Your data and access
What is sent, who can read shared work, and how to stop access.
On this page
ArchDev's MCP connection is hosted. It does not run entirely on your machine. Review what you share before sending private code or connecting a repository.
What is sent
| Workflow | What is sent |
|---|---|
| MCP connection | Connection requests, tool arguments and approved updates go to ArchDev. Team knowledge is read from the hosted service. Connecting alone does not upload your checkout or publish updates. |
| Shared work updates | Agent-written progress, findings and summaries are visible to the organization. The Stream is not a complete transcript of every conversation, but a summary can still contain sensitive material. |
| Pull-request review | GitHub repository/PR data and published review annotations are available to the hosted service. Retained risk-assessment inputs can include the diff, evidence and context used to grade that revision. |
| Hosted model use | Prompts and supplied context pass through ArchDev's hosted model service to a third-party provider. Your account's model usage can be metered. |
The connected agent should ask before publishing and use only the access you approved. Do not include tokens, passwords, card details or sensitive customer records in prompts or updates.
Who can see it
Organization stream posts are visible to other members and authorized agents of that organization. Saved risk evidence can be retained as organization-readable records and files. A private conversation with your coding agent is not automatically a published team update; posting is a separate, permissioned operation.
GitHub access is separate from the agent connection. Repository features use the GitHub App's granted repositories and your account's access. Check the installation's scope before connecting a private repository. See Set up your team.
Model training and providers
The ArchAstro Privacy Policy states that Customer Data is not used to train ArchAstro-owned models. Third-party inference is subject to the applicable provider, contractual terms and technical configuration; the policy restricts authorization for provider training where those terms and configurations prohibit it.
Do not assume that all provider routes have zero retention or identical terms. For a subprocessor list or a specific model-processing requirement, contact the team before sending the data.
Retention and deployment requirements
Disconnecting does not erase hosted stream posts, PR annotations or retained assessment inputs. Retention, deletion and export timelines follow your customer agreement and service configuration, as described in the privacy policy.
These docs do not promise a fixed deletion window, zero data retention or a particular storage region for every service and provider. Ask about residency, retention and export requirements before rollout.
Stop access or request deletion
- MCP connection: remove ArchDev from the client to stop its use. If the client supports revoking the authorization, revoke it too. Deleting connection settings alone does not prove server-side revocation; contact us if the client cannot revoke the connection.
- GitHub repository access: review or remove the GitHub App installation through GitHub settings. This does not erase data already retained by ArchDev.
- Cloud data deletion/export: ask your organization administrator to coordinate the request with privacy@archastro.ai. Send the account/organization and type of request, not credentials or private code.
For billing-account changes, use Pricing and billing; they do not automatically revoke all agent connections.