THE WINTER ARC

Privacy policy

Draft updated: 30 September 2026. The final policy is not yet effective.

The Winter Arc is a personal habit and reflection app operated by Nishant Munjal. This privacy policy explains how the Android app handles information when you use guest mode, optional Google sign-in, manual cloud backup, reminders, and support.

For privacy questions or requests, contact timepasscoding1994@gmail.com.

Your progress stays on your device unless you choose to back it up. Signing in sends account information for authentication. It does not automatically upload your habits, notes, or reflections. The app contains no advertising or dedicated analytics SDK.

1. Information stored on your device

The app stores the information you enter to run your personal arc:

After a cloud restore, the app keeps a local recovery copy so you can undo that restore. Guest progress is not uploaded to the app’s cloud-backup service. Your device’s operating-system backup or device-transfer settings may separately include app storage.

Signing out does not erase local progress. Anyone who can open the app on your unlocked device may be able to see it.

2. Optional sign-in and cloud backup

Google sign-in

If you choose Google sign-in, Google authenticates you and provides basic identity information to Supabase, our authentication provider. This can include your name, email address, account identifiers and profile metadata such as a profile-picture URL. Supabase maintains your Winter Arc account, authentication events and session information. The app stores native session credentials using secure device storage.

We do not receive your Google password or request access to your Gmail messages, Google Drive, contacts or calendar.

Manual backup and restore

When you confirm Back up this device, the app uploads a snapshot of your arc and saved chapters to your Winter Arc cloud account. This includes the habits, schedules, reminder preferences, progress, notes, mood entries and reflections described above. Depending on what you enter, this may include health, fitness or other sensitive personal information.

A new backup replaces your current cloud snapshot. Backup is manual; changes on your devices are not continuously synchronized or merged. Restoring downloads the snapshot and replaces the device’s current progress after confirmation, while keeping a local recovery copy. You can use guest features without signing in or uploading a backup.

3. Why information is used and who processes it

Information is used to provide habit tracking, reminders, account authentication, manual backup and restore, deletion controls, support and service security. Your habit entries are not public posts. We do not sell personal information or use habit records for advertising.

Authentication and infrastructure services process technical information such as IP addresses, request times, browser or client information, account identifiers, authentication events and service errors to deliver and secure the service. These records are different from tracking your habit-screen activity for analytics.

Providers may process information outside your country. The production hosting region and applicable international-transfer details are being confirmed before release.

Provider information: Supabase privacy information and Google Privacy Policy. Supabase processes our app’s customer data on our instructions; its website privacy notice does not replace this app policy.

4. Reminders and device permissions

With your permission, the app schedules local reminders on your device. Habit titles may appear on the lock screen. You can change reminders in the app or disable notifications in Android settings.

The app does not offer features that read contacts, messages, the photo library, microphone, camera, device calendar or GPS location. Fitness and mood records are entered by you; this version does not connect to Health Connect or wearable sensors.

5. How information is protected

Cloud requests use HTTPS. Cloud backups are protected by account access controls, but are not end-to-end encrypted. Native sign-in credentials use secure device storage. The local progress database is not separately encrypted by the app; protect access to your device. No storage or transmission system can be guaranteed completely secure.

6. Retention and deletion

Local progress remains until you clear it or app storage is removed, subject to separate operating-system backup and transfer settings. Cloud account information and the current backup remain until you request their deletion. A new manual backup replaces the previous active snapshot.

Open My Arc → Account & cloud backup → Privacy & data to choose what to remove:

You can also request deletion without the app through our account-deletion page. The response and completion timeframe for verified requests is being finalized; no fixed completion period is represented in this draft.

Deletion from the live database does not necessarily erase existing infrastructure logs or disaster-recovery copies immediately. Retention periods for authentication audit records, service logs and disaster-recovery backups, and any required legal exceptions, have not yet been confirmed. This draft does not promise immediate deletion from these systems.

The retention period for support and deletion correspondence after resolution is being finalized.

7. Intended audience

The intended audience includes children under 13. The current pre-release app does not yet implement age screening or a parental-consent flow. Child-specific online data safeguards and procedures for parental access and deletion are being finalized. This draft does not represent that the cloud features are ready for use by children. Parents or guardians with a question about a child’s information can contact Nishant Munjal at the email address on this page.

8. Your choices and privacy requests

You can use the app as a guest, decline manual backup, change notification permissions, edit your local records, or use the deletion controls described above. Depending on the law where you live, you may have rights to access, correct, delete, receive a copy of, or object to or restrict certain processing of your personal information, and to complain to a data-protection authority.

Contact timepasscoding1994@gmail.com to make a request. We may ask for proportionate information to confirm account ownership before disclosing or deleting cloud data. Do not send your password, one-time sign-in codes or private journal entries. We cannot retrieve guest-only progress from our servers.

9. Changes to this policy

We will publish updates on this page with a revised effective date and provide additional notice where required.