ARCFORM

API SERVICES

Privacy Policy

Arcform API Services & Sovereign Skill Chrome Extension — Operated by Arcform Ltd

Last updated: 5 July 2026

1. Data Controller

Arcform Ltd ("Arcform", "we", "us") is the data controller for personal data processed through the Arcform API Services. We are committed to protecting your privacy and processing data in compliance with the UK GDPR, the EU General Data Protection Regulation (GDPR), and applicable data protection laws.

2. Data We Collect

Account Data: email address, full name, and role — collected during registration. API Key Data: api_key_id, DID, fingerprint, usage counters, and plan tier — generated when you activate an identity. Envelope Metadata: envelope hashes, byte counts, latency metrics, mediator hops, and delivery status — logged for audit purposes. We never collect, store, or process message content. Envelope payloads are encrypted end-to-end and sealed at the transport layer.

3. How We Use Your Data

We process your data for the following purposes: (a) to provide and maintain the Service, including identity activation, envelope routing, and webhook delivery; (b) to enforce plan limits and usage quotas; (c) to send transactional emails (onboarding, usage alerts, support responses); (d) to detect and prevent fraud, abuse, or Terms of Service violations; (e) to improve the Service through aggregated, anonymised analytics.

4. Legal Basis for Processing

We process your data under the following legal bases: Contract Performance (Art. 6(1)(b) GDPR) — processing necessary to provide the Service you have signed up for. Legitimate Interests (Art. 6(1)(f) GDPR) — security monitoring, fraud detection, and service improvement. Legal Obligation (Art. 6(1)(c) GDPR) — where required by law, regulation, or lawful request.

5. Strip & Seal — Privacy by Architecture

Arcform enforces an immutable privacy model called "Strip & Seal". Every envelope has its metadata stripped before routing. Payloads are encrypted using X25519-XSalsa20-Poly1305. This is not a configurable feature — it is an architectural invariant. Every API response includes metadata_policy: 'stripped_and_sealed' as proof. Envelope logs record only: envelope_hash, proof_checksum, payload_size_bytes, latency_ms, mediator_hops, and delivery status. No content, sender identity, or recipient identity is stored in logs.

6. Data Sharing

We do not sell, trade, or rent your personal data. We share data only with: Infrastructure providers necessary to operate the Service (hosting, email delivery). Law enforcement or regulatory authorities when required by a valid legal order. We require all third-party providers to maintain equivalent data protection standards.

7. Data Retention

Account data is retained for the duration of your account plus 30 days after deletion. Envelope metadata (audit logs) is retained for 12 months for compliance and audit purposes. Ephemeral message bubbles are purged according to their lifecycle (typically within 24 hours of delivery). API keys and DID documents are retained until revoked or the account is deleted.

8. Your Rights

Under GDPR, you have the right to: Access your personal data. Rectify inaccurate data. Erase your data (right to be forgotten). Restrict processing. Data portability. Object to processing. To exercise these rights, contact us at the support page. We will respond within 30 days.

9. International Transfers

Data may be processed in the United Kingdom and the European Economic Area. Where data is transferred outside the EEA, we ensure adequate safeguards are in place, including Standard Contractual Clauses (SCCs) or adequacy decisions.

10. Cookies

The Arcform dashboard uses essential session cookies for authentication. We do not use tracking cookies, advertising pixels, or third-party analytics that process personal data. No cookie consent banner is required for essential-only cookies under ePrivacy regulations.

11. Security

We implement appropriate technical and organisational measures to protect your data, including: encrypted storage for all API keys and signing material; TLS 1.3 for all API communications; cryptographic audit checksums on all administrative actions; role-based access controls; regular security reviews.

12. Arcform Sovereign Skill — Chrome Extension

The Arcform Sovereign Skill browser extension operates under a strict local-first privacy model. Data Collection: The extension collects zero user data. No telemetry, analytics, tracking pixels, or usage statistics are transmitted from the extension. All hashing operations run entirely in-browser via the Web Crypto API (crypto.subtle). Raw input data is never transmitted or stored — only the resulting SHA-256 checksum is sent to the Arcform API for verification. Local Storage: The extension stores the following data locally on the user's device using chrome.storage.local and IndexedDB: (a) API key identifier (api_key_id) for authentication; (b) verification verdicts in the local audit spine (IndexedDB: arcform_audit_spine); (c) mesh peer node records (IndexedDB: arcform_mesh); (d) cached alert notifications (last 50 entries). This data never leaves the user's device and is not synced to any server. Network Requests: The extension makes requests only to the Arcform API (arcform-api.com) for: envelope verification, usage status checks, and alert polling (every 60 seconds via chrome.alarms). No requests are made to any third-party services. Permissions: The extension requires: storage (local credential and audit persistence), notifications (critical governance alerts), activeTab (attestation badge injection on the current page), and alarms (periodic alert polling). No permissions are used for data collection or tracking. Content Script: The content script scans the active page DOM for Arcform envelope hash patterns (16-character hex strings) to inject verification badges. It does not read, collect, or transmit any other page content. The mutation observer monitors DOM changes solely for hash pattern detection. Data Deletion: Users can clear all locally stored data at any time by removing the extension or clearing extension data via Chrome settings. No server-side data is created by extension usage beyond standard API request logs covered in Section 2.

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be communicated via email to registered developers at least 30 days before taking effect. The "Last updated" date at the top of this page indicates the most recent revision.

14. Contact

For privacy-related enquiries, data subject access requests, or complaints, please visit our Support page. If you are unsatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the United Kingdom, or your local data protection authority.

Privacy concerns? Contact Support