← Back to Arc
Privacy Policy
Last Updated: February 20, 2026
Your Privacy Matters: Arc is committed to protecting your personal health information. We do not sell your data to third parties, and we do not use your personal data to train underlying AI models.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email, phone number, age, biological sex
- Health Information: Weight, height, health history, PAR-Q+ responses, SCOFF screening results
- Goals & Preferences: Fitness goals, dietary restrictions, coaching preferences, activity level
- Workout Logs: Exercises performed, sets, reps, weights, effort levels, session duration
- Nutrition Logs: Meals consumed, estimated macros, meal photos
- Daily Check-Ins: Sleep quality, energy level, soreness, stress
- Communication: SMS messages, in-app chat messages with Arc's AI
- Photos/Videos: Form check photos/videos you upload for AI analysis
1.2 Information from Wearable Devices
If you connect wearable devices (Oura Ring, Apple Watch, Whoop, Garmin), we collect:
- Heart rate data (resting HR, active HR, HR zones)
- Sleep data (duration, sleep stages, sleep quality)
- Heart rate variability (HRV)
- Steps, distance, calories burned
- Activity/readiness scores from your device
1.3 Automatically Collected Information
- Usage Data: Pages visited, features used, time spent in app
- Device Information: Browser type, operating system, device model
- Log Data: IP address, timestamps, error logs
2. How We Use Your Information
2.1 To Provide the Service
- Generate personalized workout plans and nutrition guidance
- Track your progress and adjust recommendations
- Send proactive coaching messages and check-ins
- Analyze form via photos/videos and provide feedback
- Calculate recovery scores and adjust training intensity
2.2 To Improve Arc's AI
- Understand how users interact with Arc
- Identify bugs and technical issues
- Test new features and improvements
Important: We do NOT use your personal data (workouts, meals, photos, messages) to train the underlying AI models (Claude). Your conversations and data remain private to you.
2.3 To Communicate with You
- Send coaching messages via SMS or push notifications
- Respond to your questions and support requests
- Send important service updates (rarely)
3. How We Share Your Information
3.1 We Do NOT Sell Your Data
Arc does not sell, rent, or trade your personal information to third parties for marketing purposes.
3.2 Service Providers
We share your information with trusted service providers who help us operate Arc:
- Supabase: Database hosting (encrypted at rest and in transit)
- Anthropic: AI model provider (Claude API) - processes your messages to generate coaching responses
- Twilio: SMS messaging service
- Cloud Storage: Stores photos/videos you upload (encrypted)
These providers are contractually obligated to protect your data and only use it as directed by Arc.
3.3 Wearable Device Companies
If you connect wearables, Arc accesses your data via official APIs (Oura, Apple HealthKit, etc.). We only read data you authorize - we do not write data back or share it elsewhere.
3.4 Legal Requirements
We may disclose your information if required by law, such as:
- Responding to subpoenas or court orders
- Complying with regulatory investigations
- Protecting Arc's legal rights or defending against claims
4. Data Security
4.1 Encryption
- All data is encrypted in transit (TLS 1.3)
- All data is encrypted at rest (AES-256)
- Database connections use secure authentication
4.2 Access Controls
- Only authorized personnel can access production systems
- Multi-factor authentication required for admin access
- Database queries are logged and monitored
4.3 Data Breach Notification
In the unlikely event of a data breach, we will notify affected users within 72 hours and take immediate steps to secure systems.
5. Your Rights & Choices
5.1 Access Your Data
You can request a copy of all data Arc has stored about you. Contact support@arcapp.ai.
5.2 Correct Your Data
You can update your profile, goals, and preferences anytime in the app.
5.3 Delete Your Data
You can request deletion of your account and all associated data. Contact support@arcapp.ai. We will delete your data within 30 days, except where required to retain for legal purposes.
5.4 Export Your Data
You can export your workout logs, nutrition logs, and chat history. Contact support@arcapp.ai.
5.5 Opt Out of SMS
Reply "STOP" to any Arc SMS to unsubscribe from text messages. You can still use the app.
5.6 Disconnect Wearables
You can disconnect wearable devices anytime in settings. Previously synced data will remain unless you request deletion.
6. Data Retention
- Active Accounts: We retain your data as long as your account is active
- Inactive Accounts: If you don't log in for 2 years, we may delete your account after notice
- Deleted Accounts: Data is permanently deleted within 30 days of account deletion
- Backups: Deleted data may persist in encrypted backups for up to 90 days
7. Children's Privacy
Arc is not intended for users under 18 years old. We do not knowingly collect information from children. If we discover a user is under 18, we will delete their account immediately.
8. International Users
Arc is operated in the United States. If you access Arc from outside the U.S., your data will be transferred to and stored in the U.S. By using Arc, you consent to this transfer.
9. HIPAA Compliance
Arc is NOT a HIPAA-covered entity. Arc is a direct-to-consumer wellness app and does not receive data from healthcare providers.
If you are a healthcare provider or covered entity, do not use Arc to store patient health information (PHI).
10. State-Specific Rights
10.1 California Residents (CCPA)
California residents have additional rights:
- Right to know what personal information is collected
- Right to know if personal information is sold or shared (we don't sell)
- Right to delete personal information
- Right to opt-out of sale (not applicable - we don't sell)
- Right to non-discrimination for exercising privacy rights
To exercise these rights, email privacy@arcapp.ai.
10.2 Virginia, Colorado, Connecticut, Utah
Residents of these states have similar rights under state privacy laws. Contact privacy@arcapp.ai.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last Updated" date.
If we make significant changes, we will notify you via email or in-app notice.
12. Contact Us
Questions about privacy?
- Email: privacy@arcapp.ai
- Support: support@arcapp.ai
Summary: We collect health and fitness data to personalize your coaching. We protect your data with encryption. We don't sell your data. You can access, export, or delete your data anytime.
← Back to Arc