Privacy Policy
Last updated: July 9, 2026 · Version 1.0
1. Who is responsible for your data
HEXAR SOFTWARE FACTORY S.R.L. ("Hexar", "we", "us"), CUIT 30-71907331-6, domiciled at Las Palmas 2779 Piso 3, Ciudad Autónoma de Buenos Aires, Argentina, is the data controller for the personal data described in this Privacy Policy, collected through the Archynt platform (the "Service").
This Privacy Policy is part of Archynt's Terms of Service. Accepting the Terms means giving your express, informed consent to this Privacy Policy — required to create an Archynt account, with no exceptions.
2. What we collect
Account data you provide directly: email address, and — if you choose email/password registration — a password (handled entirely by Firebase Authentication; we never see or store it in plain text). If you sign in with Google or GitHub, we receive the email address and profile identifier those providers share with us.
Organization and billing data: your organization's name, its plan, and — for paid plans — billing details processed by Paddle, our payment processor (Paddle, not Archynt, holds your card/payment details).
Terms acceptance record: the version of these Terms you accepted, the date and time, and the IP address the acceptance request came from — kept as an audit trail.
Infrastructure data reported by your own agent, if you choose to run it: service/container topology, TCP dependency edges, host and container resource metrics, and log lines from your own systems — read-only, sent only if you deploy the agent, and scoped to your organization.
Code-derived data: when you point Archynt at a repository, we parse it to build an architecture graph (class names, package structure, relationships) and store that graph — not a copy of your repository's full source tree.
Technical data collected automatically: IP address, browser/user-agent, and basic request logs, for security and abuse-prevention purposes.
3. Why we use it
To provide the Service: authenticate you, resolve which organization and role you have, build and store your architecture graph, ingest and display your runtime topology and metrics, generate AI insights, and enforce your plan's usage limits.
To bill you, if you're on a paid plan, via Paddle.
To operate securely: detect abuse, enforce enrollment-key and session authentication, and investigate incidents.
To communicate with you about your account, service changes, or — with your consent where required — product updates.
We do not sell your personal data, and we do not use your source code or infrastructure data to train any AI model.
4. Who we share it with
Firebase Authentication (Google) — identity verification for every sign-in.
Paddle — payment processing and subscription billing for paid plans; Paddle acts as merchant of record.
Anthropic and/or OpenAI — when you request an AI-generated insight, a derived representation of your architecture graph (component names, relationships, detected findings) is sent to whichever provider is configured, strictly to generate that response. We do not send raw source code, and neither provider is authorized to use that data to train their models under our agreements with them.
GitHub — if you connect a GitHub App installation, to read repository contents for analysis and to post PR checks back to GitHub, scoped to the repositories you explicitly authorize.
Infrastructure/hosting providers — the servers and storage (Postgres, Neo4j, VictoriaMetrics, Loki) that run Archynt are ours; where third-party cloud infrastructure is used, it acts strictly as a processor under our instructions.
We disclose personal data to public authorities only when legally required to do so.
5. International transfers
Archynt's infrastructure and the third-party processors listed above may be located outside Argentina. Where a recipient country does not offer an equivalent level of data protection, we rely on contractual safeguards with that processor to preserve the same protections described in this Policy.
6. Retention
Account and organization data is kept for as long as your account exists, plus a reasonable period afterward to comply with legal or accounting obligations.
Runtime metrics and log data are retained according to your plan's limits (see /pricing) and automatically age out beyond that window — this is enforced server-side, not just a display filter.
Terms/Privacy acceptance records are kept indefinitely as a compliance audit trail.
7. Security
We apply industry-standard safeguards: passwords are never handled by our own code (Firebase Authentication only); session tokens are signed and short-lived; the runtime agent authenticates with a per-organization enrollment key and per-agent bearer tokens, hashed at rest; webhook payloads are signature-verified.
No system is perfectly secure. Where Hexar has applied the safeguards described here, it will not be liable for unlawful interception or unauthorized access to its systems that it could not reasonably have prevented.
8. Your rights
Depending on applicable law, you may have the right to access, correct, delete, or request portability of your personal data, and to withdraw consent where processing is based on it. You can exercise these rights by contacting us; account and organization data can also be managed directly from your dashboard's Organization and Profile pages.
Deleting your account removes your personal account data; data belonging to an organization you don't solely own may require an organization Owner/Admin's action instead.
9. Children
Archynt is a business/developer tool and is not directed at, or knowingly used by, children. We do not knowingly collect personal data from anyone under the age required by applicable law to consent to data processing on their own.
10. Cookies
Archynt uses a minimal set of cookies: an httpOnly session cookie that keeps you signed in, and no third-party advertising or tracking cookies. Disabling the session cookie in your browser will sign you out.
11. Changes to this Policy
We will update this Privacy Policy as the Service evolves. Material changes are communicated through the same channels as Terms changes, and — where required by law — we will request your renewed consent.
12. Governing law and jurisdiction
This Privacy Policy is governed by the laws of the Republic of Argentina. Any dispute related to its interpretation, validity or performance will be submitted to the exclusive jurisdiction of the ordinary national courts sitting in the City of Buenos Aires.
