Skip to the document

Legal

Privacy Policy

What Archetype collects when you plan a project here, why each piece is needed, and what you can ask us to do about it.

Version0.1 · specimen
EffectiveNot in force
Reading time7 min
Placeholder document

This is specimen text, written to exercise the layout and to describe how Archetype is intended to work. It has not been drafted or reviewed by counsel, it is not legal advice, and it is not in force. Nothing here creates an agreement between you and anyone.

Figures, dates and the contact address are placeholders. Replace this document before the product accepts a real account.

Scope, and who is responsible for your data

This Privacy Policy describes what Archetype Technologies, Inc. (placeholder) collects when you use the Archetype platform, why, and what you can ask us to do about it. It covers the website, the project workspace, and the emails we send you.

Not yet in force

This document is a draft written to exercise a layout. It has not been prepared or reviewed by a lawyer and it is not in force. It describes how the product is intended to handle data, which is useful for review — but it is not a commitment, and the contact route below is a placeholder.

Archetype is the controller of the personal information described here. The Terms and Conditions govern the service itself.

What we collect

You give us

  • Account information — full name, email address, password (stored hashed, never in readable form), and optionally a phone number with its country code.
  • A role selection — homeowner, or developer/designer. This is profiling only: both roles get the same product, and the value informs how we build rather than what you see.
  • Project information — a project name, the property you selected, and the program choices you make.
  • Uploads — surveys, soils declarations and inspiration images. A survey or soils report frequently identifies a property and sometimes a person, so treat these as sensitive and upload only what the project needs.
  • Messages — what you type into the plan chat, and anything you send us in support.

We generate or retrieve

  • Property data about the parcel you chose — lot geometry, zoning parameters, hazard designations and agency statuses — from public records and third-party providers.
  • Outputs — plan geometry, 360° views, summaries and cost estimates derived from your inputs.
  • Technical data — IP address, browser and device type, pages viewed, and error diagnostics.

We do not ask for, and ask you not to send us, government identification numbers, payment card numbers outside our processor's own fields, or health information. Nothing in the product needs them.

How we use it

  • To run the service — create your account, keep you signed in, retrieve property data, produce and store your outputs, and assemble a package for handoff.
  • To reach you — verification, password reset, and notices about a project or about a change to these documents.
  • To arrange consultant work you ask for, which means sharing what the consultant needs to do the job.
  • To keep the Platform working — diagnose errors, prevent abuse, and understand which parts are used.
  • To improve the product — in aggregate, and in the terms below.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.

Your content and model training

We do not use Your Content to train general-purpose models, and we do not provide it to a model vendor for their training. Content you enter is sent to a model provider only to process your request, under an agreement that forbids them retaining or training on it.

Who we share it with

We share personal information with service providers who process it on our instructions, and with people you ask us to involve. We do not sell it.

  • The Architect of Record and any consultant you engage — they receive what they need to do their work.
  • Infrastructure and hosting providers.
  • Model providers, for the duration of a request, under no-retention terms.
  • Property and hazard data providers, which generally receive an address or a parcel identifier rather than anything about you.
  • Email delivery, payment processing and identity providers — including Google, if you choose to sign in with it, which tells us your name, email address and that Google verified it.
  • Authorities, where the law requires it, or to protect someone from harm.

If Archetype is ever acquired or merged, personal information may transfer as part of that transaction, and this policy — or one at least as protective — will continue to apply.

Cookies, browser storage, and how your session is kept

We use browser storage for things the Platform cannot work without: keeping you signed in, remembering your light or dark theme preference, and holding a partially completed sign-up so returning to it does not start over.

Current build

Your session is an encrypted, HttpOnly cookie that only our server can read — scripts running in the page cannot. It lasts up to 24 hours or until you sign out, and anyone with access to that browser profile has access to your session for that long. Sign out on a shared machine.

A partially completed sign-up is held in sessionStorage and never includes your password. It is discarded when the tab closes.

We set no advertising or cross-site tracking cookies. Blocking the storage above will stop you being able to stay signed in.

How long we keep it

  • Account information — while your account is open, and for a limited period after you close it so it can be restored if the closure was a mistake.
  • Projects, uploads and outputs — while the account is open, or until you delete the project.
  • Sent packages — retained after handoff, because a set that was transmitted for professional review has to remain recoverable in the form it was reviewed in.
  • Technical logs — a short rolling window, then discarded or aggregated.
  • Backups — deleted content persists in backups until they expire on their own schedule.

The real document will state each period as a number. They are left unstated here rather than invented, because a retention period you can read is a promise and this document is not making promises yet.

Security

We protect personal information with encryption in transit, encryption at rest, access control limited to people who need it, and hashed password storage. Passwords are never stored or logged in readable form and no one at Archetype can read yours.

No system is perfectly secure, and we do not claim otherwise. The measures above reduce risk; they do not remove it. Where a breach affects you and the law requires notice, you will get it.

You hold the other half of this. Use a unique password, sign out on shared machines, and tell us if you think someone else has access to your account.

Your California privacy rights

If you are a California resident, the CCPA as amended by the CPRA gives you rights over personal information we hold about you:

  • To know what we collect, why, and who we share it with.
  • To access a copy of it, in a portable form.
  • To correct information that is inaccurate.
  • To delete it, subject to the exceptions the statute allows — a sent package we must retain being the likely one.
  • To limit the use of sensitive personal information.
  • Not to be discriminated against for exercising any of these.

We have no "sale" or "sharing" of personal information to opt out of, so there is no Do Not Sell link and its absence is deliberate rather than an omission.

To exercise a right, write to the address in the last section. We will verify that the request is yours before acting on it, which usually means confirming control of the account email.

Children

The Platform is for people aged 18 and over and is not directed at children. We do not knowingly collect personal information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.

Where your data is processed

Archetype operates in the United States and processes personal information there. Some of our service providers operate in other countries, so information may be transferred outside the one you are in.

Where a transfer needs a legal mechanism, we use one — standard contractual clauses or an equivalent — and we require providers to protect the information to the standard this policy describes.

Changes, and how to reach us

Changes

We may update this policy. A material change will be notified to account holders before it takes effect and the version and effective date at the top of this page will move. Continuing to use the Platform after a change takes effect means you accept it.

Contact

Privacy questions and rights requests go to privacy@example.invalid — a placeholder address for a placeholder document. The real one will name a postal address and a response time.

Keep a copy —CtrlPPprints this page in full.