Privacy Policy
Arbinex (a product of Arbinex B.V.)
Effective Date: February 3, 2026
1. Introduction
Welcome to Arbinex. We are committed to protecting your privacy and being transparent about how we handle your data. This Privacy Policy explains what information we collect, how we use it, and your rights regarding your personal data.
How Arbinex operates:
- Your queries are processed through Arbinex's managed API keys with supported LLM providers. Arbinex acts as a data processor for your AI interactions.
2. Information We Collect
2.1 Account Information
When you create an account, we collect:
- Email address
- Name (optional)
- Password (stored as a secure hash, never in plaintext)
- Subscription tier and billing information
- Account preferences and settings
2.2 Usage Analytics
To improve our service, we collect:
- Query counts and timestamps (not content)
- Model selection patterns
- Cost tracking data (token counts, estimated costs)
- Session duration and feature usage
- Error logs (without prompt content)
2.3 Conversation History We Store
To provide conversation history, side-by-side model comparison, cost tracking, and answer verification, we store your prompts and the model responses in our EU-hosted database, linked to your account.
- Lawful basis: performance of our contract with you (Art. 6(1)(b) GDPR) to deliver the features you use, and our legitimate interest (Art. 6(1)(f) GDPR) in service quality, cost accounting, and abuse prevention.
- Your control: you can delete any conversation at any time, which permanently removes its messages; deleting your account removes your conversation content (see Section 7 below).
- No training or resale: we do not use your prompts or responses to train models, and we do not sell them or share them with third parties for training. Prompts are sent to LLM providers solely to generate your answer, subject to the terms of those providers.
2.4 What We Do NOT Store
- Provider API keys: Arbinex does not ask for, receive, or store API keys belonging to you. Every query is billed to Arbinex's own provider accounts, so there is no user-supplied credential to protect.
3. How We Use Your Information
We use your information to:
- Provide and maintain the Arbinex platform
- Process billing and subscription management
- Calculate and display cost tracking
- Improve platform performance using aggregate, anonymized analytics
- Respond to support requests
- Comply with legal obligations
We do NOT use your data for: training AI models, selling to third parties, advertising, or profiling beyond service delivery.
4. Third-Party Data Processors
We work with trusted third-party services to operate Arbinex:
| Processor | Purpose | Data Shared |
|---|---|---|
| Stripe | Payment processing | Email, billing address, payment method |
| Supabase | Database hosting (EU) | Encrypted account data |
| LLM Providers | AI model inference | Your prompts, sent from Arbinex's servers using Arbinex's managed keys |
| Brevo | Transactional email delivery | Email address, email content (verification, password reset) |
| Railway | Application hosting | Server logs, request metadata |
| Cloudflare | CDN, DNS, DDoS protection | IP addresses, request metadata |
| Sentry | Error monitoring | Error stack traces, browser metadata (no prompt content) |
| PostHog | Product analytics | Anonymized usage events, feature interactions (cookieless) |
| Langfuse | LLM observability and tracing | Model selection metadata, latency, token counts (no prompt content) |
4.1 Sub-Processors
Your queries are routed through Arbinex's managed API keys to the following LLM providers (sub-processors). This applies to every plan — there is no configuration in which your prompts reach a provider by another route. These providers may process your prompt content as part of generating responses:
| Provider | Parent Entity | Data Processed |
|---|---|---|
| Groq | Groq, Inc. | Prompt content, generated responses |
| OpenAI | OpenAI, Inc. | Prompt content, generated responses |
| Anthropic | Anthropic PBC | Prompt content, generated responses |
| Alphabet Inc. | Prompt content, generated responses | |
| Perplexity | Perplexity AI, Inc. | Prompt content, generated responses |
| xAI | xAI Corp. | Prompt content, generated responses |
4.2 Data Flow by Tier
- Your queries are sent from Arbinex's servers to LLM providers using Arbinex's managed API keys. Arbinex acts as a data processor, and the LLM providers act as sub-processors. Your prompt content passes through our infrastructure.
Important: Each LLM provider's own terms of service and privacy policy govern how they handle your data. We encourage you to review these policies. Arbinex maintains the provider relationship on your behalf.
4.3 International Transfers
Some sub-processors are located outside the European Economic Area. Where a provider is certified under the EU-U.S. Data Privacy Framework (an EU adequacy decision), no additional transfer mechanism is required. Where a provider is not DPF-certified, transfers are governed by Standard Contractual Clauses executed between Arbinex and that provider. A current per-provider breakdown is maintained in our sub-processor list.
4.4 Data Processing Agreement
Business customers who require a Data Processing Agreement (GDPR Art. 28) can request one by emailing contact@arbinex.ai. We will provide our standard DPA, built on the European Commission's Article 28 standard contractual clauses, for signature.
5. Data Security
We implement industry-standard security measures:
- Encryption at Rest: AES-256 encryption for database storage
- Encryption in Transit: TLS 1.3 for all connections
- Access Controls: Role-based access with principle of least privilege
- Rate Limiting: Protection against abuse and automated attacks
6. Your Rights (GDPR)
If you are in the European Union, you have the following rights under GDPR:
- Access: Request a copy of your personal data
- Rectification: Correct inaccurate data
- Erasure: Delete your account and associated data
- Portability: Export your data in machine-readable format
- Restriction: Limit how we process your data
- Objection: Object to processing based on legitimate interest
- Withdraw Consent: For consent-based processing at any time
To exercise these rights, email us at contact@arbinex.ai or use the Contact Us option in your account menu.
7. Data Retention
- Account data: Retained while your account is active; deleted within 30 days of account closure
- Conversation content (prompts and responses): Retained while your account is active; deleted when you delete the conversation, or within 30 days of account closure
- Usage analytics: Aggregated and anonymized after 90 days
- Provider API keys: Not collected. Arbinex uses its own provider accounts, so no key of yours is retained or deleted.
- Legal/compliance records: Retained as required by law (typically 7 years for financial records)
8. Cookies
We use essential cookies for:
- Session management and authentication
- Remembering your preferences (theme, settings)
- Security (CSRF protection)
We do not use third-party advertising or tracking cookies.
9. Children's Privacy
Arbinex is not intended for users under 18 years of age. We do not knowingly collect personal information from children. If you believe we have collected data from a child, please contact us immediately.
10. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email at least 30 days in advance. Non-material changes are effective upon posting. Continued use of Arbinex after changes constitutes acceptance.
11. Contact Us
If you have questions about this Privacy Policy or your personal data, please email us at contact@arbinex.ai.
Data Controller
- Arbinex B.V.
- Amstelveen, Netherlands
- KvK: 42098901
- BTW: NL869715549B01