arc.
Privacy Policy

Your Privacy, Explained

Last updated: May 2, 2025

1. About This Policy

This Privacy Policy describes how Arc ("the App", "we", "our") collects, uses, and safeguards information when you use our iOS application. By using Arc, you agree to the practices described in this document.

Arc is a fitness companion app that lets you turn your workout data into beautiful, shareable visuals. We designed the App from the ground up with privacy in mind: the most sensitive information you generate — your health data — never leaves your device.

2. Information We Collect

2.1 Account Information

When you create an account using Apple Sign In, we receive and store:

  • Display name — your first and last name, as provided by Apple.
  • Email address — used to identify your account. Apple may provide a private relay address if you choose to hide your real email.
  • Account identifier — a stable, unique ID issued by Apple and Supabase to identify your account across reinstalls.

We do not collect passwords; authentication is delegated entirely to Apple.

2.2 App Preferences

To sync your experience across reinstalls and devices, we store the following preferences on our servers:

  • Distance unit preference (miles or kilometres)
  • Widget favourites (which widgets you have pinned)
  • Display font preference

2.3 Purchase Information

If you purchase a Pro subscription or lifetime plan, we store:

  • Transaction ID and purchase date (from Apple's StoreKit)
  • Subscription product ID (weekly or lifetime)
  • Subscription status and expiry date

We do not collect or store your payment card details. All payment processing is handled directly by Apple.

2.4 Photos

The App accesses your photo library only when you explicitly choose to add a photo while creating a collage or when exporting a finished image to your camera roll. Photos are processed entirely on your device and are never uploaded to our servers.

3. Health & Fitness Data

Your health data never leaves your device. Arc reads data from Apple Health solely to render your workout widgets locally. This data is processed in memory and is never transmitted to our servers, any third party, or any external service.

With your explicit permission, Arc reads the following data from Apple HealthKit:

  • Workouts — type, duration, start and end time (Pilates, Running, Walking, and others)
  • Distance — total distance covered during running and walking workouts
  • Calories burned — active energy expended during workouts
  • Heart rate — average, minimum, and maximum heart rate during workouts
  • Running pace & speed — for pace charts and pace-per-kilometre/mile displays
  • Step count — daily steps and workout-specific step totals
  • Elevation — ascent data recorded during outdoor runs
  • VO₂ Max — cardiorespiratory fitness estimate from Apple Health
  • Activity rings — Move, Exercise, and Stand data (Move ring calories, exercise minutes, stand hours)
  • Workout route — GPS presence detection only (used to determine whether route-based widgets are available; the GPS coordinates themselves are never stored or transmitted)

Arc does not write any data to Apple Health.

You can revoke Arc's access to Apple Health at any time in Settings → Privacy & Security → Health → Arc on your iPhone.

4. How We Use Your Information

We use the information we collect solely to operate and improve Arc:

  • To provide the App's core features — rendering workout widgets, creating collages, and exporting shareable images.
  • To manage your account — creating and authenticating your account, and restoring your preferences after reinstallation.
  • To fulfil your purchases — verifying Pro subscriptions and lifetime purchases, and maintaining your entitlements.
  • To sync your preferences — restoring your widget favourites, distance unit, and other settings when you reinstall or sign in on a new device.
  • To prevent fraud — verifying that in-app purchases are legitimate using Apple's StoreKit cryptographic receipts.

We do not use your information for advertising, profiling, or sale to third parties.

5. Third-Party Services

Arc relies on a small number of carefully selected third-party services. Each receives only the minimum data necessary to fulfil its function.

Supabase

We use Supabase as our backend infrastructure for user authentication and database storage. Supabase receives your account information (name, email, account ID) and your app preferences. Supabase is subject to its own Privacy Policy. Data is protected with industry-standard encryption in transit and at rest, and row-level security policies ensure that only your data is accessible to your account.

RevenueCat

We use RevenueCat to manage in-app subscriptions and verify purchase entitlements. RevenueCat receives your account identifier and purchase transaction data from Apple's StoreKit. RevenueCat is subject to its own Privacy Policy. No health data, photos, or personally identifiable information beyond account ID and purchase history are shared with RevenueCat.

Apple

Arc is built on Apple's platforms and uses the following Apple services: Apple Sign In (authentication), HealthKit (health data access, on-device only), StoreKit (payments), and the iOS photo library APIs. Apple's handling of your data is governed by Apple's Privacy Policy.

No Analytics or Tracking

Arc does not integrate any analytics SDK (such as Firebase Analytics, Mixpanel, Amplitude, or Segment), advertising network, or crash reporting service that transmits data externally. We collect no behavioural telemetry, session recordings, or usage analytics.

6. Data Sharing & Disclosure

We do not sell, rent, or trade your personal information. We may disclose information only in the following limited circumstances:

  • Service providers — as described in Section 5, we share data with Supabase and RevenueCat solely to operate the App.
  • Legal requirements — if required by applicable law, court order, or governmental authority.
  • Protection of rights — to protect the rights, property, or safety of Arc, its users, or the public.
  • Business transfer — in the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.

7. Data Retention

On-Device Data

Health data is fetched from Apple Health in real time and held in memory only for the duration of your session. It is never cached to disk by Arc. Your account preferences are stored in the iOS UserDefaults system and are cleared when you delete your account or uninstall the App.

Server-Side Data

Your account information, preferences, and subscription records are retained on our servers for as long as your account is active. When you delete your account (via Settings → Delete Account in the App), all of your data is permanently and irreversibly deleted from our servers, including your profile, preferences, and subscription records.

RevenueCat

Purchase history retained by RevenueCat is subject to RevenueCat's own data retention policies, which may apply independently of your Arc account deletion.

8. Your Rights & Controls

You have the following rights and controls over your data:

  • Access — you can view the information stored in your account at any time within the App.
  • Correction — you can update your display name in the App's Settings.
  • Deletion — you can permanently delete your account and all associated data by tapping Delete Account in Settings. This action is irreversible.
  • Health access revocation — you can revoke Arc's access to Apple Health at any time in your iPhone's Settings without deleting your account.
  • Photo access revocation — you can revoke photo library access in Settings → Privacy & Security → Photos → Arc.
  • Subscription management — you can cancel a recurring subscription at any time through your Apple ID settings at Settings → [Your Name] → Subscriptions.

To exercise any of these rights or to make a data-related enquiry, contact us at info@nocap.bio.

9. Data Security

We take reasonable technical and organisational measures to protect your information:

  • All communication between Arc and our servers is encrypted using HTTPS/TLS.
  • Authentication tokens are stored in the iOS Keychain, the most secure on-device storage available.
  • Our Supabase database uses row-level security policies so that each user can only access their own data.
  • Apple Sign In uses a cryptographic nonce to prevent replay attacks.
  • In-app purchases are verified using Apple's cryptographically signed StoreKit 2 JWS tokens.

No system is completely secure. In the event of a data breach that affects your personal information, we will notify affected users as required by applicable law.

10. Children's Privacy

Arc is not directed at children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at info@nocap.bio and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the App. Continued use of Arc after changes are posted constitutes your acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:

Arc Support
info@nocap.bio

We aim to respond to all privacy enquiries within 5 business days.