Legal
Privacy Policy
What Arcana collects, why, and how long it is kept.
Overview
Arcana is a VPN service. We collect the minimum needed to operate the account and billing relationship, and we do not log or sell your browsing activity.
TODO (legal review needed): this page is a structural draft, not a lawyer-reviewed privacy policy. It needs sign-off before real customer signups begin, and updating whenever a new data processor (Stripe, Supabase, Resend, Cloudflare, the hosting provider) or data category is added.Data we collect
- Account data: email address and password hash (via Supabase Auth), used to sign you in.
- Billing data: handled by Stripe directly — we store only your Stripe customer/subscription IDs and subscription status, never your card details.
- VPN configuration: a subscription URL/config generated for your account, stored encrypted, used solely to deliver your VPN connection details.
- Device metadata: the name, platform, and last connection time of each device you register, so you can see and revoke them from your account dashboard.
- Connection records: for the managed VPN service, a per-device record of which route and server your device was assigned and when, used to operate and load-balance the network. This is routing metadata, not a browsing history — we do not log which sites or services you connect to.
- Telegram data: if you link a Telegram account to manage your VPN through our Telegram Mini App, we store your Telegram user ID and the link between it and your account.
What we do not do
- We do not log your browsing activity, DNS queries, or the destinations you connect to through the VPN.
- We do not sell or share your data with advertisers.
Data processors
We use the following third-party processors to operate the service: Stripe (payments), Supabase (authentication and database), Cloudflare (hosting and the config-delivery API), Resend (operational email alerts), Hetzner (the VPS servers that run the VPN nodes your device connects to), and, if you choose to link your account, Telegram (the Mini App used to manage devices from Telegram). Each processes only the data necessary for its function.
Data retention
Account and billing data are retained for the duration of your subscription plus [retention period — TODO, confirm with legal; typically bounded by tax/accounting record-keeping requirements for billing data]. Connection records (which route/server a device used and when) are deleted after 30 days; raw per-node traffic samples are deleted after 7 days (daily totals are kept for capacity planning); short-lived Telegram linking codes are deleted shortly after they expire. You may request account deletion at any time by contacting us.
Your rights (GDPR)
If you are in the EU/EEA, you have the right to access, correct, delete, or export your personal data, and to object to or restrict certain processing. Contact us at [privacy contact email — TODO] to exercise these rights.
Contact
See our Impressum for the responsible entity and contact details.