Skip to content

Privacy policy

Arc collects as little as it can: what it needs to run accounts, sell Pro, send the emails you asked for, and count visits. No ads and no cross-site tracking.

On this page
  1. Who is responsible
  2. What we collect
  3. Visiting the site
  4. Visitor statistics
  5. Waitlist and email
  6. Accounts
  7. Payments
  8. Pro tokens, CLI and MCP
  9. When you write to us
  10. Cookies and local storage
  11. Service providers
  12. Transfers abroad
  13. How long we keep data
  14. Your rights
  15. Security
  16. Children
  17. Changes

Who is responsible

The controller for the processing described here is:

This policy follows the Swiss Federal Act on Data Protection (nFADP) and, where it applies to you, the EU and UK General Data Protection Regulation (GDPR). It covers uiarc.dev, the registry at uiarc.dev/r, the MCP server, and the emails we send.

What we collect

DataWhenWhy and legal basis
Request data: IP address, browser, page, timeEvery visitTo deliver the site and keep it secure. Legitimate interest (GDPR Art. 6(1)(f)).
Email address, signup source, referring page, country, confirmation and unsubscribe datesYou join the waitlistTo send the launch emails you asked for. Consent (Art. 6(1)(a)), given by double opt-in.
Name, email, password (hashed by Clerk), sign-in provider, sign-in history, onboarding answersYou create an accountTo run your account. Contract (Art. 6(1)(b)).
Name, email, billing address, country, tax ID, plan, payment statusYou buy Arc ProTo sell and deliver Pro, and to keep accounting records. Contract and legal obligation (Art. 6(1)(b), (c)).
Token name, hashed token, creation and last use timeYou create a Pro tokenTo let your CLI and AI tools reach Pro. Contract (Art. 6(1)(b)).
Pages viewed, referrer, campaign tags, time zone, language, screen size, clicks on outgoing links, scroll depth, page speed, and for a sample of visits a recording of page interactions with form inputs maskedEvery visitVisitor statistics to improve the site. Legitimate interest (Art. 6(1)(f)). [Confirm with provider whether consent is needed for recordings in the EU.]
Your message and email addressYou write to usTo answer. Legitimate interest or contract.

We don’t use your data for automated decisions or profiling, and we don’t sell or rent it.

Visiting the site

The site runs on Cloudflare Workers. Cloudflare processes each request, including your IP address, to deliver the page, block attacks and limit abuse. Our Worker logs record the request path, status, time and errors to help us fix problems; these logs are kept for a few days. We don’t run advertising pixels, and fonts are served from our own domain, not from Google.

Visitor statistics

We use mrkr (mrkr.app) to count visits and understand which pages help people. Its script sends the page address, the referring page, campaign tags, your time zone, language and window size, clicks on links to other sites, how far you scroll, and page speed measurements. For a sample of visits it also records page interactions (clicks, scrolling and page changes) to show how the site is used; text you type into forms is masked and never recorded.

mrkr does not set cookies on this site. It keeps a random session ID in your browser’s session storage, which is deleted when you close the tab. Where mrkr stores the data, how long it keeps it, and its data processing terms: [confirm with provider].

Waitlist and email

  • When you join the waitlist we store your email address, where on the page you signed up, the referring page, and the country Cloudflare derives from your IP address. We send one confirmation email; you are only on the list once you confirm.
  • We then send a few emails about Arc’s launch. Every email has a one-click unsubscribe link. Unsubscribing takes effect at once.
  • Account and purchase emails, such as sign-in codes and receipts, are service emails and are sent by Clerk and Stripe.
  • Emails are sent through Cloudflare Email Service, and email to hello@uiarc.dev is received through Cloudflare Email Routing. Some of our email designs load web fonts from Google Fonts when your email app displays them, which shares your IP address with Google.

Accounts

Accounts are provided by Clerk. When you sign up, Clerk stores your email address, a hash of your password, your name if you give it, and security data such as sign-in times, IP address and device. If you sign in with Google or GitHub, you share your name, email address and profile picture from that provider with Clerk. Clerk uses Cloudflare Turnstile to block bots at sign-up.

We store your plan and billing status in your Clerk profile so the site knows you have Pro. The answers to the optional onboarding questions (what you build, your framework, package manager and AI tool) are stored there too and only personalize your welcome page.

Payments

Payments are handled by Stripe on Stripe’s checkout page. Stripe collects your payment details, name, email and billing address, and uses them to process the payment, prevent fraud and meet its legal duties; for this Stripe is also a controller of its own (see Stripe’s privacy policy). We receive the result: your name, email, country, billing address, tax ID if given, the plan, the amount and the payment status. We never receive your full card number.

We keep invoices and payment records for ten years because Swiss accounting law requires it.

Pro tokens, CLI and MCP

Requests to the registry and the MCP server are processed like any other request. When you use a Pro token, we store only a SHA-256 hash of the token, its name, when it was created and when it was last used, in a Cloudflare D1 database. We count requests per token to enforce rate limits. We don’t log what your AI tool asks the MCP server beyond the request itself.

When you write to us

If you email hello@uiarc.dev, we use your message and address to answer and keep the conversation as long as needed to help you, and no longer than two years after it ends, unless it relates to a purchase.

Cookies and local storage

We only use storage that the site needs to work. None of it tracks you across sites, so no consent banner is needed.

NameSet byPurpose
__session, __client_uat and related cookiesClerkKeep you signed in. Only set when you use an account.
Cookies on the checkout pageStripeFraud prevention during payment, on Stripe’s domain.
__pw_session_v1, __pw_last_unload (session storage)mrkrGroup page views into one visit. Deleted when you close the tab. No cookie.
arc-theme, arc-accent, arc-library-filter (local storage)ArcRemember your theme, accent and library filter. Never sent to us.

Service providers

These providers process personal data on our behalf, under data processing agreements, or, for Stripe payments, as independent controllers:

Transfers abroad

Some providers process data in the United States and other countries. Where a country does not have an adequate level of data protection recognized by Switzerland or the EU, transfers rely on the Swiss-U.S. and EU-U.S. Data Privacy Framework where the provider is certified, or on the European Commission’s standard contractual clauses with the Swiss amendments.

How long we keep data

  • Waitlist: until you unsubscribe, or until the list is no longer used. Unconfirmed signups are deleted after 30 days.
  • Accounts: until you delete your account. Deleting it removes your profile from Clerk, and your Pro tokens stop working at once. We delete their records when we next clean up, or right away on request.
  • Payment and invoice records: ten years, as Swiss law requires.
  • Server logs: a few days.
  • Visitor statistics: [confirm with provider].
  • Pro tokens: revoked tokens stay in your token history until you delete your account.

Your rights

You can ask us to tell you what data we hold about you and give you a copy, correct it, delete it, restrict or object to its processing, and hand it over in a portable format. Where processing is based on consent, you can withdraw consent at any time; for emails, the unsubscribe link does this in one click. Write to hello@uiarc.dev. We answer within 30 days and may ask you to confirm your identity.

You can complain to a supervisory authority: in Switzerland the Federal Data Protection and Information Commissioner (FDPIC, edoeb.admin.ch), in the EU the authority of your country of residence, and in the UK the Information Commissioner’s Office.

Security

All traffic is encrypted with HTTPS. Pro tokens are stored only as hashes, secrets live in encrypted Cloudflare storage, and only the owner has access to production systems. No system is perfectly secure; if a breach affects your data, we will tell you and the authorities as the law requires.

Children

Arc is made for developers and designers and is not directed at children. You must be at least 16 to create an account. If you think a child has given us data, write to us and we will delete it.

Changes

We update this policy when Arc or the law changes. The date at the top shows the latest version. For material changes we will email account holders in advance. The terms of service and imprint have more about who we are.