ARCINE STUDIO

Privacy Policy

**Last updated: May 26, 2026**

Privacy Policy

Last updated: May 26, 2026

This Privacy Policy describes how Arcine Studio (“we”, “us”, “our”) collects, uses, and shares information when you use the ArcineOps mobile application and the related web dashboard at dashboard.arcine.studio together, the “Service”.

ArcineOps is an internal operations application for organizations. Accounts are created and managed by your organization’s administrator, not by individual users.

1. Information We Collect

1.1 Account Information You Provide

  • Name, email address, username, and hashed password
  • Profile photo, if uploaded
  • Job title, contact number, and location text, if provided by you or your administrator
  • Role within your organization

1.2 Content You Create in the Service

  • Chat messages, including text, images, video, voice recordings, and reactions
  • Comments and project updates
  • Task assignments, project participation, and time logs
  • Leave and flexible-hours requests
  • Files you attach to projects, stored via Google Drive integration if your organization has enabled it

1.3 Information Collected Automatically

  • Authentication tokens, including JWTs stored on your device
  • Push-notification tokens, including Expo and Firebase Cloud Messaging tokens, so we can deliver notifications to your device
  • Approximate IP address, used for security purposes such as brute-force protection and rate limiting
  • Timestamps of activity, including logins, task updates, and message reads
  • Attendance check-in and check-out times for employees and managers

1.4 Desktop Time-Tracking Client

If your organization uses the optional desktop time-tracking client, that client captures periodic screenshots during active work sessions. These screenshots are retained for productivity reporting available to managers and administrators.

Important: The ArcineOps mobile application does not capture screenshots at any time. Screenshot capture is limited exclusively to the separate desktop client installed on employer-managed workstations.

1.5 Permissions the Mobile App Does Not Use

The mobile app does not capture GPS location, access your contacts, or record microphone audio outside of voice messages you explicitly initiate and send. The app requests microphone permission only for the purpose of recording voice messages, and only at the moment you choose to record one.

2. How We Use Your Information

  • Authenticate you and keep you signed in
  • Deliver messages, notifications, and task information
  • Display productivity, attendance, and project data to authorized users in your organization
  • Maintain audit trails of work activity for your employer
  • Protect the Service from abuse, including rate limiting, brute-force protection, and Cloudflare Turnstile bot detection

We do not sell your personal information. We do not use your data for advertising. We do not share your data with third parties for their own marketing purposes.

3. Legal Basis for Processing

We process your data on the following legal bases:

  • Contractual necessity: Processing required to provide the Service to your organization, including authentication, messaging, task management, and time tracking.
  • Legitimate interest: Security measures, including rate limiting, brute-force protection, bot detection, and audit trails necessary for the operation and protection of the Service.
  • Consent: Optional features such as uploading a profile photo or recording a voice message. You may withdraw consent for these features at any time by deleting the relevant content.

4. Sharing

Information you create in ArcineOps is visible to other members of your organization according to their role, including employee, manager, admin, founder, or client. For example, managers and administrators can view team-wide productivity and attendance reports.

We use the following service providers strictly to operate the Service:

  • MongoDB Atlas — database hosting
  • Expo Push / Firebase Cloud Messaging — push-notification delivery
  • Google Drive API — file storage, only if your organization enables it
  • Cloudflare Turnstile — bot protection on the login screen
  • Cloud hosting provider — hosting the API at api.arcine.studio

We may disclose information if required by law, to enforce our terms, or to protect rights, property, or safety.

5. International Data Transfers

Your data may be transferred to and processed in countries other than your own. Our service providers, including MongoDB Atlas, Firebase, and our cloud hosting provider, may operate servers in different regions, including the United States and other locations where they provide services.

These providers are contractually obligated to protect your data in accordance with applicable data protection laws. Where required, such as transfers from the EEA or UK, we rely on Standard Contractual Clauses or equivalent safeguards to ensure an adequate level of protection.

6. Data Retention

We retain account and activity data for as long as your account is active or as needed to provide the Service to your organization. Your organization controls the retention period for operational records, including chats, tasks, time logs, and screenshots, according to its own internal policies.

Upon account deletion:

  • Your personal identifiers, including display name, profile photo, and push tokens, are removed or anonymized immediately.
  • Operational records you created, including messages, tasks, and time logs, are retained in anonymized form for your employer’s recordkeeping for a period determined by your organization’s data-retention policy, after which they are permanently deleted.
  • Desktop screenshots, if applicable, follow the same organization-controlled retention schedule.

7. Your Rights and Choices

7.1 Account Deletion from the Mobile App

The ArcineOps mobile app provides an in-app “Delete Account” option in the Profile screen. Using it will:

  • Sign you out of the mobile app immediately
  • Anonymize your display name for other users
  • Remove your push-notification tokens from our servers
  • Disable your login on the mobile app

Because ArcineOps is an organization-managed Service, your underlying account record is retained in anonymized form for your employer’s recordkeeping. To request full deletion of all personal data, contact your organization administrator or email us at [email protected].

7.2 Your Data Protection Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Right of Access — request a copy of the personal data we hold about you
  • Right to Rectification — request correction of inaccurate or incomplete data
  • Right to Erasure — request deletion of your personal data, subject to legal and contractual retention obligations
  • Right to Data Portability — request your data in a structured, machine-readable format
  • Right to Object — object to processing based on legitimate interest
  • Right to Restrict Processing — request that we limit how we use your data in certain circumstances
  • Right to Withdraw Consent — where processing is based on consent, withdraw it at any time without affecting prior processing

To exercise any of these rights, contact us at [email protected]. We will respond within 30 days, or the timeframe required by your local law. If you are located in the EEA or UK and believe your data protection rights have been violated, you have the right to lodge a complaint with your local supervisory authority.

8. Cookies and Similar Technologies

The ArcineOps mobile app does not use cookies. The web dashboard at dashboard.arcine.studio may use the following:

  • Session cookies — to keep you signed in during your browser session. These are essential for the dashboard to function and expire when you close your browser or sign out.
  • Cloudflare Turnstile — may set a cookie to distinguish humans from bots on the login screen.

We do not use advertising cookies, analytics cookies, or third-party tracking cookies.

9. Security

We use industry-standard measures to protect your information, including password hashing using bcrypt, encrypted JWT authentication, HTTPS for data in transit, IP-based rate limiting, and role-based access controls. No system is perfectly secure; please use a strong, unique password for your account.

10. Children

ArcineOps is intended for use in organizations and is not directed at children under 13, or the applicable age of digital consent in your jurisdiction. We do not knowingly collect information from children. If you believe a child has provided us with personal data, contact us at [email protected] and we will promptly delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. Your continued use of the Service after such notice constitutes acceptance of the updated policy. We encourage you to review this page periodically.

12. Contact

Arcine Studio
Email: [email protected]
Address: 30 N Gould Street STE R, Sheridan, Wyoming