Privacy Policy

Arqenne LLC Effective Date: April 1, 2026 Last Updated: April 1, 2026


1. Introduction

Arqenne LLC, a California limited liability company ("Arqenne," "we," "our," or "us"), provides an AI-powered creative writing and audiobook production application. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

By using Arqenne Studio, you agree to the practices described in this policy.


2. Local-First Architecture

Arqenne Studio is built with a local-first architecture. This means:

  • Your projects, manuscripts, and creative files are stored on your device by default
  • AI models (text generation, text-to-speech, image generation, embeddings) run locally on your hardware when available
  • When using local AI features, your content does not leave your device
  • Cloud features are optional and clearly indicated in the application

This design ensures you maintain sovereignty over your creative work.


3. Data We Collect

3.1 Account & Authentication Data

DataPurpose
Email addressAccount creation and login
Display name (optional)Display name within the app
User ID (UUID)Internal account identifier
JWT access & refresh tokensSession authentication

Account authentication is managed through Supabase. Tokens are stored locally on your device and encrypted with AES-256-GCM using restricted file permissions (owner-only access).

3.2 User-Generated Content (Local)

The following content is stored exclusively on your device unless you explicitly use cloud features:

DataLocation
Projects, manuscripts, scenes, and filesLocal device (project directory)
Conversations with local AILocal device (SQLite per-project database)
Generated audio (local TTS)Local device
Generated images (local image generation)Local device
Knowledge base / indexed filesLocal device (per-project SQLite with vector embeddings)
Exported files (PDF, EPUB, audiobook)Local device

3.3 Data Transmitted to Cloud Services

When you use cloud-powered features, the following data may be transmitted:

DataWhenDestination
Message content and context filesCloud AI chat/completionsCloud AI provider (see Section 6)
Text contentCloud text-to-speechOur server or RunPod (see Section 6)
Conversations (if cloud sync enabled)Optional syncSupabase PostgreSQL

3.4 Usage & Billing Data

We collect usage data for billing, budgeting, and service operation:

  • Cloud LLM usage: Model name, provider, token counts, cost, response time, success/error status
  • Cloud TTS usage: Provider, job ID, character count, audio duration, cost, GPU type, status
  • Subscription data: Tier, billing cycle dates, budget remaining
  • Payment events: Stripe customer ID, subscription ID, invoice IDs, payment amounts, currency

We do not log the content of your messages or prompts in usage records. We do not log any data from local AI operations (local TTS, local text generation, local image generation, local embeddings).

3.5 UI Preferences

We store minimal UI preferences in your browser's local storage:

  • Dark mode setting
  • Sidebar width and collapse state
  • Active sidebar view

These contain no personally identifiable information.

3.6 Analytics and Crash Reporting

Arqenne Studio includes optional analytics and crash reporting. Both are enabled by default and can be disabled at any time in Settings.

Crash Reporting:

If you opt in, crash reports are sent to a third-party error tracking service when the application encounters an error. Crash reports may include:

  • Error messages and stack traces
  • Operating system and application version
  • Device type (e.g., macOS, Linux)
  • IP address (incidentally collected by the service provider)

Crash reports do not include your project content, manuscripts, messages, or generated audio/images.

Product Analytics:

If you opt in, we collect anonymized usage events to understand how features are used and to prioritize improvements. Analytics data may include:

  • Feature usage events (e.g., "exported audiobook," "used image generation") without content details
  • Session duration and general interaction patterns
  • Application version

Analytics data does not include your project content, manuscripts, messages, prompts, or any personally identifiable information.

The specific third-party providers we use for crash reporting and analytics are listed at https://arqenne.com/subprocessors. We will update that page when providers change.


4. Data We Do NOT Collect

  • Device hardware identifiers or fingerprints
  • Location or geolocation data
  • Browsing history
  • Keystroke or input logging
  • Screen recordings
  • Advertising identifiers
  • Content processed by local AI models

We do not use any advertising trackers or sell your data to third parties.


5. How We Use Your Data

PurposeData Used
Provide and operate the serviceAccount data, usage logs
Process cloud AI requestsMessage content and context files (sent to cloud AI provider)
Generate cloud text-to-speech audioText content (sent to TTS processing server)
Billing and budgetingUsage logs, subscription data, Stripe payment data
Security and authenticationJWT tokens, user IDs
Software updatesVersion check (no personal data transmitted)
Crash reportingError data, OS/app version, device type (sent to crash reporting provider)
Product analyticsAnonymized feature usage events (no personal data or content)

6. Third-Party Services (Sub-Processors)

When you use cloud features, we share data with the following third-party services:

6.1 Supabase (Authentication & Cloud Database)

  • Receives: Email, user credentials, synced conversations (if enabled), usage logs
  • Purpose: Authentication, optional cloud storage, database hosting
  • Privacy Policy: https://supabase.com/privacy

6.2 Stripe (Payments)

  • Receives: Payment and subscription information
  • Does not receive: Project content, messages, or files
  • Purpose: Payment processing and subscription management
  • Privacy Policy: https://stripe.com/privacy

6.3 Cloudflare (Infrastructure)

  • Receives: Network requests routed through Cloudflare infrastructure; presigned URLs for model downloads
  • Does not receive: User content or project files
  • Purpose: CDN, DNS, DDoS protection, secure tunnel infrastructure, model file distribution (via R2 storage)
  • Privacy Policy: https://www.cloudflare.com/privacypolicy/

6.4 RunPod (Cloud Text-to-Speech Overflow)

  • Receives: Text content for speech synthesis, voice parameters
  • Purpose: GPU-accelerated text-to-speech generation when primary server is at capacity
  • Privacy Policy: https://www.runpod.io/privacy

6.5 Analytics and Crash Reporting Providers

  • Receives: Error data (crash reports) and/or anonymized usage events, depending on which features you enable
  • Does not receive: Project content, manuscripts, messages, or generated files
  • Purpose: Application error tracking, diagnostics, and product improvement
  • Opt-out: Both are enabled by default. You can disable either at any time in Settings.
  • Current providers: Listed at https://arqenne.com/subprocessors

6.6 Cloud AI Providers

When you use cloud-powered AI chat or completions (as opposed to local AI), your message content and attached context files may be sent to third-party AI providers. The specific provider depends on the model you select. Under standard API terms, these providers do not use your data to train their models. We will identify the active cloud AI providers on our website.

6.7 Local AI Models

When you use locally-hosted AI models (local text generation, local text-to-speech, local image generation, local embeddings), your data stays entirely on your device and is not transmitted to any external service. Local AI processing is the default for all supported features.


7. Voice Data and Audio

7.1 Local Text-to-Speech

Arqenne Studio includes a local text-to-speech engine that runs entirely on your device. Text you synthesize using local TTS is processed on-device and never transmitted externally. Generated audio files are stored locally.

7.2 Voice Cloning

Arqenne Studio includes voice cloning capabilities that allow you to create custom voice profiles from audio samples. Voice cloning runs entirely on your device:

  • Voice reference audio you provide is processed locally and is never transmitted to our servers or any third party
  • Voice profiles (voice models) derived from your reference audio are stored locally on your device
  • We do not have access to, collect, or store your voice reference audio or derived voice profiles
  • Voice profiles derived from reference audio may constitute biometric-adjacent data under certain jurisdictions. By using the voice cloning feature, you acknowledge and consent to the on-device processing of your voice data for this purpose
  • You may delete your voice profiles at any time through the application. Deletion is immediate and permanent since the data exists only on your device

7.3 Cloud Text-to-Speech

When you use cloud-powered TTS, the text content is transmitted to our server infrastructure (and potentially RunPod as overflow) for processing. Generated audio is returned to your device and the text input is not retained on our servers after processing.


8. Data Storage & Security

8.1 Local Storage

  • Project files are stored on your device in your designated project directory
  • Authentication tokens are encrypted with AES-256-GCM and stored with restricted file permissions (owner-only access)
  • Local databases (SQLite) store per-project conversations, audio metadata, knowledge base embeddings, and project settings

8.2 Cloud Storage

  • Cloud data is hosted in Supabase-managed PostgreSQL databases
  • Row-Level Security (RLS) is enforced on all database tables, ensuring users can only access their own data
  • All network communication uses HTTPS/TLS encryption
  • SQL queries use parameterized statements to prevent injection attacks
  • Payment data is handled entirely by Stripe; we do not store credit card numbers

8.3 Model Distribution

AI models are downloaded to your device from Cloudflare R2 storage using time-limited presigned URLs. Model files are stored locally after download. No user data is transmitted during model downloads.


9. Data Retention

Data TypeRetention Period
Account dataRetained until account deletion
User-generated content (local)Retained on your device until you delete it
User-generated content (cloud)Retained until you delete it or request account deletion
Conversations and messages (local)Retained on your device until you delete them
Cloud LLM usage logsRetained for up to 12 months, then archived
Cloud TTS usage logsRetained for up to 6 months, then archived
Payment event historyRetained as required for financial audit and legal compliance
UI preferencesRetained in browser local storage until cleared

10. Your Rights & Controls

10.1 Access and Portability

  • Your project files are stored locally on your device in standard formats (Markdown, JSON, WAV, PNG) and are always accessible to you without requiring our software
  • You may request a copy of your cloud-stored data at any time

10.2 Deletion

  • You can delete individual conversations, projects, audio files, and other content at any time
  • You may request full account deletion by contacting us at legal@arqenne.com
  • Upon account deletion, we will remove your account data, synced content, and usage logs, except where retention is required by law
  • Local data remains on your device under your control regardless of account status

10.3 Data Correction

  • You may update your account information (email, display name) through the app settings

10.4 Opt-Out of Cloud Features

  • Cloud sync is optional; you may use the app in a fully local mode
  • You may choose to use only local AI models, in which case no content is transmitted externally
  • Cloud AI features are clearly labeled in the interface

11. AI-Specific Disclosures

11.1 How AI Features Work

Arqenne Studio includes AI features that operate in two modes:

Local AI (on-device): Text generation, text-to-speech, image generation, and embeddings can run entirely on your device using bundled AI models. No data leaves your device.

Cloud AI (optional): When local processing is unavailable or you select a cloud model, your content is sent to our servers or third-party providers for processing. This includes the text of your messages, any context files you attach, and conversation history within the current session.

11.2 AI Provider Data Practices

  • API usage: We access third-party AI providers through their APIs. Under standard API terms, providers do not use your data to train their models.
  • Local models: When using local AI models, no data leaves your device. We have no visibility into what you process locally.
  • No training on your data: We do not use your content, prompts, or generated output to train AI models.

11.3 No Automated Decision-Making

We do not use AI to make automated decisions that produce legal or similarly significant effects on you. AI features are creative tools under your direct control.


12. Children's Privacy

Arqenne Studio is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at legal@arqenne.com and we will delete such information.


13. Cookies

Arqenne Studio is a desktop application and does not use cookies for tracking or advertising. We use browser local storage solely for UI preferences (dark mode, sidebar layout). No third-party cookies are set. Our website (https://arqenne.com) may use essential cookies for session management; see our website cookie notice for details.


14. International Data Transfers

If you are located outside the United States, data transmitted to our cloud services may be transferred to and processed in the United States or other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.


15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by updating the "Last Updated" date at the top of this policy and, where appropriate, through in-app notification. Material changes to how we handle User Content or introduce new categories of data collection will be communicated at least 30 days before taking effect.


16. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Email: legal@arqenne.com Website: https://arqenne.com


17. Jurisdiction-Specific Rights

For European Economic Area (EEA) Residents

Under the GDPR, you have additional rights including the right to access, rectify, erase, restrict processing, data portability, and to object to processing. Our legal basis for processing your data is contract performance (providing the service) and legitimate interest (service operation and security). To exercise these rights, contact us at legal@arqenne.com.

For California Residents

Under the CCPA/CPRA, you have the right to know what personal information we collect, request deletion, and opt out of the sale or sharing of personal information. We do not sell or share your personal information. To exercise these rights, contact us at legal@arqenne.com.