Privacy policy
How ArchFor handles accounts, architectural images, feedback, payments and analytics.
Last updated: 2026-10-07
ArchFor and contact
ArchFor provides architectural image workflows. For support and privacy requests, contact support@archfor.com. You can also use in-site feedback and view replies in your account.
Information and purposes
We process your name, email, profile image, sign-in provider reference, sessions and security information for sign-in and account management. Account records may also include language, referral source and sign-up IP information. Architectural projects use the model-view screenshots or exported images, references, selected results, prompts, model/resolution choices and task records you submit. We use them to store private projects, generate images, provide downloads, settle credits and investigate failures.
Feedback includes your message, optional attachments, annotated screenshots, replies and unread status. Preview and check screenshots before submitting: private architectural images and sensitive controls are masked, but masking cannot identify every private detail you type. Do not submit passwords, keys, cookies, pairing codes or others' confidential material.
Payment and credit records include order and subscription references, payment results, grants, use, expiry and refunds. Card details and PayPal payment credentials are handled by the payment provider; do not include them in feedback. Requests, errors and operational logs support security and troubleshooting.
Providers and necessary transfers
Cloudflare and sign-in
Cloudflare runs the site and stores account, project, task, feedback and financial records in D1, and private image/attachment files in R2. Private in-site reads check account ownership. When Google sign-in is enabled, Google authenticates you and supplies the profile information used for your account; this is separate from Google Analytics.
Support email uses Cloudflare Email Routing to forward messages to the support inbox. Email content and delivery records are also processed by the receiving mail service. The 90-day in-site feedback rule does not apply to email copies. Transactional email and email sign-in are available only when the relevant sending service is configured.
AI image generation
To generate images, ArchFor sends the necessary images, prompts and generation parameters to third-party AI model service providers. Generated results are saved in the site's private storage for you to view and download.
The permission you give ArchFor to use uploaded content is limited to processing needed to provide the service. It does not include additional permission for promotion or model training. Third-party providers have separate processing and retention arrangements; deleting images on this site does not automatically delete copies held by those providers.
Payments
Stripe and PayPal handle payment credentials through their checkout services. ArchFor receives order/subscription references, payment states and billing information returned by the provider for settlement, support and credit records. Provider records have their own legal and financial retention rules; site account deletion does not delete the provider's account or transaction history. See Stripe's privacy policy and PayPal's applicable privacy statement.
These providers may process information outside your country. We do not promise a single processing location, a direct contract with every upstream model provider, or immediate deletion throughout the processing chain.
Cookies, analytics and operations
GA4 and Microsoft Clarity are the selected public-page analytics services. They load only when the corresponding site configuration is present. Google Ads conversion measurement is disabled at launch. Third-party analysis is limited to the public home and pricing pages. It does not run on account, authentication, project or admin pages. Uploaded images, results and sensitive controls are masked.
Our regional consent controls separately manage Google Analytics, Clarity and, if enabled later, Ads storage. You can change or withdraw choices through Cookie settings. Choices are stored for 180 days. Declining optional cookies still permits limited cookieless GA4/Clarity requests on allowed public pages; it is not a promise of zero third-party requests. Provider page locations omit query strings and fragments; private navigation unloads the public analytics runtime. Site-owned visit statistics are collected when the Google Analytics consent choice is granted. They store a hashed visitor reference, allowed event/placement information, language, times and, where linked after sign-in, an account reference. Business/order/credit records are separate from these optional measurements.
The shared operations center receives relevant event references, business states, amounts/currencies, masked account information, times and aggregates. If notifications are enabled, summaries and event notices can be delivered to the configured Feishu administration group. Feedback notifications do not directly send feedback text or screenshots. Operations notifications are for site administration, not public display; center and messaging copies are not covered by the image or feedback deadlines.
Retention and deletion
Uploaded and generated images
Uploaded source and reference images, other image-tool images, and generated results are retained for 14 days from when each is saved on this site. Saving to a project, viewing or reusing an image does not restart its clock. After expiry, images cannot be viewed, downloaded or used for generation, and maintenance tasks clean them up. Download in time; upload an expired source or reference again to use it for generation.
Feedback, screenshots and attachments
Retained for 90 days from feedback creation, not from the latest reply. Scheduled cleanup processes eligible records; failures may delay physical deletion.
Physical object deletion
Performed by maintenance tasks after confirmed storage deletion. Access expiry is not proof that all copies were physically erased.
Orders, subscriptions and credits
Financial records have no automatic site expiry. Account deletion clears emails and selected direct identity/payment fields, while order, subscription, credit and linked account references may remain for reconciliation, refunds and disputes. This is not complete anonymization. Retention required by applicable law and the payment providers is separate from image availability.
Project/task metadata and site statistics
Project titles, descriptions, prompts, task parameters and status records do not automatically expire with image files. The current account-deletion process does not erase all project/task metadata. Site analytics events and visitor links have no automatic age-based purge, although account-linked analytics records are deleted by the account-deletion process. Request specific deletion or correction through the privacy contact.
Runtime logs and database recovery copies
Runtime logs are sent to Cloudflare for security and troubleshooting. The site does not impose its image deadline on these logs. Cloudflare's Workers Logs documentation currently lists 3 days for Free and 7 days for Paid retention; the actual plan and any exported copies determine availability.
D1 Time Travel keeps a rolling recovery window of 7 days on Free or 30 days on Paid. Deleting an active database record does not immediately erase recovery history, and a restore can reintroduce previously deleted records. Manual exports and support-mail copies have no automatic expiry imposed by this application. No single deadline is promised for all logs and backups.
Analytics-provider copies
GA4 retention controls offer 2 or 14 months for standard user/event data; they do not govern all aggregated reports. No production property retention setting is active yet. Microsoft's current Clarity retention documentation lists 30 days for playback and 9 months for click/heatmap data and labeled/favorited sessions. These published periods do not prove this site's project settings or deletion of a particular session.
Provider copies
Copies held by third-party AI model service providers, payment, email, operations-center and analytics services follow their own processing and retention arrangements. The site's 14-day image deadline and deletion operations apply to image storage controlled by ArchFor; they do not mean that those third-party copies are deleted at the same time.
After you confirm an account-deletion request, it disables account/session use and asynchronously handles subscription cancellation, private assets and associated data. Queue or paid-period handling can delay completion. The current process does not guarantee erasure of every project title, prompt, task record, log, backup, financial record or provider copy. Request verification through the privacy contact.
Requests and changes
Contact us to request access, correction, deletion, restriction, portability or to raise an objection where applicable. We verify account ownership and explain any retention limits that affect the request. You may also raise a complaint with the competent data-protection authority where that right applies. Applicable legal response periods remain in force; this policy does not replace them with a support-service guarantee.
Changes are reflected on this page with the updated date. The date identifies the text revision, not an independently certified deletion result or legal approval.