Arlong ("we," "us," or "our") operates Arlong.org (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our Service. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the Service.
We may collect the following types of information:
We collect this information when you voluntarily provide it to us, when you use our Service, or through automated technologies.
Our public search API is designed to be privacy-respecting. To protect the Service from abuse and to operate fairly, we retain the following limited data:
For signed-in accounts that have Product Analytics enabled, we record a minimal event when an Arlong feature is used. The event contains your internal account identifier, the feature category (for example, web search, AI chat, support, dashboard, API, or MCP), a success or failure status, and a timestamp.
What this does not include: product analytics does not store your search queries, AI prompts or replies, links, page content, IP address, browser details, API key value, or session-replay data. We use these limited events to understand feature adoption, improve reliability, plan product work, and investigate service misuse. Access is restricted to authorised Arlong administrators.
You can turn Product Analytics off at any time in Settings. Turning it off stops future non-essential product-analytics events for your account; it does not affect security, payment, or abuse-prevention records that are necessary to operate the Service.
Dodo Payments processes subscription checkout, payment methods, taxes, invoices, refunds, and recurring charges. Arlong does not receive complete card or bank details. We store the Dodo customer and subscription identifiers, selected plan, subscription state, billing-period dates, webhook event identifiers, and period usage counters needed to provide paid allowances and prevent duplicate event processing.
All search queries on arlong are encrypted client-side using AES-256-GCM before being sent to our servers. This means:
This encryption is applied on top of HTTPS transport encryption, providing defense-in-depth protection for your search privacy. Your queries remain encrypted end-to-end between your browser and our search engine.
We may use the information we collect for various purposes, including to:
We may use third-party service providers to monitor and analyze the use of our Service, process payments, or assist with other business functions.
We offer social login options. When you log in via a social platform, we may receive profile information as permitted by your social account settings.
We use cookies and similar tracking technologies to track activity on our Service and hold certain information. Cookies are files with a small amount of data which may include an anonymous unique identifier.
You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.
We will retain your personal information only for as long as is necessary for the purposes set out in this Privacy Policy. Product-analytics events are automatically deleted after 90 days. We will retain and use other information only to the extent necessary to comply with our legal obligations, resolve disputes, enforce our policies, and operate the Service.
The security of your data is important to us, but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
To further protect your search privacy, arlong encrypts all search queries client-side using AES-256-GCM before transmission. This means your search terms are encrypted on your device and never travel in plaintext, even over the network. Combined with HTTPS transport encryption, your search activity is protected by multiple layers of encryption.
If you are a resident of the European Economic Area (EEA), you have certain data protection rights under the General Data Protection Regulation (GDPR). Arlong aims to take reasonable steps to allow you to correct, amend, delete, or limit the use of your personal data.
You have the following rights:
If you wish to exercise any of these rights, please contact us at ahilan290@gmail.com. We will respond to your request within 30 days.
If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA).
You have the right to:
To exercise your rights, contact us at ahilan290@gmail.com. We will verify your identity before processing your request and respond within 45 days.
In accordance with the California Online Privacy Protection Act (CalOPPA), we agree to the following:
We honor Do Not Track signals and do not track, plant cookies, or use advertising when a Do Not Track browser mechanism is in place.
Our Service does not address anyone under the age of 13 ("Children"). We do not knowingly collect personally identifiable information from anyone under the age of 13. If you are a parent or guardian and you are aware that your child has provided us with personal data, please contact us at ahilan290@gmail.com. If we become aware that we have collected personal data from children without verification of parental consent, we take steps to remove that information from our servers.
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date.
You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
If you have any questions about this Privacy Policy, please contact us: