Legal
Privacy Policy
Last updated: September 26, 2026
Archon ("we", "us") operates an enterprise orchestration and governance control plane. This policy describes how we handle information when you use the Archon web application and related APIs.
Information we collect
- Account data — name, email, password hash (or OAuth identity), optional avatar and preferences.
- Workspace & project data — content you create (work items, docs, orchestration configs, connection metadata).
- Integration tokens — encrypted credentials for connected providers (GitHub, GitLab, Jira, etc.), stored only as needed to provide the feature.
- Usage & security logs — authentication events, audit trails, and operational diagnostics.
How we use information
- Provide, secure, and improve the Archon service
- Authenticate users (including email OTP for password reset and destructive confirmations)
- Send product emails you initiate (invites, verification, OTP)
- Enforce access control, policies, and audit requirements
Sharing
We do not sell personal information. We share data only with: (a) subprocessors needed to run the service (e.g. hosting, email delivery); (b) third-party products you explicitly connect; (c) when required by law.
BYOI & customer infrastructure
Archon is bring-your-own-infrastructure. Runner agents and cloud credentials typically remain in your environment. We process only the control-plane metadata and integration tokens you configure.
Retention & security
We retain account and workspace data while your account is active and as needed for legal/security purposes. Secrets are encrypted at rest where applicable. Access is gated by authentication and role-based controls.
Your choices
- Update profile and security settings in-product
- Disconnect integrations at any time
- Request account termination from Settings → Danger zone (email OTP required)
Contact
Privacy questions: support@archon.dev