Arcos — Privacy Policy

Last updated: August 28, 2026

Arcos is collaboration infrastructure for networks, communities, and movements. This policy describes what data Arcos handles, who it is shared with, and how you control it. It covers the Arcos web application and its integrations. The Marc browser extension has its own policy covering what that extension does.

What we collect

Connected accounts

Arcos can connect to services you already use. A connection is always something you initiate, and you can disconnect it at any time from Account Settings → Connected Apps. Disconnecting revokes the stored credential immediately.

Credentials for connected accounts are encrypted at rest with AES-256-GCM under a key Arcos holds separately from the database, and each is cryptographically bound to the single integration record it belongs to, so a credential cannot be read out of context.

Google user data

If you connect Google Calendar, Arcos requests two scopes and no others:

Arcos stores the resulting refresh token (encrypted, as described above), your Google account email address, and — for each collection you choose to sync — the identifier of the calendar it created and a record of which events it has published. Arcos writes event titles, times, locations, and descriptions drawn from the collection into that calendar, and keeps them up to date as the underlying items change. A sync only ever publishes items you already have permission to see.

Arcos does not read your existing calendars, does not use Google data for advertising, does not sell it, and does not use it to train machine-learning models.

Limited Use

Arcos's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use your information

To operate and improve Arcos, to render your content in the views you choose, to enable the collaboration and sharing features you use, to send you the messages you have asked for, and to meet legal obligations.

Who we share it with

Arcos does not sell your data. Information is shared in three circumstances: with other people, according to the privacy settings you choose; with the service providers Arcos runs on; and where the law requires it.

The service providers are:

Your privacy controls

Arcos is built so that visibility is a property of each thing, not of the whole account. Content can be public, restricted to the members of a space or a group within it, or personal to you and the people you name. You can change these settings per item, per note, and per field of your profile.

Retention and deletion

Your content is retained while your account is active. You can delete individual items, notes, and spaces at any time, and deletion removes them from search and from any AI feature's context. Disconnecting a connected account deletes its stored credential. Deleting a synced calendar in Google, or removing the sync in Arcos, stops publication. To delete your account and its contents, contact us at the address below.

Your rights

You may access and correct your information, request a copy of it, object to particular uses, and request deletion. To exercise any of these, contact us below.

Security

Arcos uses encryption in transit and at rest, row-level access controls in the database, and least-privilege scopes for third-party integrations. No system is perfectly secure, and we cannot guarantee absolute security.

Children

Arcos is not intended for children under 13, and we do not knowingly collect their personal data. If we learn that we have, we will delete it.

Changes

We may update this policy. If a change is significant we will say so in the application or by email, and we will update the date at the top.

Contact

Questions, requests, and deletion enquiries: info@catalist.org.