ARC Intelligence – Privacy Policy

Last Updated: 27 August 2026

1. Overview

ARC Intelligence (“we,” “us,” or “our”) operates AI that develops with the athlete: a sports performance, coaching, and educational platform that builds a persistent, evolving understanding of authorised athlete context, combining video analysis evidence, ARC Intelligence conversations, goals and milestones, Digital Twin (the evolving summary and visualisation of that understanding in the ARC app for eligible athletes), coaching tools, Jobs, ARC Arena / Events, organisation workspaces, and (where enabled for your plan and role) ARC Sports Agent (connected accounts and delegated external tasks) (collectively, the “Service”). This Privacy Policy explains how we collect, use, store, share, and protect your personal information when you use our mobile application, website, and related services.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the practices described herein, please do not use the Service.

This policy applies to all users of ARC Intelligence, including athletes, coaches, contributors, and any other individuals who interact with the Service.

2. Information We Collect

We collect information in the following categories depending on how you interact with the Service:

2.1 Account Information

When you register for an account, we collect your name, email address, and (if you choose email/password sign-up) a password (stored in hashed form only by our authentication provider). You may also sign in with Sign in with Apple, in which case we receive the identifiers and profile fields Apple provides for that flow (for example a relay email and name, depending on your Apple settings). We also collect your date of birth (required for age eligibility), your role (e.g., athlete, coach, employer, or other roles offered in the product), sport preference where applicable, and additional profile data such as a display name or biography.

2.2 Content You Provide

You may upload or submit content to the Service, including videos, images, PDFs, text submissions, coaching insights, annotations, and contributor content. You are responsible for the content you provide and should not upload content that contains sensitive personal information of third parties without their consent.

2.3 Biomechanical and Analysis Data

When you use the analysis features of the Service, we generate and store biomechanical data including pose estimation data, movement measurements, shot and motion classifications, AI-generated insights, and analysis results derived from your uploaded content.

2.4 Usage and Device Data

We automatically collect information about your interactions with the Service, including feature usage patterns, timestamps, session data, device type, operating system version, and general device information. This data helps us maintain, improve, and troubleshoot the Service.

2.5 Payment Information

Payments are processed by Apple (via StoreKit for in-app purchases) and Stripe (for web-based transactions). ARC Intelligence does not directly collect or store your credit card numbers, bank account details, or other full payment instrument data. We receive limited transaction information (such as subscription status, transaction identifiers, and purchase history) from these processors to manage your account and entitlements.

2.6 Contact Hashes

If you choose to use our friend discovery feature, phone numbers from your device contacts are processed locally and transmitted to our servers only as one-way SHA-256 cryptographic hashes. We do not store or have access to the underlying plaintext phone numbers.

2.7 Referral Data

If you participate in our referral program, we collect referral codes, referral relationships between accounts, and commission tracking data associated with your referral activity.

2.8 Notification Data

To deliver in-app notifications and push notifications, we store notification records and device tokens associated with your account.

2.9 ARC Intelligence Chat and Athlete Understanding Context

When you use ARC Intelligence (in-app chat and related reasoning features), we store conversation threads, messages, thread titles, and related usage metadata. We may also store retrieved context used to answer your questions, for example memory records, goals, milestones, prior analysis summaries, and permissioned profile or performance context (collectively part of your Athlete Understanding Context). We send a limited context packet to our AI providers as needed to generate responses. Raw video files and full pose trajectory exports are not sent as chat payloads unless a specific feature expressly requires that transfer.

ARC Intelligence is intended as performance and coaching support. It is not medical, mental health, legal, emergency, or financial advice. Generated outputs may be incomplete or incorrect.

2.10 Digital Twin Snapshots and Retrieval Extracts

For eligible athlete accounts in the ARC app, Digital Twin is the evolving summary and visualisation of ARC Intelligence’s current understanding of the athlete, built from authorised evidence, conversations, goals and development over time. We store server-generated Digital Twin snapshots (including narrative sections, confidence language, evidence references, period labels, key changes, and related synthesis fields), Digital Twin retrieval extracts used for context, and athlete corrections or feedback submitted about Twin content. Digital Twin belongs to the athlete; it is not an organisation-wide profile and is not an independent intelligence separate from ARC Intelligence. Digital Twin is not biometric cloning, a physiological simulation, a biological twin, or a medical model. It may contain errors; users may correct information; it changes as new evidence is added; it does not replace professional medical or safeguarding advice; and it is not guaranteed to predict performance.

Deleting source evidence, correcting understanding, revoking coach or organisation access, or deleting your account can affect what Twin and ARC Intelligence may retrieve or display going forward. Residual backup or de-identified research retention may still apply as described in Section 6 and Appendix B.

2.11 Goals, Timeline, Library, and Related App Content

Where you use corresponding app features, we store goals and milestones, Timeline (profile publication) posts, Library or saved analysis reopen records, ARC Arena and social interaction data where enabled, and related media references. Availability of these features may differ between the iOS app and the website; storage still occurs when the features are used in the product.

2.12 Jobs and Applications

For Jobs features, we store job listings, applications, application status, employer review actions, and related messaging or profile visibility required to operate hiring flows. Employers do not receive personal ARC Intelligence chat history, personal Library, Camera capture, or athlete Digital Twin content through the Employer workspace.

2.13 Organisation Collaboration Data

Where you participate in an organisation workspace in the app, we store membership and role records, invitations, organisation settings, Discussion collaboration content where permitted, and organisation-scoped ARC Intelligence content only for the Organisation Owner (or other expressly granted contexts). Coaches and authorised organisation users may contribute expertise, observations and Discussion; they do not share one organisation-wide ARC Intelligence by default. Athlete ARC Intelligence remains permissioned and private. The Digital Twin belongs to the athlete and is not organisation-wide. Organisation admins and authorised collaborators do not automatically receive organisation-wide ARC Intelligence solely by holding an admin or coach role.

2.14 Location Data (ARC Arena / Events)

If you grant location permission, ARC may use device location to help you discover nearby tournaments and sporting events in ARC Arena / Events, to invite check-in when you are near a venue, and to support location-verified check-in evidence. The app may request When In Use and, where you enable it, Always location (including background location capability used for nearby-event invitations). Precise location is used for these product purposes and is not published as a public live location feed. We may store check-in related location evidence and related event participation records associated with your account. You can revoke location permission in iOS Settings at any time; some Arena features will then require manual check-in or browsing without proximity assistance.

2.15 Sports Agent, Connected Accounts, and Delegated External Actions

Where ARC Sports Agent is available for your account, plan, and role, and you authorize a connection, ARC may connect to external provider accounts to help prepare and carry out user-requested sports logistics tasks (for example tournament-related email, calendar planning, contacts lookup, document preparation, portal workflows, travel or purchase handoffs, and authorized monitoring of threads or accounts when that feature is enabled).

What we store for connected accounts. We store connection metadata (provider, account labels or email addresses returned by the provider, status, granted capability/scope records, and action history needed to resume and audit delegated tasks). OAuth access/refresh tokens and browser-session materials (for example session cookies or session references used for provider portals) are stored in an encrypted server-side credential vault referenced by opaque identifiers, not as plaintext secrets in ordinary app database fields, and not in ARC Intelligence chat text. ARC does not ask you to type provider passwords, passkeys, one-time codes, or payment card numbers into ARC chat; those credentials are entered on provider- or system-owned authentication, checkout, or 3-D Secure surfaces.

Google Workspace data (when you connect Google). ARC requests Google OAuth scopes incrementally for the Sports Agent capability you authorize at the time of need. Exact scopes are shown on Google’s consent screen. As currently shipped for ordinary consumer accounts, the Google capabilities exposed in-product are primarily: send mail (gmail.send) after ARC confirmation; Calendar list/create; and Contacts search (People API readonly), plus identity scopes needed to identify the connected account. Additional Gmail read/search/compose, Drive, Docs, Sheets, and monitoring capabilities are implemented in ARC’s codebase and may request corresponding scopes (for example gmail.readonly, gmail.compose, drive.file, drive.readonly, Docs/Sheets scopes) when those capabilities are enabled for an account, they are not all consumer-exposed by default today.

Why we access Google user data / how it is used. Solely to provide or improve user-facing Sports Agent features that are prominent in the ARC app for the capabilities you authorize, for example sending sports-related email after ARC confirmation, scheduling or checking calendar conflicts, looking up contacts you authorize ARC to search, and, when enabled for your account, related mail-search, document, or monitoring workflows and resuming a delegated task after you complete provider authentication or approval. Consistent with Google’s Limited Use requirements for applicable scopes, Google user data is not sold, is not used for advertising (including retargeting or personalized ads), is not used for credit-worthiness or lending decisions, and is not used for independent data-brokerage purposes.

Google Workspace data and AI processing. Google Workspace content accessed through Sports Agent is used to provide the feature or action you request. Sports Agent retrieval and execution paths do not themselves call OpenAI. As currently implemented, Gmail and Google Drive content retrieved by Sports Agent is not automatically added to the Athlete Understanding Context used for general ARC Intelligence conversations. If Google-derived information becomes part of an ARC Intelligence conversation (including where you provide that information in chat or an ARC feature places it into the conversation) that conversation text may be processed by our configured LLM provider (currently OpenAI or an OpenAI-compatible endpoint, as described in Section 4 and Section 5.3) solely to generate that user-facing response. We do not use Google user data obtained via Google APIs to create, train, or improve a machine learning or artificial intelligence model beyond that specific user’s personalized model for the appropriate Sports Agent / ARC Intelligence use case or user-facing feature, including ARC’s proprietary biomechanics models such as MovementNet.

Storage and credentials. Retrieved Google content needed to complete a requested action may be processed to fulfill that action and may be reflected in ARC action records, confirmation cards, and related operational logs while the account and connection remain active. OAuth access/refresh tokens and related session materials are stored in an encrypted server-side credential vault (see above) and are removed from active use when you disconnect the account in ARC Sports Agent, when we successfully process provider-side revocation, or when your ARC account is deleted (see Section 7 and Appendix B).

Human access. ARC personnel do not routinely read Google user data obtained through Google API scopes. Access is limited by our internal practices to circumstances where: you ask us for support involving specific data; it is necessary for security purposes (for example investigating abuse or a technical issue); it is necessary to comply with applicable law; or the data is aggregated for internal operations in accordance with applicable law. These practices are intended to align with Google’s Limited Use human-access restrictions for applicable scopes. They are operational controls, not a separate end-user technical access-control product. Access to connected-account credentials is handled through privileged server infrastructure, and vault secrets are not exposed to the ARC iOS client.

Microsoft / Outlook. When you connect Microsoft, ARC may use Microsoft Graph permissions such as User.Read, Mail.Send, offline_access, and (when monitoring is authorized) Mail.Read, for the same Sports Agent purposes described above.

Browser-session / portal providers and payments. For certain tournament portals, travel, hotel, flight, or purchase workflows, ARC may use a secure browser worker/session to navigate provider sites after you authenticate on the provider surface, prepare entries or carts, and hand you off to provider-owned checkout, payment, or authentication pages. ARC does not operate a card vault for primary account numbers; provider terms and systems of record apply. ARC may transmit user-authorized information to providers as needed to perform the requested action. Sports Agent is not restricted to adults overall; however, purchases, bookings, payments, and similar consequential financial or tournament-submit execute actions require an adult account (18+). ARC does not provide a guardian-approval product for those actions. If age eligibility cannot be established from the account’s date of birth, those actions fail closed.

MCP and other integrations. ARC may route certain capabilities through allowlisted Model Context Protocol (MCP) or official provider APIs where configured. User-supplied arbitrary MCP servers are not accepted. Tool outputs from external systems are treated as untrusted input for consequential actions, which still require ARC confirmation where the product requires it.

Revocation and Limited Use. You may disconnect connected accounts in-app (ARC Sports Agent / connected-account management). You should also revoke ARC’s access in your Google Account (or Microsoft account) security settings. Disconnecting removes ARC’s active connection credentials from productive use; ARC also attempts provider-side token revocation where supported. Records of actions previously taken through ARC may be retained in accordance with our retention practices, and residual copies may remain in routine backups until those backups are overwritten or deleted in accordance with our infrastructure providers’ retention processes. Third-party provider terms and privacy policies also apply to data those providers hold as systems of record. ARC’s use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. How We Use Your Information

We use the information we collect for the following purposes:

4. AI and Machine Learning Processing

ARC Intelligence may use third-party AI and machine learning providers to support analysis, moderation, insight generation, chat reasoning, Digital Twin synthesis, infrastructure, platform improvement, and related services. Data processed by these providers may include uploaded content, biomechanical measurements, generated insights, chat text, Athlete Understanding Context packets, Digital Twin synthesis inputs/outputs, metadata, account information, and related operational or system information, depending on feature usage. ARC Intelligence may use a combination of on-device and secure cloud-based processing to deliver these features. We do not claim that all AI processing is self-hosted.

ARC Intelligence (reasoning). ARC Intelligence reasons over authorised athlete (or organisation Owner) context to generate recommendations, summaries, and interpretations. Outputs may be wrong or incomplete. Users should not treat ARC Intelligence as medical, legal, or emergency advice.

Digital Twin (summary visualisation). Digital Twin is the evolving summary and visualisation of ARC Intelligence’s current understanding for eligible athletes, built from authorised evidence, conversations, goals and development over time. It is not a separate intelligence from ARC Intelligence. It may include inferred statements that are not fully athlete-confirmed. Athlete corrections and source deletion can improve or remove stored understanding over time, subject to retention rules.

Camera and generated imagery. Camera measurements and any illustrative image-generation outputs (where used) are separate concepts: measurements derive from analysis pipelines; generated imagery is illustrative and not a photographic measurement record.

We select AI and ML providers that maintain appropriate security practices for the data they process. ARC Intelligence conducts or will conduct data protection impact assessments where required by applicable law. However, the specific providers, processing methods, and technical architectures we use may change over time as the Service evolves. For additional information about how data is used in connection with AI features, please see our AI, Biomechanics & Coaching Disclaimer and Data & AI Policy.

5. How We Share Your Information

ARC Intelligence does not sell your personal information. We share data only in the following circumstances:

5.1 Infrastructure Providers

We use Supabase as our primary infrastructure provider for database hosting, cloud object storage, authentication, and related backend services. Your account data, uploaded content, and associated records are stored and processed through Supabase infrastructure. Additional infrastructure used for specific features may include secure browser-worker hosting for Sports Agent portal sessions.

5.2 Payment Processors

We share limited account and transaction data with Apple and Stripe to facilitate payment processing, subscription management, and purchase verification.

5.3 AI and ML Service Providers

We share data with AI and machine learning service providers as described in Section 4 above, to the extent necessary to deliver analysis, moderation, insights, chat reasoning, Digital Twin synthesis, and other platform features. The primary cloud model provider used in production chat and related server features is OpenAI (and OpenAI-compatible endpoints where configured). Other named providers in older materials may not be active.

5.4 Connected-Account and Action Providers (Sports Agent)

When you authorize Sports Agent connections, we share user-authorized data with the relevant provider solely to perform the requested action, including Google APIs (Gmail, Calendar, People/Contacts, Drive, Docs, Sheets), Microsoft Graph (Outlook mail), allowlisted MCP servers where enabled, secure browser-worker infrastructure used for provider portal sessions, and provider-owned checkout/booking surfaces you are redirected to. Those providers process data under their own terms as systems of record. See Section 2.15 for Google Limited Use–oriented disclosures.

5.5 Legal Requirements

We may disclose your information if required to do so by law or in response to valid legal process, including subpoenas, court orders, or governmental requests. We may also disclose information when we believe in good faith that disclosure is necessary to protect our rights, your safety or the safety of others, investigate fraud, or respond to a government request.

5.6 Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, or similar transaction, your personal information may be transferred as part of that transaction. We will notify you of any such change in ownership or control of your personal information.

6. Data Retention

We retain personal data for as long as your account is active or as needed to provide the Service. Upon account deletion, identifiable account data is removed or deactivated in accordance with the process described in Section 7 below.

Certain categories of data may be retained beyond account deletion, including de-identified data, aggregated data, moderation records, security logs, backup data, analytics data, contributor content (subject to the Contributor License Agreement), and system-integrity data. Anonymized or de-identified pose data, biomechanical measurements, movement-derived metrics, analytical and system outputs, and aggregated platform data may be retained indefinitely to support ongoing research, platform improvement, and service development.

We may also retain information as required by applicable law, regulation, or legal obligation. For detailed retention schedules and deletion procedures, see Appendix B below.

7. Account Deletion

You may request deletion of your account in the ARC iOS app via Profile > Settings > Delete Account, or by emailing hello@arcintelligence.online with the subject line “Account Deletion Request.” Deleting your ARC account does not automatically cancel an Apple App Store subscription; manage App Store billing separately in Apple ID Subscriptions.

Organisation workspace knowledge (Discussion, Organisation Library, organisation analyses and related organisation records) is retained for the organisation. If you are an Organisation Owner, you must transfer ownership before account deletion can proceed.

Upon processing your deletion request:

Disconnecting a connected account in ARC Sports Agent removes ARC’s active connection credentials. Certain records of actions previously taken through ARC may be retained in accordance with our retention practices, and residual data may remain in routine backups until those backups are overwritten or deleted in accordance with our infrastructure providers’ retention processes. You should also revoke third-party OAuth grants in the provider’s account settings. If you have questions about the deletion process or need assistance, please contact us at hello@arcintelligence.online.

8. Children’s Privacy

ARC Intelligence is intended for users aged 13 and older, or the higher minimum age required in the user’s country or region. We do not knowingly create accounts for, or collect personal information from, children under 13 (or under the applicable local minimum). If we become aware that we have collected personal information from a child below the applicable minimum without meeting legal requirements, we will take steps to delete that information promptly.

If you are a parent or guardian and believe your child below the applicable minimum has provided personal information to ARC Intelligence, please contact us at hello@arcintelligence.online so that we can take appropriate action. For additional information about minors and the Service, please see Appendix D below.

9. Your Rights and Choices

9.1 General Rights

Depending on your jurisdiction, you may have the following rights regarding your personal information:

To exercise any of these rights, please contact us at hello@arcintelligence.online. We will respond to your request within the timeframe required by applicable law.

9.2 Rights Under the General Data Protection Regulation (GDPR)

For detailed information about your rights under GDPR and UK GDPR, including lawful bases, international transfers, and supervisory authorities, see Appendix C below.

9.3 Rights Under the California Consumer Privacy Act (CCPA)

If you are a California resident, the CCPA provides you with the following rights:

To submit a verifiable consumer request, contact us at hello@arcintelligence.online. We may need to verify your identity before processing your request.

10. Cookies and Tracking Technologies

For detailed information about cookies and similar technologies, see Appendix A below.

11. Data Security

We implement industry-standard security measures to protect your personal information, including encryption of data in transit and at rest, secure cloud infrastructure, role-based access controls, and regular security practices. While we strive to protect your information, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.

If you become aware of a security vulnerability or suspect unauthorized access to your account, please contact us immediately at hello@arcintelligence.online.

12. International Data Transfers

ARC Intelligence is operated from the United States. If you are accessing the Service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States and other jurisdictions where our service providers operate. By using the Service, you consent to the transfer of your information to the United States and other jurisdictions that may have different data protection laws than your country of residence.

We implement appropriate safeguards for international data transfers as required by applicable law, which may include standard contractual clauses, data privacy frameworks, or other recognized mechanisms.

13. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will notify you by updating the “Last Updated” date at the top of this policy and, where appropriate, through in-app notifications or other communication channels.

Your continued use of the Service after any changes to this Privacy Policy constitutes your acceptance of the updated policy. We encourage you to review this Privacy Policy periodically.

14. Contact Us

For questions about this policy, your account, or your personal data, contact us at hello@arcintelligence.online.

We will respond to your inquiry within a reasonable timeframe.


Appendix A — Cookie Policy

A.1 What Are Cookies

Cookies are small text files placed on your device by websites or applications you visit. They are widely used to make services work efficiently, to remember your preferences, and to provide information to site operators. Similar technologies include local storage, session storage, and device identifiers.

A.2 How ARC Intelligence Uses Cookies

ARC Intelligence uses a limited set of cookies and similar technologies for the following purposes:

Strictly Necessary Cookies

These cookies are essential for the operation of ARC Intelligence and cannot be disabled without affecting core functionality:

Functional Cookies

Limited Analytics

ARC Intelligence may use limited analytics to understand how the platform is used and to improve the service. Analytics data is aggregated and not used to personally identify individual users. ARC Intelligence does not use third-party advertising trackers.

A.3 Third-Party Cookies

ARC Intelligence does not serve third-party advertising cookies. However, if you interact with embedded third-party services (such as payment processors), those services may set their own cookies subject to their respective privacy policies.

A.4 iOS Application

The ARC Intelligence iOS application does not use browser cookies. Authentication state is maintained through secure device storage. This cookie policy primarily applies to the ARC Intelligence website at arcintelligence.online.

A.5 Managing Cookies

You can control and manage cookies through your browser settings. Most browsers allow you to:

Disabling strictly necessary cookies may prevent you from signing in or using certain features of ARC Intelligence.

For more information about managing cookies in your browser, visit your browser's help documentation or allaboutcookies.org.

For questions about this policy, your account, or your personal data, contact us at hello@arcintelligence.online.


Appendix B — Data Retention & Deletion

B.1 General Retention Principle

ARC Intelligence retains personal data for as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, and enforce agreements. We do not retain identifiable personal data longer than reasonably necessary for the purposes described in this Privacy Policy.

B.2 Retention by Data Category

Account Data

Account information (name, email, role, sport preference, profile data) is retained for the duration of your active account. Upon account deletion, identifiable account data is removed or deactivated within a reasonable timeframe.

Uploaded Content

Videos, images, and other media uploaded by users for analysis purposes are retained while your account is active. Upon account deletion, user-uploaded media files are queued for removal from active storage. Copies may persist temporarily in backups and caches before being overwritten through normal operational cycles.

Biomechanical & Analysis Data

Pose estimation data, joint angles, movement metrics, shot classifications, and AI-generated analysis results may be retained in de-identified or aggregated form indefinitely. This data supports the ongoing development and improvement of ARC Intelligence’s MovementNet technology and biomechanics systems.

De-identified biomechanical measurements, movement-derived metrics, analytical outputs, and aggregated platform data do not constitute personal data once they can no longer be linked to an identifiable individual, and are therefore not subject to deletion requests.

Contributor Content

Content submitted through the ARC Intelligence Verified (coaching insights, annotations, skill area analyses, moderation feedback) is retained in accordance with the Contributor Licensing Agreement. Contributors grant ARC Intelligence a perpetual, irrevocable license to this content. Contributor content may persist in ARC Intelligence systems, trained models, datasets, and derived outputs after account deletion. This is a condition of the contributor relationship and is disclosed at the time of contribution.

Transaction & Payment Data

Subscription status, transaction identifiers, and payment metadata are retained for the duration required by applicable tax and financial record-keeping laws (typically 7 years). ARC Intelligence does not store raw payment card numbers — these are held by Apple and Stripe respectively.

Referral Data

Referral codes, referral relationships, and commission records are retained for the duration of the referral program and any applicable financial record-keeping requirements.

Communications & Moderation

Messages exchanged through the ARC Intelligence Verified submission feedback system, moderation records, and support correspondence are retained for platform integrity, quality assurance, and dispute resolution purposes. These records may be retained after account deletion where necessary for legal compliance or platform safety.

ARC Intelligence Chat, Athlete Understanding Context, and Digital Twin

Chat threads, messages, retrieved context packets, Digital Twin snapshots, Digital Twin retrieval extracts, and athlete corrections are retained while the account is active. Upon account deletion, identifiable chat and Twin records associated with the account are removed or deactivated from active systems in line with Section 7. De-identified or aggregated research extracts, backups, and model-improvement materials may persist as described elsewhere in this appendix. Deleting source evidence or correcting Twin content can change what is retrieved thereafter, but does not guarantee immediate erasure from every backup or derived research store.

Location / ARC Arena Evidence

Check-in location evidence and related Arena/Events participation records are retained while the account is active and as needed for integrity of event participation. Precise location is not used as a public profile field. Upon account deletion, identifiable location evidence tied to the account is removed or deactivated from active systems subject to backup cycles and legal holds.

Sports Agent Connected Accounts, Vault Credentials, and Action Logs

Connected-account metadata and ARC action/audit records are retained while the account remains active as needed to operate and secure the Service. Encrypted OAuth tokens and browser-session vault materials are removed from active use when you disconnect a connected account, when provider-side revocation is successfully processed, or when your ARC account is deleted. Disconnecting removes ARC’s active connection credentials; records of actions previously taken through ARC may be retained in accordance with our retention practices. Residual copies may remain in routine backups until those backups are overwritten or deleted in accordance with our infrastructure providers’ retention processes. Google/Microsoft remain systems of record for mailbox, calendar, and file content that stays in those services after ARC disconnects.

Usage & Analytics Data

Aggregated usage data, feature interaction metrics, and de-identified analytics are retained indefinitely for platform improvement. Device-specific identifiers and session data are retained only while an account is active.

Security & Moderation Records

Records related to content moderation decisions, account enforcement actions, abuse reports, and security incidents are retained for as long as necessary to maintain platform integrity and comply with legal obligations. These records may be retained after account deletion.

B.3 Account Deletion Process

Users may request account deletion through the in-app settings or by emailing hello@arcintelligence.online with the subject line “Account Deletion Request.”

Upon receiving a valid deletion request, ARC Intelligence will:

B.4 Data That May Persist After Deletion

The following categories of data may be retained after account deletion:

ARC Intelligence does not guarantee immediate or complete removal of all data from all systems, including backups, caches, and disaster recovery infrastructure.

B.5 Data Portability

Users may request a copy of their personal data by contacting hello@arcintelligence.online. We will provide the data in a commonly used, machine-readable format within a reasonable timeframe and in accordance with applicable law (including GDPR Article 20 where applicable).

B.6 Legal Holds

Where ARC Intelligence is subject to a legal obligation, regulatory investigation, or active dispute, data that would otherwise be deleted may be retained for the duration of the applicable legal hold. Users will be notified of legal holds where legally permitted.

B.7 Children’s Data

ARC Intelligence does not knowingly collect data from children under 13. If we discover that data has been collected from a child under 13, we will take steps to delete it promptly. See Appendix D for additional information about minors.


Appendix C — GDPR & UK Privacy Addendum

C.1 Scope

This appendix supplements the ARC Intelligence Privacy Policy with additional information required under the European Union General Data Protection Regulation (GDPR), the UK General Data Protection Regulation (UK GDPR), and related data protection laws. It applies to users located in the European Economic Area (EEA), the United Kingdom, and Switzerland.

C.2 Who Is Responsible for Your Data

Who is responsible for your data. ARC Intelligence is the name under which the ARC Intelligence service is currently operated. ARC Intelligence is not yet a separately incorporated company. Until incorporation, the operator of the ARC Intelligence service is responsible for the processing described in this Privacy Policy. You can contact us about privacy matters at hello@arcintelligence.online.

For users in the EEA or UK, the operator of the ARC Intelligence service is the controller of personal data processed as described in this Policy, pending formal incorporation and any updated controller notice we publish. If applicable law requires the controller to be identified by the natural person’s legal name and address, that identifying information will be published in this section when available; contact hello@arcintelligence.online for privacy requests in the meantime.

C.3 Lawful Bases for Processing

ARC Intelligence processes personal data on the following lawful bases under GDPR Article 6:

C.3.1 Consent (Article 6(1)(a))

You may withdraw consent at any time by contacting hello@arcintelligence.online or by deleting your account. Withdrawal of consent does not affect the lawfulness of processing performed before withdrawal.

C.3.2 Performance of a Contract (Article 6(1)(b))

C.3.3 Legitimate Interests (Article 6(1)(f))

We balance our legitimate interests against your rights and freedoms. You have the right to object to processing based on legitimate interests.

C.3.4 Legal Obligation (Article 6(1)(c))

C.4 Special Category Data

ARC Intelligence may process data that could be considered health or biometric data under certain interpretations of GDPR (biomechanical measurements, movement analysis). This processing is based on your explicit consent provided during account creation and content upload, and is performed solely for the purpose of providing sports performance analysis — not medical diagnosis or health monitoring.

C.5 International Data Transfers

ARC Intelligence is based in the United States. Your data may be transferred to and processed in the United States and other countries where our infrastructure providers operate. These transfers are necessary for providing the service.

For transfers from the EEA/UK to countries not recognized as providing adequate data protection, ARC Intelligence implements appropriate safeguards as required by applicable law, which may include:

You may request information about the specific safeguards applied to your data transfers by contacting hello@arcintelligence.online.

C.6 Your Rights Under GDPR

If you are located in the EEA, UK, or Switzerland, you have the following rights:

To exercise any of these rights, contact hello@arcintelligence.online with the subject line “GDPR Rights Request.” We will respond within 30 days.

C.7 Right to Erasure — Limitations

Your right to erasure may be limited where ARC Intelligence has a lawful basis for retaining data, including:

See Appendix B for complete details on data retention and deletion.

C.8 Children’s Data

Where applicable law requires a higher minimum age than 13 (for example, 16 in certain EU member states for consent to information-society services), ARC applies or will apply that higher minimum through its account-age policy when that jurisdiction rule is activated. Until a higher local minimum is activated, the default minimum is 13. Users under 18 must have permission from a parent or legal guardian to use ARC; ARC does not independently verify that permission. See Appendix D.

C.9 Supervisory Authority

If you are located in the EEA or UK and believe ARC Intelligence has not adequately addressed your data protection concerns, you have the right to lodge a complaint with your local data protection supervisory authority. A list of EEA supervisory authorities is available at edpb.europa.eu. For UK residents, contact the Information Commissioner’s Office (ICO) at ico.org.uk.

C.10 Data Protection Impact Assessments

ARC Intelligence conducts or will conduct data protection impact assessments where required by applicable law for high-risk processing activities, including AI-powered video analysis and biomechanical data processing.

C.11 UK-Specific Provisions

For users in the United Kingdom, references to GDPR in this appendix include the UK GDPR as retained in UK law. The International Data Transfer Addendum to the EU SCCs, as issued by the ICO, applies to data transfers from the UK where applicable.

C.12 Contact for GDPR Inquiries

For GDPR-related inquiries, rights requests, or complaints: hello@arcintelligence.online with “GDPR” in the subject line.


Appendix D — Minor & Youth Athlete Protection

D.1 Age Requirement

You must be at least 13 years old (or the higher minimum age required by the law of your country or region) to create an account or use ARC Intelligence. ARC Intelligence does not knowingly provide accounts to children under 13, or under the applicable local minimum. Account creation requires a date of birth; dates of birth below the applicable minimum are rejected. If we become aware that a user is below the applicable minimum, we will take steps to deactivate the account and delete associated personal data as appropriate.

If you are a parent or guardian and believe your child below the applicable minimum has created an ARC Intelligence account or provided personal information, please contact us immediately at hello@arcintelligence.online so we can take appropriate action.

D.2 Users Between 13 and 18

Users who meet the minimum account age but are under 18 (or under the age of majority where they live) may use ARC Intelligence only with permission from a parent or legal guardian. By creating an account or continuing to use ARC while under 18, the user confirms that they have that permission. ARC records the user’s date of birth, resulting age eligibility, accepted Terms and Privacy versions, and acceptance timestamp for audit purposes.

ARC does not currently independently verify parental or guardian permission (for example, ARC does not require a parent email, linked parent account, or separate consent wizard). Parents and guardians are encouraged to monitor their minor’s use of ARC Intelligence and to discuss responsible use of sports performance and coaching technology.

D.3 Coach, Contributor, Employer, Moderator, and Admin Eligibility

Users must be at least 18 years old to register or operate as a coach, contributor, employer, moderator, or admin on ARC Intelligence, and to hold approved contributor or moderator capabilities. Verified publishing, job application features, and the referral program are restricted to adult users only.

Sports Agent age gates. ARC Sports Agent is available to eligible accounts that meet the account minimum age; it is not restricted to adults overall. Purchases, bookings, payments, and similar consequential financial or tournament-submit execute actions require an adult account (18+). ARC does not provide a guardian-approval product for those actions. If date of birth is missing so age eligibility cannot be established, those actions fail closed.

D.4 Content Involving Minors

ARC Intelligence is AI that develops with the athlete, a sports performance and coaching platform. Videos uploaded by minor users (ages 13 to 17) are used solely for the purpose of providing sports analysis and coaching insights. ARC Intelligence applies the following safeguards:

D.5 Data Collection for Minors

ARC Intelligence collects the same categories of data from minor users (ages 13+) as from adult users, as described in Section 2 of this Privacy Policy. This includes account information, uploaded content, biomechanical data, usage data, and (where the minor uses corresponding app features) ARC Intelligence chat context, Digital Twin snapshots and retrieval extracts, goals, Timeline content, and related inferred athlete understanding. We do not collect more data from minors than is reasonably necessary to provide the service.

ARC Intelligence does not engage in behavioral advertising targeted at minor users.

Parental permission (attestation, not verification): Users under 18 must have permission from a parent or legal guardian to use ARC. That requirement is stated in the Terms and in onboarding. ARC records the user’s attestation context (date of birth / age eligibility, Terms and Privacy versions, and acceptance time). ARC does not independently verify parental permission and does not operate a separate parental-consent verification product. In-product reporting, blocking, and the Safety Report contact channel in Contact remain available.

D.6 Parental Rights

Parents and guardians of minor users have the right to:

To exercise any of these rights, contact us at hello@arcintelligence.online. We may require verification of the parent-child relationship before processing requests.

D.7 Physical Activity Disclaimer for Parents

ARC Intelligence provides sports performance analysis and coaching insights for informational and educational purposes only. Parents and guardians should be aware that:

D.8 Compliance

ARC Intelligence is designed to comply with the Children’s Online Privacy Protection Act (COPPA) by not knowingly providing accounts to users under 13 in the United States, and by enforcing a configurable minimum account age that can be raised where local law requires a higher threshold. ARC Intelligence also adheres to applicable provisions of the General Data Protection Regulation (GDPR) and other privacy laws regarding the processing of minor data.

Where applicable law requires a higher minimum age than 13 (for example, 16 in certain EU member states for consent to information-society services), ARC applies or will apply that higher minimum through its account-age policy when that jurisdiction rule is activated. Until a higher local minimum is activated, the default minimum is 13, and under-18 users must still have parental or guardian permission as described above.