Arcaeon

Arcaeon Privacy Policy

Not legal advice. Every claim below was checked against the code that actually runs the site and the hosted Witness — not assumed, not copied from a template. Where we don't know something, this document says so instead of guessing.

Effective date: 24 September 2026 · Covers: arcaeon.io (marketing site), witness.arcaeon.io (the hosted Witness API), and the free arcaeon package (pip install arcaeon).

Previous version: effective 19 August 2026. It covered the free libraries under their separate package names, now one package, arcaeon (the old names are listed at /migrate). This version names that one package and adds §2, which commands open a network connection.

1. The short version

2. Which arcaeon commands open a network connection

Checked against the arcaeon package source. These connect, and only when you run them:

buy makes no request: it prints a checkout link from a file inside the package. Setting ARCAEON_WITNESS_URL points the hosted commands at a witness you choose instead of ours. Commands that start a program you name (proxy, vet probe, baseline) run that program, and what it connects to is its own business.

Every other command (log, verify, once, deal, reconcile, audit, vet, badge, compact, distill, dedup, meter, selftest, version) runs offline and sends nothing, to us or anyone.

3. What the hosted Witness stores

Data Where stored Public or private Purpose
namespace (a string you choose) Public GitHub repo dan8433-user/arcaeon-witness-pins, as a JSON file path Public Identifies whose pin this is. You choose it; we don't assign it. Don't put PII in it; see §5.
rows, chain (a hash), pinned_at, seq, cadence_hours, next_pin_due_by Same public repo, same file Public The witness mechanism itself — this is the product.
API key, hashed (full sha256, never the raw key) Private GitHub repo dan8433-user/arcaeon-witness-usage Private Usage metering, billing enforcement, idempotent credit tracking.
Usage counts / balance per key Same private repo Private Enforces your plan cap (100/mo free, 2,000/mo paid).
Payment/checkout data (name, card, email) Stripe, not our own infrastructure Held by Stripe as payment processor Billing. Our own webhook code reads a hash of your key and the pack you bought — not your email or name. Stripe's own dashboard does show us your checkout email by default, since Stripe Checkout always collects one; we can see it there even though our code never touches it.

Never stored, anywhere: the content of your ledger, log rows, or anything a pin references. Only the hash and the row count.

4. Where this data goes

5. What not to put in a namespace

Namespace names and pin fingerprints are committed to a public GitHub repository by design — that's the entire trust mechanism (see /witness-practices). So: don't use your name, email address, or anything identifying as a namespace. This is the one place your own choice, not our architecture, decides whether something private becomes public.

6. Data retention and deletion

[PENDING-DANIEL — wording below is draft, needs sign-off before this ships.]

The pin mechanism is architecturally append-only and public. A pin, once committed, can't be quietly deleted without visibly rewriting a public git history — which the anchoring described in /witness-practices §6 exists specifically to make detectable. That has a real consequence for any deletion request: we can't delete a namespace's public pin history without either (a) breaking the tamper-evidence promise you're paying for, or (b) doing it visibly, which defeats the same promise. Better you know this before choosing a namespace than discover it after asking us to delete one. Draft language:

Public pin records (namespace, rows, chain, timestamp) are, by the nature of the service, committed to a public, append-only ledger and are not designed to be deleted. If you need a right to erasure for regulatory reasons, don't use the Witness for data that requires one, or use a namespace that doesn't reference anything identifiable (see §5).

Private data (API keys, usage/balance records): email hello@arcaeon.io to request deletion. There's no self-serve deletion path yet.

7. Children's privacy

The Witness is developer/agent infrastructure. It's not directed at children under 13, and we don't knowingly collect anything from them.

8. Changes to this policy

Tracked the same way as the Terms — see /terms §7. No separate announcement mechanism exists beyond the public build-log.

9. Contact

hello@arcaeon.io — checked daily, per /witness-practices §8. This is the one privacy-contact claim in this document already backed by a real process, not a promise.