Privacy Policy
Last updated: October 2026
This Policy explains how Arkame collects, uses and protects personal data, under Brazil’s General Data Protection Law (LGPD — Law No. 13,709/2018). It covers the website, the panel and the Arkame agent installed on your servers.
Written in plain language, to be read. It is not legal advice. The Portuguese version prevails in case of discrepancy.
Who provides the service
HUGO FREITAS TECNOLOGIA LTDA
CNPJ 40.898.123/0001-06
Av. Portugal, 1148, Sala C2501 — Setor Marista, Goiânia/GO, 74150-030
Contact: contato@arkame.app · Data protection officer (DPO): privacidade@arkame.app
Arkame is the trade name. The charge shows on your card as ARKAME.APP.
1. Who the controller is
The controller of the data Arkame processes is HUGO FREITAS TECNOLOGIA LTDA, CNPJ 40.898.123/0001-06, Av. Portugal, 1148, Sala C2501 — Setor Marista, Goiânia/GO, 74150-030, Brazil. The data protection officer (DPO) can be reached at privacidade@arkame.app.
2. What data we collect
Account: name, email and, if available, profile picture, when you sign in with Google (Google gives us the account identifier and that data, never your password); or just the email, when you sign in with the link sent by email.
Organization and billing: the organization’s name and country, members and roles, servers, registered buckets (name, region and endpoint — never the keys), plans and run history. Stripe processes payments: we do not receive the full card number. For Brazilian invoices we use the tax details you provide (name or company name, CPF or CNPJ and address).
Security and usage: IP address, browser, date and time of access, sensitive actions taken in the organization (audit log) and two-step verification data, when you turn it on.
Website forms: on the waitlist, the email and, if you provide them, name, company and number of servers, plus language and the partner referral, if any. On the Partner Program application: company, name, email, country and acceptance of the Program Terms and, if you provide them, phone, website, intended way of working, number of clients and servers and a message.
Support: what you write to us by email.
We do not collect or have access to the content of your backups: it goes straight from your server to your bucket.
3. What the Arkame agent sends to the panel
The Arkame agent runs on the server you protect and sends files straight to your bucket, using the bucket key, which stays on the server and is never sent to the panel. To the panel it sends only what you need to follow and restore your backups: the server’s name, operating system, agent version and IP address, how it was installed (Docker, service or manual) and the service name on the system; a periodic heartbeat; the results of bucket connection tests; when the pre- or post-backup command fails, up to 8 KB of what it wrote to its output, so you can see the error in the panel; and the index of each backup — the path and name of each file, its size, modification date, cryptographic digest (SHA-256) and version in the bucket. When you use the folder browser while creating a plan, it sends the names of the folders and files you opened. None of this includes file contents. Removing the agent (arkame-agent uninstall) deletes its configuration, key and identity from the server.
4. Controller and processor
For account, billing, security, form and support data, Arkame is the controller.
For backup metadata — the index with file and folder paths and names, sizes, dates and digests — Arkame is a processor: it handles that data on behalf of the customer, who is the controller, only to provide the service and following their instructions. File names and paths may contain personal data (for example, "contract-maria-silva.pdf"); the customer must have a legal basis to back up those files. Backup content never reaches Arkame.
5. Purposes and legal bases
Performance of a contract and pre-contractual steps: creating and authenticating the account, running backups and restores, billing, issuing invoices, providing support and assessing partner applications.
Legal obligation: tax and accounting records and the retention of access logs required by Brazil’s Internet Civil Framework (Marco Civil da Internet).
Legitimate interest: security, fraud and abuse prevention, aggregate website visit metrics and product improvement, respecting your expectations and rights.
Consent: on the waitlist, we only use your contact to tell you when a spot opens; you can ask to be removed at any time.
We do not sell personal data or use it for advertising.
7. Partners
If your organization is a customer of an Arkame reseller, the reseller sees your organization’s data in the partner area: name, status, servers, plans, usage and members (name and email). They do not see backup content or bucket keys.
If you came through the link of a referral partner (Affiliate), they only see aggregate data: the organization’s name, status and number of servers.
The partner handles that data as an independent controller, to serve you, and is bound to protect it by the Partner Program Terms.
8. Where data lives and international transfers
Panel data is stored in Brazil, on Oracle Cloud in São Paulo (sa-saopaulo-1).
Stripe, Google, Resend, Cloudflare and GitHub process data in the United States or other countries. These international transfers rely on article 33 of the LGPD, with data protection contractual clauses in our agreements with those suppliers (including the standard clauses approved by Brazil’s ANPD, where applicable), and are limited to what each function needs.
9. Security
Encryption in transit (TLS) between browser, panel, agent and bucket. Bucket keys never leave your server. Each server has its own identity (Ed25519), approved by you.
Isolation between organizations in the database itself, through row-level security (RLS) rules. Two-step verification (2FA) for accounts, an audit log of sensitive actions, backups of the panel database and internal access restricted to those who need it.
10. Security incidents
If a security incident occurs that may bring relevant risk or harm to people, we notify Brazil’s ANPD and the affected people within a reasonable time, under the LGPD and ANPD regulations, saying what happened, which data was involved and what to do. When the incident involves backup metadata we handle as processor, we notify the controlling customer without delay.
11. How long we keep data
While the account is active. After cancellation (effective at the end of the paid period), account data and the backup catalog are kept for at least 30 days — if you come back, nothing is lost. You can ask for deletion or anonymization at any time, before or after that period, at privacidade@arkame.app: we delete it from the database within 15 days, and our database backups, which we keep for 30 days, drop it as they expire.
Kept longer only where the law requires: tax and billing records for the legal period and access logs for 6 months (Brazilian Internet Civil Framework), deleted after that. Waitlist sign-ups stay until you are invited or ask to be removed; partner applications, for as long as needed to assess them and maintain the partnership.
Backup content stays in your bucket, under your own retention policy.
13. Your rights
You may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about who we share data with, and withdraw consent, under article 18 of the LGPD. You may also file a complaint with Brazil’s ANPD.
For backup metadata, where we are a processor, we forward the request to the controlling customer and help them fulfil it.
14. Data protection officer (DPO) and contact
For questions, requests or complaints about privacy, contact the DPO at privacidade@arkame.app. We reply within 15 days.
15. Changes to this Policy
We may update this Policy. Material changes are announced by email or in the panel before they take effect.
DPO contact: privacidade@arkame.app.