Arco — Privacy Policy
Last updated: 2026-09-04
Arco is a personal finance tracker. This policy explains what data Arco handles and how. It is written to be accurate to how the app actually works — in plain language.
Arco is provided by Arco Labs PH, based in the Republic of the Philippines, the Personal Information Controller responsible for your personal data under the Data Privacy Act of 2012 (RA 10173). You can reach us about this policy or any data request at dev@arcobudget.com.
The short version
- Arco works fully offline and without an account. If you never sign in, Arco is designed so that your financial data stays on your device and is not sent to our servers.
- Signing in is optional. Apart from optional crash diagnostics you can turn off (see Diagnostics), signing in is the only thing that sends your financial data off your device — it exists purely to sync your data across your own devices.
- If you subscribe to Arco Pro, the payment is handled entirely by Google Play, the Apple App Store, or Lemon Squeezy — we never see your card details (see Payments and subscriptions).
- Arco shows no ads and contains no third-party advertising trackers. Arco uses limited, privacy-respecting diagnostics (crash and error reporting) to stay reliable — never to advertise to you or to sell your data.
What Arco stores on your device
Your accounts, transactions, categories, budgets, recurring rules, and notes are stored locally on your device. Appearance and currency settings, and — if you enable App Lock — a PIN verifier (a salted one-way hash; your PIN itself is never stored) are also stored locally. Uninstalling the app, or using Reset all data in the app, removes this local data.
What is sent off your device when you sign in
Separately, optional crash diagnostics may be sent even without an account — see Diagnostics below. Also without being signed in: if you ask to reset your password, the email address you type is sent so a one-time code can be emailed to you.
If you create an account and sign in, the following are transmitted, over encrypted connections (HTTPS), to enable cross-device sync:
- Your email address, to create and authenticate your account, and to send you a password-reset code if you ask for one.
- Your financial data (accounts, transactions, categories, budgets, recurring rules, and notes), stored in your account so it can appear on your other signed-in devices.
- Support messages you choose to send from the in-app Contact support thread (Profile → About → Contact support), stored in your account so we can read and reply to them. Only messages you type there are sent — this feature is available only while you're signed in. So that we notice and answer promptly, a message you send there — along with the email address on your account — is also delivered to our own private support inbox on a third-party messaging provider.
- A notification token for this device, on Android only, so we can tell you a support reply has arrived. It is a random identifier Google issues to this installation of Arco — not to you, and not tied to your phone or SIM. It is registered when you sign in on Android, which happens before we ask you about notifications and whether or not you allow them. See Notifications.
- A statement image or PDF you choose to import, together with the names of your own categories (Statement import — see the dedicated section below). Only a document you explicitly pick or photograph for import is sent, and only to extract its transactions; your category names are sent with it so the suggested category for each line is one you already use. Neither is stored on our servers afterward. No other data from your account — no amounts, balances, accounts or existing transactions — is sent.
This data is processed by our backend service providers acting on our behalf:
- Supabase — authentication and database hosting.
- PowerSync — the sync service that keeps your devices up to date.
- Anthropic — the AI provider that reads an imported statement to extract its transactions (Statement import only; see below).
- A third-party messaging provider — hosts the private inbox we read and answer support messages in (Contact support), and receives the operational alerts we send ourselves when a subscription record fails to save, or saves in a way that needs a human to look at it — so a payment that didn't reach your account gets fixed instead of going unnoticed. Those alerts carry your account id, the store's subscription id, which store it is, whether the subscription is active and the date it is paid through, and — where one Apple ID is shared between two Arco accounts — the id of the other account. They carry no name, no email address, and none of your financial data.
- Google (Firebase Cloud Messaging) — delivers the notification that tells you a support reply has arrived, on Android only. It carries no message content — see Notifications below.
- An email delivery provider — delivers the one-time code that lets you reset your password (password reset only — sent whether or not you are signed in).
These providers — together with Sentry (diagnostics), Frankfurter (exchange rates) and, if you subscribe, Google Play, the Apple App Store, or Lemon Squeezy (payments — see Payments and subscriptions) — process data on servers outside the Philippines. Where your personal data is transferred abroad, we remain accountable for it under the Data Privacy Act. Each provider that handles your personal data is engaged under written terms that give your data the same or an equal level of protection as this policy sets out — they must keep it confidential, secure it in transit and at rest, process it only on our instructions and for no purpose of their own, and delete or return it when we ask. We do not sell your data or share it for advertising.
Notifications
On Android, Arco can send you a notification when support replies to your message. This is the only notification Arco ever sends — there is no marketing, no re-engagement, and no other kind of alert.
- You are asked first, once. The request appears right after you send your first support message, and once you answer it — either way — you are never asked again. Leaving the thread with the question still up does not count as an answer: it is dropped and raised again after your next message, so the ask always belongs to a send you just made. If you decline, nothing is shown to you unless you later turn notifications on for Arco in your phone's settings, and the unread mark on the Profile tab is what tells you a reply arrived. Declining does not undo the token: it is registered when you sign in, before the request appears, and a reply still sends the same content-free message to your device — your phone just shows nothing for it.
- The notification contains no message content. It says only that support replied. The reply's text is never put in the notification — your device already has it from sync, and reads it from there. This is deliberate: it keeps the content away from the delivery provider, and stops a reply appearing on the lock screen of a shared phone.
- What is sent to Google to deliver it: the notification token for your device, the fixed wording above, and your account identifier — a random id, not your email — which your device uses to check the notification is meant for the account currently signed in on it.
- The token is removed when you sign out, and when you delete your account. If your device is offline at sign-out, the token stops being used the next time anyone signs in on that device, or once Google reports it as no longer valid.
- On desktop, the equivalent notification is produced by the app itself while it is running and nothing is sent to a delivery provider. On iOS there are no notifications at all.
Statement import
Statement import is optional and runs only when you choose it. When you photograph or upload a bank statement or receipt to import it:
- The document is sent over an encrypted connection to our backend (Supabase), which forwards it to our AI provider (Anthropic) purely to read the line items, work out what kind of statement it is (so each line is read the right way round) and suggest a category for each. Nothing happens until you tap to import a document, and the first time you do, a one-time in-app notice explains this and asks you to agree.
- The names of your categories are sent with the document — just the names (for example Groceries, Transport, Salary), so the suggestion for each line can be a category you already use instead of a made-up one you'd then have to correct by hand. Nothing else from your account goes with it: not your amounts, balances, account names or existing transactions. Your ledger is never sent to the AI provider, and checking a statement for lines that look like transactions you already have is done entirely on your device.
- Our servers do not store the statement image or the extracted text. The document is passed through to the AI provider and the result is returned to your device; the only thing we record is a per-account count of how many imports you've run (to enforce fair-use limits) — never any statement content.
- On your device, a photo you take for import is written to a temporary file that is deleted as soon as its contents have been read for upload — it is not kept in your gallery or the app's storage.
- Password-protected PDFs are unlocked on your device, and the password never leaves it. If a statement PDF needs a password, Arco asks you for it, uses it once, in memory, on your device to remove the file's encryption, and then discards it: the password is never written to disk, never saved, never included in a backup, and never transmitted to us or to the AI provider. Only the unlocked statement is uploaded, exactly as an ordinary PDF would be. (Many bank statements are merely restricted against printing or copying rather than locked shut; those are unlocked without asking you for anything.)
- At the AI provider (Anthropic): your document is processed only to extract the transactions and is not used to train models. Anthropic may retain it briefly for trust-and-safety and abuse-prevention purposes before deleting it, per its own retention practices. We do not claim it is deleted instantly. Anthropic handles the document as our processor under its commercial terms and data processing agreement, which give it the same or an equal level of protection as this policy sets out: it is used only to answer our request, it is not used to train models, and it is not disclosed to anyone else for any other purpose.
- The transactions you review and choose to save are then stored like any other data you enter — on your device, and in your account if you're signed in (Statement import requires an account).
Payments and subscriptions (Arco Pro)
Cloud sync and statement import are part of an optional paid subscription, Arco Pro. Imports are subject to a fair-use daily limit, so that one account can't run up an unbounded processing bill; if you reach it, Arco says so and the limit resets the next day. Arco remains fully usable for free on a single device, and if you never subscribe, nothing in this section applies to you.
We never see or handle your card. Payment is taken entirely by the store you buy through, and card numbers are never sent to, or stored by, Arco:
- On Android, the purchase runs through Google Play's billing system. Google is the seller and handles the payment.
- On iOS, the purchase runs through the Apple App Store's in-app purchase system. Apple is the seller and takes the payment, under its own privacy policy. Your subscription is managed in the App Store (Settings ▸ your name ▸ Subscriptions), not in Arco.
- On desktop, the purchase runs through a Lemon Squeezy checkout page opened in your browser. Lemon Squeezy acts as the Merchant of Record: it is the legal seller of the subscription, and it collects the billing details it needs (such as your name, email, and the country or tax information required to charge you correctly) directly from you, under its own privacy policy.
To connect a purchase to the right account, Arco passes your account identifier (the internal ID of your signed-in account, not your email) to the store at checkout. The store then tells our server about the subscription's status.
What we store is only what's needed to know whether your account is entitled to Pro: your account identifier, whether the subscription is currently active, which store it came from, the date it expires or renews, the product purchased, the store's own identifier for the subscription — that one is how a renewal, a cancellation, or a resubscription that happens outside the app (in the App Store, the Play Store, or our web checkout) is matched back to your account — and the date we last updated this record. Because you can hold a subscription with more than one store over time, and more than one at the same store, we keep each subscription's date separately from the others, so one lapsing can never cut short the one you are actually paying for; that also means the record can show which stores you hold a subscription with. We do not receive or store your card number, bank details, or billing address.
We also keep a short note when a purchase needs our attention: it couldn't be matched to an account, or the store wouldn't accept our confirmation. The note is what stops us flagging the same purchase twice. It holds the store's identifier for that purchase and no account details.
Your entitlement record is deleted when you delete your account, along with every store identifier we keep to match your subscriptions. The operational note holds no account details, so once your account is gone, there is nothing left in it that points back to you.
Why we process your data (legal basis)
Where you sign in, we process your email and financial data to perform the sync you ask for, and any support messages you send to answer your support requests (contract). If you subscribe to Arco Pro, we process your subscription record to give you the paid features you bought (contract). We process crash diagnostics with your consent (on by default, with an opt-out in settings) and our legitimate interest in keeping Arco reliable. If you never sign in and turn diagnostics off, we process no personal data about you on our servers.
Exchange rates
To show amounts in your chosen currency, Arco fetches public exchange-rate data from Frankfurter (European Central Bank reference rates). Only currency codes are included in the request — we do not send your account, email, or financial data with it. As with any internet request, your device's IP address is visible to the service.
Diagnostics (crash and error reporting)
To keep Arco reliable, the app reports crashes and technical errors to Sentry, a diagnostics service acting on our behalf. This is on by default, and you can turn it off in the app's settings. The reports contain technical information (such as the error and device/app details) to help us fix problems; they are configured not to attach personal identifiers (sendDefaultPii=false) and we apply scrubbing designed to remove personal and financial details before reports are sent. Crash diagnostics are not used to advertise to you and are never sold. This is the one thing Arco may send off your device even if you never sign in — turning the setting off stops it.
Security
Connections use HTTPS. App Lock (optional) gates the app with a 6-digit PIN and, where available, biometrics; the PIN is never stored — only a salted PBKDF2 verifier held in your platform's secure storage (Android Keystore / iOS Keychain).
No method of transmission or storage is completely secure, so while we take reasonable steps to protect your data, we can't guarantee absolute security.
If a personal-data breach likely to cause you real harm occurs, we will notify you and the National Privacy Commission as required by the Data Privacy Act.
Retaining and deleting your data
We keep your synced data for as long as your account exists, and you can remove it at any time:
- Local data: use Reset all data in the app, or uninstall.
- Synced data: signing out clears the copy on that device, and running Reset all data while signed in also clears your data across your other devices. If you have an account, Profile → Delete account deletes the account and the data synced to it — removed from our live systems promptly, with residual copies in encrypted backups overwritten in the ordinary course (typically within 30 days), and diagnostic reports deleted by our diagnostics provider after its standard retention period, except where we must keep information to comply with law. Your subscription record is deleted with the account; the store's own record of the purchase is held by Google, Apple, or Lemon Squeezy under their policies, and cancelling a subscription is done through the store, not through Arco. Support messages already delivered to our private support inbox on the third-party messaging provider — and any operational alert about your subscription record sent to that same inbox — stay there as part of our records; deleting your account does not remove those copies, but we will delete them on request.
- You can also contact us at the address below to request deletion of your account and any associated data.
Your rights
Under the Data Privacy Act of 2012 (RA 10173) you may access the data we hold about you, correct it (you can edit your records directly in the app), object to or withdraw consent for processing, request erasure or blocking, and obtain a portable copy of your data (use Export or Backup in the app). You may also complain to the National Privacy Commission (privacy.gov.ph). To exercise any right, email dev@arcobudget.com and we'll respond within a reasonable period as required by law.
Children
Arco is intended for users 18 and older and is not directed to anyone under 18. We do not knowingly collect data from anyone under 18; if you believe a minor has provided us data, contact us and we will delete it.
Changes
We may update this policy; material changes will be reflected by the "Last updated" date above.
If Arco is acquired, merged, or its assets are transferred, your data may pass to the successor, which will remain bound by this policy or a materially equivalent one.
Contact
Questions or data requests: dev@arcobudget.com
This Privacy Policy forms part of Arco's Terms of Service. Except where a non-waivable law provides otherwise, the disclaimers and limitation of liability in the Terms apply to this policy and to your use of Arco.