Privacy, in plain language.
This policy is short because we collect almost nothing. That is not a legal posture; it is the product’s architecture.
The Arca application
- Arca runs on your own computer. Your mailbox credentials, your API keys and your mail stay on your machine, in your files.
- We operate no servers that receive, store or process your email. We could not read it if we wanted to.
- Arca talks directly from your machine to the services you connect: your mail provider, your calendar, your model provider, under your own accounts and keys.
- Your credentials stay local, but the reasoning does not. The message content Arca works on is sent to whichever model provider you configure — by default Moonshot's Kimi API — and is processed on their servers under your own key. If that is not acceptable for a given mailbox, do not connect it.
- Nothing is sent, moved or deleted without your explicit approval on screen, unless you have raised the autonomy level to preauthorize that kind of action. Preauthorization is yours to give and to withdraw, and the level in force is shown in the app.
This website
- No analytics, no tracking pixels, no cookies, no third-party scripts.
- If you email us, we use your address to reply to you and for nothing else. No mailing list, no sharing, no drip campaigns.
The pilot
- During a pilot, usage is measured on your machine and shared with us only with your explicit consent, in aggregate form you can inspect first.
- A data processing agreement is available to every pilot firm before anything is installed.
Questions
Ask the people who wrote both the policy and the code: laurent@arcaops.xyz.