Legal
Pending legal review. This document is complete but has not yet been reviewed by counsel. Remove this notice once it has.
Last updated: August 12, 2026
This Privacy Policy explains how Arciom, Inc. ("Arciom," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the Arciom platform, including its web application, browser extension, and desktop capture agent (collectively, the "Service").
Arciom is a business-to-business (B2B) platform used by advertising agencies and their client organizations. This Policy is written for individuals who use Arciom on behalf of an agency or client account (each, a "user," "you"). If you are an individual whose voice, screen activity, or likeness is captured by a user of the Service in a working session, see Section 8 ("If You Were Recorded By an Arciom User").
By using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, do not use the Service.
When you register, we collect your email address, display name, hashed password, and your agency/account membership and role. Registration is restricted to email domains that your agency administrator has authorized.
If you or your agency authorizes the Service to connect to a Google Ads, Google Analytics, and/or Google Tag Manager account, we access that data via Google OAuth, using only the following scopes: your Google account's email/profile identifiers, and read-only access to the connected advertising and analytics data itself. During the Beta Period the Service does not write to your Google Ads account. If write functionality is introduced, it will require separate, explicit enablement by the account owner and a corresponding update to this Policy. This connection is used solely to detect changes, retrieve performance data, and power the governance features of the Service. Google account credentials themselves are never seen or stored by Arciom — only the OAuth tokens Google issues, which you can revoke at any time in your Google Account settings.
If the capture feature is enabled for your account, the Service may record:
This raw session data is processed by AI systems to reconstruct decision points and build a persistent record of expertise (a "digital twin") associated with your account, as described in Section 3.
Capture only runs when you start it. Nothing is recorded before you begin a session or after you end one. The raw screen video and audio remain within Arciom's systems and are not handed to your employer; what your organization receives from a session is the reconstructed decisions and reasoning.
If you leave the organization that recorded you, you may obtain a copy of the judgment layer derived from your sessions — the reasoning patterns, without anything specific to that organization's business. Their digital twin ceases to incorporate your subsequent development, and they have no visibility of what you do with your copy.
If the voice debrief feature is enabled, we record and transcribe conversational debrief sessions (audio and derived transcript). Voice debrief recordings and transcripts are retained for 90 days by default, after which they are automatically marked for deletion. Sessions are capped in length and size (approximately 30 minutes / 200 conversational turns / 200MB per session).
We use functional cookies to operate the Service, including a session cookie (arciom-session) that keeps you logged in, and a short-lived cookie used to protect the Google OAuth connection flow from cross-site request forgery. We also log session metadata such as IP address (stored in hashed form) and browser/user-agent string, for security and fraud-prevention purposes. Within the Service itself we do not use advertising, marketing, or third-party tracking cookies.
Separately from the Service, our public marketing website at arciom.com uses Google Analytics to understand how visitors find and move through the site. This sets cookies from Google and collects standard analytics data including pages viewed, referring source, approximate location derived from IP address, and device and browser type. We use it to measure which pages and channels bring us enquiries.
We do not use it to build advertising audiences, and we do not combine website analytics data with anything inside the Service. You can opt out using Google's browser add-on at tools.google.com/dlpage/gaoptout, or through your browser's cookie settings, without any loss of functionality.
If you contact support, submit a bug report, or otherwise communicate with us, we retain the content of that communication and any diagnostic information you provide.
We use the information described above to:
We do not use your recordings, captured decisions, or digital twin content to form or improve any other customer's digital twin, and we do not sell any model trained on your data. We do use de-identified data from across customers for a defined set of purposes: keeping the AI benchmark accurate, understanding how advertising platforms themselves behave, improving how well the product captures decisions, detecting faults across the Service, producing aggregate statistics, evaluating which AI models perform best, and telling an individual how their own decisions are performing. That data contains no reasoning or strategy attributable to you or to any individual. Where we report to someone how they are performing relative to others, we describe their performance; we do not pass on the specific approaches or tactics of anyone else. We do not sell your personal information, and we do not use your data to serve third-party advertising.
To provide the Service, we share information with the following categories of third-party service providers ("sub-processors"), each acting under its own terms of service. Providers marked (planned) are not yet in use and will not receive data until they are:
| Sub-processor | What it receives | Purpose |
|---|---|---|
| AI model providers (Anthropic; and/or OpenRouter as an intermediary, pinned to a specific Anthropic model) | Session transcripts, click-screenshots, window/app titles, and your typed context notes | Reconstruct decision points, generate summaries and digital twin content |
| Speech-to-text provider (OpenAI-compatible transcription endpoint) | Raw narration audio | Transcribe capture and voice debrief audio |
| Embeddings provider (OpenAI-compatible endpoint, optional) | Rationale/decision text | Score similarity between stated reasoning and outcomes |
| Backblaze B2 (cloud object storage) | Recorded media (audio, screenshots) | Store capture recordings, encrypted at rest |
| Google (Ads, Analytics, Tag Manager APIs) | OAuth-authorized access to your connected advertising/analytics accounts | Retrieve and monitor your own connected account data |
| Resend (transactional email) (planned) | Your email address, verification/notification content | Send account verification and notification emails |
| Slack (optional, only if your agency configures a webhook) | Buyer email address and a description of a detected change | Deliver change alerts to your agency's own Slack workspace |
AI processing disclosure. Because capture and voice debrief features send audio, screenshots, and text to third-party AI model and transcription providers for analysis, that content leaves Arciom's own infrastructure as part of normal operation of these features. We select vendors that publicly state they do not use API inputs to train their models by default, and we are working to formalize written data-processing and no-training agreements with each of these providers during the Beta Period. Until those agreements are fully executed, you should treat this as a known limitation of the beta service. If this is a concern for a particular session, do not enable capture or voice debrief for that session.
We may also disclose information: to comply with law, legal process, or governmental request; to protect the rights, property, or safety of Arciom, our users, or others; or in connection with a merger, acquisition, financing, or sale of assets (subject to this Policy continuing to apply to previously collected information).
We use industry-standard safeguards, including: password hashing (passwords are never stored in plaintext), hashed session tokens, rate-limited login attempts, encryption at rest for stored capture media (server-side encryption on our object storage), and role-based access controls that limit which users can see which data. No system is completely secure, and we cannot guarantee absolute security of information transmitted to or stored by the Service.
The Service is a business tool intended for use by adults acting on behalf of an organization. It is not directed at, and we do not knowingly collect information from, individuals under 18.
If an Arciom user recorded a working session that included you (for example, a screen-share, meeting, or voice debrief you participated in), that recording was made by the Arciom user or their organization, who is responsible for obtaining any consent required by law before recording you. Arciom processes that content on their behalf as described in this Policy. To request access to, or deletion of, a recording that includes you, please contact the Arciom user or organization that made the recording directly; you may also contact us at Ryan@arciom.com and we will direct your request to the responsible organization.
Arciom and its sub-processors host and process data primarily in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, where data protection laws may differ from those of your jurisdiction.
We may update this Privacy Policy from time to time. If we make material changes, we will provide reasonable notice (such as by email or an in-product notice) before the changes take effect. The "Last Updated" date at the top of this Policy indicates when it was last revised.
Questions or requests regarding this Privacy Policy can be directed to:
Arciom, Inc. 2810 N Church St, PMB 740352, Wilmington, Delaware 19802-4447, US