Privacy Notice
Version 2026-09-11 · effective 11 September 2026
1. Who controls your data
Arrota is an early-stage credential-vault service operated by Ryan Sinha. Arrota is the controller of personal data used to run holder accounts, the vault, trust and sharing features, security, support and product administration. Contact ryan@ryansinha.com for privacy questions or rights requests.
An employer, university, training provider or other issuer that submits data about you may also be an independent controller. Ask that organisation about its legal basis and privacy practices. This Notice covers Arrota's processing, not the organisation's separate systems or decisions.
2. Data we collect
- Account and contact data: authentication identifiers, personal and work email, verified phone, password policy evidence, lockout state and email-verification state. Arrota cannot read your Supabase password.
- Profile data: name, headline, location, biography, links, avatar, showcase choices, privacy settings and pinned records.
- Age and guardian data: an adult declaration and policy version, or a minor's date of birth, calculated minor status and guardian relationship. Adults do not have to provide a date of birth.
- Credential data: uploaded document files, file names and types, SHA-256 hashes, issuer, qualification or employment facts, credential identifiers, dates, skills, status, disputes, revocations, verification requests, AI provenance, cryptographic signatures and public verification identifiers.
- Consent and activity evidence: terms versions, AI-consent versions and times, audit events, account changes, claim-token state, notification delivery state and account-deletion/export job state.
- Sharing data: profile-access requests, the exact record scope approved, token hashes, expiry and revocation, plus a viewing ledger containing time, IP address and user agent.
- AI and career data: messages you submit to the Career Copilot, target-role or job-description text, generated résumé content, credential context supplied to a model and model/prompt version evidence.
- Technical and security data: IP address, user agent, request and rate-limit evidence, security events, provider delivery identifiers, diagnostics and errors. We do not intentionally put document contents or contact details into error monitoring.
- Public engagement data: credential/profile views, downloads and recipient-name matches. For unique counting, Arrota stores a truncated HMAC of the request IP and user agent under a separate secret; the analytics table does not store either raw value.
- Waitlist data: an email address and signup time if you join the waitlist.
- Enquiry and support data: contact details, Organisation, role, record type, expected scale, timeline and message content you choose to send through a published contact channel.
3. Where data comes from
We receive data from you, an issuer or guardian, people requesting access to a private profile, and the devices and providers involved in a request. We also derive structured credential facts, Trust Score evidence-coverage components, name-match results, file hashes, signatures and security signals from those inputs. Arrota does not buy advertising profiles or scrape credentials from data brokers.
4. Why we process data
- Contract: create and secure accounts; store, claim, verify, sign, display, export, share, revoke and delete credentials; deliver messages; and provide holder and issuer workflows.
- Consent: an adult holder's separate, versioned choice allows document AI, the Career Copilot and AI résumé tools. Consent is not bundled into signup and is never set for a minor. You can withdraw it for future processing.
- Legitimate interests: prevent fraud and malware, enforce access boundaries, rate-limit abuse, preserve an append-only issuance history, respond to business and support enquiries, investigate incidents, improve reliability and defend legal claims. We balance these purposes against the effect on you.
- Legal obligations and vital interests: respond to binding legal requests, meet security and record-keeping duties, and protect people or the service where necessary.
Issuer-uploaded data is stored and invitation mail is queued before a holder has an account. AI skill extraction waits until an eligible adult holder claims the credential, completes onboarding and accepts AI processing.
5. AI processing
With an eligible adult holder's consent, Mistral AI may receive document bytes to perform OCR, name matching and structured extraction. For Copilot and résumé requests, Mistral receives the holder's own message and credential context such as record type, issuer, skills, dates and verification status. Arrota does not add the holder's name, email, phone or date of birth to that career-context payload. If you put personal or sensitive information in your message, it is part of the prompt sent to the provider.
Prompts asking about current markets, salaries, news or trends may be sent to Google Vertex AI with Google Search grounding. Google states that Search grounding stores prompts, contextual information and generated output for 30 days for grounded results, debugging and testing. Vertex AI may also be used if Mistral is unavailable. Google states that it does not train or fine-tune its models on customer data without permission.
Arrota does not train its own model on your documents. Mistral's retention and model-improvement treatment depends on Arrota's commercial plan and privacy settings. Arrota must keep model-training opt-out enabled and should use zero data retention where contractually available. Do not submit confidential data if those controls have not been confirmed for the production workspace.
AI checks do not make legal or similarly significant decisions about you. A confident name mismatch can reject an upload; a low-confidence result is stored as Self Added and marked for manual issuer verification. You may add a record without relying on AI and may request issuer verification.
6. Malware scanning
Arrota does not upload your document files or Brand Kit images to third-party scanners. We only send a cryptographically secure SHA-256 hash of the file to VirusTotal to check against known threats. Unknown hashes are accepted. Your file bytes, file name and content never leave Arrota's infrastructure for scanning purposes. Brand images are also decoded and re-encoded as PNG, which strips embedded metadata before they are published.
Uploads fail closed if scanning is unavailable, incomplete, suspicious or malicious. A hash that matches a known threat is rejected; a hash VirusTotal has never seen is accepted and stored.
7. Service providers and disclosures
Arrota uses the following main provider categories:
- Supabase for authentication, Postgres, private file storage and signed download links.
- Vercel for application hosting, serverless execution and scheduled processing.
- Mistral AI and Google Cloud Vertex AI for the consent-gated uses described above.
- VirusTotal for file scanning, subject to the special disclosure above.
- Upstash for Redis-backed rate limits and QStash job delivery. QStash receives an opaque job ID, not the account's email, password, document, export, storage path or profile data.
- Resend for transactional email. Email address, template content and delivery metadata are processed to deliver and troubleshoot messages.
- Sentry for error and reliability monitoring. Arrota supplies pseudonymous account or feature context where needed to investigate failures.
We may also disclose limited data to professional advisers, a successor in a merger or financing, or authorities where required by valid law. We do not sell personal data or share it for cross-context behavioural advertising.
8. Public and private sharing
A public credential URL uses a public document identifier, never a private claim token. It may show credential type, issuer, issue date and current status, and may support recipient-name matching without revealing the stored name. Public profiles show only fields and records a holder has made public.
Private profile access uses a single plaintext link returned when the holder approves a request; Arrota stores only its SHA-256 hash. Access expires after seven days, can be revoked, and returns only record IDs within the approved scope. Arrota records each view's time, IP address and user agent for holder security. Anyone with an unexpired link may use it, so recipients must protect it.
Active issuer public keys are published so third parties can verify signed credentials independently. Private signing keys are service-role-only and are not included in public routes or data exports.
9. Security
Arrota uses row-level database security, service-role boundaries, hashed claim and sharing tokens, single-use invitations, short-lived signed file links, byte-type validation, malware scanning, rate limits, password lockouts, administrator RBAC and administrator access controls with email-based one-time authentication and 24-hour sessions. Issuer-issued credential payloads may be signed using Ed25519 keys. No system is completely secure; contact us immediately if you believe an account, invitation or credential has been compromised.
10. Retention and deletion
We keep account, credential and sharing data while the account or workflow is active and for as long as reasonably needed for the purposes above. Security, consent, delivery and audit evidence may be kept longer to prevent fraud, resolve disputes and meet legal obligations. Provider logs and backups follow provider retention schedules and are isolated or overwritten in the ordinary course.
Enquiry and support data is kept only as long as reasonably needed to answer the request, manage the resulting relationship, and meet applicable legal obligations.
Pseudonymous public-engagement events are deleted in daily bounded batches after 13 months. A missed or backlogged cleanup may delay removal, but the cleanup is designed to catch up without deleting active credential or audit evidence.
“Delete my account” first re-verifies the password, then queues a durable deletion job. The job deletes document binaries, invalidates verification tokens, cancels pending/failed outbox messages, removes contact and showcase information, anonymises the profile as “Deleted User”, and deletes the Supabase Auth user. Records, documents and audit logs are not hard-deleted: they retain an anonymised tombstone so an issuer's historical act, revocation or dispute cannot be silently rewritten. Opaque hashes, signatures and non-identifying audit evidence may therefore survive deletion.
A data export is built in a background job, stored temporarily in private storage, delivered through a time-limited signed link, and then cleaned up. It contains profile, contacts, records, document metadata and hashes, Trust Score evidence-coverage breakdown, consents, sharing and audit entries, but not document file bytes or private signing keys.
11. International processing
Arrota and its providers may process data outside your country. Where required, Arrota relies on provider data-processing terms, contractual safeguards and other lawful transfer mechanisms. The VirusTotal check described in section 6 receives only a SHA-256 fingerprint, not the uploaded document bytes or file name.
12. Your choices and rights
Vault settings let you correct editable profile data, control public visibility, revoke private access, download a JSON export and request account deletion. You may withdraw AI consent for future processing; this does not undo lawful processing already completed or erase issuer history.
Depending on where you live, you may also have rights to access, correct, delete, restrict or object to processing, obtain portable data, withdraw consent, nominate another person, or complain to a data-protection authority. Email the address in section 1. We may need to verify identity and may retain or refuse particular data where law permits or requires it. You may complain to your local supervisory authority without contacting us first.
13. Minors
Arrota records a minor's date of birth only where needed to apply the minor workflow, separates it from the public profile, blocks AI tools and requires the configured guardian controls. Adults can use an age declaration instead of a date of birth. If you believe a minor is using Arrota without required authority, contact us so we can investigate and restrict the account.
14. Changes to this Notice
We will update the version and effective date when this Notice changes. Material changes will be notified in the service or by email where appropriate, and a new consent will be requested when law requires it. Historic consent records keep the exact Terms version accepted at the time.
This Notice should be read with the Terms of Service .