Privacy Policy
How Arc Studio handles product work, evidence, and AI processing
This policy explains what we collect, how we use it, when we share it, and how long we keep it. It is written for teams using Arc Studio to turn research and product decisions into evidence-grounded PRDs.
Effective date: June 17, 2026
Short Version
Your workspace content stays yours
Arc Studio uses your PRD sections, evidence, assumptions, and comments to provide the workspace, generate drafts, review readiness, support collaboration, and export your work.
AI is used only to operate the product
When you ask Arc Studio to generate or review content, relevant workspace content is sent to our AI infrastructure. Arc Studio does not use your content to train AI models.
Analytics are intentionally limited
Product analytics use opaque IDs and event metadata. Section text, evidence text, workspace titles, and email addresses should not be included in analytics events.
Deletion follows the workspace lifecycle
Active workspaces are retained while your account is active. Archived workspaces are eligible for hard deletion after 90 days, and audit metadata is retained for limited operational periods.
Personal Information Categories
The table below summarizes the types of information Arc Studio may process, depending on how your organization uses the product.
| Category | Examples |
|---|---|
| Identifiers | Name, email, user ID, organization ID, account role, invitation records |
| Commercial information | Plan, seat count, billing status, invoices, usage records |
| Internet or network activity | Session events, device metadata, IP address, browser information, diagnostic logs |
| Professional information | Role or team information you provide, reviewer role labels, organization membership |
| User-generated content | PRD sections, evidence, assumptions, comments, sign-offs, exports, and connected-tool drafts |
| Inferences and product signals | Readiness scores, evidence classifications, AI draft acceptance, feature usage, aggregated product metrics |
1. Scope
This Privacy Policy explains how EnContext, Inc. ("EnContext," "Arc Studio," "we," "us," or "our") collects, uses, discloses, protects, and retains personal information when you use Arc Studio, our websites, and related services.
Arc Studio is a product requirements workspace for teams. It helps users create PRDs, link evidence, run AI-assisted drafting and readiness reviews, collaborate with teammates, and export work to connected tools.
This policy applies to personal information we process as a service provider and as a business operator. If your organization provides Arc Studio to you, your organization may also control some information in your workspace and may have additional privacy notices or policies.
2. Information We Collect
Account and organization information: name, work email, organization name, authentication information, plan selection, role, workspace membership, invitations, and account settings.
Workspace content: PRD workspace titles, summaries, section text, evidence artifacts, links, notes, assumptions, reviewer comments, sign-off records, exports, and other information you or your teammates add to Arc Studio.
AI and product usage information: generation requests, accepted or rejected drafts, readiness review activity, evidence classification events, export actions, feature usage, timestamps, workspace IDs, user IDs, and other operational metadata.
Billing and commercial information: plan, seat counts, billing status, usage records, invoices, and payment-related metadata. Payment card details are processed by our payment provider and are not stored by Arc Studio.
Device and log information: IP address, browser type, device information, pages viewed, referral URLs, session events, error traces, diagnostic logs, and security events.
Support communications: messages you send to us, attachments you choose to provide, consent records for support access, and information needed to investigate support requests.
3. How We Use Information
We use information to provide, secure, maintain, and improve Arc Studio; authenticate users; create and manage workspaces; support collaboration; generate and review PRD content; classify evidence; calculate readiness; provide exports; administer billing; provide support; and communicate with users about the service.
We also use limited product analytics to understand activation, reliability, feature adoption, and retention. Analytics should use opaque identifiers and operational metadata, not PRD content, evidence text, workspace titles, or email addresses.
We may use aggregated or de-identified information for analytics, product planning, security, reporting, and business operations. We do not attempt to re-identify de-identified information except as permitted by law.
4. AI Processing
Arc Studio uses AI to help draft and review PRD content. When you trigger AI-assisted features, Arc Studio assembles a prompt from relevant workspace content, evidence, assumptions, and product instructions, then sends that prompt to our AI infrastructure.
Arc Studio does not include billing information, authentication tokens, Supabase JWTs, audit logs, unrelated workspace data, or user identifiers in AI prompts unless you typed that information into the workspace content yourself.
Arc Studio currently uses Amazon Bedrock with Anthropic Claude models for production AI processing. AWS states that Amazon Bedrock inputs and outputs are not shared with model providers and are not used to train foundation models. Arc Studio does not store assembled prompts before or after transmission.
AI output may be inaccurate or incomplete. You are responsible for reviewing AI-generated drafts, readiness findings, role summaries, and export drafts before relying on them.
In local development or testing modes, Arc Studio may use deterministic mock AI responses. In those modes, workspace content is not sent to an external AI model.
6. Retention And Deletion
Workspace content is retained while your account or organization remains active, unless you or your organization deletes it sooner. Archived workspaces are eligible for hard deletion after 90 days.
Evidence, sections, collaboration records, sign-offs, and AI generation job records follow the lifecycle of the workspace they belong to and are deleted when the workspace is hard-deleted.
AI audit metadata is retained for a limited operational period, with a default retention period of up to 90 days. Raw prompts and raw model outputs are not stored in the AI audit log.
Application audit events are retained for limited operational and security periods, generally 30 days by default and up to 90 days when configured. Cloud diagnostic logs and support/debug payloads are generally retained for 30 days.
Billing, tax, invoice, and usage records may be retained for the duration of the customer relationship and for up to 7 years or longer where required by law, accounting rules, dispute resolution, or legitimate business needs.
Backups and cached copies may persist for a limited time after deletion, but are protected from ordinary use and are overwritten according to our backup lifecycle.
7. Security And Access Controls
We use technical and organizational safeguards designed to protect information, including encryption in transit, access controls, row-level security, separation of server-only credentials, service-role restrictions, audit logging, and limited internal access.
Internal support access to workspace content is limited. Tier-1 support may access workspace metadata needed to confirm account or workspace status. Access to PRD content for support escalation requires customer consent and should be logged with an actor, timestamp, and reason.
No system is perfectly secure. You are responsible for using strong authentication, keeping credentials confidential, and managing workspace invitations carefully.
8. Your Choices And Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, or object to processing of your personal information. You may also have the right to appeal certain decisions and to opt out of certain types of sharing or targeted advertising.
California residents may have rights under the California Consumer Privacy Act, including the right to know, delete, correct, opt out of sale or sharing, limit certain uses of sensitive personal information, and not be discriminated against for exercising privacy rights. Arc Studio does not use or disclose sensitive personal information for purposes that require a right to limit under the CCPA.
Users in the European Economic Area, United Kingdom, and Switzerland may have rights under applicable data protection laws. Where required, our legal bases may include performance of a contract, legitimate interests, consent, and compliance with legal obligations.
To exercise privacy rights, contact us using the details below. If your account is provided by an organization, we may direct your request to that organization or ask for authorization before acting on workspace content controlled by that organization.
9. International Transfers
Arc Studio is operated from the United States and may process information in the United States and other countries where we or our service providers operate. Those countries may have privacy laws that differ from the laws where you live.
When required, we use appropriate safeguards for international transfers, such as contractual protections or other legally recognized transfer mechanisms.
10. Children
Arc Studio is intended for professional use and is not directed to children under 13 or the age required by local law. We do not knowingly collect personal information from children.
11. Changes To This Policy
We may update this Privacy Policy from time to time. If changes are material, we will provide notice through the service, by email, or by another reasonable method. The updated policy will be effective when posted unless it states otherwise.
12. Contact Us
Questions or privacy requests can be sent to EnContext, Inc. at privacy@encontext.io. Please include enough information for us to verify your request and identify the account or organization involved.
This policy is intended to be a clear public notice for Arc Studio users. It is not a substitute for a negotiated data processing agreement, security addendum, or customer-specific enterprise terms where those are required.