This policy explains how Arca, the encrypted file vault for Mac, iPhone and iPad made by John Floyd ("we", "us"), handles your information.
The short version
- We don't collect any data about you. Arca has no accounts, no analytics, no advertising and no third-party code, and it never sends anything to us.
- Your files are encrypted on your device before they're saved. Only you can decrypt them.
- If you use iCloud, your vault is stored in your own iCloud account — already encrypted. We can't access it, and Apple stores only data it can't read.
- We never see your password, your recovery key, your file names or your files.
1. Information we collect
None. Arca doesn't contain analytics, tracking or crash-reporting code of its own, doesn't use third-party software development kits, and never sends your data to us or to anyone else. Because we collect nothing, we have nothing to sell, share or rent.
2. What Arca keeps on your device
Arca stores the following on your device, in storage that only Arca can reach:
- Your vault, if you choose to keep it on this device only. Everything in it is encrypted.
- Your settings, such as your auto-lock time, sort order and view preferences, and where your vault is kept.
- An encrypted copy of your vault's header, so the lock screen appears instantly and your vault can open offline. It can't be read without your password or recovery key.
- Failed-password counts, kept in your device's keychain to enforce the lockout after repeated wrong passwords.
- Temporary decrypted copies, created only when you open or export a file. They're kept in Arca's private temporary storage and deleted when your vault locks.
- A Face ID or Touch ID unlock key, only if you turn that feature on. It's kept in your device's keychain, can be used only after a successful Face ID or Touch ID check on that device, never moves to another device, and is never synced to iCloud Keychain.
Arca never receives your biometric data. Face ID and Touch ID checks are performed by Apple's operating system, which tells Arca only whether the check succeeded.
3. iCloud
If you choose to keep your vault in iCloud, Arca stores it in its own iCloud Drive folder in your Apple Account, and Apple syncs it to your other devices signed into the same account.
Everything Arca places in iCloud is encrypted first: file contents, file names, folder structure and thumbnail previews. The keys that decrypt your vault never leave your devices. Someone with access to the stored files could still see how many items there are, roughly how large they are, and when they changed — but not what they are or what they're called.
We have no access to your iCloud account. Apple's handling of data stored in iCloud is described in Apple's Privacy Policy.
4. Photos and files you add
Photos. Add Photos uses Apple's system photo picker. Arca receives only the photos and videos you select, and has no access to the rest of your photo library. Arca doesn't ask for permission to access your photo library.
Other files. When you add files — from the toolbar, by drag and drop, from Finder, or from the share sheet — Arca encrypts its own copy. It never changes or deletes your original. Temporary copies that the system hands to Arca are deleted once they've been encrypted.
5. When information leaves Arca's protection
Some actions deliberately take information outside the vault. These happen only when you choose them:
- Exporting a file saves an unencrypted copy wherever you choose.
- Saving your recovery key to a file creates a copy that Arca doesn't protect.
- Copying your recovery key places it on your device's clipboard, where other apps can read it and Universal Clipboard can make it available on your other nearby Apple devices. Paste it somewhere safe, then copy something else to replace it.
Copying items inside Arca puts only an internal reference on the clipboard, never the contents of your files.
6. Crash reports and the App Store
Arca doesn't include its own crash reporting. If you've chosen in your device's settings to share analytics with app developers, Apple may provide us with crash reports and app usage statistics, which Apple shares without identifying you. You control this in your device's privacy settings.
Downloads and any purchases are handled by Apple. We receive only aggregated reports from Apple, never your payment details or your identity.
7. Children
Arca doesn't collect personal information from anyone, including children.
8. Keeping and deleting your data
We don't hold any data about you, so there's nothing for us to delete, export or correct on your behalf. Everything is under your control:
- Deleting items in Arca deletes each file's encrypted data along with the key that decrypts it.
- Stop Using This Vault on This Device, in Settings, removes from that device Arca's record of where your vault is kept, its cached vault header, and its Face ID or Touch ID unlock key. It doesn't delete the vault itself.
- To delete a vault kept in iCloud, remove Arca's data from your iCloud storage settings, where each app that stores data in iCloud is listed. On iPhone or iPad, start from Settings › [your name] › iCloud; on Mac, from System Settings › Apple Account › iCloud.
- On iPhone and iPad, deleting Arca also deletes a vault kept on that device only.
Deleting a vault can't be undone. And if you lose both your password and your recovery key, nobody — including us — can recover your files.
9. Security
Arca encrypts your files with AES-256-GCM, protects your vault with a key derived from your password, and locks after a period without use and after repeated wrong passwords. No security measure is perfect: Arca can't protect your files from malicious software running on your device while your vault is unlocked, or from anyone who has your password or recovery key. Choose a strong password and keep your recovery key safe.
10. Changes to this policy
If this policy changes, we'll post the updated version on this page and update the effective date above.
11. Contact
If you have any questions about this policy or your privacy, contact John Floyd at support@madjackcreations.com.
