ARC AGENT← Back to Arc
THE DETAILS, IN PLAIN SIGHT

Privacy Policy

How Arc handles your account, your work and your personal information.

Version 5 October 2026United Kingdom
Contact details are being finalised. Arc’s dedicated contact email will be published here before commercial launch.
ON THIS PAGEWho is responsibleInformation Arc processesWhy we use itServices that receive informationWhere information is processedStorage and retentionYour choices and rightsChildren and sensitive informationChanges to this policyPrepare a request
01

Who is responsible

Arc is operated by Micah Ojo, based in the United Kingdom. Micah Ojo is the controller of personal information processed to operate Arc.

Privacy and support email: [to be added]. A dedicated contact address is being set up. Until it is published, the request form below lets you prepare and save a request, but does not send it.

02

Information Arc processes

  • Account information: your email address, chosen username, account identifier, authentication state and signup acknowledgements. Email passwords are handled by Supabase Auth. If you use Google, Google and Supabase provide account identity information such as your email address, name and profile image; Arc does not receive your Google password.
  • Your work: prompts, messages, attachments you submit, generated code and animations, saved conversations and memories. Connected Studio tools can submit relevant project hierarchy, properties and script contents needed for your request.
  • Operation and diagnostics: task progress, tool results, errors, connection/device identifiers, settings and diagnostic reports. Reports can contain messages, script artifacts and project details. Review reports before sharing them.
  • Usage and entitlement records: model usage, credits, plan entitlement and metering records used to provide access and calculate usage. Any future payment checkout must identify its payment processor and terms before you buy.
  • Technical information: service providers may process IP addresses, browser/device information and security logs when serving and protecting Arc.
03

Why we use it

PurposeUK data protection basis
Create accounts, authenticate you, provide chat, animation and connected Studio featuresPerformance of our contract with you
Measure usage and administer access, credits and account requestsContract; legal obligation where applicable
Protect accounts, investigate abuse and troubleshoot errorsLegitimate interests in a reliable, secure service, balanced against your rights
Keep records required by law and respond to lawful requestsLegal obligation
Optional features that require separate permission, if introducedConsent, requested separately and withdrawable

Accepting the Terms is agreement to the service contract. Acknowledging this policy is not blanket consent to marketing, tracking or every use of your data.

04

Services that receive information

Supabase provides account authentication and profile/account infrastructure. Cloudflare hosts the public website, Arc Cloud gateway and cloud conversation/task storage. Google provides the optional Google sign-in service.

When you request AI work through Arc Cloud, relevant prompt and project context is sent to the provider selected for that request, such as DeepSeek, Google Vertex AI or Pareto. Supported custom-provider connections use the endpoint you configure. Provider processing, retention and any use for model improvement depend on that provider and your account arrangements. Do not submit secrets or data you are not authorised to share.

Arc's pages load some public assets from services including Google Fonts and jsDelivr. Those services receive ordinary connection information when your browser requests an asset. Information may also be disclosed where legally required or necessary to protect rights and security.

05

Where information is processed

Arc's current Supabase project is hosted in the EU West region. Cloudflare and AI/authentication providers may process information internationally, including outside the UK. Applicable contractual and transfer safeguards must be used where required; the location of one database does not mean all processing stays in that region.

06

Storage and retention

Your browser and desktop app store session credentials and preferences to keep you signed in and remember settings. Signing out clears the local session; it does not delete your cloud account or work. Public pages do not currently implement advertising trackers or optional analytics cookies.

Account/profile records are kept while the account is needed. Saved cloud conversations, generated animation versions and memories remain available until removed or displaced by service storage limits; current limits retain up to 50 conversations and 200 memories per account. Local desktop and Studio history/diagnostics may remain on your device separately.

Security, support and usage records may be retained while needed to investigate issues, settle usage or meet legal obligations. Backup and provider-held copies may persist for their applicable retention periods. There is no single automatic deletion period covering every record; a deletion request must be assessed across the systems concerned. We do not promise immediate removal from every backup.

07

Your choices and rights

Depending on the circumstances, you can request access, correction, erasure, restriction, portability or object to processing based on legitimate interests. You can withdraw consent for a consent-based feature without affecting prior lawful processing. We may need proportionate proof of identity to protect your account.

You can delete individual cloud conversations or memories using the available account controls. Those controls are distinct from deleting your account or local files. Prepare an account/privacy request below. We aim to respond within the applicable legal time limit, normally one month, subject to permitted extensions.

You can complain to the Information Commissioner's Office (ICO) or your local regulator. You do not have to contact us first to use that right.

08

Children and sensitive information

Arc is intended for people aged 13 or older. If you are below the age needed to enter a contract in your location, a parent or guardian must authorise your use. Where valid parental permission is required by law for a particular feature, that feature must not be used without it.

Do not submit passwords, private keys, medical information, financial account details or other sensitive personal information in chat or diagnostics. Contact the operator if you believe a child has provided information that should not be held.

09

Changes to this policy

This policy describes the current service. We will update it when data practices change and communicate material changes through the service or an appropriate account channel. The version date identifies the policy presented at signup.

10

Prepare a privacy request

This form prepares a text file for you to send when Arc's contact email is published. It does not submit or store your request on a server. Do not include passwords or sensitive project content.

© 2026 Arc
Privacy PolicyTerms & ConditionsHome