Privacy Policy
Privacy Policy
This Privacy Policy explains how Arconi Inc ("Arconi," "Arconi AI," "we," "us," or "our") collects, uses, and protects personal data when you use the Arconi platform and any services operated on it, including the Whiskey app.
This Privacy Policy applies to all services operated by Arconi, including branded conversational experiences such as "Whiskey" (each, a "Service").
If you do not agree with this Privacy Policy, please do not use the Services.
Language
This Privacy Policy may be provided in languages other than English for convenience. The English version is the legally binding and controlling version. If there is any inconsistency between a translated version and the English version, the English version will prevail.
Contents
- Who We Are
- What the Services Are
- What Data We Collect
- How We Use Your Data
- AI Training and Service Improvement
- Lawful Bases for Processing (GDPR)
- Safety, Moderation, and Monitoring
- Cookies and Tracking Technologies
- Data Retention
- How We Share Your Data
- International Data Transfers
- Your Privacy Rights
- Additional Rights for EU/UK Users (GDPR)
- Additional Rights for California Users (CCPA/CPRA)
- Additional Rights for Other Jurisdictions
- Children's Privacy
- Security
- Third-Party Links
- Changes to This Privacy Policy
- Contact Us
1. Who We Are
Arconi is operated by Arconi Inc, a Delaware corporation.
For the purposes of data protection laws (including the GDPR), Arconi Inc is the data controller responsible for your personal data.
Contact details
| Purpose | Contact |
|---|---|
| General privacy inquiries | privacy@arconi.ai |
| Legal matters | legal@arconi.ai |
| GDPR / European inquiries | gdpr@arconi.ai |
| General support | help@arconi.ai |
Mailing address: Arconi Inc 169 Madison Ave STE 36083, New York, 10016, United States
2. What the Services Are
Arconi provides AI-powered conversational experiences.
Important context for this Privacy Policy:
- You are interacting with artificial intelligence, not real humans
- AI personas (like "Mr. Darcy") are fictional characters
- Conversations are not confidential or privileged communications
- You should not share sensitive personal information in chats
- AI systems may generate inaccurate or inappropriate outputs despite safeguards
All Services are 18+ only. We do not knowingly collect data from children.
3. What Data We Collect
A. Information you provide directly
- Account information: email address, username, password
- Profile information: any optional details you add to your profile
- Conversation content: messages and prompts you send to AI systems
- Uploads: images or files you upload (if this feature is enabled)
- Communications: support requests, feedback, surveys
- Payment information: handled by third-party processors (we do not store full card numbers)
B. Information generated through use
- Chat data: messages, AI responses, timestamps, interaction metadata
- Device information: device type, operating system, browser type
- Usage data: features used, pages visited, actions taken
- Log data: IP address, access times, error logs
- Location: approximate location based on IP address (country/region only)
C. Information from third parties
- Payment processors: transaction status, billing country (from Stripe etc.)
- Authentication providers: basic profile info if you sign in via Google, Apple, etc.
- Analytics providers: aggregated usage data
What we do NOT collect
- We do not collect date of birth or government ID
- We do not collect precise GPS location
- We do not purchase personal data from data brokers
- We do not intentionally collect special category personal data (such as health, biometric, or genetic data), and users should not provide such information through the Services. However, you may optionally choose to provide certain personal characteristics, such as sexual orientation or relationship preferences, where this information is voluntarily provided, clearly optional, and used solely to personalize how the Services interact with you.
Where required by law, we process such information based on your explicit consent, which you may withdraw at any time.
4. How We Use Your Data
We use personal data for the following purposes:
| Purpose | Examples |
|---|---|
| Provide the Services | Create accounts, process conversations, deliver AI responses |
| Process payments | Handle subscriptions, process transactions |
| Customer support | Respond to inquiries, resolve issues |
| Safety and security | Detect abuse, enforce policies, prevent fraud |
| Improve the Services | Analyze usage, fix bugs, develop new features |
| AI improvement | Train and improve AI models (using anonymized data) |
| Communications | Send service updates, deliver messages from your characters and the concierge (in-app, push, or email), respond to requests |
| Legal compliance | Comply with laws, respond to legal requests |
5. AI Training and Service Improvement
We may use anonymized and/or de-identified conversation data to:
- Improve AI models
- Improve safety systems and reduce harmful outputs
- Improve overall service quality and performance
How we protect your privacy
- Anonymization: We remove or obscure personal identifiers before using data for training
- Aggregation: We analyze patterns across many users, not individual conversations
- Technical safeguards: We implement measures to reduce memorization of specific conversations
- Purpose limitation: Training data is used solely to improve the Services, not for advertising or resale
We do not attempt to re-identify anonymized or de-identified data, except where required to comply with applicable law or legal obligations.
6. Lawful Bases for Processing (GDPR)
If you are located in the EU, UK, or Switzerland, we process personal data based on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Providing the Services | Performance of contract |
| Account management | Performance of contract |
| Processing payments | Performance of contract |
| Customer support | Performance of contract; Legitimate interests |
| Proactive service communications (messages from your characters or the concierge, delivered in-app, by push, or by email) | Legitimate interests — you can stop these emails at any time via the unsubscribe link in any such email or in your notification preferences |
| Service improvement | Legitimate interests |
| First-party analytics (our own product and funnel measurement) | Legitimate interests |
| AI training (anonymized) | Legitimate interests |
| Safety and security | Legitimate interests |
| Fraud prevention | Legitimate interests |
| Error and crash monitoring | Legitimate interests |
| Third-party analytics and session replay | Consent |
| Advertising and conversion measurement | Consent |
| Legal compliance | Legal obligation |
First-party analytics
We measure how the Services are used — which pages are viewed, which features are used, where people stop — and we write that measurement to our own systems. This data is not sold and is not shared with advertising platforms. We rely on legitimate interests for this processing: it is how we operate, debug and improve the Services, and it is limited to what we need for that purpose.
This is separate from the third-party analytics and advertising described in Section 8, both of which require your consent where consent is legally required. Declining those does not stop our own first-party measurement, and we do not imply otherwise in our consent controls.
Where we rely on legitimate interests as a legal basis, we have considered and balanced our interests against the rights and freedoms of users.
Users located in the EU, UK, or Switzerland may object to processing based on legitimate interests as described in Section 12.
Where we process special category personal data, we do so only where you have explicitly provided it and explicitly consented to its use for the purposes described. Providing this information is not required to use the Services, and you may remove or update it at any time through your account settings.
Our legitimate interests include
- Operating and improving the Services
- Ensuring platform security and integrity
- Preventing fraud and abuse
- Understanding how users interact with the Services
You may contact us to request information about our legitimate interests assessments.
7. Safety, Moderation, and Monitoring
To keep the platform safe, we may:
- Automatically scan content for policy violations
- Review content manually where necessary
- Investigate abuse, fraud, or harmful behavior
- Take enforcement action, including account suspension or termination
These measures are applied proportionately and on a risk-based basis, and are not intended to result in continuous or systematic monitoring of all user activity.
We have no obligation to monitor all activity, but we reserve the right to do so where necessary for safety, compliance, or operational purposes.
Illegal content may be reported to appropriate authorities, including law enforcement and child safety organizations (such as NCMEC for content involving minors).
8. Cookies and Tracking Technologies
What are cookies?
Cookies are small text files placed on your device when you visit a website. They help websites function and provide information to operators.
Types of cookies we use
| Type | Purpose | Can be disabled? |
|---|---|---|
| Strictly necessary | Keep you logged in, enable core functionality, age verification, security, error monitoring | No |
| Functional | Remember preferences, enhance experience | Yes |
| First-party analytics | Our own measurement of how the Services are used, written to our own systems | No — see Section 6 (legitimate interests) |
| Third-party analytics | External analytics tools, session replay | Yes |
| Advertising | Conversion measurement, click identifiers, and the tag manager container | Yes |
Third-party cookies and similar technologies
Some cookies and similar technologies (such as local storage) are placed by the third-party services we use to operate the Services:
| Provider | Purpose | Requires consent? |
|---|---|---|
| PostHog | Product analytics — understanding how the Services are used so we can improve them | Yes (third-party analytics) |
| Google Tag Manager | Tag management. Where the operator of a site has enabled it, it may load additional analytics or advertising tags that the operator has configured. Because a container can carry tags we cannot audit in advance, we gate it on advertising consent — the stricter of the two | Yes (advertising) |
| Sentry — error and performance monitoring | Detecting, diagnosing and fixing faults and performance problems | No (strictly necessary) |
| Sentry — session replay | Recording a masked playback of an app session to diagnose faults that logs alone cannot explain. Text is masked and media is blocked before the recording leaves your device, so conversation content is not captured | Yes (third-party analytics) |
| Stripe | Payment processing | No (strictly necessary) |
| Supabase, Google | Account authentication and sign-in | No (strictly necessary) |
Advertising measurement
When you arrive from an advertisement, the advertising platform may add a click identifier to the link you followed (for example fbclid, rdt_cid, ttclid, epik or li_fat_id). We store that identifier with your account. If you later take an action such as entering the site, sending your first message, registering, starting a checkout or subscribing, we report that action directly from our servers to the platform that sent you — which may be Meta, Reddit, TikTok, Pinterest or LinkedIn.
Those reports can include the click identifier, a hashed (irreversibly scrambled) form of your email address, a hashed account identifier, your IP address and your browser's user agent. The platform uses them to match the action to the advertisement you clicked and to improve which advertisements it shows. Under US state privacy laws this is sharing personal information for cross-context behavioral advertising; under EU and UK law it requires your consent.
These reports only happen with advertising consent. The check is made at the moment each report would be sent, against the choice stored on your account — so it applies to reports sent hours or days later, from our servers, after your browsing session has ended. Withdrawing consent stops them from the next action onwards. It does not retroactively recall reports already sent, and we do not imply that it does.
We do not load those platforms' advertising pixels or tracking scripts into your browser ourselves. Where an operator has configured such tags in Google Tag Manager, the container itself only loads with advertising consent.
Managing cookies
You can manage cookies and tracking through:
- Our cookie controls: Visit /cookies at any time — from the age gate, or from the privacy and cookies section at the bottom of your profile page — to accept or reject third-party analytics and advertising separately. Strictly necessary processing cannot be switched off, because the Services cannot run without it. Where consent is legally required, we do not place non-essential cookies or send advertising reports before consent is given.
- Browser settings: Most browsers let you block or delete cookies.
Opt-out links:
- Google Analytics, where an operator's tag manager loads it: tools.google.com/dlpage/gaoptout
Global Privacy Control
We honour the Global Privacy Control (GPC) signal. If your browser or an extension sends GPC, we treat it as a refusal of advertising consent — in every jurisdiction, not only where the law requires it — and we record that refusal against your account so it also applies to reports sent later from our servers.
A GPC signal is never overridden by a later default. If you send GPC and then press an "accept" button, we record the refusal, because the signal is the more deliberate expression of your choice. To grant advertising consent you would need to stop sending GPC and then make the choice explicitly.
Do Not Track
There is no industry standard for Do Not Track signals. We do not currently respond to DNT signals but will update this policy if a standard is established. Global Privacy Control, described above, is honoured — it is a separate and more recent standard.
9. Data Retention
We retain personal data only as long as necessary. Specific retention periods:
| Data Type | Retention Period |
|---|---|
| Account information | Duration of account + 30 days after deletion |
| Conversation history | Duration of account, or until you delete. Deleted or anonymized within 30 days of account deletion, except where retention is required for legal or safety purposes |
| Payment records | 7 years (legal/tax requirements) |
| Support communications | 3 years from resolution |
| Usage logs | Retained for a limited period necessary for security, fraud prevention, and system integrity (typically 12–24 months) |
| Anonymized training data | Retained for as long as necessary to improve and maintain the Services (no longer linked to you) |
| Consent records (including advertising and analytics choices) | Retained indefinitely. These records are the evidence that a choice was made, when, and under which version of this policy — deleting them would destroy the proof they exist to provide. They are held separately from your account data and are not deleted when your account is |
Account deletion
When you delete your account:
- Account information is deleted within 30 days
- Conversation history associated with your account is deleted or anonymized
- Anonymized data already incorporated into training datasets cannot be removed (it is no longer linked to you)
- Some data may be retained as required by law
Conversation deletion
You can delete individual conversations or all history through your account settings. Deletion is processed within 30 days.
10. How We Share Your Data
We may share data with:
| Recipient | Purpose |
|---|---|
| Cloud providers | Infrastructure, hosting, storage |
| Payment processors | Process transactions (e.g., Stripe) |
| AI/ML providers | Power AI features (contractually restricted) |
| Analytics providers | Understand usage patterns (third-party analytics — consent-gated) |
| Advertising platforms | Conversion measurement — reporting that an action occurred, with a click identifier and hashed identifiers, so the platform can attribute it to an advertisement (consent-gated; see below) |
| Security providers | Fraud prevention, abuse detection |
| Customer support tools | Manage support requests |
| Legal authorities | When required by law or to protect safety |
Sharing with advertising platforms
Where you have given advertising consent — or, in jurisdictions where advertising may run by default, where you have not opted out — we report conversion events to Meta, Reddit, TikTok, Pinterest and LinkedIn, as described in Section 8. Those reports can include a click identifier, a hashed email address, a hashed account identifier, your IP address and your user agent.
Under the CCPA/CPRA and comparable US state laws, this constitutes "sharing" personal information for cross-context behavioral advertising, and may constitute a "sale" under the broad definition those statutes use. We do not receive money for it; the definitions are broader than money.
You can stop it at any time. Use the controls at /cookies, the "Do Not Sell or Share My Personal Information" link in the privacy and cookies section of your profile, or the Global Privacy Control signal — all three reach the same setting and all three take effect from the next event onwards. See Section 14.
What we do NOT do:
- We do not sell personal data for money
- We do not share the content of your conversations with advertising platforms
- We do not share personal data with data brokers
- We do not share personal data for third parties' own direct marketing purposes
Business transfers
If Arconi is involved in a merger, acquisition, or sale of assets, your data may be transferred. We will notify you of any such change.
Aggregated data
We may share aggregated or anonymized data that cannot identify you (e.g., usage statistics).
11. International Data Transfers
Arconi operates globally. Your data may be processed in the United States or other countries where we or our service providers operate. These countries may have different data protection laws than your country.
Transfer safeguards
When transferring data internationally, we use appropriate safeguards:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Contractual protections with all service providers
- Technical measures to secure data during transfer
Where international data transfers occur, we take steps to ensure appropriate safeguards are in place as described above.
12. Your Privacy Rights
Depending on your location, you may have the right to:
- Access your personal data
- Correct inaccurate data
- Delete your data
- Restrict certain processing
- Object to certain processing
- Port your data (receive it in a portable format)
- Withdraw consent where processing is based on consent
How to exercise your rights
Contact us at: privacy@arconi.ai
We will respond within the timeframe required by applicable law (typically 30 days).
Verification
To protect your privacy, we may need to verify your identity before processing requests.
No discrimination
We will not discriminate against you for exercising your privacy rights.
13. Additional Rights for EU/UK Users (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have additional rights under the GDPR.
Your GDPR rights
- Access (Article 15): Get confirmation and a copy of your data
- Rectification (Article 16): Correct inaccurate data
- Erasure (Article 17): Delete your data ("right to be forgotten")
- Restriction (Article 18): Limit how we process your data
- Portability (Article 20): Receive your data in a portable format
- Object (Article 21): Object to processing based on legitimate interests
- Withdraw consent (Article 7): Withdraw consent at any time
- Automated decisions (Article 22): Rights related to automated decision-making
Right to complain
You have the right to lodge a complaint with a supervisory authority in your country.
Find your data protection authority: edpb.europa.eu/about-edpb/board/members_en
Contact for GDPR matters
Email: gdpr@arconi.ai
14. Additional Rights for California Users (CCPA/CPRA)
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA).
Categories of personal information we collect
| Category | Examples | Collected? |
|---|---|---|
| Identifiers | Email, username, IP address, device IDs | Yes |
| Personal info (Cal. Civ. Code § 1798.80) | Name, account credentials | Yes |
| Commercial information | Subscription history, purchases | Yes |
| Internet/network activity | Usage data, browsing history | Yes |
| Geolocation | Approximate location from IP | Yes |
| Inferences | Preferences derived from usage | Yes |
| Sensitive personal information | Account credentials | Yes |
Your CCPA/CPRA rights
- Know: Request what personal data we collect and how we use it
- Access: Request a copy of your personal data
- Delete: Request deletion of your personal data
- Correct: Request correction of inaccurate data
- Limit sensitive data use: Request limits on sensitive personal information
- Opt out of sale/sharing: Direct us to stop sharing your personal information for cross-context behavioral advertising
- Non-discrimination: Not be discriminated against for exercising rights
Do Not Sell or Share My Personal Information
We share personal information for cross-context behavioral advertising, as described in Section 10: when you take an action such as registering or subscribing, we report it to the advertising platform that sent you, together with a click identifier and hashed identifiers. We do not receive money for this, but it falls within the CCPA/CPRA definitions of "sharing" and potentially "sale".
You have three ways to stop it, and all three set the same control:
- Do Not Sell or Share My Personal Information — also linked from the privacy and cookies section at the bottom of your profile page, where it is shown persistently to California residents and residents of other states with comparable statutes.
- The cookie controls at /cookies.
- Global Privacy Control — we honour the GPC browser signal automatically, in every jurisdiction, and record it as a refusal. No request or account is needed.
Opting out takes effect from the next event onwards. It does not recall reports already sent. Opting out does not degrade the Services in any way: chat, characters, memory and history are unchanged, and we do not charge a different price or offer a different level of service to anyone who opts out.
We do NOT:
- Sell personal information for money
- Share the content of your conversations with advertising platforms
- Share personal information with data brokers
- Knowingly sell or share the personal information of consumers under 16 (the Services are 18+)
How to exercise your rights
Email: privacy@arconi.ai Subject line: "California Privacy Request"
We will respond within 45 days (extendable to 90 days with notice).
You may designate an authorized agent to make requests on your behalf.
Shine the Light
California Civil Code § 1798.83 permits California residents to request information about disclosure to third parties for direct marketing. We do not disclose personal information to third parties for their direct marketing purposes.
15. Additional Rights for Other Jurisdictions
Australia
If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and Australian Privacy Principles. You may:
- Access your personal information
- Request correction of inaccurate information
- Complain to the Office of the Australian Information Commissioner (OAIC)
Canada
If you are in Canada, you have rights under PIPEDA and provincial privacy laws. You may:
- Access your personal information
- Request correction of inaccurate information
- Withdraw consent (subject to legal restrictions)
- Complain to the Office of the Privacy Commissioner of Canada
Brazil
If you are in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including access, correction, deletion, portability, and information about sharing.
Other locations
If you are in a jurisdiction with privacy laws not specifically addressed above, contact us at privacy@arconi.ai to learn how we accommodate your rights.
16. Children's Privacy
The Services are not intended for anyone under 18 years of age. We do not knowingly collect personal data from minors.
Age verification
We implement reasonable age-verification and age-gating measures, including:
- Age confirmation gates upon first access
- Age confirmation during registration
- Payment verification for subscriptions
If a minor has used the Services
If you are a parent or guardian and believe your child under 18 has provided us with personal data, please contact us immediately at privacy@arconi.ai.
We will take steps to delete the information as quickly as possible.
17. Security
We implement reasonable technical and organizational measures to protect personal data.
Technical measures
- Encryption in transit (TLS/SSL)
- Encryption at rest
- Access controls and authentication
- Regular security assessments
- Monitoring and logging
Organizational measures
- Employee training on data protection
- Confidentiality obligations for staff
- Access limited to those who need it
- Incident response procedures
No guarantee
No system is 100% secure. We cannot guarantee absolute security. You use the Services at your own risk.
Breach notification
In the event of a data breach affecting your personal data, we will notify you and relevant authorities as required by applicable law.
Your responsibilities
You are responsible for:
- Keeping your account credentials confidential
- Using strong, unique passwords
- Notifying us of any unauthorized access
18. Third-Party Links
The Services may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties.
We are not responsible for the privacy practices of third parties. We encourage you to read their privacy policies.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time.
How we notify you
For material changes, we will provide notice through:
- Posting the updated policy on our website
- Updating the "Last updated" date
- Email notification (for material changes)
- In-app notification
Your continued use
Continued use of the Services after changes take effect means you accept the updated Privacy Policy. If you do not agree, stop using the Services.
Prior versions
We maintain prior versions of this Privacy Policy and can provide them upon request.
20. Contact Us
For privacy questions or requests:
Arconi Inc
| Purpose | Contact |
|---|---|
| General privacy | privacy@arconi.ai |
| GDPR / European | gdpr@arconi.ai |
| California requests | privacy@arconi.ai (subject: "California Privacy Request") |
| Legal matters | legal@arconi.ai |
| General support | help@arconi.ai |
Mailing address: Arconi Inc 169 Madison Ave STE 36083, New York, 10016, United States
We aim to respond to all inquiries within 30 days.
Summary of Key Points
| Topic | Summary |
|---|---|
| Who we are | Arconi Inc, a Delaware corporation |
| What we collect | Account info, conversation data, usage data, payment info |
| What we don't collect | DOB, government ID, precise location, data from brokers |
| How we use it | Provide Services, improve AI (anonymized), ensure safety |
| AI training | We use anonymized conversation data to improve AI |
| Sharing | Service providers only; we don't sell data |
| Retention | Varies by data type; you can delete your account anytime |
| Your rights | Access, correction, deletion, portability (varies by location) |
| Security | Industry-standard measures; no system is 100% secure |
| Children | 18+ only; we don't knowingly collect data from minors |
| Contact | privacy@arconi.ai |
Acknowledgment
By using the Services, you acknowledge that:
- You understand the Services involve AI, not humans
- Conversations are not confidential
- Data may be processed to operate and improve the platform
- Anonymized data may be used to improve AI models
- You have read and understood this Privacy Policy
Arconi Inc — We are committed to protecting your privacy.
© 2026 Whiskey. All rights reserved.