "Data Rights Request" and include your account email address. We will verify your identity before processing any request.