ARCHPATTERNS · DECISION REGISTRY

Privacy · Decision Registry

Back to the registry

This notice covers app.archpatterns.io and the operator console at admin.archpatterns.io. The free tool at archpatterns.io is unchanged and separate: no account, and wizard answers never leave your browser. Its own notice covers that site, including the advertising it carries. There is no advertising and no analytics of any kind on this service.

What is stored, and why

Your email address, to send sign-in codes and identify your account. Never shared, never used for marketing, never sold.

A display name, if you choose to set one, and a two-factor secret, so your authenticator app and this service can agree on a code. The secret is generated inside this service and is never sent anywhere else.

Any passkey you register: its identifier, its public key, the name you gave it and when it was last used. A public key is safe to hold, the private half never leaves your device, and a passkey identifies your device to this service rather than identifying you to anyone else.

The decisions you explicitly save: a label you write, the answer encoding from the results link you paste, the engine version, timestamps, and the status you record. Nothing about your use of the free tool reaches this service unless you paste it here yourself.

Your IP address, with each sign-in code, for the sole purpose of rate limiting, so that neither your address nor anyone else's can be used to flood the service with codes. It is discarded with the code record.

An activity record, held to keep the service accountable and to investigate abuse: the account concerned and what happened, namely registration, sign-in, two-factor enrolment, email change, account deletion, any operator action, and unsuccessful attempts, meaning a wrong emailed code, a wrong authenticator code, or an attempt from a suppressed address. Each row is chained to the one before it so that an edited or deleted row is detectable, and some of these events cause an alert email to the operator so that abuse is noticed rather than discovered later. The operator console reads this record; nobody else can.

How long each thing is kept

Sign-in codes expire after ten minutes and are purged daily. Sessions last up to thirty days and are deleted when you sign out, change your email or delete your account. Activity records are deleted after one hundred and eighty days. Your account and decisions are kept until you delete them, which takes effect immediately. Deleted data may persist briefly in Cloudflare's point-in-time database recovery, which covers a rolling thirty days. The operator may also keep one encrypted backup copy outside the hosting account, so that losing that account does not lose the service; only the most recent copy is kept, earlier copies are destroyed when it is taken, and a deletion is applied to it at the next backup, which is at most thirty days later.

Account recovery

Recovery codes issued when you enrol are stored only as keyed hashes, so a copy of the database yields no working codes; the codes themselves exist only where you saved them. If you start a waiting-period reset, the request is held with your address, the time it was made, the address it was requested from and a single-use cancellation token, and it is deleted when the reset completes, is cancelled, or lapses. Every reset, every use of a recovery code and every cancellation is written to the activity record, and this address is emailed at each step, because a recovery path that operates silently is a recovery path for whoever else has your mailbox.

If an account is removed for abuse

An account used abusively may be closed by the operator, and its address kept on a suppression list with the reason and the date so that it cannot be used to register again. That list holds nothing but the address, the reason and the date, is never used for any other purpose, and is the one case in which an address survives the deletion of an account. The lawful basis is the operator's legitimate interest in keeping the service usable. If you believe an address was listed in error, say so through the contact page and it will be reviewed.

Your rights and controls

Every right is self-service in the Account section, without asking anyone: access and portability (Export my data downloads everything held about you as JSON), rectification (display name directly; an email change is verified by a code sent to the new address, and the old address is notified), and erasure (Delete account removes the account and every decision at once). Restriction and objection are available on request via the contact page, though for a service that holds this little, erasure is usually the faster remedy. There is no profiling and no automated decision-making about you; the engine decides about architectures, not about people. The lawful basis is performance of the service you asked for. Any request made by email is answered within thirty days.

Who processes it, and where

The operator, and two processors. Cloudflare runs the service and the database, with the database created in the European Union. Resend delivers the sign-in code emails, sending through Amazon Simple Email Service in the Ireland region. Both may process data outside the European Economic Area in the course of operating global infrastructure, under the safeguards in their own data processing terms, including standard contractual clauses. There are no other recipients.

If something goes wrong

A personal data breach affecting this service will be reported to the President of the Personal Data Protection Office (UODO) within seventy-two hours of the operator becoming aware of it, and to you directly, by email to the address on your account, where the risk to you is high. Incidents are recorded in the project's incident log.

Cookies

Only strictly necessary cookies, each serving a function you have requested, which is why no consent banner appears: aps_session (keeps you signed in; up to thirty days), aps_mfa (carries the sign-in between your emailed code and your authenticator code), aps_dev (only if you tick "Remember this device"; thirty days), aps_save (carries a decision link you brought from the main site through sign-in; about fifteen minutes, deleted on delivery), and aps_adm (operator only; holds the elevated console session for fifteen minutes), and aps_rc (carries newly issued recovery codes to the page that shows them once, for a few minutes, then deleted). All are scoped to archpatterns.io so one sign-in serves the registry and the console. There is no advertising, no analytics and no tracking cookie of any kind here. If your browser blocks cookies entirely, sign-in cannot work, because there would be no way to keep you signed in; the sign-in page says so.

Who is responsible

The controller is W Khan, an individual based in Poland, trading as ArchPatterns, reachable via the contact page. There is no data protection officer, because the scale and nature of this processing does not require one. You may complain to the President of the Personal Data Protection Office (UODO) in Poland, or to the supervisory authority for your own country.

Accessibility

The accessibility statement covers this service as well as the main site.