// DATA & PRIVACY

Privacy

Last updated: 14 September 2026

This page describes the data handled by the current Arc Terminal beta.

1. Account and saved work

Arc Terminal links your account to your public wallet address and stores your display name, wallet authentication challenges, and server-side session records. Wallet sign-in does not require an email address or password. Existing email accounts, where enabled, store an email address and salted password hash. Saved data includes your manual holdings, tracked public addresses, research questions and results, saved backtests and their price snapshots, and followed strategies. Contact form submissions are stored in the feedback queue.

2. Public content

Publishing a playbook makes its title, methodology, risk label, display name, and follower count publicly visible. Your portfolio and research history are private to your account.

3. Connected services

Global market data is fetched from Coinbase Exchange and Kraken. Your connected wallet address and other public addresses you choose to track are sent to the configured Arc RPC service to retrieve testnet balances. When ARCOS AI is enabled, your research question and public market evidence are sent to Anthropic; your private portfolio is not automatically included. Stripe processes checkout and billing when paid subscriptions are enabled. Resend processes verification and password recovery emails for existing email accounts when account email is configured.

4. Sessions and security

An essential HttpOnly session cookie keeps you signed in for up to seven days. Your browser remembers your chosen wallet provider so it can check that the same wallet is still connected. Signing out invalidates that session. Wallet authentication uses a signed message to verify address ownership; it does not send a transaction or grant trading access. Request rate limits use hashed network identifiers. The application does not accept exchange trading keys, seed phrases, or wallet private keys. Production hosting must provide HTTPS.

5. Retention and requests

Saved work remains in the application database until removed. You can remove individual holdings and tracked addresses, and unfollow playbooks in the terminal. Account offers a JSON export, session controls, and deletion for free accounts without billing records. Wallet accounts confirm deletion with a fresh signed message; existing email accounts use their password. Accounts linked to billing require a request through Contact so subscriptions and retained billing records can be handled correctly. Verified operators can moderate public strategies and manage contact requests; account security and moderation actions are recorded in an audit log. Hosting backups may retain earlier database copies according to the operator’s backup policy.

Questions about this document? Submit a request through the contact page.