Effective 31 August 2026 · version 2026-08-31

dewit privacy notice

This notice explains what dewit collects during the early-user beta, why it is used, and the choices you have. dewit is operated by Arkis. Each account is treated as its own private workspace.

Information we process

  • Account: your email address, name if supplied, password hash, timezone, verification state, and consent version.
  • Planning: tasks, projects, notes, routines, schedules, time entries, and activity history you create.
  • Calendar: connected-account identifiers, encrypted OAuth tokens, calendar metadata, and event information needed for the calendar features you enable.
  • AI agents: credential names, scopes, one-way token digests, last-use times, and attributed activity. Plaintext agent tokens are shown once and are not stored.
  • Feedback: the report, page context, optional contact details, screenshots, and recording links you choose to send.
  • Security and operations: request, error, rate-limit, and audit information needed to protect and operate the service.

How we use it

We use this information to provide your workspace, authenticate you, sync the integrations you request, attribute agent actions, answer support and feedback, prevent abuse, diagnose faults, back up the service, and improve the beta. We do not sell your personal information or use private workspace content for advertising.

Service providers and disclosures

Information is shared only where needed to run features you choose or operate the service. Current categories include VPS hosting and backups, email delivery, Cloudflare Turnstile for signup abuse prevention, and Google when you connect Google Calendar. We may also disclose information when required by law or needed to protect users and the service.

Retention and security

Account and workspace data is kept while your account is active and for a limited period afterward when needed for backup recovery, security, or legal obligations. Revoked credentials cannot be used again. Feedback evidence follows its own private access and retention controls. We use access controls, encryption for sensitive calendar tokens, one-way agent-token digests, HTTPS, and backups, but no online service can promise perfect security.

Your choices

You can edit account details and timezone, disconnect calendars, revoke agent credentials, and choose what to include in feedback. You may ask to access, correct, export, or delete your information. Some records may be kept temporarily where required for security, backup recovery, or legal reasons.

Contact and updates

Privacy questions or requests can be sent to solomon@arkis.io. Material changes will update the version shown above and, where appropriate, require fresh notice or consent.