Arca
FeaturesSecurityBetaGuidesDocs
Sign inCreate my account
FeaturesSecurityBetaGuidesDocsSign in
LanguageFR

← Arca Budget

Privacy Policy

Last updated: 26 August 2026

In this article
  1. In short
  2. 1. Who is responsible for your data
  3. 2. What our servers hold, and what we see of it
  4. 3. What we process, why, on what legal basis, and for how long
  5. 4. Who receives your data
  6. 5. Transfers outside the European Union
  7. 6. Security
  8. 7. Your rights
  9. 8. Directives on your data after death
  10. 9. Lodging a complaint
  11. 10. Cookies and local storage
  12. 11. Free beta and future billing
  13. 12. Changes to this policy
  14. 13. Contact

In short

  • Our servers hold your budget in the clear. That is what lets them do the arithmetic for you. Nobody on our team accesses it: no admin screen returns its contents.
  • We also hold your email address — in the clear, so we can write to you, and as a hash so we can find your account at sign-in — plus an account identifier.
  • The disks holding the database and the backups are encrypted at rest. That is not end-to-end encryption, and we do not call it that.
  • No advertising, no resale, no tracking, no analytics cookies. That is why this site shows no cookie banner.
  • Everything is hosted in the European Union.
  • You can export everything from the app, at any time, for free.
  • The beta is free: no payment details are collected at all.
  • A forgotten password does not destroy your budget: resetting it gives you back the account and the data.

This summary is here for readability. Only the sections below are binding.

1. Who is responsible for your data

The data controller is Takieddine Boumerah (Entrepreneur individuel (EI)), trading as Arca Budget, SIREN 931302947, France. Contact for any privacy matter: privacy@arcabudget.app.

No Data Protection Officer has been appointed. None is required under Article 37 GDPR: we are a sole trader, we carry out no large-scale monitoring, and we process no special categories of data. Requests are handled directly by the controller at the address above.

2. What our servers hold, and what we see of it

Your budget — accounts, transactions, categories, amounts, notes — is stored in the clear on our servers. That is what lets them work out your balances, what is available and your month ahead once and for all, instead of redoing that work in every browser.

Until 25 August 2026 this was not the case: your budget was encrypted on your device and we only ever received unreadable blocks. We gave that up, and we write it here rather than let the word “encrypted” keep a false idea alive. The technical detail, and what it no longer protects against, are on the security page.

What we process is therefore, plainly, personal data:

  • the contents of your budget;
  • your email address — in the clear so we can write to you, and as a hash so we can find your account — and an opaque identifier if you sign in with Google;
  • technical metadata for routing and ordering: identifier, vault identifier, record type, last-modified timestamp, deletion marker;
  • connection and security records (see the table in section 3).

What we undertake not to do. Nobody on our team accesses the contents of a budget: the admin console only ever returns metadata — a record count, dates, a subscription state — and no endpoint exposes a transaction. Admin actions are logged. If support ever needed access to help you, it would be with your explicit consent, and it would leave a trace. We do not sell or hand over your data, and we draw no advertising from it.

3. What we process, why, on what legal basis, and for how long

DataPurposeLegal basis (Art. 6 GDPR)Retention
Email address (and its hash), password hash, Google identifierCreating your account, signing you inPerformance of a contract — 6(1)(b)Until you delete your account, or 24 months of inactivity, after a warning email
Performance measurements: screen name, durations, app version, order of magnitude of vault size, device typeFinding and fixing slow screens in the appConsent — 6(1)(a). Off by default, revocable at any time90 days
The contents of your budget and its routing metadataStoring, syncing and computing your budget — this is the servicePerformance of a contract — 6(1)(b)Until you delete your account. Purged within 30 days of account deletion
Email address, message contentTransactional email only: address verification, password reset, security alertsPerformance of a contract — 6(1)(b)Deleted once sent; failed messages purged after retries
Session and refresh tokensKeeping you signed in; revoking access on sign-outPerformance of a contract — 6(1)(b)30 days, rotated on each use and revoked on sign-out
Audit log of sensitive actions (sign-in, account changes)Security of the service and traceability of actions affecting your accountLegitimate interest — 6(1)(f)12 months
Rate-limiting and anti-abuse recordsPreventing brute-force and fraudulent access attemptsLegitimate interest — 6(1)(f)12 months
Diagnostics (app version, operating system, device model — redacted on your device)Diagnosing crashes and defectsLegitimate interest — 6(1)(f)90 days

The legitimate interests we rely on are named above, one by one, as Article 13(1)(d) requires: securing the service, tracing actions that affect your account, preventing abuse, and diagnosing defects. We have carried out and documented a balancing test for each.

Is providing this data required? An email address is contractually necessary to create an account: without it we cannot provide the service and no account can be created. Everything else listed above is generated by using the service.

Financial data is not a “special category” within the meaning of Article 9 GDPR, and we process no special-category data.

4. Who receives your data

RecipientRoleLocationWhat they receive
Hetzner Online GmbHHosting (processor)Germany — European UnionYour budget (accounts, transactions, categories, amounts, notes), account records, logs. Stored on encrypted disks.
Zoho Corporation B.V. (ZeptoMail)Transactional email (processor)Utrecht, Netherlands — European UnionYour email address and the content of transactional messages
Google Ireland LtdSign-in with Google (independent controller)Ireland — European Union, with onward transfers to Google LLC (USA)Only what is needed to authenticate you, if you choose Google sign-in

We name our recipients here rather than describing vague “categories”. Each processor is bound by a data processing agreement meeting Article 28 GDPR. We never sell your data, and we share it with no advertiser and no data broker.

During the free beta, no payment details are collected and nothing is transmitted to any payment provider. If and when paid subscriptions open, Paddle.com Market Ltd (30 Old Bailey, London EC4M 7AU, United Kingdom) will act as Merchant of Record and as an independent controller for the purchase; this policy will be updated beforehand.

5. Transfers outside the European Union

Hosting and storage take place within the European Union, with no transfer to a third country. The only possible transfer concerns Sign-in with Google, if you choose it: Google Ireland Ltd may transfer data to Google LLC in the United States, on the basis of the EU–US Data Privacy Framework, under which Google LLC is certified.

You may obtain a copy of the safeguards applying to these transfers by writing to privacy@arcabudget.app. Certifications can also be checked on the Data Privacy Framework register.

6. Security

The measures we apply (Article 32 GDPR):

  • encryption at rest: the database, the backups and the swap file live on an encrypted volume (LUKS); the backups are additionally encrypted with a public key whose private half is not on the server;
  • your password never reaches us: your browser derives a fingerprint from it (PBKDF2-HMAC-SHA256, 600,000 iterations) and sends only that, which we re-hash with Argon2id;
  • two-factor authentication (TOTP) and passkeys available on your account;
  • encryption in transit (HTTPS/TLS) for every exchange;
  • passwords stored as salted hashes, never in clear;
  • short-lived sessions with rotating refresh tokens, revocable at any time;
  • rate limiting and brute-force protection;
  • an audit log kept separately from application data;
  • hosting within the European Union.

In the event of a data breach, we notify the CNIL (Commission Nationale de l'Informatique et des Libertés) within 72 hours where Article 33 GDPR requires it. We do not claim the exemption in Article 34(3)(a): it assumes data made unintelligible to a third party, which encryption at rest does not deliver against access obtained on a running machine. A breach affecting the contents of budgets would therefore be notified to you. Where there is any doubt, we undertake to inform you anyway.

7. Your rights

You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and not to be subject to automated decision-making (Art. 22). Here is honestly what each one means given the encryption:

  • Access and portability. Your budget is exportable at any time, for free, from the app, in an open format (arca.vault.v1). On request we additionally provide everything we hold on our side (email address and its hash, identifiers, metadata, logs).
  • Rectification. You correct the contents of your budget from the app; we correct your account details on request.
  • Erasure. Fully available. Deleting your account removes the contents of your budget, the metadata, your email address and its hash, and the tokens. Backups are purged within 30 days. Audit-log entries may be kept until the end of their retention period, on the security ground set out in section 3.
  • Restriction. You may ask us to suspend the processing based on legitimate interest (diagnostics, audit log) while a request is being examined.
  • Automated decisions. We make none. No profiling, no scoring, no automated decision producing legal effects for you.

We reply within one month (Art. 12(3)), extendable by two months for complex requests, in which case we tell you within the first month. If we cannot act on a request, we explain why, and you may lodge a complaint or seek a judicial remedy (Art. 12(4)).

Your right to object (Art. 21 GDPR)

You may object at any time, on grounds relating to your particular situation, to the processing we carry out on the basis of our legitimate interest — namely diagnostics and the audit log. Write to privacy@arcabudget.app. We will stop that processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms.

8. Directives on your data after death

Under Article 85 of the French Data Protection Act, you may give directives on the retention, erasure and communication of your data after your death — either general directives registered with a certified trusted third party, or specific directives sent to us at privacy@arcabudget.app. We are able to act on those directives: the contents of your budget are accessible to us, and are therefore not lost with you.

9. Lodging a complaint

If you consider that your rights are not respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — https://www.cnil.fr. We would rather you write to us first, but that is your right and it is not conditional on contacting us.

10. Cookies and local storage

This site and the app show no cookie banner, because we place no tracking cookie. No advertising, no third-party analytics. We store only what is strictly necessary for the service you asked for:

ItemPurposeLifetime
Session tokenKeeping you signed inSession, renewed while you are active
Refresh tokenAvoiding signing you out every hour30 days, rotated on each use and revoked on sign-out
Preferences (language, theme, currency)Showing the interface the way you set itUntil you clear your browser data
Local copy of your budgetMaking the app work, stay fast and remain usable offlineUntil you sign out or clear your browser data

These items are exempt from consent under Article 82 of the French Data Protection Act, being strictly necessary to provide a service you expressly requested.

Audience measurement on this marketing site

We measure traffic on this marketing site only. In the app we do not observe your usage; we can only measure how long screens take, and only if you let us — see the next section. This site measurement sets no cookie and creates no identifier that would follow you.

For each page viewed, we record exactly three things:

DataPrecision keptRetention
Page viewedThe path only (never URL parameters, which could contain a personal link)13 months
Where you came fromThe site's name (“google.com”), never the full address nor your search terms13 months
Visit durationIn seconds13 months
Device typeThree families only — phone, tablet or computer — never the exact model or browser13 months
Browser languageThe main language only ("fr", "en"), never your full preference list13 months
CountryThe country alone ("France"), derived from the truncated address before it is discarded — never the city or region13 months

To count visitors without identifying them, your IP address — truncated first, that is, stripped of its ending, as the French regulator recommends — and your browser are turned into a one-way fingerprint, mixed with a random secret that is renewed every day and held in memory only. That secret is never written to disk: it vanishes each night. The direct consequence — nobody, not even us, can link your visit today to your visit tomorrow, or work back from a fingerprint to an IP address. Your IP address and browser are themselves never stored.

This measurement runs on our own servers, in Europe, for our use alone. No data is shared with a third party, cross-referenced with any other processing, or used to track you across sites. It therefore falls under the consent exemption for audience measurement in Article 82 of the French Data Protection Act — which is why this site does not confront you with a banner. Should we ever add a tracker that falls outside that exemption, we would ask for your consent beforehand.

App performance measurements — only if you agree

Some screens may be slow, and we cannot know it without measuring. You can help by turning on “Performance measurements” in the app settings. It is off by default, and nothing is measured until you say yes: the instruments themselves are not put in place.

If you agree, each measurement contains exactly this:

DataPrecision keptRetention
Screen concernedA name from a fixed list (“budget”, “transactions”…), never the address — which would carry an account identifier90 days
DurationIn milliseconds: time to display, or time to respond to a gesture, broken into waiting, computing and painting90 days
App versionThe version number alone90 days
Vault sizeAn order of magnitude (“between 2,000 and 5,000 transactions”), never the exact count — an exact count would almost certainly single you out90 days
Device typeThree families — mobile, tablet, computer90 days

What is never in it: no transaction, no amount, no payee, no envelope, no account name, no date from your budget. There is no field where any of these could go, not even by a programming mistake.

These measurements are not linked to your account. They are sent without your sign-in token, to an address that does not ask for one: our servers therefore have no way to match a measurement to a person, even if they wanted to. They carry the same daily fingerprint as the site measurement — truncated IP address, secret renewed every night and never stored — which serves only to avoid counting the same session ten times in one day, and allows nothing else.

Legal basis: your consent — GDPR art. 6(1)(a). We keep the record of that agreement separately (your account, the date, and the version of the text you read), because the law requires us to be able to show it. You can withdraw at any time from the same setting; withdrawal takes effect immediately, and it is as easy to take back as it was to give.

11. Free beta and future billing

Arca is currently in free public beta. We collect no payment details, and no billing provider receives any data about you. Arca will become paid one day: you will be informed at least 60 days in advance, by email, and nothing will ever be charged to you without an explicit order on your part. This policy will be updated before any payment processing begins.

12. Changes to this policy

If we change this policy, we update the date at the top of this page. For any change that materially affects your rights or introduces a new purpose, we inform you by email before it takes effect (Art. 13(3)).

13. Contact

Privacy: privacy@arcabudget.app · Support: support@arcabudget.app
Takieddine Boumerah — France
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany

Arca BudgetFR

Product

FeaturesSecurityBeta

Resources

GuidesDocumentation

Account

Sign inCreate account
© 2026 Arca · Envelope budgeting
TermsPrivacyRefundsLegal notice