Privacy Policy
The short version: Be.Ark is local-first by design. Your conversations, agent memory, Living Files, and imported documents are stored on your own machine and are not uploaded to our servers. We only ever receive the minimum needed to run your account, subscription, and support.
1. Data that stays on your device
The core of Be.Ark runs entirely on your computer:
- Chat history, agent memory, and profiles
- Living Files and any documents you import (PDF, DOCX, KakaoTalk exports, etc.)
- Content processed by local AI models (via the bundled Ollama runtime) — fully offline
- API keys and service tokens you connect (stored in the local vault on your device)
None of this is transmitted to Be.Ark servers. Deleting the app's data folder or uninstalling the app removes it.
2. Data we collect on our servers
- Account: your email address and authentication data, managed via Supabase, when you choose to create an account. An account is optional for core features.
- Subscription & payments: processed by Stripe. We receive your subscription status; we never see or store your card number.
- Helpdesk: if you use the built-in helpdesk channel, the messages you type there and an anonymous identifier are sent to our support server. The helpdesk has no access to your local data.
- Optional statistics: company and job title, only if you explicitly opt in from the account screen. You can withdraw consent at any time.
3. Google user data
If you choose to connect a Google account, Be.Ark may request access to Gmail (read and send), Google Drive (read-only), and Google Calendar (read-only). This data is:
- Processed locally on your device to show you digests, read documents you request, and draft emails
- Never uploaded to, stored on, or read by Be.Ark servers
- Never used for advertising, never sold, and never used to train AI models
- Sent only with your explicit approval: every outgoing email requires a separate, per-message confirmation step
OAuth tokens are stored only in the local vault on your device. Disconnecting the service in Be.Ark, or revoking access at myaccount.google.com/permissions, removes access.
If you ask the agent to work on this content while a cloud model is selected, the relevant part of it is included in that request to the model provider — see section 4. With a local model, it is processed entirely on your device.
Be.Ark's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
4. Third-party AI providers (your own key or account)
Be.Ark works fully offline with local models. If you instead choose a cloud model — by entering your own API key, or by signing in to a provider's CLI (e.g. Claude Code, Codex, Gemini CLI) — that provider processes your requests under their own terms and privacy policy. Be.Ark servers are not in that path; the connection is made directly from your device.
In that case, what is sent is whatever the agent needs to answer you. Besides your message, this can include context drawn from your local data — for example relevant excerpts of documents, memory about your writing style and working habits, or details of people and schedules related to your request. Your local database as a whole is never uploaded; only the portions used for a given request are included.
Choosing a local model keeps this processing entirely on your device. Retention and model-training practices for cloud providers are governed by that provider's settings and policies, which you control in your own account with them.
5. Data retention and deletion
- Local data: under your control at all times; delete it from the app or by removing the app's data folder.
- Account data: kept while your account exists. To delete your account and associated server data, email ark@re-be.world — we complete deletion within 30 days.
- Helpdesk logs: retained only as long as needed to provide support.
6. What we don't do
- We do not sell personal data.
- We do not show ads or use your data for advertising.
- We do not train AI models on your data.
- We do not share personal data with third parties, except the processors named above (Supabase, Stripe) as required to operate the service, or where required by law.
7. Children
Be.Ark is not directed to children under 14, and we do not knowingly collect their data.
8. Changes
We will post any changes to this policy on this page and update the effective date above. Material changes will be announced in the app.
9. Contact
REBE WORLD FZCO · Dubai, United Arab Emirates
Email: ark@re-be.world