Arca Privacy Policy

Last updated: September 1, 2026

Arca is built by an independent developer. We do not sell your data, share it with advertisers, or track you across other apps and websites. This policy explains the small amount of data the app does handle and why.

What stays on your device

Your bookmarks, article-reading history, reading streaks, recent searches, app preferences, cached articles, and downloaded podcast files are stored locally on your device. They are not uploaded to Arca except when you choose an optional service described below, such as Anonymous Analytics, Enhanced Voice, or Arca Digest. The Android app disables cloud backup and excludes its app data from Android 12 and later cloud-backup and device-transfer rules. On Apple devices, limited podcast playback and widget state can sync through your Apple iCloud account as described below; it is not sent to Arca's server.

Analytics

Arca does not include a third-party analytics service. Only if you turn on Anonymous Analytics in Profile → Privacy does Arca send us a random on-device identifier and daily aggregate counts of active days, reader opens, saves, listening, podcast starts, paywall views, and completed subscriptions. This helps us understand whether the app is useful after an install.

Those counts do not include your name, email, Apple ID, advertising ID, article title, URL, publisher, reading preferences, device model, or a precise timestamp. We do not sell them, share them with advertisers, or use them to track you across apps or websites.

Anonymous Analytics is not available in the current Android build, and the Android app does not send these analytics events.

Crash diagnostics

Sentry runs only in non-debug builds on physical Apple devices; it is never started in a debug build or a simulator. It sends crash and watchdog-termination reports so we can diagnose reliability problems. These reports may include the app version, device and operating-system details, stack traces, and technical app-lifecycle breadcrumbs. Arca disables app-hang reporting, performance tracing, sessions, default personal data, screenshots, view hierarchies, logs, network breadcrumbs, failed network requests, session replays, and analytics events. Diagnostic reports are used only to fix app reliability and are processed by Sentry.

The current Android app does not include Sentry or another automatic crash-reporting service. If you choose Send Feedback or Contact Support, your email app opens a message that you control and that can include the Arca version, device manufacturer and model, and Android version.

Accounts on Android

The current Android app does not require or offer an Arca account or sign-in flow. Google Play processes Android subscription purchases, but Arca does not receive your payment-card or bank information.

Sign in with Apple

If you choose to sign in with Apple, Arca stores the user identifier Apple provides on your device. Providing your email is optional and controlled by you through Apple's Sign in with Apple flow. We do not require an account to use the app, and the identifier is not sent to the Arca+ server.

Sign in with Google

If you choose to sign in with Google, Google's sign-in service processes the authentication and provides Arca with your Google user identifier, display name, and email address. Arca stores those profile fields on your device to display your local profile and does not send them to the Arca+ server. The Google Sign-In 9.2 SDK's privacy manifest conservatively declares Name, Email Address, Phone Number, Other Data Types, Coarse Location, User ID, Device ID, and Other Usage Data as linked to you for App Functionality and/or Analytics; it declares no tracking. Arca requests only the basic sign-in profile described above. You can sign out in Arca, and Delete My Data clears Arca's local Google profile and asks Google to disconnect the authorization when that service is reachable.

Arca+ daily edition

Arca's server creates one shared daily edition from public headlines, publisher names, links, and excerpts carried in the app's RSS feeds. That public story information is sent to OpenAI to generate the edition. Every subscriber receives the same cached edition; your reading history, searches, source preferences, bookmarks, and on-device ranking profile are not sent with the request.

For paid access, the Apple app sends an Apple-signed transaction and the Android app sends a Google Play purchase token so the server can verify that the subscription is active. Raw platform entitlement identifiers are used transiently for verification and are not stored in Arca's quota tables. For limited daily paid-feature quotas, the server persists a domain-separated one-way hash instead. Those quota rows contain only daily counts for the current and immediately previous UTC date. They are pruned on use, server startup, and a six-hour maintenance sweep, so a stale row may remain for up to six additional hours on a quiet server. They do not include article titles, URLs, text, bookmarks, searches, or preferences. Arca does not receive or store your payment card or bank information. Apple or Google Play processes the purchase.

Article intelligence

For approved built-in publishers, Arca may process public article evidence in the background to prepare shared, extractive story briefs. Arca uses substantial article text supplied in a publisher's RSS feed when available. When a permitted feed contains only a short excerpt, Arca may fetch the public publisher page only when the source policy and robots instructions allow it. Arca does not bypass paywalls or other access controls.

The extracted, normalized article body is kept for no more than 30 days from its first capture in a separate evidence store that is excluded from scheduled backups and snapshots. Re-reading or re-fetching unchanged text does not extend that deadline. After the body is deleted, Arca may retain public article metadata and the exact publisher sentences, body hashes, and offsets already selected for a validated brief so the source wording can remain auditable.

A locally operated Qwen language model may select those exact publisher sentences and propose cited metadata for a story shared by multiple sources. Deterministic Arca code validates the result and decides whether it can appear. The model is not given your account or installation identifier, reading history, searches, bookmarks, likes, saves, source preferences, or on-device ranking profile, and it does not control feed ranking. If validation fails or the evidence is insufficient, no brief is shown.

Enhanced article narration

Enhanced Voice runs only after you tap Listen on an article. Opening or reading an article does not start enhanced narration. To create the requested audio, Arca sends the article URL, extracted article text, and the applicable Apple- or Google Play-issued entitlement proof to Arca's server. The server verifies access and sends the article text to its configured speech provider. The speech provider does not receive your bookmarks, searches, source preferences, name, or digest email address.

Generated narration may be kept in a shared operational cache with bounded storage so another request for the same article can reuse it. That cache entry keeps a copy of the article text the audio was made from, because the follow-along highlight has to be checked against the exact words that were spoken. It is stored under a one-way hash derived from the article address, provider version, and exact article text; it is not linked to your account or to any identifier of yours and is removed when the cache reaches its size limit.

Arca also keeps bounded, rotating operational records for narration requests. These can include the request time, provider details, character count, cache status, latency, duration, estimated cost, and outcome, but not the article title, URL, text, or a user or account identifier. Short-lived daily synthesized-character totals are keyed by a domain-separated one-way hash of the verified entitlement identifier and are used to enforce service limits. These records are not used for advertising or to build a reading profile.

On Android, completed Enhanced Voice audio and its timing data are also kept in the app's local cache for replay until Android evicts them or you delete Arca's local data or uninstall the app.

Arca Digest

If you ask to receive Arca Digest, the app sends the email address you enter to Arca's server and its email-delivery provider so Arca can confirm the address and deliver the digest. The address and consent status are used only to operate the subscription and honor confirmation and unsubscribe requests. Every digest email includes an unsubscribe link.

Offline podcast downloads

Arca+ can save the audio file a podcast publisher includes in its RSS feed to your device for offline playback. Downloaded audio files and download settings stay on your device until you delete them or remove the app. No audio file is uploaded to Arca's server. On Android, downloads and podcast playback state stay on that Android device. On Apple devices, limited podcast playback, download-list, and Up Next details can sync through Apple's iCloud key-value service so playback and audio widgets can continue across your Apple devices; audio files themselves are not stored in iCloud.

Network and sources

Arca fetches articles and podcasts directly from publishers' RSS feeds. When an approved source's feed contains only an excerpt, Arca may fetch the public publisher page, extract readable article content on your device, and keep that extracted content in a bounded local cache. Saving a story does not pin extracted publisher-page text: complete RSS text remains with the saved story, while extracted text stays available only while the bounded cache retains it. Arca does not bypass publisher access controls: unsupported, unavailable, and subscriber-only pages use the publisher link instead. The Arca+ server uses only public RSS story information to create the shared daily edition.

What we do not collect

Arca itself does not request device-location permission or collect precise location, contacts, photos, payment information, or advertising identifiers. The Google Sign-In SDK used by the Apple app has the aggregate declaration described above; the current Android app has no sign-in SDK. There is no advertising in the app. Arca does not sell your data, track you across apps or websites, or use article-listening requests to advertise to you.

Apple iCloud playback sync

Arca uses Apple's iCloud key-value service for two things, and nothing else: podcast playback state including the last played episode, and the small snapshot that draws Arca's audio widgets. That widget snapshot carries podcast episode details — titles, show names, durations, artwork addresses — for your downloaded episodes and your Up Next queue, the currently playing episode with its position, and a summary of the day's Arca+ edition. It contains no audio files and no article content. The same snapshot is sent to your Apple Watch over Apple's device-to-device connection so the watch widgets can draw it. Apple associates iCloud data with your iCloud account; Arca's server does not receive any of it. Bookmarks, article-reading history, searches, preferences, cached articles, article narration positions, and downloaded audio files remain on the device where you created them.

Retention and deletion

Arca's server retains shared daily editions and the public story information used to create them. Article-intelligence bodies follow the 30-day limit described above; validated publisher quotes, offsets, hashes, and public provenance may remain after the body expires. Enhanced narration uses bounded shared-cache storage and bounded operational-log rotation. One-way-hashed paid-feature quota counters keep the current and immediately previous UTC date and are pruned on use, server startup, and a six-hour maintenance sweep; a stale row may remain for up to six additional hours on a quiet server. They do not contain the article title, URL, or text. Digest email and consent records are retained only as needed to deliver the subscription and honor the choices you make. Apple or Google Play manages subscription and billing records.

Optional anonymous analytics records are retained for no more than 30 days. Turning off Anonymous Analytics clears the local queue and asks our server to erase the associated anonymous records. If your device is offline, Arca retries that erasure the next time you open it.

Deleting your Arca data does not cancel an Arca+ subscription. Arca+ is billed by Apple and keeps renewing until you cancel it in your Apple subscription settings; Arca has no way to cancel it for you, so Delete My Data tells you this before and after the deletion and offers Apple's Manage Subscription screen. Delete My Data clears Arca's local profile and content state and removes Arca's podcast-playback and widget entries from iCloud. It also asks Google to disconnect a Google authorization when that service is reachable; if the request cannot be completed, Arca explains how to remove the authorization from your Google Account. Deleting the app by itself removes local app files but may leave iCloud playback entries or an external sign-in authorization until you remove them through Arca, iCloud, Google, or Apple account controls.

On Android, Profile → Delete local app data removes saved articles, reading history, preferences, cached content, podcast state, and onboarding choices from that device. Deleting the Android app also removes its local data because Arca disables platform backup and excludes its data from device transfer. Neither action cancels a Google Play subscription or unsubscribes a digest email address. Manage the subscription in Google Play and use the unsubscribe link in a digest email.

Contact

Questions about this policy? Reach out via the support page or email support@arcareader.app.