The short version: the app collects nothing, the site does not track you, and all we keep is what you type into the forms on this site.
Arked is an application that runs entirely on your device. We collect none of the data you put into it. In detail:
The app goes online for three things only: downloading the AI model the first time, checking whether there is an update, and reading the state of the beta — which versions are still active and which invite codes are valid. In all three cases an ordinary HTTP request travels, with none of your data attached.
The state of the beta is read from a server of ours, api.arked.app, with a copy on GitHub if the first does not answer: whoever answers sees your IP address, as with any request. The invite code is never sent: it is checked on your Mac against the published list, which holds only fingerprints of the codes and not the codes themselves.
Syncing between Mac, iPhone and iPad is optional, and off until you turn it on. When it is on, the archive lives in your iCloud Drive: the data goes through your Apple account, under Apple's terms and encryption, and passes through no system of ours. We have no way to read it and do not know it exists.
How Apple handles that data is covered by its own privacy notice, not this one. If you would rather not use iCloud, turn syncing off: Arked keeps working as a purely local archive.
Arked is in private beta and runs with an invite code. You ask for the code with the request form: what you type there reaches a server of ours.
Sending the form twice does not create a second request: the address is the key, and a later submission updates what is already there. The form gives the same answer in both cases, otherwise it would be a way of finding out which addresses have asked for access.
When a request arrives, a notification goes to the developer. It only says there is something to read: no name, no address, nothing of what you wrote.
If you send us a bug report during the beta, we receive what you choose to write — nothing leaves the app on its own.
Withdrawing consent is as easy as giving it. There is a page for it: Erase my data. Replying to any email from Arked and asking works just the same.
Asking to be erased creates a record of its own: the address, what you wrote, the IP address and a trace of the emails sent. It is kept to carry the erasure out and to be able to show it was done in time. The basis is the legal obligation to answer you (GDPR Art. 6(1)(c)), not consent: that is why that form has no box to tick. When nothing of yours is left, that record is deleted too.
The contact form is the way to write to us: a question, a problem, something about the beta or about your data.
Please do not put documents or sensitive data into the form. If a document is involved, describe it: there is no need to send it.
The forms are protected by Cloudflare Turnstile. It sets no cookies, does not profile you and is not used to follow you from site to site.
It does make a request to challenges.cloudflare.com, which discloses your IP address and your browser's user agent to Cloudflare, Inc., acting as a processor under the European Commission's Standard Contractual Clauses. The lawful basis is the legitimate interest in keeping a form open to everyone usable (GDPR Art. 6(1)(f)).
It loads when you start filling in the form, not when the page opens. Read the page and leave, and no request to Cloudflare is made at all.
This site is made of static pages. It uses no cookies, has no analytics and no tracking pixels, and does not profile its visitors.
One honest caveat: the typefaces on this page are served by Google Fonts, so your browser makes a request to Google's servers, which see your IP address in the process. We receive nothing of that request and do not use it to identify you. If we host the fonts on the site itself, this line will go.
Arked's builds are published on GitHub. When you press “Download” or open the release notes you go to GitHub, and from there you are on their site under their terms: GitHub sees your IP address. It is a request you make yourself, on purpose. How they handle that data is described in the GitHub privacy statement.
Like any website, the provider hosting these pages keeps technical access logs for security and diagnostics, for as long as that provider's own retention rules say.
Over the data you have left through the forms you can ask us at any time to access it, correct it, erase it, restrict its use or object to its processing, and you can obtain a copy. We answer within thirty days. You also have the right to complain to your national data protection authority; in Italy that is the Garante per la protezione dei dati personali.
For erasure there is a form. For everything else, or for any question about this page, use the contact below.
Data controller: Fabio Della Selva, the developer of Arked.
If we change this notice we will update the date at the top of the page. If the change concerns the beta data, we will also write to those who have sent a request.