Arkitype

Privacy

Last updated 18 September 2026

Arkitype is a tool for building design systems. This page says what it stores, who can see it, and how to get it back or get rid of it. It describes what the software actually does — if you find something here that does not match the product, that is a bug and we want to hear about it.

What we hold

Your account

Your email address, the name you gave us, and a password Supabase stores as a hash we never see. If you filled in the questions after signing up, your answers to those.

Your design systems

The documents you build: colours, type scales, spacing, components, comments, version history, and any logos or images you upload. This is the product, and it is stored in Supabase (Postgres), hosted in the region configured for the project.

Your organization, and what you pay

Every account has an organization — your own by default, or a shared one if you work in a team — and it carries the plan, the number of seats and the state of the subscription. If you have paid us, Stripe holds the billing contact, the payment method and the invoice history. We never see your full card number, and Stripe never sees your design work.

Technical records

Standard server logs kept by our hosting provider, and — on the marketing pages only — Google Analytics, described below.

Analytics, and where it does not run

Google Analytics runs on the marketing pages: the home page, the manual, and the guides. It records page views and a small number of events like “started a system”. It is loaded from a layout that covers those pages and nothing else.

It does not run on a published styleguide. Those pages live at /p/…, and their URL is also their access key — anyone with the link can read the page. Reporting that URL to a third party would mean handing out the key, so analytics is structurally excluded from those routes rather than conditionally disabled on them.

Who else can see your work

  • People you invite. A collaborator sees the file you invited them to, at the level you gave them, and nothing else.
  • Anyone with a published link. Publishing a styleguide makes a frozen copy readable by anyone who has its address. The address contains 120 bits of random data, so it cannot be guessed, but it is not otherwise protected. Unpublish to withdraw it.
  • People in your organization. If you are in a shared organization, its administrators can reach the design files that belong to it. That is deliberate — it is what stops a company's design system leaving with whoever made it — and it does not apply to a personal workspace, which has exactly one member.
  • Our processors. Supabase, our hosting provider, Stripe for payments, and Google Analytics on the marketing pages. Every one of them is named on the trust page, with what they can reach, where, and under what safeguard — kept there rather than restated here so the two cannot fall out of step.

We do not sell your data, and we do not use the contents of your design systems to train anything.

How long we keep it

Your design systems stay until you delete them or delete your account. Automatic version snapshots are kept for a period that depends on your plan — see the pricing page — and versions you name yourself are kept until you remove them. Deleting your account removes everything within 30 days, including from backups as those backups age out.

Invoices and the records behind them are kept for as long as tax law requires, which is longer than the rest and is not something we can delete on request. Saying so is more useful than a blanket promise we would have to break.

What you can do

Both of these are in Settings → Account, and both take effect immediately without anyone having to approve them:

  • Download my data gives you every design system you own, your profile and your comments, as one JSON file.
  • Delete account removes your account, your design systems and your published styleguides. Links you have shared stop working. Comments you left on other people's files stay as their record of the review, with your name removed from them — their file, their history.

If you are in the UK or the EU, these are your rights of access and erasure under UK GDPR and GDPR Articles 15 and 17. You also have the right to complain to your data protection authority.

Security

Access is enforced in the database with row-level security, not only in the interface: a request for a file you have no seat on returns nothing, whatever it was sent from. Traffic is encrypted in transit. Passwords are hashed by Supabase.

Arkitype is in beta. It is careful software and it is not finished software, and the honest advice for anything you cannot afford to lose is to keep your own export.

Getting in touch

For anything about your data — access, correction, erasure, objection, or a complaint — write to privacy@arkitype.srinidhibhat.com. We answer within one month, which is the statutory deadline rather than an aspiration. You can also complain to your data protection authority without coming to us first.

The controller is Srinidhi Bhat, trading as Arkitype. Where you use Arkitype to process other people's personal data, you are the controller and we are your processor — the data processing agreement covers that.

Children

Arkitype is not intended for anyone under 16, and we do not knowingly hold their data.

Changes

If this notice changes in a way that affects you, we will say so by email before it takes effect. The date at the top is always the date of the version you are reading.

Questions about any of this? srinidhibhat45@gmail.com