Privacy Policy
Last updated: September 2026
1. Introduction
ArchVibe ("we", "us", or "our") respects your privacy. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use our website and course platform (the "Service").
2. Data We Collect
We collect the following types of information:
- Account information: Email address and hashed password (managed by our authentication provider, Logto).
- Purchase information: Order details, tier purchased, and transaction IDs. Payment details (card numbers, billing address) are handled entirely by Creem and never stored on our servers.
- Usage data: Pages visited and lessons accessed, used to track course progress.
- Architect MCP data: If you use the Architect MCP, we keep a log of each call your AI tool makes: which tool it called, when, which tier answered (sketch or build), the name of the AI tool itself (for example "claude-code"), the plain-language description of the feature it was asking about, how many decisions the answer marked as required and how many were already met, and a one-way hash of the project identifier your tool sends. The hash lets us count how many different projects use it; it cannot be turned back into a name, and we never store the name itself.
- Architect MCP sign-in: On the build tier your AI tool signs in with your ArchVibe account, through Logto, the same way this website does. The token that results is held by your AI tool on your own machine, not by us. If you use an API key instead (for a tool that cannot sign in), we store only a hash of it, never the key itself.
- The free sketch, without an account: The sketch tier needs no account. Its calls are logged the same way, with no person attached: there is no user to attach them to.
- Links from a sketch: A sketch ends with links to this website. When you follow one, we record which decisions the sketch named and which AI tool produced it, so we know the notes reached a person. No name, no email, no cookie.
What the Architect MCP deliberately does not collect. It does not receive or store your code. It does not store your repository name, URL, or any identifier for your project. It does not store the architectural decisions you record: those are written to a file inside your own project, which is why they keep working when you change machines, and why cancelling never takes them away.
The one thing we do keep from your project is that plain-language feature description, and we keep it for a reason worth stating: reading what someone asked for next to what our guidance actually surfaced is the only way we find the questions our own graph is blind to. Do not put anything confidential in it, and if you would rather we did not hold it, you can delete the whole log at any time from your account page.
3. How We Use Your Data
We use your data to:
- Provide access to your purchased course content
- Track your lesson progress
- Process refunds and handle support requests
- Send important product updates (no marketing emails unless you opt in)
- Improve the Architect MCP's guidance, by reviewing which questions it failed to raise
4. Third-Party Services
We share data with the following services, each for a specific purpose:
| Service | Purpose | Data Shared |
|---|---|---|
| Creem | Payment processing (Merchant of Record) | Email, purchase details, payment info |
| Logto | Authentication (account sign-in) | Email, hashed password |
| Oracle Cloud | Application database and file storage | Account ID, purchase details, course progress, audio files |
| Cloudflare | Website hosting and CDN | IP address (for serving content), standard web logs |
| Meta | Advertising measurement, when we are running ads (see section 5) | Pages visited, the ad you clicked, and on purchase your email in hashed form |
| Microsoft Clarity | Heatmaps and session recordings, on our marketing pages only (see section 5) | Pages visited, clicks, scrolling, and a recording of your visit to those pages |
Creem is our Merchant of Record and processes all payment data. We never see or store your credit card number, billing address, or other payment details.
5. Cookies, advertising measurement and session recording
Essential cookies. Authentication session tokens, required to keep you logged in. These are always on, because the site cannot work without them.
Advertising measurement. When we run ads, we use the Meta pixel to see which
ads bring people here and which of those visits lead to a purchase. It sets the
_fbp and _fbc cookies, which identify your browser and the ad you
clicked. When you buy, our server also reports that sale to Meta through their Conversions API,
and when you start a checkout, the checkout start. Both carry your IP address and browser type,
and the sale also carries your email address in hashed form, so the purchase can be matched to
the ad. Under California law this counts as sharing personal information for cross-context
behavioral advertising. We do not sell personal information.
Session recording. On our marketing pages only, meaning the home page, the
pricing page and our advertising landing pages, we use Microsoft Clarity to see how those
pages are actually used: where people click, how far down they scroll, and where they give
up. It records your visit to those pages so we can watch it back and fix what is broken. Text
you type into forms is masked and never reaches a recording. It sets the _clck
and _clsk cookies, which are first-party and let Clarity tell one visit from
another.
Clarity never runs on lessons, on the toolkit, or on any page you reach by logging in. We also switch off Clarity's advertising storage for every visitor, so nothing it collects is used to target ads to you or shared with Microsoft's advertising products. That means this is not sharing or selling under California law, unlike the pixel described above. We run no other analytics or advertising trackers.
Your choice depends on where you are. In the European Economic Area, the United Kingdom, Switzerland, Quebec and Brazil, nothing loads until you accept: the pixel and the recording are both off by default and the banner asks first. One choice covers both. In the United States, Canada outside Quebec, Australia and New Zealand, measurement runs by default and you can turn it off. Anywhere we cannot place, we ask first.
How to opt out, at any time. Use the Privacy choices button in the footer of any page. We also honour the Global Privacy Control signal everywhere, not only where the law requires it: if your browser or extension sends it, we treat it as an opt out and never show you a banner about it.
6. Your Rights (GDPR)
If you're in the European Economic Area, you have the right to:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate data.
- Erasure: Ask us to delete your personal data ("right to be forgotten").
- Portability: Request your data in a portable format.
- Objection: Object to processing of your data for specific purposes.
To exercise any of these rights, email us at tamir@archvibe.app. We will respond within 30 days.
For the Architect MCP specifically, you do not need to ask us: the account page has a button that deletes your entire call log immediately.
7. Data Retention
We retain your account and purchase data for as long as your account is active. If you request account deletion, we will remove your personal data within 30 days, except where we're legally required to retain it (e.g., financial records for tax purposes).
Architect MCP call log. When an Architect subscription ends, whether you cancel, it lapses, or it is refunded, we automatically erase the feature descriptions from your call log. What remains is anonymous counts (how many calls, which tool, which AI client, which tier, the project hash) that we use to understand whether the product is working at all. You can delete the log yourself at any time, without cancelling, from your account page. Sketch calls made without an account were never attached to anyone and are kept as those same counts.
8. Security
We use industry-standard security measures including encrypted connections (HTTPS), hashed passwords, and access controls. Payments are handled entirely by Creem, a PCI-compliant payment processor.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes by updating the "Last updated" date and, when possible, sending a notice to the email on your account.
10. Contact
If you have questions about this Privacy Policy or want to exercise your data rights, contact us at tamir@archvibe.app.