Privacy Policy
In short
- Our servers hold your budget in the clear. That is what lets them do the arithmetic for you. Nobody on our team accesses it: no admin screen returns its contents.
- We also hold your email address — in the clear, so we can write to you, and as a hash so we can find your account at sign-in — plus an account identifier.
- The disks holding the database and the backups are encrypted at rest. That is not end-to-end encryption, and we do not call it that.
- No advertising, no resale, no tracking, no analytics cookies. That is why this site shows no cookie banner.
- Everything is hosted in the European Union.
- You can export everything from the app, at any time, for free.
- The beta is free: no payment details are collected at all.
- A forgotten password does not destroy your budget: resetting it gives you back the account and the data.
1. Who is responsible for your data
The data controller is Takieddine Boumerah (Entrepreneur individuel (EI)), trading as Arca Budget, SIREN 931302947, France. Contact for any privacy matter: privacy@arcabudget.app.
No Data Protection Officer has been appointed. None is required under Article 37 GDPR: we are a sole trader, we carry out no large-scale monitoring, and we process no special categories of data. Requests are handled directly by the controller at the address above.
2. What our servers hold, and what we see of it
Your budget — accounts, transactions, categories, amounts, notes — is stored in the clear on our servers. That is what lets them work out your balances, what is available and your month ahead once and for all, instead of redoing that work in every browser.
Until 25 August 2026 this was not the case: your budget was encrypted on your device and we only ever received unreadable blocks. We gave that up, and we write it here rather than let the word “encrypted” keep a false idea alive. The technical detail, and what it no longer protects against, are on the security page.
What we process is therefore, plainly, personal data:
- the contents of your budget;
- your email address — in the clear so we can write to you, and as a hash so we can find your account — and an opaque identifier if you sign in with Google;
- technical metadata for routing and ordering: identifier, vault identifier, record type, last-modified timestamp, deletion marker;
- connection and security records (see the table in section 3).
What we undertake not to do. Nobody on our team accesses the contents of a budget: the admin console only ever returns metadata — a record count, dates, a subscription state — and no endpoint exposes a transaction. Admin actions are logged. If support ever needed access to help you, it would be with your explicit consent, and it would leave a trace. We do not sell or hand over your data, and we draw no advertising from it.
3. What we process, why, on what legal basis, and for how long
| Data | Purpose | Legal basis (Art. 6 GDPR) | Retention |
|---|---|---|---|
| Email address (and its hash), password hash, Google identifier | Creating your account, signing you in | Performance of a contract — 6(1)(b) | Until you delete your account, or 24 months of inactivity, after a warning email |
| Performance measurements: screen name, durations, app version, order of magnitude of vault size, device type | Finding and fixing slow screens in the app | Consent — 6(1)(a). Off by default, revocable at any time | 90 days |
| The contents of your budget and its routing metadata | Storing, syncing and computing your budget — this is the service | Performance of a contract — 6(1)(b) | Until you delete your account. Purged within 30 days of account deletion |
| Email address, message content | Transactional email only: address verification, password reset, security alerts | Performance of a contract — 6(1)(b) | Deleted once sent; failed messages purged after retries |
| Session and refresh tokens | Keeping you signed in; revoking access on sign-out | Performance of a contract — 6(1)(b) | 30 days, rotated on each use and revoked on sign-out |
| Audit log of sensitive actions (sign-in, account changes) | Security of the service and traceability of actions affecting your account | Legitimate interest — 6(1)(f) | 12 months |
| Rate-limiting and anti-abuse records | Preventing brute-force and fraudulent access attempts | Legitimate interest — 6(1)(f) | 12 months |
| Diagnostics (app version, operating system, device model — redacted on your device) | Diagnosing crashes and defects | Legitimate interest — 6(1)(f) | 90 days |
The legitimate interests we rely on are named above, one by one, as Article 13(1)(d) requires: securing the service, tracing actions that affect your account, preventing abuse, and diagnosing defects. We have carried out and documented a balancing test for each.
Is providing this data required? An email address is contractually necessary to create an account: without it we cannot provide the service and no account can be created. Everything else listed above is generated by using the service.
Financial data is not a “special category” within the meaning of Article 9 GDPR, and we process no special-category data.
4. Who receives your data
| Recipient | Role | Location | What they receive |
|---|---|---|---|
| Hetzner Online GmbH | Hosting (processor) | Germany — European Union | Your budget (accounts, transactions, categories, amounts, notes), account records, logs. Stored on encrypted disks. |
| Zoho Corporation B.V. (ZeptoMail) | Transactional email (processor) | Utrecht, Netherlands — European Union | Your email address and the content of transactional messages |
| Google Ireland Ltd | Sign-in with Google (independent controller) | Ireland — European Union, with onward transfers to Google LLC (USA) | Only what is needed to authenticate you, if you choose Google sign-in |
We name our recipients here rather than describing vague “categories”. Each processor is bound by a data processing agreement meeting Article 28 GDPR. We never sell your data, and we share it with no advertiser and no data broker.
During the free beta, no payment details are collected and nothing is transmitted to any payment provider. If and when paid subscriptions open, Paddle.com Market Ltd (30 Old Bailey, London EC4M 7AU, United Kingdom) will act as Merchant of Record and as an independent controller for the purchase; this policy will be updated beforehand.
5. Transfers outside the European Union
Hosting and storage take place within the European Union, with no transfer to a third country. The only possible transfer concerns Sign-in with Google, if you choose it: Google Ireland Ltd may transfer data to Google LLC in the United States, on the basis of the EU–US Data Privacy Framework, under which Google LLC is certified.
You may obtain a copy of the safeguards applying to these transfers by writing to privacy@arcabudget.app. Certifications can also be checked on the Data Privacy Framework register.
6. Security
The measures we apply (Article 32 GDPR):
- encryption at rest: the database, the backups and the swap file live on an encrypted volume (LUKS); the backups are additionally encrypted with a public key whose private half is not on the server;
- your password never reaches us: your browser derives a fingerprint from it (PBKDF2-HMAC-SHA256, 600,000 iterations) and sends only that, which we re-hash with Argon2id;
- two-factor authentication (TOTP) and passkeys available on your account;
- encryption in transit (HTTPS/TLS) for every exchange;
- passwords stored as salted hashes, never in clear;
- short-lived sessions with rotating refresh tokens, revocable at any time;
- rate limiting and brute-force protection;
- an audit log kept separately from application data;
- hosting within the European Union.
In the event of a data breach, we notify the CNIL (Commission Nationale de l'Informatique et des Libertés) within 72 hours where Article 33 GDPR requires it. We do not claim the exemption in Article 34(3)(a): it assumes data made unintelligible to a third party, which encryption at rest does not deliver against access obtained on a running machine. A breach affecting the contents of budgets would therefore be notified to you. Where there is any doubt, we undertake to inform you anyway.
7. Your rights
You have the rights of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and not to be subject to automated decision-making (Art. 22). Here is honestly what each one means given the encryption:
- Access and portability. Your budget is exportable at any time, for free, from the app, in an open format (
arca.vault.v1). On request we additionally provide everything we hold on our side (email address and its hash, identifiers, metadata, logs). - Rectification. You correct the contents of your budget from the app; we correct your account details on request.
- Erasure. Fully available. Deleting your account removes the contents of your budget, the metadata, your email address and its hash, and the tokens. Backups are purged within 30 days. Audit-log entries may be kept until the end of their retention period, on the security ground set out in section 3.
- Restriction. You may ask us to suspend the processing based on legitimate interest (diagnostics, audit log) while a request is being examined.
- Automated decisions. We make none. No profiling, no scoring, no automated decision producing legal effects for you.
We reply within one month (Art. 12(3)), extendable by two months for complex requests, in which case we tell you within the first month. If we cannot act on a request, we explain why, and you may lodge a complaint or seek a judicial remedy (Art. 12(4)).
Your right to object (Art. 21 GDPR)
You may object at any time, on grounds relating to your particular situation, to the processing we carry out on the basis of our legitimate interest — namely diagnostics and the audit log. Write to privacy@arcabudget.app. We will stop that processing unless we demonstrate compelling legitimate grounds which override your interests, rights and freedoms.
8. Directives on your data after death
Under Article 85 of the French Data Protection Act, you may give directives on the retention, erasure and communication of your data after your death — either general directives registered with a certified trusted third party, or specific directives sent to us at privacy@arcabudget.app. We are able to act on those directives: the contents of your budget are accessible to us, and are therefore not lost with you.
9. Lodging a complaint
If you consider that your rights are not respected, you may lodge a complaint with the CNIL (Commission Nationale de l'Informatique et des Libertés): 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — https://www.cnil.fr. We would rather you write to us first, but that is your right and it is not conditional on contacting us.
10. Cookies and local storage
This site and the app show no cookie banner, because we place no tracking cookie. No advertising, no third-party analytics. We store only what is strictly necessary for the service you asked for:
| Item | Purpose | Lifetime |
|---|---|---|
| Session token | Keeping you signed in | Session, renewed while you are active |
| Refresh token | Avoiding signing you out every hour | 30 days, rotated on each use and revoked on sign-out |
| Preferences (language, theme, currency) | Showing the interface the way you set it | Until you clear your browser data |
| Local copy of your budget | Making the app work, stay fast and remain usable offline | Until you sign out or clear your browser data |
These items are exempt from consent under Article 82 of the French Data Protection Act, being strictly necessary to provide a service you expressly requested.
Audience measurement on this marketing site
We measure traffic on this marketing site only. In the app we do not observe your usage; we can only measure how long screens take, and only if you let us — see the next section. This site measurement sets no cookie and creates no identifier that would follow you.
For each page viewed, we record exactly three things:
| Data | Precision kept | Retention |
|---|---|---|
| Page viewed | The path only (never URL parameters, which could contain a personal link) | 13 months |
| Where you came from | The site's name (“google.com”), never the full address nor your search terms | 13 months |
| Visit duration | In seconds | 13 months |
| Device type | Three families only — phone, tablet or computer — never the exact model or browser | 13 months |
| Browser language | The main language only ("fr", "en"), never your full preference list | 13 months |
| Country | The country alone ("France"), derived from the truncated address before it is discarded — never the city or region | 13 months |
To count visitors without identifying them, your IP address — truncated first, that is, stripped of its ending, as the French regulator recommends — and your browser are turned into a one-way fingerprint, mixed with a random secret that is renewed every day and held in memory only. That secret is never written to disk: it vanishes each night. The direct consequence — nobody, not even us, can link your visit today to your visit tomorrow, or work back from a fingerprint to an IP address. Your IP address and browser are themselves never stored.
This measurement runs on our own servers, in Europe, for our use alone. No data is shared with a third party, cross-referenced with any other processing, or used to track you across sites. It therefore falls under the consent exemption for audience measurement in Article 82 of the French Data Protection Act — which is why this site does not confront you with a banner. Should we ever add a tracker that falls outside that exemption, we would ask for your consent beforehand.
App performance measurements — only if you agree
Some screens may be slow, and we cannot know it without measuring. You can help by turning on “Performance measurements” in the app settings. It is off by default, and nothing is measured until you say yes: the instruments themselves are not put in place.
If you agree, each measurement contains exactly this:
| Data | Precision kept | Retention |
|---|---|---|
| Screen concerned | A name from a fixed list (“budget”, “transactions”…), never the address — which would carry an account identifier | 90 days |
| Duration | In milliseconds: time to display, or time to respond to a gesture, broken into waiting, computing and painting | 90 days |
| App version | The version number alone | 90 days |
| Vault size | An order of magnitude (“between 2,000 and 5,000 transactions”), never the exact count — an exact count would almost certainly single you out | 90 days |
| Device type | Three families — mobile, tablet, computer | 90 days |
What is never in it: no transaction, no amount, no payee, no envelope, no account name, no date from your budget. There is no field where any of these could go, not even by a programming mistake.
These measurements are not linked to your account. They are sent without your sign-in token, to an address that does not ask for one: our servers therefore have no way to match a measurement to a person, even if they wanted to. They carry the same daily fingerprint as the site measurement — truncated IP address, secret renewed every night and never stored — which serves only to avoid counting the same session ten times in one day, and allows nothing else.
Legal basis: your consent — GDPR art. 6(1)(a). We keep the record of that agreement separately (your account, the date, and the version of the text you read), because the law requires us to be able to show it. You can withdraw at any time from the same setting; withdrawal takes effect immediately, and it is as easy to take back as it was to give.
11. Free beta and future billing
Arca is currently in free public beta. We collect no payment details, and no billing provider receives any data about you. Arca will become paid one day: you will be informed at least 60 days in advance, by email, and nothing will ever be charged to you without an explicit order on your part. This policy will be updated before any payment processing begins.
12. Changes to this policy
If we change this policy, we update the date at the top of this page. For any change that materially affects your rights or introduces a new purpose, we inform you by email before it takes effect (Art. 13(3)).
13. Contact
Privacy: privacy@arcabudget.app · Support: support@arcabudget.app
Takieddine Boumerah — France
Hosting: Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany
