Skip to content

Privacy Policy

Last updated: October 2026

This Policy explains how Arkame collects, uses and protects personal data, under Brazil’s General Data Protection Law (LGPD — Law No. 13,709/2018). It covers the website, the panel and the Arkame agent installed on your servers.

Written in plain language, to be read. It is not legal advice. The Portuguese version prevails in case of discrepancy.

Who provides the service

HUGO FREITAS TECNOLOGIA LTDA

CNPJ 40.898.123/0001-06

Av. Portugal, 1148, Sala C2501 — Setor Marista, Goiânia/GO, 74150-030

Contact: contato@arkame.app · Data protection officer (DPO): privacidade@arkame.app

Arkame is the trade name. The charge shows on your card as ARKAME.APP.

1. Who the controller is

The controller of the data Arkame processes is HUGO FREITAS TECNOLOGIA LTDA, CNPJ 40.898.123/0001-06, Av. Portugal, 1148, Sala C2501 — Setor Marista, Goiânia/GO, 74150-030, Brazil. The data protection officer (DPO) can be reached at privacidade@arkame.app.

2. What data we collect

Account: name, email and, if available, profile picture, when you sign in with Google (Google gives us the account identifier and that data, never your password); or just the email, when you sign in with the link sent by email.

Organization and billing: the organization’s name and country, members and roles, servers, registered buckets (name, region and endpoint — never the keys), plans and run history. Stripe processes payments: we do not receive the full card number. For Brazilian invoices we use the tax details you provide (name or company name, CPF or CNPJ and address).

Security and usage: IP address, browser, date and time of access, sensitive actions taken in the organization (audit log) and two-step verification data, when you turn it on.

Website forms: on the waitlist, the email and, if you provide them, name, company and number of servers, plus language and the partner referral, if any. On the Partner Program application: company, name, email, country and acceptance of the Program Terms and, if you provide them, phone, website, intended way of working, number of clients and servers and a message.

Support: what you write to us by email.

We do not collect or have access to the content of your backups: it goes straight from your server to your bucket.

3. What the Arkame agent sends to the panel

The Arkame agent runs on the server you protect and sends files straight to your bucket, using the bucket key, which stays on the server and is never sent to the panel. To the panel it sends only what you need to follow and restore your backups: the server’s name, operating system, agent version and IP address, how it was installed (Docker, service or manual) and the service name on the system; a periodic heartbeat; the results of bucket connection tests; when the pre- or post-backup command fails, up to 8 KB of what it wrote to its output, so you can see the error in the panel; and the index of each backup — the path and name of each file, its size, modification date, cryptographic digest (SHA-256) and version in the bucket. When you use the folder browser while creating a plan, it sends the names of the folders and files you opened. None of this includes file contents. Removing the agent (arkame-agent uninstall) deletes its configuration, key and identity from the server.

4. Controller and processor

For account, billing, security, form and support data, Arkame is the controller.

For backup metadata — the index with file and folder paths and names, sizes, dates and digests — Arkame is a processor: it handles that data on behalf of the customer, who is the controller, only to provide the service and following their instructions. File names and paths may contain personal data (for example, "contract-maria-silva.pdf"); the customer must have a legal basis to back up those files. Backup content never reaches Arkame.

5. Purposes and legal bases

Performance of a contract and pre-contractual steps: creating and authenticating the account, running backups and restores, billing, issuing invoices, providing support and assessing partner applications.

Legal obligation: tax and accounting records and the retention of access logs required by Brazil’s Internet Civil Framework (Marco Civil da Internet).

Legitimate interest: security, fraud and abuse prevention, aggregate website visit metrics and product improvement, respecting your expectations and rights.

Consent: on the waitlist, we only use your contact to tell you when a spot opens; you can ask to be removed at any time.

We do not sell personal data or use it for advertising.

6. Subprocessors

We use these suppliers, each only for its own function:

Oracle Cloud — hosting of the panel and database (Brazil, São Paulo region).

Stripe — payments and subscriptions (United States).

Google — sign-in with a Google account, when you choose that option (United States).

Resend — transactional email, such as the sign-in link and backup and billing notices (United States).

Cloudflare — CDN, DNS and proxy for the website and panel, aggregate visit metrics (Web Analytics) and forwarding of incoming email (United States).

GitHub — distribution of the Arkame agent program; whoever downloads the agent has their IP address seen by GitHub (United States).

We also share data when required by law or court order, and with your organization’s partner, within the limits of section 7.

7. Partners

If your organization is a customer of an Arkame reseller, the reseller sees your organization’s data in the partner area: name, status, servers, plans, usage and members (name and email). They do not see backup content or bucket keys.

If you came through the link of a referral partner (Affiliate), they only see aggregate data: the organization’s name, status and number of servers.

The partner handles that data as an independent controller, to serve you, and is bound to protect it by the Partner Program Terms.

8. Where data lives and international transfers

Panel data is stored in Brazil, on Oracle Cloud in São Paulo (sa-saopaulo-1).

Stripe, Google, Resend, Cloudflare and GitHub process data in the United States or other countries. These international transfers rely on article 33 of the LGPD, with data protection contractual clauses in our agreements with those suppliers (including the standard clauses approved by Brazil’s ANPD, where applicable), and are limited to what each function needs.

9. Security

Encryption in transit (TLS) between browser, panel, agent and bucket. Bucket keys never leave your server. Each server has its own identity (Ed25519), approved by you.

Isolation between organizations in the database itself, through row-level security (RLS) rules. Two-step verification (2FA) for accounts, an audit log of sensitive actions, backups of the panel database and internal access restricted to those who need it.

10. Security incidents

If a security incident occurs that may bring relevant risk or harm to people, we notify Brazil’s ANPD and the affected people within a reasonable time, under the LGPD and ANPD regulations, saying what happened, which data was involved and what to do. When the incident involves backup metadata we handle as processor, we notify the controlling customer without delay.

11. How long we keep data

While the account is active. After cancellation (effective at the end of the paid period), account data and the backup catalog are kept for at least 30 days — if you come back, nothing is lost. You can ask for deletion or anonymization at any time, before or after that period, at privacidade@arkame.app: we delete it from the database within 15 days, and our database backups, which we keep for 30 days, drop it as they expire.

Kept longer only where the law requires: tax and billing records for the legal period and access logs for 6 months (Brazilian Internet Civil Framework), deleted after that. Waitlist sign-ups stay until you are invited or ask to be removed; partner applications, for as long as needed to assess them and maintain the partnership.

Backup content stays in your bucket, under your own retention policy.

12. Cookies and browser storage

We only use what the site and panel need to work. No advertising cookies.

authjs.session-token (prefixed with __Secure- over HTTPS): keeps you signed in to the panel until you sign out or for up to 30 days. Alongside it, authjs.csrf-token and authjs.callback-url protect and complete the sign-in. When signing in with Google, authjs.pkce.code_verifier and authjs.state exist only during the round trip to Google.

arkame_2fa: remembers for 12 hours that you already confirmed the second-factor code in this session. arkame_link_nav: keeps the sign-in link sent by email for 15 minutes, between opening the link and confirming it.

arkame_modo (backoffice only, for people who are both staff and partner): remembers which of the two roles you're in, for 30 days.

arkame-locale: stores the language chosen in the panel, for 1 year. arkame-tz: stores the browser's time zone, for 1 year, so the panel shows dates and times in your time.

arkame_ref: created when you arrive through a partner's referral link (arkame.app/r/…), to attribute the referral; it lasts 90 days. You can decline it when creating the organization in the panel, which shows who referred you, or in the waitlist form while it is open.

Browser local storage (not a cookie, and it never leaves your computer): the light or dark theme (arkame-site-theme on the site, arkame-theme in the panel, arkame-admin-theme in the backoffice), the language suggestion already answered on the site, the notifications and updates you've already seen in the panel, and arkame-tz-recarregou (sessionStorage, gone when you close the tab), which avoids reloading the page more than once when setting the time zone.

Cloudflare Web Analytics: counts visits in aggregate, without cookies and without identifying you.

13. Your rights

You may request confirmation of processing, access, correction, anonymization, blocking or deletion of unnecessary data, portability, information about who we share data with, and withdraw consent, under article 18 of the LGPD. You may also file a complaint with Brazil’s ANPD.

For backup metadata, where we are a processor, we forward the request to the controlling customer and help them fulfil it.

14. Data protection officer (DPO) and contact

For questions, requests or complaints about privacy, contact the DPO at privacidade@arkame.app. We reply within 15 days.

15. Changes to this Policy

We may update this Policy. Material changes are announced by email or in the panel before they take effect.

DPO contact: privacidade@arkame.app.

Privacy Policy · Arkame