ARCHPDF · ARCH LABS
Privacy Policy
This policy explains how Arch Labs collects, uses, stores, and protects ArchPDF data under applicable privacy law.
1. Data we collect
ArchPDF collects only the information needed to operate the Android application. This may include your name, email address, account identifier, login information, preferences, locally stored document history, annotations, and technical information required for security and support.
PDF operations normally happen on your device. We do not receive the contents of files processed locally. If you authorise Google Drive or External Storage, ArchPDF processes the files, metadata, and quota usage needed to provide that service.
Where a feature requires tax identification, the application may request a CPF for validation. Purchases and subscriptions are processed by Google Play; Arch Labs does not receive or store card details.
ArchPDF has no advertising SDKs, behavioural analytics, tracking cookies, or advertising profiles. Preferences such as theme and viewing settings are used to provide the features you select.
2. Why we use this information
We use account information for authentication, account management, transactional communication, support, fraud prevention, service security, and legal compliance. Local history, preferences, and annotations are used to provide the features you request on your device.
Authorised Google Drive access is used to list and open files and, where supported by the plan, upload files selected by you. External Storage is used only for user-selected uploads within the plan quota. Downloads do not consume quota, and deleting a file does not restore previously consumed quota.
We also use account and service data to respond to support requests, enforce plan permissions, prevent abusive uploads, maintain the service, and communicate important changes.
3. Legal bases
Depending on the country and the activity, processing is based on providing the service you request, your consent for optional integrations, our legitimate interest in protecting the service, and compliance with legal obligations. You may withdraw consent for an optional integration by disconnecting it in the application.
4. Sharing and service providers
We do not sell personal information or use it for behavioural advertising. Google Play processes purchases, Google may process authorised Drive access, and our infrastructure providers may process account, security, or storage data only as needed to provide the service and protect it. Providers operate under their own applicable terms and privacy notices.
The external-storage service processes files that you deliberately upload. Supabase or equivalent account infrastructure processes authentication and account records. None of these providers receives locally processed PDFs unless you choose an integration that sends the file.
5. Retention and deletion
Account information is kept while your account is active. After a confirmed deletion request, eligible account information and cloud files are removed according to the deletion workflow. Some security, fraud-prevention, transaction, or legal records may be retained for the period required by law or reasonably necessary to protect the service.
As operational targets, account data is normally removed within 30 days after a valid confirmed request, while security records may be kept for up to 90 days when needed for security, fraud prevention, or legal compliance. Mandatory retention takes precedence where required by law.
6. Your rights
Subject to applicable law, you may request access, correction, deletion, portability, restriction, objection, or withdrawal of consent. Contact privacy@archlabs.app.br. We may need to verify your identity before completing a request.
7. Security
We use HTTPS/TLS, authentication controls, access restrictions, and local processing of PDF operations. No online service can guarantee absolute security, so keep backups of documents that are important to you.
Files sent to Google Drive or External Storage are transferred only after your action and authorization. You remain responsible for reviewing the destination account and keeping copies of important documents.
8. International and regional law
This English version is intended for visitors in the United States and the United Kingdom. The law applicable to a particular person depends on the service relationship, location, and mandatory local rules. Where the GDPR, UK GDPR, LGPD, or another privacy law applies, the rights and obligations required by that law also apply.
9. Contact and changes
For privacy questions, contact privacy@archlabs.app.br. We may update this policy when the application, services, or law changes. Material changes will be communicated through the application or by email.