ARCSFIELD OSPrivacy Policy

ARCS advocates for information access as a right. That obligation runs both ways. This policy tells you exactly what we collect, how long we keep it, who can see it, and what we will never do. Receipted, not promised.

What happens to your data

Three categories. Read all three.

AlwaysUnconditional. No carve-outs. No exceptions for business reasons.
What
Why it's locked
Input never trains a model
Anthropic API terms + architectural separation
Anonymous compass sessions store nothing
No auth = no write path to DB for your questions or receipts
Delete within 30 days, permanently
One-way gate: no backups retained after confirmation
Source code stays public
You can verify our architecture claims yourself
30 days notice before material policy changes
You decide whether new terms apply before they do
SometimesConditional. You control the trigger. We state the condition clearly.
What
Trigger (you control this)
Receipts stored
Only when you sign in
A shared bearing travels in the link, not our DB
Only if you create a one-time share link. Content is encoded in the URL fragment (never sent to us); a per-device flag flips it to a sign-in page after the first view
Email contact
Only if you provided an address
Debrief reminder emails
Signed in, the first time a receipt of yours reaches its horizon you get one check-in email asking how it landed. That is the only one sent without asking. Later ones come only if you turn reminders on, and every reminder carries a one-click link to turn them off
Waitlist or advisory request stored
Only if you join the waitlist or ask for a consult. Stored in our database, emailed to the ARCS team, confirmation delivered through Resend
Service providers process data to run ARCS
Vercel (hosting and privacy-friendly page analytics), Supabase (database), Resend (email), Anthropic (compass reasoning). None may use it for their own purposes
Your question goes to the ARCS scoring service
Each compass run sends the question, horizon and stakes to SAGE, ARCS's own scoring pipeline, which returns an advisory signal. It informs the reasoning; it never decides
Anyone with a share link you made can read that brief
A signed-in brief is visible only to you until you mint a share link. The link carries a random token in its fragment; we store only a hash of it, and you can revoke it. A shared view shows the decision and its reading, never your account id or your private prep notes
Decision text in a link you open
Only if you click "add to calendar" or "share on X". Those buttons put the decision or its bearing into a Google Calendar or X link, so it reaches Google or X under their own terms. Nothing is sent until you click
LinkedIn files you upload
Only if you upload them during onboarding. Your profile PDF and data export ZIP are stored as private files in Vercel Blob, linked to your account, and deleted when you delete your account. Nothing reads them yet
Demand-probe clicks on good.arcs.care
If you view or click "I'd use this" on a probe, we store the probe name, the action, the page and a random id your browser keeps so a repeat click counts once. No IP, no user agent, no account. Used only to decide whether to build the feature (ADR-076). Kept until that decision is made, then deleted
Usage analytics
Vercel Analytics counts page views and a few actions, such as sharing a brief or saving a receipt, with the receipt id. No cookies, no decision text
Legal disclosure of your data
Only under valid legal compulsion. We notify you if permitted
Session logs (request metadata, no content)
Standard infra logging, purged after 30 days
NeverScout's honor. Enforced by architecture and covenant, not just policy.
What we won't do
How we're proving it
Sell or share your decision content
No third-party data agreements. Verify in source code
Use your data for advertising or profiling
No ad infrastructure exists in the codebase
Hold your data hostage to keep you subscribed
Delete is always available regardless of subscription
Publish content from your sessions without consent
Journalism pipeline requires explicit opt-in per session
§ 01 · What we collect
Data types and their paths
Data inventory
Question textBROWSER ONLY · anonymous (tab; up to 7 days in local storage if you choose to save, cleared on sign-in) / DB · signed-in
DEWY receipt (bearing, NCI, Y-gate)DB · signed-in only
Email addressDB · only if you sign in (magic link) or join the waitlist
Waitlist / advisory requestDB · email, time, optional brief link; advisory adds name + message · not tied to an account
Request metadata (timestamps, codes)INFRA LOGS · 30d TTL · no decision content
Prep session (stakes, horizon, protecting)DB · signed-in only · linked to receipt
Brief share linksDB · token hash, brief, creator, revoked time · signed-in owners only
LinkedIn profile PDF / export ZIPVERCEL BLOB (private) · only if you upload · deleted with your account
Demand probe (probe, action, page, random browser id)DB · no IP, no user agent, no account · deleted once the build decision is made
§ 02
⚠ NOT BUILT YET
What we don't have yet but should
Export: not yet built. You can delete, but you can't yet download your receipt history in a portable format. This is on the roadmap. Until it ships, contact us directly if you need your data.

Audit log: you can't yet see a log of every time your data was accessed. We log it internally; the user-facing view isn't built. On the roadmap.

Consent revocation per-receipt: if a receipt was used in the journalism pipeline and you later want it removed, the workflow for that isn't formalized yet. Contact us directly.
§ 03 · Journalism pipeline
When ARCS produces content from sessions
ARCS operates @TILbyARCS as a journalism engine. Content is produced from ARCS's own analysis, not from your sessions. Your compass queries are never published without an explicit, session-specific opt-in, not buried in account settings, not assumed from prior consent. If we ever build a feature where you can voluntarily contribute an anonymized receipt to the journalism corpus, that will be a separate, prominent, reversible consent step.
§ 04 · Your rights
What you can do, right now
Delete everything: Signed in, you can delete your account yourself, immediately (POST /api/account/delete; a settings button is coming). It removes your receipts, outcomes, uploaded files and personal data. Or email us and we do it within 30 days. One-way gate.
Correct your data: Email to correct stored information.
Question this policy: If something here conflicts with what you observe in the source code, flag it. We will investigate and correct the discrepancy or the code.
Exit without penalty: No dark patterns, no retention loops, no data held to encourage you to stay.
Privacy policy v1.5 · effective 2026-10-05
Trust contractTerms of serviceOpen the compass →
Interested in ARCS powered sprints by Mañana?Inquire directly 
TrustPrivacyTerms