Last updated: September 2026
Arcy is an account-based service. To use it you create an account, and the work you do — your brand details, your offers, the ads you generate, and the things you type into the app — is stored in our database so it is there when you come back. We use it to run the product and to make it better. We do not sell it.
Your account (email, name, and a hashed password — we never store the password itself), your brand profile and offers, products you add, competitor ads you save, workflows and generated ads, campaign drafts, editor projects, credit and billing history, and messages you send to Arcy through Telegram, Slack, or WhatsApp. This lives in a hosted Postgres database on our servers, not in your browser.
The prompts and descriptions you type — what you ask the studio to create, what you search for, what you tell us about your business — are stored with your account. We review this in aggregate to understand what people are trying to do and to improve the product: which requests the app handles badly, which features are missing, which wording confuses people. Where we surface this internally, email addresses and phone numbers are stripped out first. We do not use it to build a profile of you for advertising.
When you connect a social platform or ad account, or enter your own API key, the credential is stored encrypted in our database (AES-256-GCM). It is used only to act on your behalf — to publish what you schedule, or to read your own ad data. It is never shared with another customer or sold. You can disconnect an account at any time, which removes the stored credential.
Card payments are handled entirely by Stripe on Stripe-hosted pages. Arcy never sees or stores your card number. We keep only your Stripe customer reference and your plan status.
Running Arcy means sending some of your data to service providers who act on our behalf: Vercel (hosting and file storage), Neon (database), Anthropic, OpenAI, fal.ai, Kie, Higgsfield, Together, WaveSpeed and ElevenLabs (generating text, images, video and voice from your prompts), Meta (the public Ad Library, and your own ad account if you connect it), Apify (competitor ad research), Stripe (payments), Resend (transactional email), Google (if you sign in with Google), and Telegram, Slack or WhatsApp if you link a chat companion. When you publish a post, its content goes to the platform you chose.
We use PostHog for product analytics — which screens get used and where people get stuck — and Sentry for crash and error reports. PostHog sets its own cookies. When our generation-tracing tool (Langfuse) is enabled, the prompts you send and the model responses behind generated output may also be recorded there so we can debug bad output. We do not run advertising trackers.
A sign-in cookie that keeps you logged in for 30 days, a cookie remembering which workspace you last had open, and short-lived security cookies during a sign-in or account-connection flow. Beyond those, see the analytics section above.
Images and videos you upload or generate are stored in Vercel Blob and served from a long, randomly generated link. Anyone holding that exact link can open the file without signing in, so treat a generated-media link as semi-public and avoid putting anything confidential into media you share.
You can delete individual items — ads, workflows, saved competitor ads, offers — from inside the app at any time. To delete your whole account, open Settings, then Profile, and use Delete account: it removes the account and cascades to the data listed above, with no email and no waiting. Export my data, on the same card, gives you a copy first. If you cannot sign in, email support@arcy.io from the address on the account and we will do it for you. We reply within 1 business day.Two caveats we would rather state than hide: files already generated may persist in file storage after the account row is gone, and data already sent to a provider such as Anthropic or Stripe is subject to that provider's own retention rules.
Arcy is not directed to children under 13 and does not knowingly collect information from them.
This policy may be updated from time to time. Continued use of Arcy after a change constitutes acceptance of the revised policy.
A copy of your data and deletion are both self-serve under Settings, then Profile. Questions about this policy, or anything either control does not cover, go to support@arcy.io. We reply within 1 business day.