Effective July 3, 2026. Account-specific controls stay inside the app; this page is the canonical public policy linked from the client app.
1. Who we are and what this covers
Effective July 3, 2026. Last updated July 3, 2026. Version July 2026.
Arthact is operated by Sanghance. This Privacy Policy explains how Arthact handles personal information across the Arthact website, mobile apps, web app, support operations, admin operations, and Fix This handoffs into Arthact.
Arthact is a person-centric, moving-context, multi-intent matching product. It uses goals, context, trust, timing, and location signals to help users form warm introductions while keeping private contact information locked until the product allows it.
2. Information you provide
You may provide information when you create an account, complete onboarding, create goals, use Fix This handoffs, update your profile, configure preferences, request introductions, send messages, report abuse, ask for support, request export, or delete your account.
- Account and identity data such as name, email address, phone number, auth provider, profile photo, account status, and legal acceptance records.
- Profile and professional context such as headline, company, bio, portfolio link, skills, role, work preferences, trust signals, and profile completeness inputs.
- Goal and intent data such as what you are trying to do, categories, keywords, skills, role preferences, city or country context, availability, discovery scope, work mode, and goal lifecycle.
- Contact-card data such as email, phone number, LinkedIn, scheduling link, preferred contact channel, and any details you choose to share after mutual introduction acceptance.
- Communication and interaction data such as introduction requests, accept or decline decisions, chat messages, message edits, soft deletions, read state, follows, saves, validations, reports, and support messages.
- Safety data such as reports, blocks, moderation context, account deletion reason category, abuse-prevention signals, and operator review notes where needed.
- Verification data such as phone, email, provider identity, LinkedIn, work-email, or similar verification status when those flows are enabled.
- Media and files such as profile photos or other supported uploads.
3. Information collected automatically
Some information is collected automatically so the app can authenticate users, keep sessions reliable, protect the service, deliver notifications, diagnose failures, and improve product quality.
- Firebase Auth identifiers, anonymous or linked account state, session information, and app bootstrap state.
- Device, app, and platform information such as app version, operating system, device model, browser, language, timezone, and basic network state.
- Firebase Remote Config, App Check, rate-limit, abuse-prevention, and feature-flag signals.
- Push notification tokens and delivery state used by OneSignal, Firebase Cloud Messaging, and Apple Push Notification service.
- Usage analytics for onboarding, matching, introductions, notifications, Fix This handoffs, reliability, and aggregate product health.
- Crash, diagnostic, and performance information from Firebase Crashlytics and related error-reporting paths.
4. Location and moving context
Arthact uses location only when you grant permission or provide location context yourself. Location helps keep city context current, support nearby or city-relevant discovery, and make moving-context matching practical.
Precise coordinates are not shown publicly to other users. Product surfaces use reduced context such as city, approximate nearby relevance, freshness, and discovery scope. You can revoke location permission from your device settings.
Background or headless presence refresh may run only where the app, operating system, Remote Config, and your permission settings allow it. The product is designed to avoid constant tracking and to suspend unnecessary location work when discovery state does not need it.
5. Public and private surfaces
Fix This is the public demand graph. Arthact is the execution graph. A Fix This handoff may carry problem, action, city, category, signal snapshot, lifecycle, suggested opener, and goal context into Arthact.
Public Fix This activity may include validations, follows, saves, discussions, solution attempts, reports, city or category momentum, and aggregate trend signals. Private Arthact account data, contact cards, introductions, and chats are not made public through Fix This.
The admin surface is separate from the consumer app and is intended for restricted operator access.
6. How we use information
We use information to provide, secure, operate, support, and improve Arthact. We do not sell personal information.
- Create and maintain your account, profile, goals, contact card, preferences, and legal-consent records.
- Run matching, ranking, eligibility, trust scoring, opportunity discovery, Fix This goal creation, introduction workflows, and match refresh.
- Enable mutual introduction decisions, private contact-card unlocks, participant-only chats, and conversation notifications.
- Send service messages, push notifications, strong-match alerts, high-signal digests, account notices, and support replies.
- Provide data export, account deletion, account recovery, moderation, abuse prevention, block or report enforcement, and safety reviews.
- Measure reliability, diagnose crashes, improve product flows, tune Remote Config, and monitor aggregate usage patterns.
- Comply with law, respond to lawful requests, enforce our terms, and protect users, Sanghance, and the public.
7. What other users can see
Arthact is built around controlled visibility. The product shows enough context for a useful introduction without exposing private contact details or exact location by default.
- Profile and goal signals may be shown to relevant users in matching, discovery, inbox, and introduction surfaces, subject to your settings and product eligibility rules.
- Contact cards stay private until both sides accept an introduction and the server grants access.
- Chat messages are visible to participants in that conversation and to restricted operators only when needed for safety, support, legal compliance, or abuse investigation.
- Blocks, reports, moderation state, deletion feedback, data export payloads, and support context are not public social content.
8. Service providers
We use service providers to operate Arthact. They process information for us, or as otherwise described in their own terms, and are not permitted by us to use your data to build unrelated profiles.
- Google Firebase and Google Cloud for authentication, Firestore, Cloud Functions, Cloud Storage, Remote Config, App Check, hosting, analytics, diagnostics, and crash reporting.
- Firebase Analytics and Firebase Crashlytics for product measurement, stability, and error diagnosis.
- OneSignal, Firebase Cloud Messaging, and Apple Push Notification service for notification delivery.
- Google, Apple, email, phone, LinkedIn, and work-email verification providers where you choose or where a feature is enabled.
- Device operating systems, app stores, browser vendors, and network providers involved in delivering the app.
- Support, email, legal, security, and operational vendors where needed to respond to requests or comply with obligations.
9. Legal bases, consent, and controls
Where privacy law requires a legal basis, we process information to perform our contract with you, based on your consent, for our legitimate interests, to comply with legal obligations, or to protect vital interests in urgent safety situations.
Consent-based features include device permissions, push notifications, some verification flows, and acceptance of updated legal terms where required. You can withdraw device and notification permissions from system settings, though some features may work less well after that.
10. Retention, deletion, and export
We keep information for as long as needed to provide Arthact, maintain safety, comply with law, resolve disputes, enforce agreements, run backups, and keep reliable audit trails.
- Active account, profile, goal, preference, contact-card, and introduction data is generally kept while your account is active.
- Conversation, report, moderation, block, and safety records may be retained for a reasonable period after account deletion when needed to protect users, investigate abuse, or comply with law.
- Analytics and diagnostic data may be retained in aggregated, pseudonymous, or provider-managed form according to configured retention policies.
- Account deletion can be started inside the app and through the public deletion request page. We delete or anonymize personal data within a reasonable period unless retention is required or permitted for legal, safety, fraud-prevention, dispute, backup, or operational reasons.
- You can request an export of account data where the feature is enabled or by contacting support.
11. Your rights
You can update many profile, goal, discovery, notification, contact-card, and location choices directly in the app. Depending on your location, you may also have rights to access, correct, delete, restrict, object, port, or withdraw consent for certain processing.
To exercise rights not available directly in the app, contact support. We may need to verify your account before acting on sensitive requests.
- All users can ask for support with access, correction, export, deletion, consent withdrawal, and account questions.
- EEA, UK, and Swiss users may have GDPR-style rights, including complaint rights with a supervisory authority.
- California users may have CPRA rights to know, delete, correct, opt out of sale or sharing, and avoid discrimination. Arthact does not sell personal information.
- Indian users and users in other regions may have rights under applicable digital personal-data or consumer-protection laws.
12. Children, security, transfers, and updates
Arthact is not intended for children. You must be old enough to lawfully use a professional networking and communication service in your jurisdiction. We do not knowingly collect personal information from children.
We use safeguards including authentication, Firebase Security Rules, server-owned sensitive workflows, participant-gated reads, contact-access grants, rate limits, App Check rollout controls, separation of admin surfaces, and encrypted transport. No online service can be guaranteed to be completely secure.
Arthact and its providers may process information in countries other than where you live. Where required, we rely on appropriate contractual, technical, and organizational safeguards for cross-border processing.
We may update this policy as the product, law, or operating model changes. Material updates may be shown in the app, on the website, by email, by push notification, or through a re-acceptance flow where required. Contact Sanghance at support@arthact.com for privacy, deletion, export, or safety requests.