RapidArch

Privacy Policy

Last updated on September 1, 2026

Last reviewed on May 16, 2026

This privacy notice describes how RapidArch(“RapidArch,” “we,” “us,” or “our”) collects, uses, and shares your information when you use the website at rapidarch.com or the editor at /editor (together, the “Services”).

If you do not agree with our practices, please do not use the Services. Questions can be sent to info@rapidarch.com.

1. What We Collect

The information we collect depends on how you interact with the Services.

Information you provide

When you submit the signup form on the landing page, we collect the email address you enter. We do not collect names, payment information, or any other personal information during pre-launch.

Information collected automatically

Some information is collected automatically when you visit the Services, including your Internet Protocol (IP) address, browser type, operating system, referring URL, pages viewed, and approximate location derived from your IP. This information is used for security, debugging, and aggregate usage analytics.

Information we do not collect

The editor runs in your browser. Patient files (STLs, scans), pipeline outputs, and any derived restorations are processed on your device. Outside of the remote-support situations described in the next section, RapidArch staff do not view, open, or copy the contents of your cases, and our analytics never receive the geometry of your files.

Remote support (RapidHelp)

When you ask for help from inside the editor, you choose exactly what a support technician may access. Each of the following is off unless you turn it on for that request, is recorded in an audit log together with the wording you agreed to, and can be withdrawn at any time with one click:

  • Screen share. You may share your RapidArchbrowser tab with the technician who accepts your request. Sharing starts only when you start it yourself after the technician connects — never automatically. On Chrome and Edge only that tab can be shared: if you pick a window or your screen, we stop the share and ask you for the tab instead. On browsers that cannot limit a share to a single tab, we tell you what would be visible and ask you to confirm before a window or your whole screen is shared; those shares are recorded in the audit log, and the technician can never be given control during them. If you separately allow it, the technician can move the pointer inside the editor; that control is limited to the editor, pauses when you move your own mouse, and ends when you press Escape twice or stop sharing. We do not record the shared video.
  • Case access on our servers. You may allow the technician to open the files of the one case you asked about from your RapidArch storage. That access is read-only, is limited to the technician who accepted your request, expires automatically (four hours by default, at most twenty-four), ends when the ticket is resolved or you revoke it, and every file opened is logged. A copy of the case as it stood when you asked for help may be kept for up to ninety (90) days for troubleshooting and then deleted.
  • Your description of the problem. The note you type when requesting help, any chat with the technician, and an optional phone number and time zone are stored with the ticket and shown only to support staff who sign in. Please do not include patient names or other patient identifiers in these fields.
  • Connection relay. Screen sharing uses browser-native, end-to-end encrypted WebRTC. When a direct connection between you and the technician is not possible, the encrypted stream is relayed through a TURN server operated by our infrastructure provider. The relay forwards ciphertext only; neither the relay operator nor RapidArch’s servers can view the shared screen, and relay credentials are issued per request and expire within hours.

2. How We Use Information

We process your information to:

  • Send you a one-time notification when RapidArch launches, and occasional product updates you can unsubscribe from at any time;
  • Operate, secure, and improve the Services, including diagnosing errors and detecting abuse;
  • Comply with applicable legal obligations and respond to lawful requests from public authorities.

If you are located in the European Economic Area, United Kingdom, or Switzerland, we rely on the following legal bases: your consent (when you submit your email), our legitimate interest in operating and improving the Services, and compliance with our legal obligations.

4. Who We Share Information With

We share information only with the service providers we use to operate the Services, each under a written agreement that requires them to protect it:

  • Hosting: Vercel (serves the website and editor).
  • Database: Neon (stores the email list).
  • Analytics: PostHog (product analytics and session replay). Replays capture how the editor interface is used — clicks, navigation, and the page layout — so we can diagnose problems. Text you type into any field is masked before it leaves your browser, as are the patient and case names shown in the editor and in your case list; other pages that list your patients by name are not masked in this way, so replays are handled as confidential. The geometry of your files is never captured, and recording is paused entirely while a technician views your case. Replays are viewable only by RapidArch staff who sign in to PostHog and may be linked from a support ticket to help resolve it.
  • Screen-share relay: Cloudflare (TURN relay for remote-support connections that cannot connect directly; carries encrypted media only, as described in “Remote support” above).

We do not sell personal information. We may disclose information when required by law, to enforce these terms, or in connection with a corporate transaction such as a merger, financing, or sale of assets, provided the recipient is bound by terms no less protective than this policy.

5. Cookies and Tracking

We use a small number of first-party cookies for PostHog analytics and session replay (see “Who We Share Information With” for what replays contain and how they are masked). We do not use third-party advertising trackers, retargeting pixels, or social-network embeds that set cross-site cookies.

6. Data Retention

We retain your email address for as long as you remain subscribed, or until you request deletion. Server logs are retained for up to thirty (30) days for security and debugging.

7. Your Rights

Depending on where you live, you may have rights to access, correct, delete, or export the personal information we hold about you, or to object to or restrict certain processing. To exercise any of these rights, email info@rapidarch.com; we will respond within thirty (30) days. If you are located in the European Economic Area or United Kingdom, you have the right to lodge a complaint with your local data protection authority.

8. Security

We use reasonable administrative, technical, and physical measures designed to protect personal information from unauthorized access, disclosure, alteration, or destruction. No method of transmission over the Internet is one hundred percent (100%) secure, and we cannot guarantee absolute security.

9. Children

The Services are not directed to children under sixteen (16) years of age, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.

10. International Transfers

We are based in the United States. If you access the Services from outside the United States, your information will be transferred to and processed in the United States, which may have different data protection rules than your jurisdiction.

11. Changes to This Policy

We may update this policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, notified to subscribers by email. Continued use of the Services after the changes take effect constitutes acceptance.

12. Contact

Questions, requests, or complaints can be sent to info@rapidarch.com.