Privacy Policy
In short
- We cannot read your budget. Not as a policy choice — technically. It is encrypted on your device with a key we never receive.
- We hold a hashed version of your email, an account identifier, and unreadable encrypted blocks.
- No advertising, no resale, no tracking, no analytics cookies. That is why this site shows no cookie banner.
- Everything is hosted in the European Union.
- You can export everything from the app, at any time, for free.
- The beta is free: no payment details are collected at all.
- If you lose your passphrase and your recovery key, nobody can recover your data — including us.
1. Who is responsible for your data
The data controller is Takieddine Boumerah (Entrepreneur individuel (EI)), trading as Arca Budget, SIREN 931302947, France. Contact for any privacy matter: privacy@arcabudget.app.
No Data Protection Officer has been appointed. None is required under Article 37 GDPR: we are a sole trader, we carry out no large-scale monitoring, and we process no special categories of data. Requests are handled directly by the controller at the address above.
2. What end-to-end encryption changes here
Your budget — accounts, transactions, categories, amounts, notes — is encrypted in your browser, with a key derived from a passphrase that only you know, before anything is sent to us. Our server only ever receives opaque encrypted blocks. We cannot read, decrypt, sell or hand over the contents of your budget, because we never hold the key.
What the server does necessarily see, and which is personal data:
- a hash of your email address, and an opaque identifier if you sign in with Google;
- technical metadata needed to route and order the encrypted blocks: identifier, vault identifier, record type, last-modified timestamp, deletion marker;
- connection and security records (see the table in section 3).
We say this plainly rather than calling it “anonymous”: a hash is not anonymous data, and metadata about you remains data about you.
The trade-off is real. If you lose your passphrase and your recovery key, your data is permanently unreadable. We cannot reset it for you. That is the direct consequence of us not holding your key.
3. What we process, why, on what legal basis, and for how long
| Data | Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|
| Hashed email address, password hash, Google identifier | Creating your account, signing you in | Performance of a contract — 6(1)(b) | Until you delete your account, or 24 months of inactivity, after a warning email |
| Encrypted blocks and their routing metadata | Storing and syncing your budget — this is the service | Performance of a contract — 6(1)(b) | Until you delete your account. Purged within 30 days of account deletion |
| Email address, message content | Transactional email only: address verification, password reset, security alerts | Performance of a contract — 6(1)(b) | Deleted once sent; failed messages purged after retries |
| Session and refresh tokens | Keeping you signed in; revoking access on sign-out | Performance of a contract — 6(1)(b) | 30 days, rotated on each use and revoked on sign-out |
| Audit log of sensitive actions (sign-in, account changes) | Security of the service and traceability of actions affecting your account | Legitimate interest — 6(1)(f) | 12 months |
| Rate-limiting and anti-abuse records | Preventing brute-force and fraudulent access attempts | Legitimate interest — 6(1)(f) | 12 months |
| Diagnostics (app version, operating system, device model — redacted on your device) | Diagnosing crashes and defects | Legitimate interest — 6(1)(f) | 90 days |
The legitimate interests we rely on are named above, one by one, as Article 13(1)(d) requires: securing the service, tracing actions that affect your account, preventing abuse, and diagnosing defects. We have carried out and documented a balancing test for each.
Is providing this data required? An email address is contractually necessary to create an account: without it we cannot provide the service and no account can be created. Everything else listed above is generated by using the service.
Financial data is not a “special category” within the meaning of Article 9 GDPR, and we process no special-category data.
4. Who receives your data
| Recipient | Role | Location | What they receive |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (processor) | Germany — European Union | Encrypted blobs, routing metadata, account records, logs |
| Zoho Corporation B.V. (ZeptoMail) | Transactional email (processor) | Utrecht, Netherlands — European Union | Your email address and the content of transactional messages |
| Google Ireland Ltd | Sign-in with Google (independent controller) | Ireland — European Union, with onward transfers to Google LLC (USA) | Only what is needed to authenticate you, if you choose Google sign-in |
We name our recipients here rather than describing vague “categories”. Each processor is bound by a data processing agreement meeting Article 28 GDPR. We never sell your data, and we share it with no advertiser and no data broker.
During the free beta, no payment details are collected and nothing is transmitted to any payment provider. If and when paid subscriptions open, Paddle.com Market Ltd (30 Old Bailey, London EC4M 7AU, United Kingdom) will act as Merchant of Record and as an independent controller for the purchase; this policy will be updated beforehand.
5. Transfers outside the European Union
Hosting and storage take place within the European Union, with no transfer to a third country. The only possible transfer concerns Sign-in with Google, if you choose it: Google Ireland Ltd may transfer data to Google LLC in the United States, on the basis of the EU–US Data Privacy Framework, under which Google LLC is certified.
You may obtain a copy of the safeguards applying to these transfers by writing to privacy@arcabudget.app. Certifications can also be checked on the Data Privacy Framework register.
6. Security
The measures we apply (Article 32 GDPR):
- encryption of your budget on your device (AES-GCM), with a key derived from your passphrase and never transmitted;
- encryption in transit (HTTPS/TLS) for every exchange;
- passwords stored as salted hashes, never in clear;
- short-lived sessions with rotating refresh tokens, revocable at any time;
- rate limiting and brute-force protection;
- an audit log kept separately from application data;
- hosting within the European Union.
In the event of a data breach, we notify the CNIL (Commission Nationale de l'Informatique et des Libertés) within 72 hours where Article 33 GDPR requires it. A breach affecting only the encrypted blocks would very likely fall within the exemption in Article 34(3)(a), since the data would be unintelligible without your key. That exemption would not apply to a breach affecting hashed email addresses, identifiers, tokens or the audit log — which are not end-to-end encrypted. Where there is any doubt, we undertake to inform you anyway.
7. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and not to be subject to automated decision-making (Art. 22). Here is honestly what each one means given the encryption:
- Access and portability. Your budget is exportable at any time, for free, from the app, in an open format. The export is generated on your device and decrypted with your key — which is the only way it can be readable. On request we additionally provide everything we hold on our side (hashed email, identifiers, metadata, logs). Direct transmission to another controller (Art. 20(2)) is not technically feasible, precisely because we cannot decrypt your data.
- Rectification. We can correct your account details. We cannot correct the contents of your budget: only you can, from the app, because only you hold the key.
- Erasure. Fully available. Deleting your account removes the encrypted blocks, the metadata, the hashed email and the tokens. Backups are purged within 30 days. Audit-log entries may be kept until the end of their retention period, on the security ground set out in section 3.
- Restriction. You may ask us to suspend the processing based on legitimate interest (diagnostics, audit log) while a request is being examined.
- Automated decisions. We make none. No profiling, no scoring, no automated decision producing legal effects for you.
We reply within one month (Art. 12(3)), extendable by two months for complex requests, in which case we tell you within the first month. If we cannot act on a request, we explain why, and you may lodge a complaint or seek a judicial remedy (Art. 12(4)).
Your right to object (Art. 21 GDPR)
You may object at any time, on grounds relating to your particular situation, to the processing we carry out on the basis of our legitimate interest — namely diagnostics and the audit log. Write to privacy@arcabudget.app. We will stop that processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms.
8. Directives on your data after death
Under Article 85 of the French Data Protection Act, you may give directives on the retention, erasure and communication of your data after your death — either general directives registered with a certified trusted third party, or specific directives sent to us at privacy@arcabudget.app. Note the limit imposed by the encryption: without your passphrase and recovery key, nobody — us included — can make the contents of your budget readable.
9. Lodging a complaint
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — https://www.cnil.fr. We would rather you write to us first, but that is your right and it is not conditional on contacting us.
10. Cookies and local storage
This site and the app show no cookie banner, because we place no tracking cookie. No advertising, no third-party analytics. We store only what is strictly necessary for the service you asked for:
| Item | Purpose | Lifetime |
|---|---|---|
| Session token | Keeping you signed in | Session, renewed while you are active |
| Refresh token | Avoiding signing you out every hour | 30 days, rotated on each use and revoked on sign-out |
| Preferences (language, theme, currency) | Showing the interface the way you set it | Until you clear your browser data |
| Local encrypted copy of your budget | Making the app work and stay fast; never leaves your device in clear | Until you sign out or clear your browser data |
These items are exempt from consent under Article 82 of the French Data Protection Act, being strictly necessary to provide a service you expressly requested.
Audience measurement on this marketing site
We measure traffic on this marketing site only — not in the app, where your data is encrypted and there is nothing for us to observe. This measurement sets no cookie and creates no identifier that would follow you.
For each page viewed, we record exactly three things:
| Data | Precision kept | Retention |
|---|---|---|
| Page viewed | The path only (never URL parameters, which could contain a personal link) | 13 months |
| Where you came from | The site's name (“google.com”), never the full address nor your search terms | 13 months |
| Visit duration | In seconds | 13 months |
To count visitors without identifying them, your IP address and browser are turned into a one-way fingerprint, mixed with a random secret that is renewed every day and held in memory only. That secret is never written to disk: it vanishes each night. The direct consequence — nobody, not even us, can link your visit today to your visit tomorrow, or work back from a fingerprint to an IP address. Your IP address and browser are themselves never stored.
This measurement runs on our own servers, in Europe, for our use alone. No data is shared with a third party, cross-referenced with any other processing, or used to track you across sites. It therefore falls under the consent exemption for audience measurement in Article 82 of the French Data Protection Act — which is why this site does not confront you with a banner. Should we ever add a tracker that falls outside that exemption, we would ask for your consent beforehand.
11. Free beta and future billing
Arca is currently in free public beta. We collect no payment details, and no billing provider receives any data about you. Arca will become paid one day: you will be informed at least 60 days in advance, by email, and nothing will ever be charged to you without an explicit order on your part. This policy will be updated before any payment processing begins.
12. Changes to this policy
If we change this policy, we update the date at the top of this page. For any change that materially affects your rights or introduces a new purpose, we inform you by email before it takes effect (Art. 13(3)).
13. Contact
Privacy: privacy@arcabudget.app ·
Support: support@arcabudget.app
Takieddine Boumerah — France
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
