Privacy policy
Last updated: 2026-10-07
Arkush is a tool for building visualizations and dashboards from data. This page describes what the installation at arkush.app stores about you, why it stores it, and what you can do about it.
The installation is run by Oleh Omelchenko. Contact with questions about this policy or about your data via [email protected].
Arkush is in beta
Arkush is a small service run by one person, with no uptime commitment. A dashboard saved here keeps opening in later versions of the software, and every upgrade keeps a copy of the database before it changes anything. Even so, export anything you would mind losing, because your export is the only copy kept outside this server. Please keep personal or otherwise sensitive data out of the dashboards you build here.
What we store about you
| What | Why | How long |
|---|---|---|
| Your email address | To identify you, to record which dashboards are yours, and to record who changed what | Until you ask us to delete your account |
| A sign-in code we email you, with the address you typed. We keep a scrambled form of the code, never the code itself | To check the code you type back | One hour at most |
| Passkeys you add. We keep the passkey's public key. Your fingerprint, face or PIN never leaves your device | To let your device sign you in again | Until you remove the passkey or delete your account |
| Dashboards you create, with the data shown on them | To show them to you | Until you move them to the trash, plus 30 days |
| Dashboards you publish | To show them to anyone who has the link | Until you unpublish them |
| Your username | To name you on the dashboards you publish, in place of your email address | Until you delete it or your account |
| Comments you write | To show them on the dashboard | Until you delete them. A deleted comment leaves a marker with your address |
| Files you upload | To build dashboards from them | Until you delete them |
| AI agents you connect | To let an agent you choose act for you | Until you disconnect the agent |
| Server logs | To run the service and look into faults | 30 days |
Server logs record each request, the result, and a code that stands for your account in place of your email address. They never record the contents of a dashboard, a query or a password. They are kept with Google Cloud Logging, as described under "Where your data lives".
We use all of this only to run the service. We do not sell it or use it for advertising, and we do not use it to train machine-learning models.
How we protect your data
Your connection to the service is encrypted, and so is the service's connection to Google.
The service checks who you are on every request. Only you can reach a dashboard you create, until you publish it.
Your Google sign-in, and any access to your Google data that you grant, stays between your browser and Google. Our server never receives it.
How you sign in
You can sign in with Google, with GitHub, or with a code we email you. We never ask for a password.
Signing in with Google gives us your email address and nothing else. Signing in with GitHub gives us the verified email addresses on your GitHub account. We use the first one to sign you in and keep only that one. If you sign in with a code, we send an eight-digit code to the address you type, and you type it back in the same browser within ten minutes.
After you sign in, you can add a passkey, so that next time your device signs you in with your fingerprint, face or PIN. You can remove a passkey at any time from the account menu.
Your Google account
Regardless of the sign-in method, you can also connect your Google account to read your own data. We ask for read-only access to BigQuery when you run a query, and for access to one sheet when you pick that sheet. Queries run between your browser and Google. The dashboard keeps the query and the rows it returned. The access you grant lasts about an hour and stays in your browser. You can disconnect in the same place you connected, or revoke arkush at myaccount.google.com/permissions.
Arkush's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
AI and machine learning
Arkush contains no AI model and calls no AI service. We do not use your data, including anything read from Google, to create, train or improve any machine-learning model, ours or anyone else's. We do not pass it to anyone else for that purpose either.
You can connect an AI agent of your own choosing over MCP, the standard that AI tools use to connect to other software. The agent acts as you. It can read and change the dashboards you can, and every change it makes is recorded under your account. What the agent does with what it reads is covered by your agreement with the company that runs it. Arkush itself sends nothing to any AI provider. You can disconnect an agent at any time.
Who can see your dashboards
- A dashboard you create is private to you until you publish it.
- If you publish a dashboard, anyone on the internet can read the published copy without an account. The next section describes what that copy holds.
- The person who runs this installation can technically read what is stored on the server. We read your dashboards only to look into a fault you report, to keep the service running, or when the law requires it.
- An AI agent you connect can read and change the dashboards you can.
Published dashboards
Publishing makes a frozen copy of your dashboard at its own address, and anyone can open it without an account. Each chart also gets its own page and a preview picture for when the link is shared. The copy holds the charts and the data they draw. It names you by your username, never by your email address, and it leaves out your comments and how its data was fetched. The copy changes only when you publish again.
Unpublishing deletes the copy from our server, and its address stops working. Moving the dashboard to the trash stops the address at once, but the copy stays on the server until the dashboard is unpublished. Write to us if you want it deleted sooner.
Published pages reach readers through Cloudflare's network, which keeps copies of each page's files close to its readers so that a busy page stays fast. After you unpublish, those copies can stay reachable at their exact addresses until we clear them from Cloudflare's cache. Write to us and we will clear them.
Deleting a dashboard
Deleting a dashboard moves it to the trash. It disappears at once for any connected agent. If it was published, its public address stops working too.
The dashboard stays in the Trash section of your library for 30 days, and you can restore it yourself during that time.
After 30 days we delete it completely. The dashboard, every stored version of it, the data saved with it, and its stored files are deleted together. Nobody can restore it from the service. A copy can remain in our backups until they are replaced, as described under "Where your data lives".
When you change a dashboard, the version you replaced is kept so that you can undo a mistake. Every change is kept for two days. After that we keep the dashboard as it stood at the end of each day, for 90 days, and then delete it. A dashboard's history is capped at 50 MB, and the oldest versions go first. A version holds the charts, the layout and the settings. The saved data is kept separately, as one copy per data source, and a refresh replaces it. Deleted files and deleted comments are removed straight away. A deleted comment leaves a marker showing that a comment was there and who wrote it, without its text.
Dashboards you keep only in your browser have no trash. Deleting one removes it at once, and we never had a copy.
Where your data lives
This installation runs on a server in Helsinki, Finland, rented from Hetzner Online GmbH, a German company. Everything you store here is on that server. Hetzner is our hosting provider and handles the data only on our instructions.
The service keeps copies of its own data on the same server: its two most recent daily copies, and one copy taken before each upgrade, which the next upgrade replaces. Something you delete can stay in these copies for up to two days, or until the next upgrade.
Every request to arkush.app passes through Cloudflare, Inc., which protects the site against attacks and keeps the cached copies of published pages described above. Cloudflare is our network provider and handles the traffic only on our instructions.
When you ask for a sign-in code, we send it through Resend, Inc., a US company, from its servers in Ireland. Resend receives your email address and the code, and nothing else. Resend is our email provider and handles the data only on our instructions.
Backups and server logs are kept with Google, a different provider from our host, so that losing one account cannot take both the service and its backups. A daily copy of the installation goes to Google Cloud Storage in Finland, is encrypted there, and is deleted after 90 days. Server logs go to Google Cloud Logging and are deleted after 30 days. Google is our backup and logging provider and handles the data only on our instructions.
Apart from these providers, arkush itself loads nothing from anyone else: no analytics, no error reporting, no web fonts and no advertising. The only scripts loaded from another site are Google's, and each one loads only when you use it: the sign-in library when you press Connect, and the file picker when you pick a sheet. A dashboard can show a picture from another website that its author added. Your browser then fetches the picture from that website, which sees your visit.
Cookies and browser storage
Arkush sets no tracking or advertising cookies. Signing in sets one session cookie, which keeps you signed in and does nothing else. The cookie lasts 30 days from your last visit and never more than 90 days from the moment you signed in, after which you sign in again. While you sign in or add a passkey, a short-lived cookie ties that step to your browser. It is deleted when the step finishes, or after ten minutes. Because these cookies are needed for the service to work, there is no cookie banner.
Your browser also keeps some arkush data in its own storage, and that data never leaves your browser: the dashboards you keep only in your browser, changes you have not saved yet, a few display settings, whether you said no to adding a passkey, and the last version of arkush we told you about, so that the note about a new version appears only once.
Your rights
Write to [email protected] if you want to:
- get a copy of what we hold about you
- correct something that is wrong
- delete your account and everything in it
- object to how we use your data
We answer within 30 days. You can also export any dashboard yourself at any time, from the dashboard itself.
When we delete your account, we delete your dashboards and every stored version of them, the data saved with them, your uploaded files, your comments, your published copies, your passkeys and your username.
If you are in the EU or the UK and believe we have mishandled your data, you can complain to your national data protection authority.
Changes to this policy
If we change this policy in a way that affects you, we will say so on this page and update the date at the top. This page always shows the current version.