AArc Studio

Privacy Policy

How Arc Studio handles product work, evidence, and AI processing

This policy explains what we collect, how we use it, when we share it, and how long we keep it. It is written for teams using Arc Studio to turn research and product decisions into evidence-grounded PRDs.

Effective date: June 17, 2026

Short Version

Your workspace content stays yours

Arc Studio uses your PRD sections, evidence, assumptions, and comments to provide the workspace, generate drafts, review readiness, support collaboration, and export your work.

AI is used only to operate the product

When you ask Arc Studio to generate or review content, relevant workspace content is sent to our AI infrastructure. Arc Studio does not use your content to train AI models.

Analytics are intentionally limited

Product analytics use opaque IDs and event metadata. Section text, evidence text, workspace titles, and email addresses should not be included in analytics events.

Deletion follows the workspace lifecycle

Active workspaces are retained while your account is active. Archived workspaces are eligible for hard deletion after 90 days, and audit metadata is retained for limited operational periods.

Personal Information Categories

The table below summarizes the types of information Arc Studio may process, depending on how your organization uses the product.

CategoryExamples
IdentifiersName, email, user ID, organization ID, account role, invitation records
Commercial informationPlan, seat count, billing status, invoices, usage records
Internet or network activitySession events, device metadata, IP address, browser information, diagnostic logs
Professional informationRole or team information you provide, reviewer role labels, organization membership
User-generated contentPRD sections, evidence, assumptions, comments, sign-offs, exports, and connected-tool drafts
Inferences and product signalsReadiness scores, evidence classifications, AI draft acceptance, feature usage, aggregated product metrics

1. Scope

This Privacy Policy explains how EnContext, Inc. ("EnContext," "Arc Studio," "we," "us," or "our") collects, uses, discloses, protects, and retains personal information when you use Arc Studio, our websites, and related services.

Arc Studio is a product requirements workspace for teams. It helps users create PRDs, link evidence, run AI-assisted drafting and readiness reviews, collaborate with teammates, and export work to connected tools.

This policy applies to personal information we process as a service provider and as a business operator. If your organization provides Arc Studio to you, your organization may also control some information in your workspace and may have additional privacy notices or policies.

2. Information We Collect

Account and organization information: name, work email, organization name, authentication information, plan selection, role, workspace membership, invitations, and account settings.

Workspace content: PRD workspace titles, summaries, section text, evidence artifacts, links, notes, assumptions, reviewer comments, sign-off records, exports, and other information you or your teammates add to Arc Studio.

AI and product usage information: generation requests, accepted or rejected drafts, readiness review activity, evidence classification events, export actions, feature usage, timestamps, workspace IDs, user IDs, and other operational metadata.

Billing and commercial information: plan, seat counts, billing status, usage records, invoices, and payment-related metadata. Payment card details are processed by our payment provider and are not stored by Arc Studio.

Device and log information: IP address, browser type, device information, pages viewed, referral URLs, session events, error traces, diagnostic logs, and security events.

Support communications: messages you send to us, attachments you choose to provide, consent records for support access, and information needed to investigate support requests.

3. How We Use Information

We use information to provide, secure, maintain, and improve Arc Studio; authenticate users; create and manage workspaces; support collaboration; generate and review PRD content; classify evidence; calculate readiness; provide exports; administer billing; provide support; and communicate with users about the service.

We also use limited product analytics to understand activation, reliability, feature adoption, and retention. Analytics should use opaque identifiers and operational metadata, not PRD content, evidence text, workspace titles, or email addresses.

We may use aggregated or de-identified information for analytics, product planning, security, reporting, and business operations. We do not attempt to re-identify de-identified information except as permitted by law.

4. AI Processing

Arc Studio uses AI to help draft and review PRD content. When you trigger AI-assisted features, Arc Studio assembles a prompt from relevant workspace content, evidence, assumptions, and product instructions, then sends that prompt to our AI infrastructure.

Arc Studio does not include billing information, authentication tokens, Supabase JWTs, audit logs, unrelated workspace data, or user identifiers in AI prompts unless you typed that information into the workspace content yourself.

Arc Studio currently uses Amazon Bedrock with Anthropic Claude models for production AI processing. AWS states that Amazon Bedrock inputs and outputs are not shared with model providers and are not used to train foundation models. Arc Studio does not store assembled prompts before or after transmission.

AI output may be inaccurate or incomplete. You are responsible for reviewing AI-generated drafts, readiness findings, role summaries, and export drafts before relying on them.

In local development or testing modes, Arc Studio may use deterministic mock AI responses. In those modes, workspace content is not sent to an external AI model.

5. How We Share Information

Service providers: we share information with vendors that help us operate Arc Studio, including cloud hosting, authentication, database, storage, AI infrastructure, logging, analytics, email, billing, and customer support providers. These providers may process information only for authorized purposes.

Your organization and collaborators: workspace content and activity may be visible to the account owner, organization administrators, invited collaborators, reviewers, and other users with access to the relevant workspace.

Connected services: if you export to or connect Arc Studio with tools such as Jira, Linear, cloud storage, or communication platforms, we share the information needed to complete the integration you request.

Legal, safety, and compliance: we may disclose information if required by law, legal process, or enforceable governmental request, or if we believe disclosure is necessary to protect rights, safety, security, or the integrity of Arc Studio.

Business transfers: information may be disclosed or transferred as part of a merger, acquisition, financing, reorganization, sale of assets, or similar corporate transaction.

We do not sell personal information in the traditional sense, and we do not share workspace content for cross-context behavioral advertising.

6. Retention And Deletion

Workspace content is retained while your account or organization remains active, unless you or your organization deletes it sooner. Archived workspaces are eligible for hard deletion after 90 days.

Evidence, sections, collaboration records, sign-offs, and AI generation job records follow the lifecycle of the workspace they belong to and are deleted when the workspace is hard-deleted.

AI audit metadata is retained for a limited operational period, with a default retention period of up to 90 days. Raw prompts and raw model outputs are not stored in the AI audit log.

Application audit events are retained for limited operational and security periods, generally 30 days by default and up to 90 days when configured. Cloud diagnostic logs and support/debug payloads are generally retained for 30 days.

Billing, tax, invoice, and usage records may be retained for the duration of the customer relationship and for up to 7 years or longer where required by law, accounting rules, dispute resolution, or legitimate business needs.

Backups and cached copies may persist for a limited time after deletion, but are protected from ordinary use and are overwritten according to our backup lifecycle.

7. Security And Access Controls

We use technical and organizational safeguards designed to protect information, including encryption in transit, access controls, row-level security, separation of server-only credentials, service-role restrictions, audit logging, and limited internal access.

Internal support access to workspace content is limited. Tier-1 support may access workspace metadata needed to confirm account or workspace status. Access to PRD content for support escalation requires customer consent and should be logged with an actor, timestamp, and reason.

No system is perfectly secure. You are responsible for using strong authentication, keeping credentials confidential, and managing workspace invitations carefully.

8. Your Choices And Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information. You may also have the right to appeal certain decisions and to opt out of certain types of sharing or targeted advertising.

California residents may have rights under the California Consumer Privacy Act, including the right to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. Arc Studio does not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.

Users in the European Economic Area, United Kingdom, and Switzerland may have rights under applicable data protection laws. Where required, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations.

To exercise privacy rights, contact us using the details below. If your account is provided by an organization, we may direct your request to that organization or ask for authorization before acting on workspace content controlled by that organization.

9. International Transfers

Arc Studio is operated from the United States and may process information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws that differ from the laws where you live.

When required, we use appropriate safeguards for international transfers, such as contractual protections or other legally recognized transfer mechanisms.

10. Children

Arc Studio is intended for professional use and is not directed to children under 13 or the age required by local law. We do not knowingly collect personal information from children.

11. Changes To This Policy

We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, by email, or by another reasonable method. The updated policy will be effective when posted unless it states otherwise.

12. Contact Us

Questions or privacy requests can be sent to EnContext, Inc. at privacy@encontext.io. Please include enough information for us to verify your request and identify the account or organization involved.

This policy is intended to be a clear public notice for Arc Studio users. It is not a substitute for a negotiated data processing agreement, security addendum, or customer-specific enterprise terms where those are required.