Privacy Policy Version: 2026-09-27-v2. This version applies when presented for acceptance in Arkeego. 1. Who is responsible Arkeego is operated by 张烨, an individual developer based in 中国. Contact address: 中国北京市石景山区八大处甲一号院. For privacy requests, support and complaints, email 13241745521chauny@gmail.com. You do not need an Arkeego account to contact us. We offer idea capture, planning and fictional AI companion features. We do not offer the service in mainland China. 2. Age and guardian permission Arkeego is for people aged 13 or older and is not offered in mainland China. The sign-in privacy notice includes these eligibility requirements. By checking the box and continuing, you declare that you meet them and have any parent or guardian permission required where you live. The current sign-in flow does not ask for a numeric age, birth date or country selection. We record the declaration and its version, not a verified age or guardian identity. A declaration is not independent guardian verification. Where additional verification is required, it must be completed before the relevant access or processing; contact support. Previously recorded guardian reviews and access restrictions remain effective and cannot be replaced by a new declaration. Guardians may contact support to withdraw permission, and an incorrect decision can be appealed. Do not send identity documents through AI chat or general feedback. 3. Information we process • Account: Apple or Google sign-in identifiers, internal account ID, account status and agreement records. The sign-in provider may provide a name or email depending on the authorization you grant. We do not receive your Apple or Google password. • Your content: ideas, schedules, completion records, chat messages, tool results, conversation summaries, saved memories and their retrieval indexes. These may contain personal information you choose to enter. Avoid submitting passwords, identity documents or unnecessary sensitive information about yourself or others. • App state: companion selection and progress, preferences, language, task rewards, allowance balances and model usage. These support the functions you request and help prevent duplicate rewards or charges. • Notifications: device push token and delivery state if you enable notifications. You can turn notifications off in system settings. • Support and safety: feedback text, a screenshot if you choose to attach one, reported message references, decisions and necessary correspondence. A report is sent only when you submit it. • Technical records: request identifiers, network and security information, errors, crash diagnostics and performance information needed to operate and protect the service. We apply access controls and redaction, but no system can promise that every item of personal information is automatically detected. After you explicitly accept usage analytics in the sign-in privacy notice, we use PostHog to understand active use, retention and feature usage. We send an internal account identifier, event time, environment and limited feature-event properties, not your chat, idea or schedule text, email or sign-in credentials. Events pass through our server; we do not enable session replay or automatic screen capture. Acceptance of the usage analytics notice is a condition of access to Arkeego product features. Analytics remains off until you actively accept. If you decline, or later withdraw in Settings → AI and privacy, product access is blocked; reading policies, signing out, contacting support and requesting account deletion remain available. AI permission is separate. Withdrawal stops future analytics delivery; it does not automatically delete previously delivered events. Account deletion includes a request to delete your PostHog profile and associated events. PostHog processes this data in the United States. We record your explicit choice and the version of the analytics notice. This access condition does not waive rights or override applicable law. We do not sell personal information or use it for cross-app behavioral advertising. We do not ask for location, contacts or unrestricted photo-library access. Selecting a feedback image shares only the image you select. Your chat messages, idea text and schedule text are stored in our business database to provide history, synchronization and the features you request. Excluding this content from PostHog does not prevent that storage. Analytics exports exclude content-object IDs, internal request IDs and unrestricted text properties; they retain account-linked event counts, timestamps and limited categorical or numeric feature properties. 4. AI processing and your choice The sign-in privacy notice explains AI processing before you check the acceptance box and continue. After successful sign-in, we record your explicit AI permission and the notice version together with your analytics choice. We do not treat acceptance of an earlier notice that omitted AI permission as permission for AI processing. After withdrawing AI permission, non-AI features remain available. You may withdraw permission in Settings → AI and privacy. Withdrawal stops new authorized AI requests, including background requests; it cannot recall data already sent. To reply, summarize or retrieve relevant context, the service sends the necessary messages, selected history, ideas, memories and tool results to external model services. The current integration uses DeepSeek's official API for conversation and related generation, and OpenRouter and its downstream model providers for configured retrieval functions. Provider eligibility and contractual restrictions also apply. We do not send age verification evidence or sign-in credentials as AI context. We use local word matching to check model replies before displaying them. This does not send content to an additional moderation company. It can miss harmful content or reject harmless content. Arkee is AI, not a human or emergency service. We do not use your private content to train our own general-purpose AI model. This is not a promise that every external provider has zero retention or identical training terms. External provider handling is governed by the applicable API contract and settings, not by a consumer app's settings. We do not claim end-to-end encryption: authorized servers and model services must process relevant content. 5. Service providers and international processing We use Supabase for account authentication, database and selected file storage; Fly.io for application hosting; Apple and Google for sign-in, and Apple for push delivery; DeepSeek and OpenRouter/model providers for enabled AI; and configured Sentry/Grafana services for necessary technical diagnostics. Backup infrastructure may use Supabase and Cloudflare R2. This release does not offer purchases; if purchases are introduced, the payment provider and processing will be disclosed before use. Providers receive information needed for their functions. Processing can occur outside your country, including in the United States and, for relevant DeepSeek processing, China. Not distributing the app in mainland China does not mean no data can be processed there. Where required, international transfers need applicable contractual or other legal safeguards. Contact us for information about the safeguards applicable to your data. We may disclose limited information to meet a valid legal obligation, protect rights and safety, or carry out a lawful business transfer with appropriate notice and protections. 6. Purposes and legal bases We process necessary account and content information to provide the requested service; obtain consent for optional external AI processing and other uses requiring consent; use proportionate technical and security records to protect the service and users; and retain limited records to meet legal obligations or resolve disputes. Where legitimate interests are available as a legal basis, we balance them against users' rights, especially children's rights. We do not rely on agreement to these terms as blanket consent to sensitive-data processing. If a feature requires a further legal basis or guardian authorization, it must be obtained before that processing. 7. Retention and deletion Saved content remains available while you keep it in your account. Removing a single item is not the same as deleting all historical conversations or all information already sent to a model provider. For a broader request, use account deletion or contact support with the scope of your request. Account deletion is available in Settings. Once accepted, access ends and server cleanup proceeds asynchronously, including content, derived memories, authentication and feedback attachments. Some limited accounting, security, deletion and dispute records may need to remain for their applicable purpose or legal retention period. These are not used to continue personalization. Support correspondence is retained while the request or a related dispute remains active and for any necessary legal recordkeeping afterward. Backups are restricted recovery copies that expire under the relevant backup schedule. Deletion is reapplied before restored data is returned to service. External provider copies follow the applicable contract and deletion process. We do not promise immediate erasure of every backup or provider copy, or a fixed period that has not been verified for that provider. We can explain the relevant retention criteria in response to a request. 8. Your rights and choices Depending on your location, you may request access, a copy, correction, deletion, portability, restriction, objection, withdrawal of consent or review of a decision. Contact 13241745521chauny@gmail.com; include only the information needed to identify your account and request. We may proportionately verify identity or representative authority before disclosure. A guardian does not automatically receive a child's complete private conversations. We respond within applicable statutory time limits and explain a refusal, extension or available appeal. You may complain to your local data-protection authority. We do not discriminate against you for exercising applicable privacy rights. 9. Security and changes We use transport encryption, access controls and account-isolated server operations. No service is completely secure. Contact support if you suspect misuse. Material policy changes will be notified appropriately; where renewed consent is necessary we will ask before the changed processing. Continuing to use the app is not blanket consent to new optional processing.