Privacy policy
Arc collects as little as it can: what it needs to run accounts, sell Pro, send the emails you asked for, and count visits. No ads and no cross-site tracking.
Draft, pending review. This text has not been reviewed by a lawyer yet and may change before launch.
On this page
Who is responsible
The controller for the processing described here is:
- Controller
- Elia Kuratli (sole proprietorship, trading as Arc)
- Address
- Unterfeldstrasse 3D, 8500 Frauenfeld, Switzerland, Switzerland
- hello@uiarc.dev
This policy follows the Swiss Federal Act on Data Protection (nFADP) and, where it applies to you, the EU and UK General Data Protection Regulation (GDPR). It covers uiarc.dev, the registry at uiarc.dev/r, the MCP server, and the emails we send.
What we collect
| Data | When | Why and legal basis |
|---|---|---|
| Request data: IP address, browser, page, time | Every visit | To deliver the site and keep it secure. Legitimate interest (GDPR Art. 6(1)(f)). |
| Email address, signup source, referring page, country, confirmation and unsubscribe dates | You join the waitlist | To send the launch emails you asked for. Consent (Art. 6(1)(a)), given by double opt-in. |
| Name, email, password (hashed by Clerk), sign-in provider, sign-in history, onboarding answers | You create an account | To run your account. Contract (Art. 6(1)(b)). |
| Name, email, billing address, country, tax ID, plan, payment status | You buy Arc Pro | To sell and deliver Pro, and to keep accounting records. Contract and legal obligation (Art. 6(1)(b), (c)). |
| Token name, hashed token, creation and last use time | You create a Pro token | To let your CLI and AI tools reach Pro. Contract (Art. 6(1)(b)). |
| Pages viewed, referrer, campaign tags, time zone, language, screen size, clicks on outgoing links, scroll depth, page speed, and for a sample of visits a recording of page interactions with form inputs masked | Every visit | Visitor statistics to improve the site. Legitimate interest (Art. 6(1)(f)). [Confirm with provider whether consent is needed for recordings in the EU.] |
| Your message and email address | You write to us | To answer. Legitimate interest or contract. |
We don’t use your data for automated decisions or profiling, and we don’t sell or rent it.
Visiting the site
The site runs on Cloudflare Workers. Cloudflare processes each request, including your IP address, to deliver the page, block attacks and limit abuse. Our Worker logs record the request path, status, time and errors to help us fix problems; these logs are kept for a few days. We don’t run advertising pixels, and fonts are served from our own domain, not from Google.
Visitor statistics
We use mrkr (mrkr.app) to count visits and understand which pages help people. Its script sends the page address, the referring page, campaign tags, your time zone, language and window size, clicks on links to other sites, how far you scroll, and page speed measurements. For a sample of visits it also records page interactions (clicks, scrolling and page changes) to show how the site is used; text you type into forms is masked and never recorded.
mrkr does not set cookies on this site. It keeps a random session ID in your browser’s session storage, which is deleted when you close the tab. Where mrkr stores the data, how long it keeps it, and its data processing terms: [confirm with provider].
Waitlist and email
- When you join the waitlist we store your email address, where on the page you signed up, the referring page, and the country Cloudflare derives from your IP address. We send one confirmation email; you are only on the list once you confirm.
- We then send a few emails about Arc’s launch. Every email has a one-click unsubscribe link. Unsubscribing takes effect at once.
- Account and purchase emails, such as sign-in codes and receipts, are service emails and are sent by Clerk and Stripe.
- Emails are sent through Cloudflare Email Service, and email to hello@uiarc.dev is received through Cloudflare Email Routing. Some of our email designs load web fonts from Google Fonts when your email app displays them, which shares your IP address with Google.
Accounts
Accounts are provided by Clerk. When you sign up, Clerk stores your email address, a hash of your password, your name if you give it, and security data such as sign-in times, IP address and device. If you sign in with Google or GitHub, you share your name, email address and profile picture from that provider with Clerk. Clerk uses Cloudflare Turnstile to block bots at sign-up.
We store your plan and billing status in your Clerk profile so the site knows you have Pro. The answers to the optional onboarding questions (what you build, your framework, package manager and AI tool) are stored there too and only personalize your welcome page.
Payments
Payments are handled by Stripe on Stripe’s checkout page. Stripe collects your payment details, name, email and billing address, and uses them to process the payment, prevent fraud and meet its legal duties; for this Stripe is also a controller of its own (see Stripe’s privacy policy). We receive the result: your name, email, country, billing address, tax ID if given, the plan, the amount and the payment status. We never receive your full card number.
We keep invoices and payment records for ten years because Swiss accounting law requires it.
Pro tokens, CLI and MCP
Requests to the registry and the MCP server are processed like any other request. When you use a Pro token, we store only a SHA-256 hash of the token, its name, when it was created and when it was last used, in a Cloudflare D1 database. We count requests per token to enforce rate limits. We don’t log what your AI tool asks the MCP server beyond the request itself.
When you write to us
If you email hello@uiarc.dev, we use your message and address to answer and keep the conversation as long as needed to help you, and no longer than two years after it ends, unless it relates to a purchase.
Cookies and local storage
We only use storage that the site needs to work. None of it tracks you across sites, so no consent banner is needed.
| Name | Set by | Purpose |
|---|---|---|
__session, __client_uat and related cookies | Clerk | Keep you signed in. Only set when you use an account. |
| Cookies on the checkout page | Stripe | Fraud prevention during payment, on Stripe’s domain. |
__pw_session_v1, __pw_last_unload (session storage) | mrkr | Group page views into one visit. Deleted when you close the tab. No cookie. |
arc-theme, arc-accent, arc-library-filter (local storage) | Arc | Remember your theme, accent and library filter. Never sent to us. |
Service providers
These providers process personal data on our behalf, under data processing agreements, or, for Stripe payments, as independent controllers:
- Cloudflare, Inc. (USA)
- Hosting (Workers), content delivery, security, databases (D1), rate limiting, email sending and receiving, logs.
- Clerk, Inc. (USA)
- Accounts, sign-in, sessions, bot protection.
- Stripe (Stripe Payments Europe, Ltd., Ireland, and Stripe, Inc., USA)
- Payments, subscriptions, invoices, tax calculation, fraud prevention.
- mrkr (mrkr.app)
- Visitor statistics and sampled session recordings. Company and location: [confirm with provider].
- Google LLC and GitHub, Inc. (USA)
- Only if you choose to sign in with them.
Transfers abroad
Some providers process data in the United States and other countries. Where a country does not have an adequate level of data protection recognized by Switzerland or the EU, transfers rely on the Swiss-U.S. and EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s standard contractual clauses with the Swiss amendments.
How long we keep data
- Waitlist: until you unsubscribe, or until the list is no longer used. Unconfirmed signups are deleted after 30 days.
- Accounts: until you delete your account. Deleting it removes your profile from Clerk, and your Pro tokens stop working at once. We delete their records when we next clean up, or right away on request.
- Payment and invoice records: ten years, as Swiss law requires.
- Server logs: a few days.
- Visitor statistics: [confirm with provider].
- Pro tokens: revoked tokens stay in your token history until you delete your account.
Your rights
You can ask us to tell you what data we hold about you and give you a copy, correct it, delete it, restrict or object to its processing, and hand it over in a portable format. Where processing is based on consent, you can withdraw consent at any time; for emails, the unsubscribe link does this in one click. Write to hello@uiarc.dev. We answer within 30 days and may ask you to confirm your identity.
You can complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch), in the EU the authority of your country of residence, and in the UK the Information Commissioner’s Office.
Security
All traffic is encrypted with HTTPS. Pro tokens are stored only as hashes, secrets live in encrypted Cloudflare storage, and only the owner has access to production systems. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.
Children
Arc is made for developers and designers and is not directed at children. You must be at least 16 to create an account. If you think a child has given us data, write to us and we will delete it.
Changes
We update this policy when Arc or the law changes. The date at the top shows the latest version. For material changes we will email account holders in advance. The terms of service and imprint have more about who we are.