Privacy Policy
Effective July 19, 2026 · Last updated July 19, 2026
Arka Intelligence is a MSMM Engineering product. The Arka Intelligence platform (the “Service”) is owned and operated by MSMM Engineering (“MSMM”, “we”, “us”) and is available at chat.arkaintelligence.com and related subdomains.
This Privacy Policy explains what information the Service collects, why, how we store and protect it, who we share it with, and the choices you have. Privacy and security contact: contact@msmmeng.com.
1. Our role
The Service is provided to an organization — your employer or the entity that licensed it (the “Customer”).
- For content you or your organization put into the Service — documents, connected mailbox data, chat history — the Customer is the controller and MSMM acts as a processor on the Customer’s documented instructions.
- For account records, authentication logs, billing, and Service telemetry, MSMM acts as a controller.
If you are an individual user of a Customer’s deployment and want your data accessed, corrected, or deleted, contact your organization’s administrator first; we will support their instruction. You may also contact us directly and we will route the request appropriately.
2. Information we collect
Account and identity data. Name, email address, organization and project membership, role assignments, authentication material (password hashes, TOTP enrollment), API keys, and session records.
Content you provide. Documents, drawings, spreadsheets, and other files you or your organization upload or make available for indexing; chat prompts and conversation history; dashboards, reports, and annotations you create.
Connected mailbox data. If you connect a mailbox, we access the data described in Section 3 — message content, headers and metadata, attachments, and labels or folders — plus calendar data where you authorize it.
Technical and usage data. IP address, browser and user-agent string, timestamps, request paths, audit records, error and performance telemetry, and infrastructure logs.
What we do not collect. We do not process payment card data through the Service. We do not use advertising or cross-site tracking cookies, and we do not operate or participate in advertising networks.
3. Google user data — what we access and why
The Service requests the following Google OAuth scopes. Each supports a specific user-facing feature, and scopes beyond the default set are requested only when you explicitly enable the corresponding feature.
| Scope | Granted | Why we need it |
|---|---|---|
| gmail.readonly | At connection | Read your messages and attachments so the Service can display your inbox and index it for search and question answering |
| openid, email, profile | At connection | Identify which Google account is connected and bind it to your Service account |
| gmail.send | Only if you enable sending | Send replies and messages you compose in the Service |
| gmail.modify | Only if you enable mailbox actions | Apply your changes back to Gmail — read/unread state, labels, archiving, and moves you perform in the Service |
| calendar.readonly | Only if you enable calendar | Display your schedule alongside your mail |
| calendar.events | Only if you enable calendar writes | Create and update events you schedule in the Service |
We request the narrowest scopes that support the features you turn on. If you do not enable sending, mailbox actions, or calendar, those permissions are never requested and that data is never accessed. A refresh token is retained so the mailbox can stay in sync in the background; you can revoke it at any time (Section 8).
3.1 Google API Services Limited Use commitment
Arka Intelligence’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Google user data only to provide and improve the user-facing features described in Section 3.
- We do not transfer Google user data to third parties except (a) to the subprocessors listed in Section 6, strictly as necessary to provide those features; (b) where required by law; or (c) as part of a merger or acquisition, subject to your prior consent where required.
- We do not use Google user data for advertising of any kind, including personalized, retargeted, or interest-based advertising.
- We do not allow humans to read your Google user data, except: (i) with your explicit consent for specific messages; (ii) where necessary for security purposes such as investigating abuse; (iii) to comply with applicable law; or (iv) where the data is aggregated and anonymized for internal operations.
- We do not use Google user data to develop, train, or improve generalized artificial intelligence or machine learning models. AI processing serves your own retrieval, drafting, and classification of your own mailbox only. See Section 5.
4. How we use information
- Operate the Service: authenticate you, sync your mailbox, index content, and return search and chat results.
- Retrieval and question answering over content you are permitted to see.
- Security: detect and investigate abuse, unauthorized access, and integrity failures; maintain audit logs.
- Reliability: diagnose errors, monitor performance, plan capacity.
- Support: respond to requests you or your administrator raise.
- Legal compliance and enforcement of our Terms of Service.
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
5. AI and automated processing
Indexing. Content, including mailbox content, is split into fragments and converted into numerical embeddings held in our search and vector indexes so relevant passages can be retrieved for your queries. These indexes are scoped to your organization and your mailbox.
In-tenant generation. The Service’s primary generation model is self-hosted on our own infrastructure. Prompts and retrieved context for those requests do not leave our environment.
Third-party model processing. One feature sends content outside our infrastructure: automated email classification and tagging submits message content — up to 10,000 characters of message body per message, plus subject and sender metadata — to Anthropic, PBC, using the Claude Haiku model, which returns category labels. Anthropic processes this data solely to return that result and does not use it to train its models. Where the Customer enables document synthesis features, document content is submitted to the same provider on the same terms.
No model training on your data. We do not train, fine-tune, or otherwise improve any generalized model using your content or your Google user data.
No automated decisions with legal effect. The Service produces suggestions and answers; it does not make automated decisions producing legal or similarly significant effects about you.
6. Subprocessors and disclosure
| Subprocessor | Purpose | Data involved | Location |
|---|---|---|---|
| Amazon Web Services, Inc. | Cloud infrastructure — compute, storage, database, key management | All hosted data, encrypted at rest | United States (us-east-1) |
| Anthropic, PBC | Email classification and tagging; document synthesis where enabled | Message subject, sender metadata, and up to 10,000 characters of body per message; not retained for training | United States |
| Google LLC | The mail provider you connect | Only data you authorize under the scopes in Section 3 | Per Google |
| Microsoft Corporation | The mail provider you connect, where used | Only data you authorize at consent | Per Microsoft |
We also disclose information to the Customer administrator who controls your deployment; to professional advisors under confidentiality obligations; when compelled by valid legal process (we will notify you unless legally prohibited); and to a successor entity in a merger or acquisition, subject to this policy.
We do not sell your data. We do not provide it to data brokers or advertising networks.
7. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including:
- Encryption in transit (TLS) and at rest, using cloud key-management keys under our exclusive control.
- Credential protection. OAuth refresh tokens and provider secrets are encrypted with dedicated keys and held in a managed secrets service. They are never written to application logs or source code.
- Tenant isolation. Each customer deployment runs in isolated infrastructure — its own cluster, storage buckets, database, and secret namespace — so no customer’s data shares a store with another’s.
- Access control. Role-based permissions; per-document and per-folder access controls that default to closed, meaning a user sees nothing until granted; and mailbox-level isolation that fails closed, so search and question answering cannot return another user’s mailbox content even indirectly.
- Least privilege for internal administrative access, with authentication and audit logging of administrative actions.
- Monitoring of infrastructure and application events, with alerting.
No system is perfectly secure. We cannot and do not guarantee that unauthorized access will never occur. Our Terms of Service allocate risk between us; nothing in this policy or those Terms limits our liability for gross negligence, willful misconduct, or any liability that cannot be limited under applicable law. If a security breach affecting your data occurs, we will notify the Customer without undue delay and within any timeframe required by applicable law, and will cooperate with the Customer’s own notification obligations.
Your responsibilities. Keep credentials confidential, enable multi-factor authentication, revoke access for departed users promptly, and notify us immediately at contact@msmmeng.com if you suspect a compromise. We are not responsible for exposure resulting from your own credential sharing, device compromise, configuration of systems we do not control, or a security failure at a third-party provider, including your mail provider.
8. Retention, revocation, and deletion
Mailbox data. Retained while the mailbox remains connected. Disconnecting a mailbox in the Service stops synchronization immediately and removes the stored message content and its derived search and vector index entries.
Documents and derived indexes. Retained for the life of the Customer’s account, subject to deletions performed in the Service. Deleting an item removes it from search and retrieval.
Operational telemetry — logs, traces, and metrics — expires automatically 90 days after collection.
Backups. Encrypted backups may retain copies after deletion; those copies age out on the backup rotation cycle and are not returned to the live Service.
Revoking access. You may revoke the Service’s access to your Google account at any time at Google Account permissions, or to your Microsoft account through your Microsoft account settings. Revocation takes effect immediately and stops all further access.
Deletion requests. Contact contact@msmmeng.com or your administrator. We honor verified deletion requests within 30 days, except where retention is required by law.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of your personal information, and to withdraw consent.
California residents have rights under the CCPA/CPRA including the right to know, delete, and correct, and to opt out of sale or sharing — we do not sell or share personal information as those terms are defined, and we do not use or disclose sensitive personal information beyond the purposes described here.
Residents of the EEA and UK have rights under the GDPR, including the right to lodge a complaint with a supervisory authority. Our legal bases are: performance of a contract; our legitimate interests in operating, securing, and improving the Service; your consent where required, such as connecting a mailbox; and compliance with legal obligations.
To exercise any right, contact contact@msmmeng.com. We will not discriminate against you for exercising these rights. Where we act as a processor for a Customer, we will forward your request to that Customer and support their response.
10. International transfers
The Service is hosted in the United States. If you access it from outside the United States, your information will be transferred to and processed there. Where required for transfers from the EEA or UK, we rely on appropriate safeguards including the European Commission’s Standard Contractual Clauses. Contact us for details.
11. Children
The Service is not directed to children under 16 and we do not knowingly collect their personal information. If you believe a child has provided us information, contact contact@msmmeng.com and we will delete it.
12. Changes to this policy
We may update this policy. Material changes will be announced in the Service or by email at least 30 days before taking effect, and the “Last updated” date above will change. Continued use after the effective date constitutes acceptance.
13. Contact
MSMM Engineering — Arka Intelligence
Privacy and security: contact@msmmeng.com