Privacy Policy
Arc Agent - Sprint Intelligence
Last Updated: December 1, 2024
Summary: Arc Agent is designed with privacy in mind. We do not collect, store, or share your personal information. All data processing happens on your device or through your organization's secure API. Your GitHub credentials and API keys are stored securely on your device using iOS Keychain.
1. Introduction
This Privacy Policy describes how Arc Agent ("we", "our", or "the app") handles information when you use our iOS and iPadOS mobile application. Arc Agent is a client application that connects to your organization's Sprint Intelligence API to analyze GitHub repositories and generate sprint reports.
2. Information We Do NOT Collect
Arc Agent is designed to respect your privacy. We do not collect, transmit, or store:
- Personal Information: No names, email addresses, phone numbers, or contact information
- Location Data: We do not access or track your device location
- Device Information: No device identifiers, advertising IDs, or hardware information
- Usage Analytics: No tracking of how you use the app
- Crash Reports: No automatic crash or error reporting
- Cookies or Tracking: No cookies, beacons, or tracking technologies
3. Information You Provide
To use Arc Agent, you must configure the following credentials, which are stored locally on your device only:
| Data Type |
Purpose |
Storage Location |
| API Endpoint URL |
Connect to your organization's Sprint Intelligence API |
iOS Keychain (encrypted) |
| API Key |
Authenticate with your organization's API |
iOS Keychain (encrypted) |
| GitHub Personal Access Token |
Access GitHub repositories for analysis |
iOS Keychain (encrypted) |
| Default Repositories |
Pre-fill repository list for convenience |
App preferences (local) |
| Date Range Settings |
Pre-fill analysis date ranges |
App preferences (local) |
4. How Your Data is Used
Local Storage Only
All credentials and settings are stored exclusively on your device using:
- iOS Keychain: Secure, encrypted storage for sensitive credentials (API keys, tokens)
- App Sandbox: Isolated storage for cached reports and preferences
- No Cloud Sync: Your credentials are never synced to iCloud or any cloud service
API Communication
When you run a sprint analysis, the app communicates with:
- Your Organization's API: Sends analysis requests with your API key over HTTPS
- GitHub API: Your GitHub token is sent directly to GitHub's API (not stored on any server)
Cached Reports
Sprint reports are cached locally on your device for offline viewing. These cached reports:
- Are stored in the app's sandbox (isolated from other apps)
- Are deleted when you uninstall the app
- Can be manually cleared through app settings (if available)
- Are never transmitted to any third party
5. Data Sharing and Third Parties
Arc Agent does not share any data with third parties. The only external communications are:
Your Organization's API
- What is sent: Analysis requests, API key for authentication, GitHub token (passed through)
- Purpose: Generate sprint intelligence reports
- Your organization's responsibility: Review your organization's privacy policy for how they handle data
GitHub API
- What is sent: Your GitHub personal access token, repository queries
- Purpose: Retrieve repository data, pull requests, and code changes
- GitHub's privacy policy: GitHub Privacy Statement
Important: Arc Agent acts as a client that connects your device to your organization's infrastructure. We do not operate servers, collect data, or act as an intermediary. All data flows directly between your device, your organization's API, and GitHub.
6. Data Security
We implement industry-standard security measures:
Encryption
- In Transit: All network communications use HTTPS/TLS encryption
- At Rest: Credentials stored in iOS Keychain with hardware-backed encryption
- App Sandbox: iOS sandboxing prevents other apps from accessing Arc Agent's data
No Cloud Storage
- We do not operate cloud servers or databases
- We do not sync your data to any cloud service
- Your data stays on your device unless you explicitly share it
Secure Credential Management
- API keys and tokens are never logged or displayed in plain text
- Credentials are protected by iOS biometric authentication (Face ID/Touch ID) if enabled
- You can delete credentials at any time through app settings
7. Your Rights and Choices
Access and Control
You have complete control over your data:
- View Settings: Review configured credentials in app settings
- Update Credentials: Change API keys, tokens, or endpoints at any time
- Delete Data: Uninstall the app to remove all locally stored data
- Clear Cache: Clear cached reports through app settings (if available)
Data Portability
Since all data is stored locally on your device:
- You can export reports using the system share sheet
- Reports can be saved as PDF for external storage
- No data is locked in any proprietary format or remote server
8. Children's Privacy
Arc Agent is not directed to children under the age of 13. We do not knowingly collect information from children. The app is designed for professional use by software development teams and requires technical credentials to operate.
9. International Data Transfers
Arc Agent does not transfer data internationally. All data processing occurs:
- On your local device (iOS/iPadOS)
- Through your organization's API (location determined by your organization)
- Through GitHub's API (subject to GitHub's data handling practices)
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes:
- The "Last Updated" date at the top will be revised
- Significant changes will be communicated through app updates
- Continued use of the app constitutes acceptance of the updated policy
We encourage you to review this Privacy Policy periodically.
11. Third-Party Services
Arc Agent integrates with the following third-party services:
GitHub
- Purpose: Repository data access
- Data shared: Your GitHub personal access token, repository queries
- Privacy policy: GitHub Privacy Statement
Your Organization's Sprint Intelligence API
- Purpose: Sprint analysis and report generation
- Data shared: Analysis requests, API authentication
- Privacy policy: Contact your organization for their privacy practices
12. Apple App Store
Arc Agent is distributed through Apple's TestFlight and App Store. Apple may collect certain information as described in their privacy policy:
13. California Privacy Rights (CCPA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):
- Right to Know: We do not collect personal information
- Right to Delete: Uninstall the app to delete all local data
- Right to Opt-Out: We do not sell personal information
- Non-Discrimination: We do not discriminate based on privacy rights exercise
14. European Privacy Rights (GDPR)
If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):
- Legal Basis: We process data based on your consent and legitimate interests
- Data Controller: Your organization is the data controller for API-processed data
- Your Rights: Access, rectification, erasure, restriction, portability, and objection
- Data Retention: Data is stored locally until you delete the app
15. Permissions
Arc Agent requests the following iOS permissions:
| Permission |
Purpose |
Required |
| Internet Access |
Communicate with Sprint Intelligence API and GitHub |
Yes |
| Keychain Access |
Securely store API credentials |
Yes |
Arc Agent does NOT request:
- Location services
- Camera or photo library
- Microphone
- Contacts or calendar
- Bluetooth
- Motion or fitness data
Privacy by Design: Arc Agent was built with privacy as a core principle. We believe your data belongs to you, and we've designed the app to keep it that way. All processing happens locally or through services you control.
Arc Agent © 2024-2025
Sprint Intelligence Platform
Version 1.0