Table of Contents
- Arcs & Angles Privacy Policy
- 1. Scope
- 2. Information We Process
- 3. Legal Bases for Processing (UK GDPR)
- 4. Local Storage
- 5. Third-Party Services
- 6. How We Use Information
- 6a. Export Provenance
- 7. International Data Transfers
- 8. Sharing
- 9. Data Retention
- 10. Security
- 11. Children's Privacy
- 12. Your Rights
- 13. Cookies and Similar Technologies
- 14. Changes to This Policy
- 15. Contact
Arcs & Angles Privacy Policy
Effective Date: March 6, 2026
Last Updated: August 16, 2026
This Privacy Policy explains how IMBENJI.NET LTD ("we", "us", "our") handles information when you use Arcs & Angles (the "Service").
1. Scope
This policy applies to the Arcs & Angles web and desktop applications and related features.
2. Information We Process
Depending on how you use the Service, we may process:
- Content you create in the app (for example map files, labels, and exports).
- Provenance identifiers embedded in files you export under a paid license, and requests we receive when somebody scans the QR code on an exported map (see Section 6a).
- Technical and usage data needed to run core features (for example IP address, device/browser information, request timestamps, and application version checks).
- Local settings and recovery data stored on your device (for example preferences, recent files, and recovery drafts).
- Account or backend-related data processed through our backend services when those features are enabled (for example authentication identifiers and related metadata). This authentication infrastructure is operated by IMBENJI.NET LTD, not a third party.
- Content you send to or generate through the AI Assistant/agent feature when you use it (for example your prompts, relevant map content, and the Assistant's responses), routed through our backend to OpenRouter, our third-party AI model provider, under a zero data retention configuration (see Section 5).
3. Legal Bases for Processing (UK GDPR)
Where UK GDPR applies, we process personal data under one or more of the following legal bases:
- Contract: where processing is necessary to provide the Service you request.
- Legitimate Interests: where processing is necessary for service security, reliability, abuse prevention, and product improvement, and does not override your rights.
- Legal Obligation: where processing is needed to comply with applicable law.
- Consent: where required by law, including where you choose to enable optional features.
4. Local Storage
Arcs & Angles stores certain data locally on your device to provide core features, including save/recovery and app preferences.
You control your local files and may delete them from your device at any time.
5. Third-Party Services
The Service uses third-party services to support functionality, including external links and font delivery for exports.
The optional AI Assistant/agent feature is powered by OpenRouter, a third-party AI model routing provider. We use OpenRouter with zero data retention (ZDR) enabled: for inference requests, OpenRouter routes only to model providers that do not store or train on your data. This ZDR guarantee covers the core chat/inference requests but does not extend to optional plugins or tools (for example, the Assistant's web search capability), which may be subject to those tools' own data handling. Account authentication and other backend services are operated directly by IMBENJI.NET LTD and are not third-party processing.
Those services are governed by their own privacy policies and terms.
6. How We Use Information
We use information to:
- Provide and operate the Service.
- Maintain reliability, security, and performance.
- Support export, update, and recovery functionality.
- Improve and develop Service features.
- Improve the Service, including the AI Assistant/agent feature, using information from how the Assistant/agent is used.
6a. Export Provenance
Files exported under a paid license carry provenance information identifying the seat that produced them. This section explains what that is, because it is personal data even though it contains no name.
What is in an exported file. Every PDF, SVG and PNG exported under a paid license contains a signed token in its file metadata recording an opaque seat identifier, the license tier, and the date of export. On the Personal and Commercial tiers the visible mark also carries a QR code containing an opaque reference. Operational and Authority licensees may switch the metadata token off, in which case their exports carry no provenance information at all.
The identifier is a stable pseudonym. It is not a name, an email address or a company name, and it cannot be resolved to a person by anyone other than us. It is nonetheless the same identifier on every file a given seat produces, so anyone holding several files can establish that one producer made all of them, and we hold the mapping from that identifier to your account. Under UK GDPR that makes it personal data in our hands, and we treat it as such.
When somebody scans a QR code. The code resolves against our server, so we receive the request: the reference, an IP address, approximate location derived from it, the time, and browser information. A person scanning a code sees only the Arcs & Angles website and learns nothing about the licensee. Our staff, when signed in with an administrator account, can resolve the reference to the account that holds the seat.
Administrator lookups are logged. Every occasion on which a member of our staff resolves a seat identifier to an account is recorded, including who performed the lookup, which identifier, and when.
Retention. Three different things are kept for three different periods, because they serve different purposes:
- The mapping from seat identifier to account is kept for as long as the license exists and for six years after it ends. Six years is the period in which a claim arising from a licensed export could still be brought, and the mapping is what makes such a question answerable at all.
- Scan request logs — the records created when somebody scans a QR code on an exported map — are kept for 90 days. These are operational and analytical records rather than evidence, and they are the most sensitive thing in this section, since they can indicate where a diagram is being looked at. They are not retained beyond the period in which they are useful for running the service.
- Administrator lookup logs — the record of each occasion a member of our staff resolved a seat identifier to an account — are kept for six years, matching the mapping itself. This log exists to hold us to account for accessing that data, so it is retained for as long as the data it governs.
Deleting your account removes the mapping ahead of these periods where we are not required to retain it.
The application does not report your exports to us. Exporting requires no network connection and sends us nothing. We learn about an export only if somebody scans its code or sends us its file.
7. International Data Transfers
If personal data is transferred outside the United Kingdom, we use appropriate safeguards required by applicable law, which may include adequacy decisions or approved standard contractual clauses.
8. Sharing
We do not sell personal information.
We may share information only when necessary to operate the Service (including with third-party providers such as font delivery), comply with legal obligations, enforce our terms, or protect rights and safety. Processing by our own backend and authentication infrastructure (operated by IMBENJI.NET LTD) is not third-party sharing.
9. Data Retention
Retention depends on the data type and purpose.
Local app data remains on your device until removed, overwritten, or cleared by app actions.
10. Security
We use reasonable technical and organizational measures to protect information we process. No method of transmission or storage is completely secure.
11. Children's Privacy
The Service is not directed to children under 13. If we become aware that personal data from a child has been collected in violation of applicable law, we will take appropriate steps to address it.
12. Your Rights
Depending on your location, you may have rights regarding your personal data, including access, correction, deletion, or objection.
To exercise rights requests, contact us using the details below with the subject line Privacy Request and a description of your request.
13. Cookies and Similar Technologies
The Service may use essential local storage or equivalent browser/device storage to support core app features (for example preferences and recovery behavior). We do not use advertising cookies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes may be communicated through the Service or other reasonable means.
15. Contact
For privacy questions or requests, contact:
- Legal Entity: IMBENJI.NET LTD
- Email: benjamin.watt@imbenji.net
- Address: IMBENJI.NET LTD, 127 Ching Way, London, E4 8YE, United Kingdom