The highlighted blanks below are the details only the operator of this deployment can supply. They must be filled in before this notice is published, because an unfinished privacy notice is not a privacy notice.
Who runs Arca
Arca is operated by legal entity name, registered in country / state. Privacy questions go to privacy contact address, and we answer within response window.
What we collect
Your account
When you sign up we store your email address, an optional display name, and, if you sign in with GitHub, the avatar URL GitHub returns. Passwords are never stored by us: authentication runs on Supabase Auth, which holds the credential.
Your organisation
An organisation record holds its name, URL slug, plan, and creation date. Membership records hold the member's user id, role, and when they joined. Invites hold the invited email address until the invite is accepted or expires.
Your scans
For every scan we store:
- the repository URL you submitted, and which account or API key submitted it
- timestamps for queued, started, and finished, plus any error the run produced
- each finding: the rule that fired, its severity, the file path and line, the evidence excerpt the tool captured, and the suggested fix
- per-agent reports for
secrets,dependencies,staticandconfig: status, runner, duration, and finding count - the combined score plus the separate code and dependency scores
Evidence excerpts contain source code. Arca only accepts public repositories, so this is code that is already public, but it is copied into our database and it is worth knowing that before you scan something.
API keys
We store a key's name, its short public prefix, its scopes, its expiry, and when it was last used. The secret itself is shown once at creation and is not recoverable from us afterwards.
Product events
We record first-party product events such as signup, scan submitted, and finding expanded, with the event name and a timestamp. There is no third-party analytics script, no advertising pixel, and no cross-site tracker on this site.
What we do not collect
- private repositories: Arca does not ask for, and cannot use, a private-repo token
- payment card numbers, which are handled by the payment processor, never by us
- any special-category data, which the service has no reason to hold
Why we are allowed to hold it
Account, organisation, and scan data is processed to perform the contract you entered when you created an account. Product events and security logs are processed under legitimate interest, to keep the service working and to see where it fails. Where applicable privacy law requires consent instead, we ask for it before collecting.
Who else processes it
Running a scan means handing data to a small number of subprocessors:
- Supabase — authentication and the Postgres database holding accounts, organisations, scans, and findings
- E2B — the disposable cloud sandbox a scan runs in when the deployment is configured for it. The sandbox receives the repository being scanned and is destroyed after the run
- GitHub — only when you choose GitHub sign-in, and only to verify your identity
- Anthropic — only on deployments with LLM-suggested fixes enabled. When it is on, finding context is sent to the Claude API to draft the suggested fix
- hosting provider — application hosting
We do not sell personal data, and we do not share it with advertisers. The current subprocessor list with processing locations lives at subprocessor page URL.
How long we keep it
- Scans and findings: kept until you delete them or close the account, and no longer than scan retention period
- Account and organisation records: kept while the account is open, then deleted within deletion window of closure
- Security and access logs: log retention period
Your rights
You can ask for a copy of your data, ask us to correct it, ask us to delete it, or object to processing based on legitimate interest. Write to privacy contact address and we will act within statutory response window. If you are unhappy with the outcome you can complain to supervisory authority.
You can delete an individual scan from the scan page at any time without contacting us.
Security
Data is encrypted in transit. Database access is constrained by row-level security so an organisation reaches only its own rows. API keys are stored as hashes with only the prefix in the clear. Scans run in a sandbox that is discarded after the run. No system is perfect: if a breach affects you we will tell you and the relevant regulator as the law requires.
Cookies
Arca sets a session cookie so you stay signed in. That is a strictly necessary cookie and there is no advertising or analytics cookie on this site.
Changes
When this notice changes materially we will say so on this page and, for changes that affect how we use data you have already given us, by email before the change takes effect.
See also the Terms of Service.