Arked
Private beta Request access
Updated 29 September 2026 · English edition, revision 3

Privacy

The short version: the app collects nothing, the site does not track you, and all we keep is what you type into the forms on this site.

0
bytes of your documents that reach us. Our server publishes the state of the beta and receives what you send through the forms, nothing else.
0
telemetry events, automatic crash reports, tracking cookies.
3
forms where you leave us any data: the invite request, the contact form and the erasure request.

1 · The Arked app

Arked is an application that runs entirely on your device. We collect none of the data you put into it. In detail:

  • The archive is a folder on your disk. The files, their names and the index stay there.
  • Text recognition (OCR) uses the macOS engines, on the device.
  • The AI model is downloaded once and then works offline: the contents of your documents are not sent to any service, ours or anyone else's.
  • There is no account to create, so we hold no profile, no history and no identifier of yours.
  • There is no telemetry, no in-app analytics and no automatic crash reporting.

The app goes online for three things only: downloading the AI model the first time, checking whether there is an update, and reading the state of the beta — which versions are still active and which invite codes are valid. In all three cases an ordinary HTTP request travels, with none of your data attached.

The state of the beta is read from a server of ours, api.arked.app, with a copy on GitHub if the first does not answer: whoever answers sees your IP address, as with any request. The invite code is never sent: it is checked on your Mac against the published list, which holds only fingerprints of the codes and not the codes themselves.

2 · iCloud sync

Syncing between Mac, iPhone and iPad is optional, and off until you turn it on. When it is on, the archive lives in your iCloud Drive: the data goes through your Apple account, under Apple's terms and encryption, and passes through no system of ours. We have no way to read it and do not know it exists.

How Apple handles that data is covered by its own privacy notice, not this one. If you would rather not use iCloud, turn syncing off: Arked keeps working as a purely local archive.

3 · The private beta

Arked is in private beta and runs with an invite code. You ask for the code with the request form: what you type there reaches a server of ours.

  • What we ask. Name and email, both required. If you like, the Mac you would run it on, its macOS version and a couple of lines about what you would archive.
  • What is recorded with it. The IP address the form was sent from, the moment it arrived, the version of this notice you consented to and the version of the Beta terms you accepted. The IP address makes abuse of a form open to everyone traceable; the two versions are kept to be able to show which text you had in front of you (GDPR Art. 7(1)).
  • What it is for. To decide on the request and to answer you. If it is accepted, to issue an invite code in your name, so that it can be revoked.
  • Lawful basis. Your consent (GDPR Art. 6(1)(a)), given by ticking the box on the form. The box is never ticked for you, and the form does not send without it. Accepting the Beta terms is a separate box: it is a contract, not a consent, and it is kept in order to perform and evidence that contract (Art. 6(1)(b)).
  • Where it goes. To the server that runs Arked's backend, under the developer's control. It is not sold or shared, and it goes through no advertising, analytics or newsletter service: there are none here.
  • How long. Until six months after the private beta ends, after which the requests are deleted. Sooner, if you ask.
  • What you get. The invite with instructions for installing the beta and, if needed, a notice about important updates. No marketing. The reply goes out through an ordinary mail provider, which handles your address the way it handles the address of anyone who receives an email.

Sending the form twice does not create a second request: the address is the key, and a later submission updates what is already there. The form gives the same answer in both cases, otherwise it would be a way of finding out which addresses have asked for access.

When a request arrives, a notification goes to the developer. It only says there is something to read: no name, no address, nothing of what you wrote.

If you send us a bug report during the beta, we receive what you choose to write — nothing leaves the app on its own.

4 · Erasing your data

Withdrawing consent is as easy as giving it. There is a page for it: Erase my data. Replying to any email from Arked and asking works just the same.

  • What is deleted. The access request — name, email, the Mac, what you wrote, the IP address it came from — every invite code issued to you, and the messages you sent through the contact form with our replies. Whole rows, not a flag on them. An erased code stops working.
  • It waits for you to confirm. Sending the form starts nothing on its own. An email goes to the address you gave, with a button to confirm and one to cancel, and nothing is deleted until you press the first. It is the identity check the GDPR asks for where there is reasonable doubt about who is asking (Art. 12(6)).
  • If you never answer. Two reminders, after 7 and 15 days. At 30 days the request lapses without having deleted anything, and a final email says so.
  • If it wasn't you. Press “cancel” in that email: the request closes and nothing is touched.
  • How long it takes. A month at the outside from your confirmation (GDPR Art. 12(3)), normally a few days.

Asking to be erased creates a record of its own: the address, what you wrote, the IP address and a trace of the emails sent. It is kept to carry the erasure out and to be able to show it was done in time. The basis is the legal obligation to answer you (GDPR Art. 6(1)(c)), not consent: that is why that form has no box to tick. When nothing of yours is left, that record is deleted too.

5 · The contact form

The contact form is the way to write to us: a question, a problem, something about the beta or about your data.

  • What we ask. Name, email, a topic and your message.
  • What is recorded with it. The IP address the form was sent from, the moment it arrived and the version of this notice shown next to the form.
  • What it is for. To read your message and to answer you. The answer goes by email to the address you gave, and a copy is kept with your message.
  • Lawful basis. The legitimate interest in answering whoever writes to us (GDPR Art. 6(1)(f)) and, when you write to exercise a right, the legal obligation to answer you (Art. 6(1)(c)). There is no box to tick: writing is your own initiative.
  • Where it goes. To the server that runs Arked's backend, under the developer's control. It is not sold or shared. The answer goes out through an ordinary mail provider.
  • How long. For as long as it takes to answer you and to follow the conversation up. It is deleted when you ask.

Please do not put documents or sensitive data into the form. If a document is involved, describe it: there is no need to send it.

6 · The anti-spam check on the forms

The forms are protected by Cloudflare Turnstile. It sets no cookies, does not profile you and is not used to follow you from site to site.

It does make a request to challenges.cloudflare.com, which discloses your IP address and your browser's user agent to Cloudflare, Inc., acting as a processor under the European Commission's Standard Contractual Clauses. The lawful basis is the legitimate interest in keeping a form open to everyone usable (GDPR Art. 6(1)(f)).

It loads when you start filling in the form, not when the page opens. Read the page and leave, and no request to Cloudflare is made at all.

7 · This website

This site is made of static pages. It uses no cookies, has no analytics and no tracking pixels, and does not profile its visitors.

One honest caveat: the typefaces on this page are served by Google Fonts, so your browser makes a request to Google's servers, which see your IP address in the process. We receive nothing of that request and do not use it to identify you. If we host the fonts on the site itself, this line will go.

Arked's builds are published on GitHub. When you press “Download” or open the release notes you go to GitHub, and from there you are on their site under their terms: GitHub sees your IP address. It is a request you make yourself, on purpose. How they handle that data is described in the GitHub privacy statement.

Like any website, the provider hosting these pages keeps technical access logs for security and diagnostics, for as long as that provider's own retention rules say.

8 · Your rights

Over the data you have left through the forms you can ask us at any time to access it, correct it, erase it, restrict its use or object to its processing, and you can obtain a copy. We answer within thirty days. You also have the right to complain to your national data protection authority; in Italy that is the Garante per la protezione dei dati personali.

For erasure there is a form. For everything else, or for any question about this page, use the contact below.

9 · Controller and changes

Data controller: Fabio Della Selva, the developer of Arked.

  • Contact: the contact form
  • Scope: the Arked app, its private beta and this website, arked.app

If we change this notice we will update the date at the top of the page. If the change concerns the beta data, we will also write to those who have sent a request.