Privacy policy
Last updated: 28 August 2026
Argive (“we”, “us”) is an independent verification service for web apps, operated at argive.dev. This policy explains what we collect, why, and what we deliberately do not do. Questions: contact@argive.dev.
What we collect
- Your account, your email address and a password (stored only as a scrypt hash, never in plain text). Signed-in state lives in one essential cookie (
hm_session, 30 days). - The apps you register, their address, the flows and rules we draft for them, and the evidence: screenshots, short films, console and network logs of your app’s own pages. This evidence exists so you can see proof, and it is shown only to you unless you explicitly publish a report.
- Waitlist and contact, the email you give us, used only to write to you about Argive.
- Server logs, IP address and user agent, kept briefly for security and abuse prevention.
What we deliberately don’t do
- No ad trackers and no third-party analytics scripts. There is nothing on this site that reports your visit to anyone else.
- We never sell or share your data for marketing.
- We never hold your app’s passwords on the free tier. Attended audits mean you sign in yourself; credentials never pass through us. On a paid plan, session material for scheduled checking is stored encrypted so that it can only be read by the checking worker, is never placed in any AI prompt or log, and is deleted when you disconnect it.
- Your app’s end users are not our subject. Verification is designed to run against test and demo data. Do not point Argive at real personal data of your users; if evidence accidentally captures some, write to us and we will delete it.
Improving Argive
To make Argive better at catching real defects, we learn from the checks themselves, not from your content. When a verification runs, we may add de-identified, aggregated findings and technical metadata to our detection corpus: which checks fired and how often, structural facts about the page (security headers present or absent, control and layout measurements, whether a data endpoint answered without a login), and which builder the app was made on.
We never pool your screenshots, films, page text, database records, end-user data, app name, or address into this corpus. It is statistics about defects, not a copy of your app; it is never tied back to you and never published per app. You can turn this off for any app in its settings. The separate corpus of apps we do not own stays, as it always has been, anonymous statistics from public pages only.
Where your data lives
Our servers are hosted by Netcup GmbH (Germany, EU). Our sub-processors, each handling only what its role requires:
- Cloudflare, DNS and network security.
- Resend, email delivery, both what we send you and what you send us.
- OpenRouter, the gateway to the language models that read a change and judge whether it matters. It receives the page path, the name of the control, and what changed. It never receives your credentials, your session, or your evidence files.
- Lemon Squeezy, our merchant of record for paid plans. It handles your billing name, email and payment details; we never see or store a card number.
- Cloudflare R2, encrypted off-site backups.
The deterministic part of Argive, the walking, the pressing and the comparing, runs entirely on our own servers and sends nothing to a model.
Retention
Evidence follows a retention window: full media for recent checks, plus the last-working and first-breaking evidence per flow; older evidence is reduced to its written report. Account data is kept while your account exists. Ask us to delete your account and we delete it: your flows and rules, your evidence, and all.
Your rights
Under the GDPR and equivalent laws you can ask for access, correction, export, or deletion of your data, and you can complain to your local supervisory authority. Write to contact@argive.dev, a human answers.
Changes
When this policy changes in substance, we update the date above and, for material changes, tell you by email before they take effect.