Arp

Arp Privacy Policy

Effective date: September 2026

Who we are

Arp is a procurement workspace at arp.aralabs.net, operated by ИП QDigital, Kazakhstan ("Arp", "we", "us"). Contact us at threegiskz@gmail.com.

This policy explains how we handle personal information when you use Arp, including connected Google and Microsoft accounts. Where your organization controls a workspace, we process its documents on its instructions; its own privacy policies may also apply.

Information we access and collect

  • Account and workspace information: your name, email, account identifiers, workspace membership, chats, documents you provide, and support communications.
  • Google: with your permission, your basic account profile (including name, email, profile picture if available, and account identifier), file and folder metadata needed to display lists, and the contents of Google Drive files and Google Docs you select for import or folder sync. Google permissions are openid, email, profile, and https://www.googleapis.com/auth/drive.readonly.
  • Microsoft: with your permission, your basic account profile, file/folder/site metadata needed to browse, and contents of files you select in OneDrive or SharePoint, including files in selected folders or sites. Delegated permissions are User.Read, Files.Read.All, Sites.Read.All, and offline_access.
  • Connection and technical information: OAuth access and refresh tokens, connection and sync status, and operational records such as IP addresses, request times, and error logs needed to run and secure the service. We do not receive your Google or Microsoft password.

These OAuth permissions can technically allow reading more files than you select. Arp uses metadata to help you browse and select sources, and imports or syncs content from the sources you choose. Selecting a folder includes files within the configured sync scope, including files added later. Read-only access does not mean that Arp never stores copies.

How we use information

We use information to identify your connected account, display available files and folders, import documents into chats, index selected sources into knowledge bases, and keep selected sources up to date. This can involve storing document copies, extracted text, search indexes or embeddings, and document excerpts in chats, and sending relevant content to AI service providers to answer your requests.

Refresh tokens let Arp obtain new access tokens and continue authorized background sync without asking you to sign in each time. Microsoft authorizes this through offline_access; Google may issue refresh tokens when offline access is requested.

We also use necessary account and technical information to provide support, prevent abuse, and maintain the service. These integrations do not edit, upload, or delete files in your Google or Microsoft account. We do not sell personal information, use connected-account data for advertising, or use it for credit or lending decisions.

Sharing and Google Limited Use

We share information only with service providers necessary to operate Arp, such as hosting, storage, document processing, and AI providers, subject to purpose restrictions, and as described below. Workspace content is available to members you or your organization authorize; importing a document into a shared workspace may expose its contents to those members.

Arp's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.

For Google data, including derived data:

  • We use it only to deliver the visible, user-facing features described here.
  • Transfers are limited to delivering those features with your consent, security needs, legal compliance, or a merger, acquisition, or asset sale with advance notice and your explicit prior consent.
  • We do not permit staff or providers to read it except with your affirmative agreement to specific data access, when necessary for security or legal compliance, or for legally permitted internal operations using aggregated, anonymized data.
  • We do not sell it or provide it to advertising platforms, data brokers, or information resellers, or use it for advertising, creditworthiness, or lending.

We do not use connected Google or Microsoft content to train general-purpose AI models, or authorize our providers to do so. Providers may process it to deliver the AI features you request. Applicable Google Workspace data restrictions also apply.

Retention and deletion

  • Tokens: kept while the connection is active. After disconnection, account deletion, or detection of revocation, we stop using them and delete stored tokens within 7 days.
  • Imported and synced content: copies, extracted text, indexes, embeddings, and chat excerpts are kept while needed for your chosen workspace features, subject to applicable provider storage limits. Disconnecting stops future sync but does not itself delete existing imports or chats. When you or an authorized administrator delete the relevant content or request workspace deletion, we delete associated active copies and derived indexes within 30 days.
  • Backups: deleted information may remain in restricted backups for up to 90 days, then expires. It is not used for ordinary service operations.
  • Account, support, and operational records: kept while your account is active or a support request remains open, then deleted within 90 days after account closure or resolution of the request. Routine operational logs are retained for up to 90 days. Records legally required to be retained, or necessary for a specific dispute or security investigation, are restricted and deleted when that need ends.

Deletion requests cover copies and derived data held by our providers as well as by Arp. Retention is not permission to retain Google data beyond applicable API terms or cache limits.

Disconnecting and controlling your data

Stop a folder sync or disconnect an account using Arp's connection/sync controls. If you cannot access those controls, email us for help.

  • Google: visit Google Account connections, select Arp, and remove its access to your Google Account.
  • Microsoft: visit My Apps, open Arp's menu, choose Manage your application, then Revoke Permissions. Your administrator must revoke permissions granted on your behalf. See Microsoft's instructions.

Revocation prevents continued authorized access; it does not erase previously imported copies. To request deletion of your account, connected data, or workspace content, email threegiskz@gmail.com, identifying your account and the data concerned. Do not send passwords or tokens. We may verify your identity and authority over shared workspace data. We respond within 30 calendar days, or sooner where law requires, and explain any lawful retention or organization-controlled data that affects the request.

Depending on your location, you may also have rights to access, correct, export, restrict, or object to processing of your personal information, withdraw consent, and complain to a privacy regulator. Contact us to exercise applicable rights. Withdrawing consent does not invalidate earlier lawful processing.

Security and processing locations

We use HTTPS for data in transit, encryption at rest for stored connected content and OAuth tokens, and access controls limiting access to authorized people and services. No system is completely secure.

Our service providers may process information outside your country. Where required by law, we protect international transfers using an applicable adequacy decision or approved contractual safeguards, such as standard contractual clauses. Contact us for information about processing locations and applicable safeguards.

Where data protection law requires a legal basis, we process account and service information to perform our agreement with you, rely on our legitimate interests to secure and support Arp where those interests do not override your rights, and process information as needed to comply with legal obligations. We obtain your permission before connecting Google or Microsoft accounts and rely on consent where legally required. For organization-controlled documents, we act on the organization's instructions; it is responsible for establishing its legal basis.

Children

Arp is a business service for adults aged 18 or older. We do not knowingly collect personal information from children. Contact us if a child has provided information so we can investigate and delete it where appropriate.

Changes and contact

We will post changes here and update the effective date. For material changes, we will provide notice in Arp or by email before they take effect, and obtain consent where required.

Privacy questions: threegiskz@gmail.com. See our Terms of Service.

Home Privacy Policy Terms of Service