Privacy Policy

Last updated: July 2026

1. Who we are

ArxGate Inc. (“ArxGate”, “we”, “us”, or “our”) operates arxgate.io and the ArxVault consumer application. This policy describes how we collect, use, store, and share information when you use our products and services.

2. Information we collect

  • Account information — name, email address, and password when you register.
  • Vault content — documents, estate metadata, and beneficiary contacts you store in ArxVault. All vault content is encrypted on your device before transmission; we cannot read it.
  • Identity verification data — if you use ArxGate's IDV features, liveness frames are processed to issue an attestation and are not stored beyond the verification session.
  • Usage and analytics — page views and feature interactions collected through privacy-preserving analytics (Umami). No cross-site tracking or advertising profiles are created.
  • Support communications — messages you send us via the contact form or email.

3. How we use your information

  • To provide, operate, and improve our products and services.
  • To authenticate your identity and protect your account.
  • To send transactional communications (check-in reminders, alerts, receipts).
  • To respond to your support requests.
  • To detect and prevent fraud, abuse, and security incidents.
  • To comply with legal obligations.

We do not sell your personal information to third parties. We do not use your data for advertising purposes.

4. ArxVault — privacy by design

  • Vault documents and estate metadata are encrypted on your device. ArxGate never holds your encryption keys.
  • ArxPulse check-in location data (if enabled) captures only city and state — never precise GPS coordinates.
  • Next-of-kin beneficiary shares are distributed directly between devices. ArxGate does not hold or have access to your Shamir key shares.

5. Information sharing

  • Service providers — AWS (infrastructure), Stripe (billing), and similar vendors who process data on our behalf under written data processing agreements.
  • Legal requirements — when required by law, subpoena, or to protect the rights and safety of ArxGate or others.
  • Business transfers — in connection with a merger or acquisition, with prior notice to affected users.

6. Data retention

We retain account data for as long as your account is active and for a reasonable period thereafter to comply with legal obligations. Vault content is deleted within 30 days of account closure upon request. Contact privacy@arxgate.io to request deletion.

7. Your rights

  • Access a copy of the personal information we hold about you.
  • Correct inaccurate information.
  • Request deletion of your data (right to be forgotten).
  • Object to or restrict certain processing activities.
  • Data portability — receive your data in a structured, machine-readable format.

To exercise any of these rights, contact privacy@arxgate.io.

8. Cookies and tracking

We use functional cookies required for authentication and session management. Our analytics provider (Umami) is configured in privacy-preserving mode and does not use cookies or fingerprinting. We do not use advertising cookies.

9. Security

We use TLS 1.2+ encryption in transit, encryption at rest, and access controls. If you believe your account has been compromised, contact security@arxgate.io immediately.

10. Children

Our services are not directed to children under 18. We do not knowingly collect personal information from minors. Contact us if you believe a minor has provided us with personal information and we will delete it promptly.

11. Changes to this policy

We may update this Privacy Policy from time to time. We will notify registered users of material changes by email. Continued use of our services after changes take effect constitutes acceptance of the revised policy.

12. Contact us

Questions? Email privacy@arxgate.io.