Contents
1. About This Policy
This Privacy Policy describes how Arc ("the App", "we", "our") collects, uses, and safeguards information when you use our iOS application. By using Arc, you agree to the practices described in this document.
Arc is a fitness companion app that lets you turn your workout data into beautiful, shareable visuals. We designed the App from the ground up with privacy in mind: the most sensitive information you generate — your health data — never leaves your device.
2. Information We Collect
2.1 Account Information
When you create an account using Apple Sign In, we receive and store:
- Display name — your first and last name, as provided by Apple.
- Email address — used to identify your account. Apple may provide a private relay address if you choose to hide your real email.
- Account identifier — a stable, unique ID issued by Apple and Supabase to identify your account across reinstalls.
We do not collect passwords; authentication is delegated entirely to Apple.
2.2 App Preferences
To sync your experience across reinstalls and devices, we store the following preferences on our servers:
- Distance unit preference (miles or kilometres)
- Widget favourites (which widgets you have pinned)
- Display font preference
2.3 Purchase Information
If you purchase a Pro subscription or lifetime plan, we store:
- Transaction ID and purchase date (from Apple's StoreKit)
- Subscription product ID (weekly or lifetime)
- Subscription status and expiry date
We do not collect or store your payment card details. All payment processing is handled directly by Apple.
2.4 Photos
The App accesses your photo library only when you explicitly choose to add a photo while creating a collage or when exporting a finished image to your camera roll. Photos are processed entirely on your device and are never uploaded to our servers.
3. Health & Fitness Data
With your explicit permission, Arc reads the following data from Apple HealthKit:
- Workouts — type, duration, start and end time (Pilates, Running, Walking, and others)
- Distance — total distance covered during running and walking workouts
- Calories burned — active energy expended during workouts
- Heart rate — average, minimum, and maximum heart rate during workouts
- Running pace & speed — for pace charts and pace-per-kilometre/mile displays
- Step count — daily steps and workout-specific step totals
- Elevation — ascent data recorded during outdoor runs
- VO₂ Max — cardiorespiratory fitness estimate from Apple Health
- Activity rings — Move, Exercise, and Stand data (Move ring calories, exercise minutes, stand hours)
- Workout route — GPS presence detection only (used to determine whether route-based widgets are available; the GPS coordinates themselves are never stored or transmitted)
Arc does not write any data to Apple Health.
You can revoke Arc's access to Apple Health at any time in Settings → Privacy & Security → Health → Arc on your iPhone.
4. How We Use Your Information
We use the information we collect solely to operate and improve Arc:
- To provide the App's core features — rendering workout widgets, creating collages, and exporting shareable images.
- To manage your account — creating and authenticating your account, and restoring your preferences after reinstallation.
- To fulfil your purchases — verifying Pro subscriptions and lifetime purchases, and maintaining your entitlements.
- To sync your preferences — restoring your widget favourites, distance unit, and other settings when you reinstall or sign in on a new device.
- To prevent fraud — verifying that in-app purchases are legitimate using Apple's StoreKit cryptographic receipts.
We do not use your information for advertising, profiling, or sale to third parties.
5. Third-Party Services
Arc relies on a small number of carefully selected third-party services. Each receives only the minimum data necessary to fulfil its function.
Supabase
We use Supabase as our backend infrastructure for user authentication and database storage. Supabase receives your account information (name, email, account ID) and your app preferences. Supabase is subject to its own Privacy Policy. Data is protected with industry-standard encryption in transit and at rest, and row-level security policies ensure that only your data is accessible to your account.
RevenueCat
We use RevenueCat to manage in-app subscriptions and verify purchase entitlements. RevenueCat receives your account identifier and purchase transaction data from Apple's StoreKit. RevenueCat is subject to its own Privacy Policy. No health data, photos, or personally identifiable information beyond account ID and purchase history are shared with RevenueCat.
Apple
Arc is built on Apple's platforms and uses the following Apple services: Apple Sign In (authentication), HealthKit (health data access, on-device only), StoreKit (payments), and the iOS photo library APIs. Apple's handling of your data is governed by Apple's Privacy Policy.
No Analytics or Tracking
Arc does not integrate any analytics SDK (such as Firebase Analytics, Mixpanel, Amplitude, or Segment), advertising network, or crash reporting service that transmits data externally. We collect no behavioural telemetry, session recordings, or usage analytics.
6. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information. We may disclose information only in the following limited circumstances:
- Service providers — as described in Section 5, we share data with Supabase and RevenueCat solely to operate the App.
- Legal requirements — if required by applicable law, court order, or governmental authority.
- Protection of rights — to protect the rights, property, or safety of Arc, its users, or the public.
- Business transfer — in the event of a merger, acquisition, or sale of assets, your information may be transferred. We will notify you before your data is transferred and becomes subject to a different privacy policy.
7. Data Retention
On-Device Data
Health data is fetched from Apple Health in real time and held in memory only for the duration of your session. It is never cached to disk by Arc. Your account preferences are stored in the iOS UserDefaults system and are cleared when you delete your account or uninstall the App.
Server-Side Data
Your account information, preferences, and subscription records are retained on our servers for as long as your account is active. When you delete your account (via Settings → Delete Account in the App), all of your data is permanently and irreversibly deleted from our servers, including your profile, preferences, and subscription records.
RevenueCat
Purchase history retained by RevenueCat is subject to RevenueCat's own data retention policies, which may apply independently of your Arc account deletion.
8. Your Rights & Controls
You have the following rights and controls over your data:
- Access — you can view the information stored in your account at any time within the App.
- Correction — you can update your display name in the App's Settings.
- Deletion — you can permanently delete your account and all associated data by tapping Delete Account in Settings. This action is irreversible.
- Health access revocation — you can revoke Arc's access to Apple Health at any time in your iPhone's Settings without deleting your account.
- Photo access revocation — you can revoke photo library access in Settings → Privacy & Security → Photos → Arc.
- Subscription management — you can cancel a recurring subscription at any time through your Apple ID settings at Settings → [Your Name] → Subscriptions.
To exercise any of these rights or to make a data-related enquiry, contact us at info@nocap.bio.
9. Data Security
We take reasonable technical and organisational measures to protect your information:
- All communication between Arc and our servers is encrypted using HTTPS/TLS.
- Authentication tokens are stored in the iOS Keychain, the most secure on-device storage available.
- Our Supabase database uses row-level security policies so that each user can only access their own data.
- Apple Sign In uses a cryptographic nonce to prevent replay attacks.
- In-app purchases are verified using Apple's cryptographically signed StoreKit 2 JWS tokens.
No system is completely secure. In the event of a data breach that affects your personal information, we will notify affected users as required by applicable law.
10. Children's Privacy
Arc is not directed at children under the age of 13 (or the equivalent minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at info@nocap.bio and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you through the App. Continued use of Arc after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact us:
Arc Support
info@nocap.bio
We aim to respond to all privacy enquiries within 5 business days.