Privacy Policy
1. Who we are
This Privacy Policy explains how ARCA collects, uses and protects your personal data when you use our Android app, iOS app and web app.
The data controller responsible for your personal data is:
- Name: Po-An Chen and Fei Liu, trading as ARCA
- Contact email: brianchen3157@gmail.com and liufei520.02@gmail.com
If you have any questions about this policy or your data, contact us at the email above.
2. The short version
- ARCA is a read-only financial data aggregation tool. We can see your account data when you allow it; we can never move money or change your accounts.
- We use your data only to show you dashboards, categorise your transactions and give you spending insights.
- We do not sell your data or share it with advertisers.
- You can disconnect a bank or delete your account at any time.
- Nothing in the app is financial, tax, investment or legal advice.
3. Data we collect
| Category | What it includes | Where it comes from |
|---|---|---|
| Account details | Name, email address, encrypted password | You, when you register |
| Connected account data | Account balances; transaction history (income and expenditure); merchant names; transaction dates and amounts; account type and identifiers | Your bank, via our Open Banking provider, only after you authorise it |
| Categories and insights | Transaction categories, budgets, spending summaries and any categories you edit | Generated by the Service or entered by you |
| Technical and diagnostic data | Device model, operating system version, app version, crash reports and error logs | Your device, automatically |
| Support messages | Anything you send us by email or feedback form | You |
We do not collect your online banking username or password. You enter those only with your bank.
4. How we use your data and our legal basis
UK data protection law requires a legal basis for each use of your data. Ours are:
| Purpose | Data used | Legal basis (UK GDPR) |
|---|---|---|
| Create and run your account | Account details | Performance of our contract with you |
| Aggregate your connected accounts and show dashboards, charts and summaries | Connected account data | Performance of our contract with you |
| Categorise transactions (e.g. income, groceries) and provide spending insights | Connected account data, categories | Performance of our contract with you |
| Fix bugs, keep the Service secure and prevent misuse | Technical and diagnostic data | Our legitimate interests in running a reliable, secure service |
| Respond to support requests | Support messages, account details | Our legitimate interests in helping you |
| Manage paid subscriptions | Payment data | Performance of our contract with you |
| Meet legal obligations | Any relevant data | Legal obligation |
Accessing your bank data also requires your explicit authorisation, which you give through the Open Banking connection flow (see section 5). We do not use your data for advertising or marketing profiling.
5. Connecting your bank: read-only access
Connecting a bank account is optional. If you choose to connect one, we use Open Banking through TrueLayer Limited, which is authorised and regulated by the Financial Conduct Authority (firm reference number 901096). TrueLayer provides the account information service, and you will be asked to agree to TrueLayer's own terms before connecting.
Our access is read-only at all times. We are strictly unable to:
- send or receive money on your behalf;
- initiate, authorise, modify or reverse any payment or transaction;
- change standing orders, direct debits or scheduled payments;
- change your account settings or personal details.
Only read-only data retrieval endpoints are accessed.
Keeping your data up to date. While an account is connected, we refresh your data periodically so your dashboard stays current. Some institutions may also send updates when new transactions occur. How often we can refresh depends on limits set by your bank and our Open Banking provider.
Reconfirming access. You will be asked to reconfirm that you want to keep an account connected at least every 90 days. If you do not, we stop retrieving new data for that account.
6. Automatic transaction categorisation
We automatically sort your transactions into categories such as Food & Dining, Transportation, Bills & Housing and Entertainment & Subscriptions, so your spending can be shown on your dashboard.
We do this in two steps. First, we check the merchant name against a list of well-known brands. If there's no match, we use an open-source machine-learning model to suggest a category. Both steps run on our own servers, hosted by Railway. Only the transaction description, such as the merchant name, is used. Your name, account details and amounts are not.
The model is pre-trained and used as-is. We do not use your transactions to train it or any other model, and your data is not shared with any third-party AI provider.
This is automated processing, but it does not make decisions that have legal or similarly significant effects on you. It only labels transactions for your own dashboard. You can change any category yourself, and we will keep your choice when transactions are re-categorised.
7. Who we share data with
We do not sell, rent or share your financial data with advertisers or any unauthorised party. We share data only with service providers that help us run the Service, under contracts that require them to protect it and use it only on our instructions:
| Provider | What they do | Location of data |
|---|---|---|
| TrueLayer | Regulated Open Banking connection to your bank | UK / EU |
| Neon | Database hosting | UK – London |
| Railway | Backend server hosting | Netherlands |
| smartfinanceapp12@gmail.com | Account emails and support | UK |
Your data passes through our Open Banking provider only for the purpose of secure retrieval. We may also disclose data if required by law, or to a buyer or successor if ARCA is reorganised or sold, in which case this policy will continue to protect it.
8. International transfers
We aim to store your data in the UK or the European Economic Area. Where a provider processes data outside these areas, we make sure appropriate safeguards are in place, such as UK adequacy regulations or the UK International Data Transfer Agreement / Addendum.
9. How we protect your data
- All data sent between the app and our servers is encrypted in transit using HTTPS (TLS 1.2 or above). Connections between our servers and our database, banking and payment partners are also encrypted.
- Your password is never stored. We keep only a one-way hash, using bcrypt.
- The credentials that let us read your bank data (via our Open Banking provider, TrueLayer) are encrypted with AES-256 before they are stored.
- Our database is hosted by Neon, which encrypts stored data at rest using AES-256.
- Session and password-reset tokens are stored only in hashed form. Sign-in sessions expire, and repeated failed sign-in attempts are temporarily blocked.
- Each account can access only its own data. Access to our production systems (our server host and database) is limited to the members of the ARCA development team who maintain the Service, and only when needed to run, secure or support it, for example to fix a problem you've reported.
- Secrets such as API keys and database credentials are kept out of our source code and stored as protected environment variables.
No system is perfectly secure. If a personal data breach occurs that is likely to put you at risk, we will tell you and the ICO as the law requires.
Your responsibilities: keep your login details and devices secure, and do not give other people access to your account.
10. How long we keep your data
We keep your data only for as long as your account is active, or as needed to provide the Service:
| Data | How long we keep it |
|---|---|
| Account details, transactions, budgets and connected account data | Until you delete your account. Deletion from our live database is immediate. |
| Data from a disconnected bank account | We delete the stored bank data credentials straight away. |
| Support messages | Until you delete your account. Copies sent to our support inbox are kept for up to 12 months after the conversation ends. |
| Database backups | Our database provider, Neon, keeps a short restore history of up to 7 days. After that, deleted data is permanently removed. |
Accounts with no activity for 24 months may be closed and deleted after we notify you.
11. Your control and your rights
Disconnecting an account. You can disconnect any linked account at any time on the Accounts page in the app. You can also revoke access directly with your bank where it supports this. Either way, we immediately stop retrieving new data for that account.
Deleting your account. You can delete your account and personal data at any time in Settings → Edit Profile → Delete account. If you no longer have the app, you can request deletion by emailing smartfinanceapp12@gmail.com. See also our account deletion page.
Your rights under UK data protection law. You have the right to:
- access the personal data we hold about you;
- correct data that is wrong or incomplete;
- have your data deleted;
- receive your data in a portable format;
- object to or restrict how we use your data;
- withdraw any consent you have given, without affecting earlier processing.
To use any of these rights, email smartfinanceapp12@gmail.com. We will reply within one month and will not charge you.
12. No financial advice, and data accuracy
The information in ARCA is for informational purposes only. Nothing in the app is financial, tax, investment or legal advice, and you remain responsible for any financial decisions you make.
Your financial data comes from third-party financial institutions. We are not responsible for delays, missing transactions or inaccuracies that originate with those data providers.
13. Changes and complaints
Changes to this policy. If we make significant changes, we will tell you in the app or by email before they take effect, and update the "Last updated" date above.
Contact us. smartfinanceapp12@gmail.com
Complaints. If you are unhappy with how we handle your data, please contact us first so we can try to fix it. You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk/make-a-complaint or on 0303 123 1113.