Arc is run by Vadym Prysiazhnenko, acting as an individual ("we"). This policy describes exactly what the app collects, who it goes to, and how to get it back or deleted. It describes what the app actually does today — not what it might do later.
1. What we collect
- Account: your name, email address and avatar, received from Google when you sign in. Arc has no password of its own.
- Profile: gender, age, height, weight, fitness level, goal, available equipment, training days, and any health notes you enter.
- Activity: workouts and the sets, reps and weights in them; food and water logs; body measurements; daily and weekly check-ins; readiness answers.
- AI memory (optional, Premium): injuries, food intolerances and preferences, training preferences, and free-text notes you choose to give Ask Arc. Off unless you turn it on.
- Friends: if you connect with someone, the progress you explicitly choose to share becomes visible to them.
- Membership: your Patreon account ID and the amount you pledge. Card numbers never reach Arc — Patreon handles payment entirely.
- Voice: if you dictate instead of typing, only the recognised text reaches us — the audio is handled by your browser and never arrives at Arc.
- Technical: a salted, irreversible hash of your IP address, used only to rate-limit AI requests. The IP itself is never stored.
We do not run analytics. There is no PostHog, no Google Analytics, no advertising or tracking pixel of any kind, and no third-party cookies.
2. Health data
Weight, body measurements, injuries, menstrual cycle data and health notes are special category data under GDPR Article 9. We process them only on the basis of your explicit consent, which you give by ticking the consent box at the end of onboarding — before any of it is saved. We record when you gave it. You can withdraw consent at any time by deleting your account, which erases this data immediately and irreversibly.
3. Legal basis
- Performance of a contract (Art. 6(1)(b)) — running your account and the features you use.
- Consent (Art. 6(1)(a), and Art. 9(2)(a) for health data) — AI memory and health data.
- Legitimate interests (Art. 6(1)(f)) — keeping the service up and preventing abuse, such as rate-limiting AI requests.
4. How we use it
To calculate your readiness score, assign and adapt training plans, set nutrition targets, and generate AI responses. We do not sell your data, we do not share it for advertising, and we do not profile you for any purpose other than producing the guidance the app exists to give.
5. AI processing
When you use Ask Arc, the Morning Brief, AI meal plans, diet analysis or the weekly review, relevant profile and activity context is sent to an AI provider to generate a response. The primary provider is Google (Gemini); Groq is used as a fallback when the primary is unavailable. If AI memory is on, the notes you added are included in that context. You can turn AI memory off at any time in Settings → Arc AI.
If you leave scientific sources enabled, your question is also sent to Europe PMC to search published literature. You can turn that off per question.
6. Voice input and speech
Ask Arc lets you dictate a question instead of typing it, and can read the answer back aloud. Both are done by the speech engine built into your browser, not by us: Arc has no audio backend, and no recording ever reaches our server. In Chrome and Edge the audio from your microphone goes to Google's speech servers; in Safari, to Apple's. We say so plainly even though it is your browser that makes the transfer, because what matters to you is where your voice goes, not whose code sends it.
- Only the recognised text reaches Arc. It is saved in the same conversation as anything you type — and nothing beyond that. The audio itself is stored nowhere: not on our server, not in your browser.
- Your voice is processed to turn speech into text, not to work out who is speaking. We build no voiceprint and cannot identify you by your voice, so this is not biometric data under GDPR Article 9. What you dictate, on the other hand, may well be health data — see below.
- Dictating is easier than typing, so injuries, weight, medication and how you feel come up more often. That is health data, and the same explicit consent covers it as covers the rest: saying it out loud instead of typing it changes nothing about how it is handled.
- In conversation mode the microphone listens to the room, not only to you. If other people are nearby, their voices can be captured and sent for recognition along with yours — and they have agreed to nothing. Use voice where you would be comfortable taking a phone call.
- The answer is read out by the voices installed on your device. Some of them work entirely offline; others are network voices, and then the text being spoken goes to the supplier of that voice — the maker of your operating system or browser. Which one you get is decided by your system, not by us.
- Safeguards in the app: the microphone switches itself off after eight seconds of silence, a single dictation is capped at two minutes, and the microphone and the speaker never run at the same time.
Voice is entirely optional. Everything works from the keyboard, the microphone turns on only when you tap it yourself, and you can withdraw the microphone permission at any time in your browser's site settings.
7. Who else receives data
- Supabase — database and authentication. Hosted in the EU (Frankfurt).
- Google — sign-in, and Gemini for AI responses.
- Google or Apple — speech recognition and network voices inside your browser, if you use voice input or have answers read aloud. Which of the two depends on your browser, not on Arc.
- Groq — fallback AI provider.
- Patreon — membership and payment processing.
- Open Food Facts — food catalogue and product images.
- UPCitemdb — fallback barcode lookup.
- Europe PMC — scientific literature search, when sources are enabled.
- YouTube (no-cookie mode) — exercise technique videos.
8. Transfers outside the EU
The database is in the EU. Google, Groq, Patreon and UPCitemdb are in the United States, so using AI features, signing in or subscribing transfers data there. Those transfers rely on the providers' Standard Contractual Clauses and, where applicable, their EU-US Data Privacy Framework certification. Voice is a separate case: when you dictate, or have an answer read aloud by a network voice, it is your browser that sends the audio or the text to Google or Apple in the United States. That transfer happens under the terms between you and the maker of your browser or operating system — we are not a party to it and have no agreement covering it.
9. How long we keep it
Your data is kept for as long as your account exists. Deleting your account removes your profile, logs, measurements, check-ins, AI memory and membership link immediately and irreversibly — there is no grace period and no backup we can restore it from. AI providers may retain request data briefly under their own policies; we do not control that.
10. Your rights
You can access and correct your data in the app, export all of it as JSON (Settings → Export JSON), and delete it entirely (Settings → Delete data and account). You may also object to processing or withdraw consent — for AI memory, by switching it off. If you are in the EEA or UK, you can complain to your national data protection authority; in Ukraine, to the Ombudsman's office.
11. Cookies and local storage
Arc sets no tracking cookies. Your login session and a handful of preferences (theme, language, dismissed hints) live in your browser's local storage. Clearing site data signs you out and resets those preferences.
12. Children
Arc is not intended for anyone under 16. We do not knowingly collect data from children. If you believe a child has given us data, write to us and we will delete it. Voice input raises the stakes here rather than lowering them: in conversation mode the microphone picks up whoever is in the room, so do not use it where children are speaking.
13. Changes
If this policy changes in a way that affects you, we will say so in the app before the change takes effect.
14. Contact
Privacy questions and requests: support@arcculture.app.