Privacy Policy

Privacy Policy

September 1, 2026Effective: September 1, 2026

This Privacy Policy explains how Arconi Inc ("Arconi," "Arconi AI," "we," "us," or "our") collects, uses, and protects personal data when you use the Arconi platform and any services operated on it, including the Whiskey app.

This Privacy Policy applies to all services operated by Arconi, including branded conversational experiences such as "Whiskey" (each, a "Service").

If you do not agree with this Privacy Policy, please do not use the Services.

Language

This Privacy Policy may be provided in languages other than English for convenience. The English version is the legally binding and controlling version. If there is any inconsistency between a translated version and the English version, the English version will prevail.


Contents

  1. Who We Are
  2. What the Services Are
  3. What Data We Collect
  4. How We Use Your Data
  5. AI Training and Service Improvement
  6. Lawful Bases for Processing (GDPR)
  7. Safety, Moderation, and Monitoring
  8. Cookies and Tracking Technologies
  9. Data Retention
  10. How We Share Your Data
  11. International Data Transfers
  12. Your Privacy Rights
  13. Additional Rights for EU/UK Users (GDPR)
  14. Additional Rights for California Users (CCPA/CPRA)
  15. Additional Rights for Other Jurisdictions
  16. Children's Privacy
  17. Security
  18. Third-Party Links
  19. Changes to This Privacy Policy
  20. Contact Us

1. Who We Are

Arconi is operated by Arconi Inc, a Delaware corporation.

For the purposes of data protection laws (including the GDPR), Arconi Inc is the data controller responsible for your personal data.

Contact details

PurposeContact
General privacy inquiriesprivacy@arconi.ai
Legal matterslegal@arconi.ai
GDPR / European inquiriesgdpr@arconi.ai
General supporthelp@arconi.ai

Mailing address: Arconi Inc 169 Madison Ave STE 36083, New York, 10016, United States


2. What the Services Are

Arconi provides AI-powered conversational experiences.

Important context for this Privacy Policy:

  • You are interacting with artificial intelligence, not real humans
  • AI personas (like "Mr. Darcy") are fictional characters
  • Conversations are not confidential or privileged communications
  • You should not share sensitive personal information in chats
  • AI systems may generate inaccurate or inappropriate outputs despite safeguards

All Services are 18+ only. We do not knowingly collect data from children.


3. What Data We Collect

A. Information you provide directly

  • Account information: email address, username, password
  • Profile information: any optional details you add to your profile
  • Conversation content: messages and prompts you send to AI systems
  • Uploads: images or files you upload (if this feature is enabled)
  • Communications: support requests, feedback, surveys
  • Payment information: handled by third-party processors (we do not store full card numbers)

B. Information generated through use

  • Chat data: messages, AI responses, timestamps, interaction metadata
  • Device information: device type, operating system, browser type
  • Usage data: features used, pages visited, actions taken
  • Log data: IP address, access times, error logs
  • Location: approximate location based on IP address (country/region only)

C. Information from third parties

  • Payment processors: transaction status, billing country (from Stripe etc.)
  • Authentication providers: basic profile info if you sign in via Google, Apple, etc.
  • Analytics providers: aggregated usage data

What we do NOT collect

  • We do not collect date of birth or government ID
  • We do not collect precise GPS location
  • We do not purchase personal data from data brokers
  • We do not intentionally collect special category personal data (such as health, biometric, or genetic data), and users should not provide such information through the Services. However, you may optionally choose to provide certain personal characteristics, such as sexual orientation or relationship preferences, where this information is voluntarily provided, clearly optional, and used solely to personalize how the Services interact with you.

Where required by law, we process such information based on your explicit consent, which you may withdraw at any time.


4. How We Use Your Data

We use personal data for the following purposes:

PurposeExamples
Provide the ServicesCreate accounts, process conversations, deliver AI responses
Process paymentsHandle subscriptions, process transactions
Customer supportRespond to inquiries, resolve issues
Safety and securityDetect abuse, enforce policies, prevent fraud
Improve the ServicesAnalyze usage, fix bugs, develop new features
AI improvementTrain and improve AI models (using anonymized data)
CommunicationsSend service updates, deliver messages from your characters and the concierge (in-app, push, or email), respond to requests
Legal complianceComply with laws, respond to legal requests

5. AI Training and Service Improvement

We may use anonymized and/or de-identified conversation data to:

  • Improve AI models
  • Improve safety systems and reduce harmful outputs
  • Improve overall service quality and performance

How we protect your privacy

  • Anonymization: We remove or obscure personal identifiers before using data for training
  • Aggregation: We analyze patterns across many users, not individual conversations
  • Technical safeguards: We implement measures to reduce memorization of specific conversations
  • Purpose limitation: Training data is used solely to improve the Services, not for advertising or resale

We do not attempt to re-identify anonymized or de-identified data, except where required to comply with applicable law or legal obligations.


6. Lawful Bases for Processing (GDPR)

If you are located in the EU, UK, or Switzerland, we process personal data based on the following legal bases:

Processing ActivityLegal Basis
Providing the ServicesPerformance of contract
Account managementPerformance of contract
Processing paymentsPerformance of contract
Customer supportPerformance of contract; Legitimate interests
Proactive service communications (messages from your characters or the concierge, delivered in-app, by push, or by email)Legitimate interests — you can stop these emails at any time via the unsubscribe link in any such email or in your notification preferences
Service improvementLegitimate interests
First-party analytics (our own product and funnel measurement)Legitimate interests
AI training (anonymized)Legitimate interests
Safety and securityLegitimate interests
Fraud preventionLegitimate interests
Error and crash monitoringLegitimate interests
Third-party analytics and session replayConsent
Advertising and conversion measurementConsent
Legal complianceLegal obligation

First-party analytics

We measure how the Services are used — which pages are viewed, which features are used, where people stop — and we write that measurement to our own systems. This data is not sold and is not shared with advertising platforms. We rely on legitimate interests for this processing: it is how we operate, debug and improve the Services, and it is limited to what we need for that purpose.

This is separate from the third-party analytics and advertising described in Section 8, both of which require your consent where consent is legally required. Declining those does not stop our own first-party measurement, and we do not imply otherwise in our consent controls.

Where we rely on legitimate interests as a legal basis, we have considered and balanced our interests against the rights and freedoms of users.

Users located in the EU, UK, or Switzerland may object to processing based on legitimate interests as described in Section 12.

Where we process special category personal data, we do so only where you have explicitly provided it and explicitly consented to its use for the purposes described. Providing this information is not required to use the Services, and you may remove or update it at any time through your account settings.

Our legitimate interests include

  • Operating and improving the Services
  • Ensuring platform security and integrity
  • Preventing fraud and abuse
  • Understanding how users interact with the Services

You may contact us to request information about our legitimate interests assessments.


7. Safety, Moderation, and Monitoring

To keep the platform safe, we may:

  • Automatically scan content for policy violations
  • Review content manually where necessary
  • Investigate abuse, fraud, or harmful behavior
  • Take enforcement action, including account suspension or termination

These measures are applied proportionately and on a risk-based basis, and are not intended to result in continuous or systematic monitoring of all user activity.

We have no obligation to monitor all activity, but we reserve the right to do so where necessary for safety, compliance, or operational purposes.

Illegal content may be reported to appropriate authorities, including law enforcement and child safety organizations (such as NCMEC for content involving minors).


8. Cookies and Tracking Technologies

What are cookies?

Cookies are small text files placed on your device when you visit a website. They help websites function and provide information to operators.

Types of cookies we use

TypePurposeCan be disabled?
Strictly necessaryKeep you logged in, enable core functionality, age verification, security, error monitoringNo
FunctionalRemember preferences, enhance experienceYes
First-party analyticsOur own measurement of how the Services are used, written to our own systemsNo — see Section 6 (legitimate interests)
Third-party analyticsExternal analytics tools, session replayYes
AdvertisingConversion measurement, click identifiers, and the tag manager containerYes

Third-party cookies and similar technologies

Some cookies and similar technologies (such as local storage) are placed by the third-party services we use to operate the Services:

ProviderPurposeRequires consent?
PostHogProduct analytics — understanding how the Services are used so we can improve themYes (third-party analytics)
Google Tag ManagerTag management. Where the operator of a site has enabled it, it may load additional analytics or advertising tags that the operator has configured. Because a container can carry tags we cannot audit in advance, we gate it on advertising consent — the stricter of the twoYes (advertising)
Sentry — error and performance monitoringDetecting, diagnosing and fixing faults and performance problemsNo (strictly necessary)
Sentry — session replayRecording a masked playback of an app session to diagnose faults that logs alone cannot explain. Text is masked and media is blocked before the recording leaves your device, so conversation content is not capturedYes (third-party analytics)
StripePayment processingNo (strictly necessary)
Supabase, GoogleAccount authentication and sign-inNo (strictly necessary)

Advertising measurement

When you arrive from an advertisement, the advertising platform may add a click identifier to the link you followed (for example fbclid, rdt_cid, ttclid, epik or li_fat_id). We store that identifier with your account. If you later take an action such as entering the site, sending your first message, registering, starting a checkout or subscribing, we report that action directly from our servers to the platform that sent you — which may be Meta, Reddit, TikTok, Pinterest or LinkedIn.

Those reports can include the click identifier, a hashed (irreversibly scrambled) form of your email address, a hashed account identifier, your IP address and your browser's user agent. The platform uses them to match the action to the advertisement you clicked and to improve which advertisements it shows. Under US state privacy laws this is sharing personal information for cross-context behavioral advertising; under EU and UK law it requires your consent.

These reports only happen with advertising consent. The check is made at the moment each report would be sent, against the choice stored on your account — so it applies to reports sent hours or days later, from our servers, after your browsing session has ended. Withdrawing consent stops them from the next action onwards. It does not retroactively recall reports already sent, and we do not imply that it does.

We do not load those platforms' advertising pixels or tracking scripts into your browser ourselves. Where an operator has configured such tags in Google Tag Manager, the container itself only loads with advertising consent.

Managing cookies

You can manage cookies and tracking through:

  • Our cookie controls: Visit /cookies at any time — from the age gate, or from the privacy and cookies section at the bottom of your profile page — to accept or reject third-party analytics and advertising separately. Strictly necessary processing cannot be switched off, because the Services cannot run without it. Where consent is legally required, we do not place non-essential cookies or send advertising reports before consent is given.
  • Browser settings: Most browsers let you block or delete cookies.

Opt-out links:

Global Privacy Control

We honour the Global Privacy Control (GPC) signal. If your browser or an extension sends GPC, we treat it as a refusal of advertising consent — in every jurisdiction, not only where the law requires it — and we record that refusal against your account so it also applies to reports sent later from our servers.

A GPC signal is never overridden by a later default. If you send GPC and then press an "accept" button, we record the refusal, because the signal is the more deliberate expression of your choice. To grant advertising consent you would need to stop sending GPC and then make the choice explicitly.

Do Not Track

There is no industry standard for Do Not Track signals. We do not currently respond to DNT signals but will update this policy if a standard is established. Global Privacy Control, described above, is honoured — it is a separate and more recent standard.


9. Data Retention

We retain personal data only as long as necessary. Specific retention periods:

Data TypeRetention Period
Account informationDuration of account + 30 days after deletion
Conversation historyDuration of account, or until you delete. Deleted or anonymized within 30 days of account deletion, except where retention is required for legal or safety purposes
Payment records7 years (legal/tax requirements)
Support communications3 years from resolution
Usage logsRetained for a limited period necessary for security, fraud prevention, and system integrity (typically 12–24 months)
Anonymized training dataRetained for as long as necessary to improve and maintain the Services (no longer linked to you)
Consent records (including advertising and analytics choices)Retained indefinitely. These records are the evidence that a choice was made, when, and under which version of this policy — deleting them would destroy the proof they exist to provide. They are held separately from your account data and are not deleted when your account is

Account deletion

When you delete your account:

  • Account information is deleted within 30 days
  • Conversation history associated with your account is deleted or anonymized
  • Anonymized data already incorporated into training datasets cannot be removed (it is no longer linked to you)
  • Some data may be retained as required by law

Conversation deletion

You can delete individual conversations or all history through your account settings. Deletion is processed within 30 days.


10. How We Share Your Data

We may share data with:

RecipientPurpose
Cloud providersInfrastructure, hosting, storage
Payment processorsProcess transactions (e.g., Stripe)
AI/ML providersPower AI features (contractually restricted)
Analytics providersUnderstand usage patterns (third-party analytics — consent-gated)
Advertising platformsConversion measurement — reporting that an action occurred, with a click identifier and hashed identifiers, so the platform can attribute it to an advertisement (consent-gated; see below)
Security providersFraud prevention, abuse detection
Customer support toolsManage support requests
Legal authoritiesWhen required by law or to protect safety

Sharing with advertising platforms

Where you have given advertising consent — or, in jurisdictions where advertising may run by default, where you have not opted out — we report conversion events to Meta, Reddit, TikTok, Pinterest and LinkedIn, as described in Section 8. Those reports can include a click identifier, a hashed email address, a hashed account identifier, your IP address and your user agent.

Under the CCPA/CPRA and comparable US state laws, this constitutes "sharing" personal information for cross-context behavioral advertising, and may constitute a "sale" under the broad definition those statutes use. We do not receive money for it; the definitions are broader than money.

You can stop it at any time. Use the controls at /cookies, the "Do Not Sell or Share My Personal Information" link in the privacy and cookies section of your profile, or the Global Privacy Control signal — all three reach the same setting and all three take effect from the next event onwards. See Section 14.

What we do NOT do:

  • We do not sell personal data for money
  • We do not share the content of your conversations with advertising platforms
  • We do not share personal data with data brokers
  • We do not share personal data for third parties' own direct marketing purposes

Business transfers

If Arconi is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you of any such change.

Aggregated data

We may share aggregated or anonymized data that cannot identify you (e.g., usage statistics).


11. International Data Transfers

Arconi operates globally. Your data may be processed in the United States or other countries where we or our service providers operate. These countries may have different data protection laws than your country.

Transfer safeguards

When transferring data internationally, we use appropriate safeguards:

  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Contractual protections with all service providers
  • Technical measures to secure data during transfer

Where international data transfers occur, we take steps to ensure appropriate safeguards are in place as described above.


12. Your Privacy Rights

Depending on your location, you may have the right to:

  • Access your personal data
  • Correct inaccurate data
  • Delete your data
  • Restrict certain processing
  • Object to certain processing
  • Port your data (receive it in a portable format)
  • Withdraw consent where processing is based on consent

How to exercise your rights

Contact us at: privacy@arconi.ai

We will respond within the timeframe required by applicable law (typically 30 days).

Verification

To protect your privacy, we may need to verify your identity before processing requests.

No discrimination

We will not discriminate against you for exercising your privacy rights.


13. Additional Rights for EU/UK Users (GDPR)

If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the GDPR.

Your GDPR rights

  • Access (Article 15): Get confirmation and a copy of your data
  • Rectification (Article 16): Correct inaccurate data
  • Erasure (Article 17): Delete your data ("right to be forgotten")
  • Restriction (Article 18): Limit how we process your data
  • Portability (Article 20): Receive your data in a portable format
  • Object (Article 21): Object to processing based on legitimate interests
  • Withdraw consent (Article 7): Withdraw consent at any time
  • Automated decisions (Article 22): Rights related to automated decision-making

Right to complain

You have the right to lodge a complaint with a supervisory authority in your country.

Find your data protection authority: edpb.europa.eu/about-edpb/board/members_en

Contact for GDPR matters

Email: gdpr@arconi.ai


14. Additional Rights for California Users (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).

Categories of personal information we collect

CategoryExamplesCollected?
IdentifiersEmail, username, IP address, device IDsYes
Personal info (Cal. Civ. Code § 1798.80)Name, account credentialsYes
Commercial informationSubscription history, purchasesYes
Internet/network activityUsage data, browsing historyYes
GeolocationApproximate location from IPYes
InferencesPreferences derived from usageYes
Sensitive personal informationAccount credentialsYes

Your CCPA/CPRA rights

  • Know: Request what personal data we collect and how we use it
  • Access: Request a copy of your personal data
  • Delete: Request deletion of your personal data
  • Correct: Request correction of inaccurate data
  • Limit sensitive data use: Request limits on sensitive personal information
  • Opt out of sale/sharing: Direct us to stop sharing your personal information for cross-context behavioral advertising
  • Non-discrimination: Not be discriminated against for exercising rights

Do Not Sell or Share My Personal Information

We share personal information for cross-context behavioral advertising, as described in Section 10: when you take an action such as registering or subscribing, we report it to the advertising platform that sent you, together with a click identifier and hashed identifiers. We do not receive money for this, but it falls within the CCPA/CPRA definitions of "sharing" and potentially "sale".

You have three ways to stop it, and all three set the same control:

  1. Do Not Sell or Share My Personal Information — also linked from the privacy and cookies section at the bottom of your profile page, where it is shown persistently to California residents and residents of other states with comparable statutes.
  2. The cookie controls at /cookies.
  3. Global Privacy Control — we honour the GPC browser signal automatically, in every jurisdiction, and record it as a refusal. No request or account is needed.

Opting out takes effect from the next event onwards. It does not recall reports already sent. Opting out does not degrade the Services in any way: chat, characters, memory and history are unchanged, and we do not charge a different price or offer a different level of service to anyone who opts out.

We do NOT:

  • Sell personal information for money
  • Share the content of your conversations with advertising platforms
  • Share personal information with data brokers
  • Knowingly sell or share the personal information of consumers under 16 (the Services are 18+)

How to exercise your rights

Email: privacy@arconi.ai Subject line: "California Privacy Request"

We will respond within 45 days (extendable to 90 days with notice).

You may designate an authorized agent to make requests on your behalf.

Shine the Light

California Civil Code § 1798.83 permits California residents to request information about disclosure to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.


15. Additional Rights for Other Jurisdictions

Australia

If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and Australian Privacy Principles. You may:

  • Access your personal information
  • Request correction of inaccurate information
  • Complain to the Office of the Australian Information Commissioner (OAIC)

Canada

If you are in Canada, you have rights under PIPEDA and provincial privacy laws. You may:

  • Access your personal information
  • Request correction of inaccurate information
  • Withdraw consent (subject to legal restrictions)
  • Complain to the Office of the Privacy Commissioner of Canada

Brazil

If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including access, correction, deletion, portability, and information about sharing.

Other locations

If you are in a jurisdiction with privacy laws not specifically addressed above, contact us at privacy@arconi.ai to learn how we accommodate your rights.


16. Children's Privacy

The Services are not intended for anyone under 18 years of age. We do not knowingly collect personal data from minors.

Age verification

We implement reasonable age-verification and age-gating measures, including:

  • Age confirmation gates upon first access
  • Age confirmation during registration
  • Payment verification for subscriptions

If a minor has used the Services

If you are a parent or guardian and believe your child under 18 has provided us with personal data, please contact us immediately at privacy@arconi.ai.

We will take steps to delete the information as quickly as possible.


17. Security

We implement reasonable technical and organizational measures to protect personal data.

Technical measures

  • Encryption in transit (TLS/SSL)
  • Encryption at rest
  • Access controls and authentication
  • Regular security assessments
  • Monitoring and logging

Organizational measures

  • Employee training on data protection
  • Confidentiality obligations for staff
  • Access limited to those who need it
  • Incident response procedures

No guarantee

No system is 100% secure. We cannot guarantee absolute security. You use the Services at your own risk.

Breach notification

In the event of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.

Your responsibilities

You are responsible for:

  • Keeping your account credentials confidential
  • Using strong, unique passwords
  • Notifying us of any unauthorized access

18. Third-Party Links

The Services may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties.

We are not responsible for the privacy practices of third parties. We encourage you to read their privacy policies.


19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

How we notify you

For material changes, we will provide notice through:

  • Posting the updated policy on our website
  • Updating the "Last updated" date
  • Email notification (for material changes)
  • In-app notification

Your continued use

Continued use of the Services after changes take effect means you accept the updated Privacy Policy. If you do not agree, stop using the Services.

Prior versions

We maintain prior versions of this Privacy Policy and can provide them upon request.


20. Contact Us

For privacy questions or requests:

Arconi Inc

PurposeContact
General privacyprivacy@arconi.ai
GDPR / Europeangdpr@arconi.ai
California requestsprivacy@arconi.ai (subject: "California Privacy Request")
Legal matterslegal@arconi.ai
General supporthelp@arconi.ai

Mailing address: Arconi Inc 169 Madison Ave STE 36083, New York, 10016, United States

We aim to respond to all inquiries within 30 days.


Summary of Key Points

TopicSummary
Who we areArconi Inc, a Delaware corporation
What we collectAccount info, conversation data, usage data, payment info
What we don't collectDOB, government ID, precise location, data from brokers
How we use itProvide Services, improve AI (anonymized), ensure safety
AI trainingWe use anonymized conversation data to improve AI
SharingService providers only; we don't sell data
RetentionVaries by data type; you can delete your account anytime
Your rightsAccess, correction, deletion, portability (varies by location)
SecurityIndustry-standard measures; no system is 100% secure
Children18+ only; we don't knowingly collect data from minors
Contactprivacy@arconi.ai

Acknowledgment

By using the Services, you acknowledge that:

  • You understand the Services involve AI, not humans
  • Conversations are not confidential
  • Data may be processed to operate and improve the platform
  • Anonymized data may be used to improve AI models
  • You have read and understood this Privacy Policy

Arconi Inc — We are committed to protecting your privacy.

© 2026 Whiskey. All rights reserved.