ARCA

Privacy Policy

Last updated: 7 October 2026

1. Who we are

This Privacy Policy explains how ARCA collects, uses and protects your personal data when you use our Android app, iOS app and web app.

The data controller responsible for your personal data is:

If you have any questions about this policy or your data, contact us at the email above.

2. The short version

3. Data we collect

CategoryWhat it includesWhere it comes from
Account detailsName, email address, encrypted passwordYou, when you register
Connected account dataAccount balances; transaction history (income and expenditure); merchant names; transaction dates and amounts; account type and identifiersYour bank, via our Open Banking provider, only after you authorise it
Categories and insightsTransaction categories, budgets, spending summaries and any categories you editGenerated by the Service or entered by you
Technical and diagnostic dataDevice model, operating system version, app version, crash reports and error logsYour device, automatically
Support messagesAnything you send us by email or feedback formYou

We do not collect your online banking username or password. You enter those only with your bank.

4. How we use your data and our legal basis

UK data protection law requires a legal basis for each use of your data. Ours are:

PurposeData usedLegal basis (UK GDPR)
Create and run your accountAccount detailsPerformance of our contract with you
Aggregate your connected accounts and show dashboards, charts and summariesConnected account dataPerformance of our contract with you
Categorise transactions (e.g. income, groceries) and provide spending insightsConnected account data, categoriesPerformance of our contract with you
Fix bugs, keep the Service secure and prevent misuseTechnical and diagnostic dataOur legitimate interests in running a reliable, secure service
Respond to support requestsSupport messages, account detailsOur legitimate interests in helping you
Manage paid subscriptionsPayment dataPerformance of our contract with you
Meet legal obligationsAny relevant dataLegal obligation

Accessing your bank data also requires your explicit authorisation, which you give through the Open Banking connection flow (see section 5). We do not use your data for advertising or marketing profiling.

5. Connecting your bank: read-only access

Connecting a bank account is optional. If you choose to connect one, we use Open Banking through TrueLayer Limited, which is authorised and regulated by the Financial Conduct Authority (firm reference number 901096). TrueLayer provides the account information service, and you will be asked to agree to TrueLayer's own terms before connecting.

Our access is read-only at all times. We are strictly unable to:

Only read-only data retrieval endpoints are accessed.

Keeping your data up to date. While an account is connected, we refresh your data periodically so your dashboard stays current. Some institutions may also send updates when new transactions occur. How often we can refresh depends on limits set by your bank and our Open Banking provider.

Reconfirming access. You will be asked to reconfirm that you want to keep an account connected at least every 90 days. If you do not, we stop retrieving new data for that account.

6. Automatic transaction categorisation

We automatically sort your transactions into categories such as Food & Dining, Transportation, Bills & Housing and Entertainment & Subscriptions, so your spending can be shown on your dashboard.

We do this in two steps. First, we check the merchant name against a list of well-known brands. If there's no match, we use an open-source machine-learning model to suggest a category. Both steps run on our own servers, hosted by Railway. Only the transaction description, such as the merchant name, is used. Your name, account details and amounts are not.

The model is pre-trained and used as-is. We do not use your transactions to train it or any other model, and your data is not shared with any third-party AI provider.

This is automated processing, but it does not make decisions that have legal or similarly significant effects on you. It only labels transactions for your own dashboard. You can change any category yourself, and we will keep your choice when transactions are re-categorised.

7. Who we share data with

We do not sell, rent or share your financial data with advertisers or any unauthorised party. We share data only with service providers that help us run the Service, under contracts that require them to protect it and use it only on our instructions:

ProviderWhat they doLocation of data
TrueLayerRegulated Open Banking connection to your bankUK / EU
NeonDatabase hostingUK – London
RailwayBackend server hostingNetherlands
smartfinanceapp12@gmail.comAccount emails and supportUK

Your data passes through our Open Banking provider only for the purpose of secure retrieval. We may also disclose data if required by law, or to a buyer or successor if ARCA is reorganised or sold, in which case this policy will continue to protect it.

8. International transfers

We aim to store your data in the UK or the European Economic Area. Where a provider processes data outside these areas, we make sure appropriate safeguards are in place, such as UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.

9. How we protect your data

No system is perfectly secure. If a personal data breach occurs that is likely to put you at risk, we will tell you and the ICO as the law requires.

Your responsibilities: keep your login details and devices secure, and do not give other people access to your account.

10. How long we keep your data

We keep your data only for as long as your account is active, or as needed to provide the Service:

DataHow long we keep it
Account details, transactions, budgets and connected account dataUntil you delete your account. Deletion from our live database is immediate.
Data from a disconnected bank accountWe delete the stored bank data credentials straight away.
Support messagesUntil you delete your account. Copies sent to our support inbox are kept for up to 12 months after the conversation ends.
Database backupsOur database provider, Neon, keeps a short restore history of up to 7 days. After that, deleted data is permanently removed.

Accounts with no activity for 24 months may be closed and deleted after we notify you.

11. Your control and your rights

Disconnecting an account. You can disconnect any linked account at any time on the Accounts page in the app. You can also revoke access directly with your bank where it supports this. Either way, we immediately stop retrieving new data for that account.

Deleting your account. You can delete your account and personal data at any time in Settings → Edit Profile → Delete account. If you no longer have the app, you can request deletion by emailing smartfinanceapp12@gmail.com. See also our account deletion page.

Your rights under UK data protection law. You have the right to:

To use any of these rights, email smartfinanceapp12@gmail.com. We will reply within one month and will not charge you.

12. No financial advice, and data accuracy

The information in ARCA is for informational purposes only. Nothing in the app is financial, tax, investment or legal advice, and you remain responsible for any financial decisions you make.

Your financial data comes from third-party financial institutions. We are not responsible for delays, missing transactions or inaccuracies that originate with those data providers.

13. Changes and complaints

Changes to this policy. If we make significant changes, we will tell you in the app or by email before they take effect, and update the "Last updated" date above.

Contact us. smartfinanceapp12@gmail.com

Complaints. If you are unhappy with how we handle your data, please contact us first so we can try to fix it. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.