Privacy
Privacy
Privacy Policy
Revision date: September 28, 2026
1. General provisions
1.1. This Policy describes how Триарх processes and protects personal data.
1.2. The data controller is Общество с ограниченной ответственностью «ТРИАРХ», Primary State Registration Number (OGRN) 1269100009485, Tax ID (INN) 9100005672, Tax Registration Reason Code (KPP) 910001001 (the Controller).
1.3. Consent to personal-data processing is collected separately from acceptance of the Terms when the User signs in.
1.5. The Policy is governed by applicable Russian personal-data law.
2. Data processed by the Service
The Service may process:
- account data supplied by an OAuth provider available on the sign-in page, including provider ID, name, email address, and profile image;
- OAuth tokens, token expiry data, session IP address, User-Agent, and session timestamps required for authentication;
- uploaded images, generation parameters, prompts, analysis results, generated images, ratings, and generation history;
- subscription, plan, quota, payment, and usage identifiers;
- technical logs required for operation, security, and diagnostics.
Full bank-card details are processed by YooKassa. The Controller does not receive or store the full card number or CVV.
3. Purposes
Data is processed to authenticate Users, provide the image-generation Service, operate accounts and subscriptions, process payments, enforce quotas, provide support, secure and diagnose the Service, and comply with legal obligations.
4. Legal grounds
Processing is based on the User's consent, performance of the service agreement, the Controller's legitimate security and operational interests where permitted, and mandatory legal obligations.
5. Service providers
Data may be disclosed to providers actually connected to the deployment:
| Provider category | Data and purpose |
|---|---|
| Available OAuth provider | Account and authorization data used to sign in |
| Configured LLM/VLM provider | Uploaded image, prompt, and analysis parameters |
| Configured ComfyUI operator | Uploaded image and generation parameters |
| FlexPrice | User identifiers, plan, subscription, quota, and usage information |
| YooKassa | Amount, currency, description, technical IDs, and payment-method data processed by YooKassa |
| Hosting, logging, and backup providers | Data required to operate and secure the deployed Service |
The exact legal entities and processing locations depend on the production configuration and must be published by the Controller before public launch.
6. Retention and deletion
6.1. Data is retained only for as long as required for the purposes above and mandatory legal obligations. Production retention periods must be approved before public launch.
6.2. Fixed-period automatic deletion of uploaded and generated images is not implemented in the current version. A User may submit a verified deletion request to the Controller's email address.
6.3. Payment and accounting records are retained for the period required by applicable law.
6.4. Retention and deletion procedures for technical logs and backups must be approved before public launch.
7. User rights
The User may request access, correction, restriction, or deletion of personal data, withdraw consent where applicable, and complain to the competent authority or a court.
The current version does not provide self-service account deletion. Requests must be sent to support@aaarch.ru. Subscription cancellation and account deletion are separate actions. Records required by law remain stored for the mandatory period.
8. Security
The Controller applies organizational and technical safeguards appropriate to the deployed infrastructure and applicable requirements. The final safeguard inventory, data locations, and processor register must be completed before public launch.
9. Cookies and local storage
The Service uses Better Auth cookies required for authentication and sessions. Their names, lifetime, and attributes depend on the deployed authentication configuration. The interface locale may be stored in PARAGLIDE_LOCALE; the visual theme is stored in browser localStorage.
Required cookies are used to operate authentication and sessions. Users may disable cookies in their browser, but parts of the Service may then stop working correctly. If the Service introduces optional cookies that require consent, they will not be set before that consent is obtained. The Service does not use these values for third-party advertising tracking.
10. Cross-border transfers
Cross-border processing depends on the OAuth, LLM/VLM, ComfyUI, billing, hosting, logging, and backup providers configured in production. Before public launch, the Controller must identify the relevant countries, recipients, data categories, purposes, legal grounds, and required procedures.
11. Changes
The Controller may update this Policy by giving at least seven calendar days' notice through the Site before the revision takes effect.
12. Contacts
| Controller | Общество с ограниченной ответственностью «ТРИАРХ» |
|---|---|
| OGRN | 1269100009485 |
| Tax ID | 9100005672 |
| KPP | 910001001 |
| Address | 295011, Республика Крым, г. Симферополь, ул. Караимская, д. 23 |
| support@aaarch.ru | |
| Site | https://app.aaarch.ru |