Who is responsible
Architect AI provides the service at architect-ai.online. Formal operator and billing details are shown before purchase and on invoices. Privacy questions and rights requests can be sent to the privacy contact shown on this page.
Data we process
We process account and authentication details; profile language and plan; prompts, reasoning answers, generated output, memories, and uploaded knowledge files; usage, device, security, and diagnostic records; bug reports you choose to submit; and billing identifiers and subscription status received from Stripe. Architect does not store complete payment-card details.
Purposes and legal bases
We use data to provide and secure the service, save progress, run the AI workflow you request, manage billing, prevent abuse, respond to support, and meet legal obligations. Processing is based on performing the service contract, legitimate interests in security and improvement, legal obligations, and consent where the law requires it.
AI providers and international processing
The model you select receives the prompt context needed to perform your request, which may include enabled memories or knowledge excerpts. Authentication, hosting, security, payment, email, and AI providers process only the data needed for their role. Some providers may process data outside the EEA under applicable transfer safeguards. When you use your own API key, your chosen provider also processes the request under your direct account with that provider.
Retention and security
Account content is generally kept while the account is active or until you delete it, subject to limited backups, security records, disputes, and legal retention duties. Passwords are handled by the authentication service and are not stored as plain text by Architect. Saved provider keys are protected on the server and are never returned to the browser after storage.
Your rights
Depending on the law that applies, you may request access, correction, deletion, restriction, portability, or objection; withdraw consent where processing relies on consent; and complain to your data-protection authority. We may need to verify your identity before acting on a request.