Who we are
ArcDemo is run by Stackwise Oy, a company registered in Helsinki, Finland. Business ID to confirm. For account, billing and website data we are the controller.
For the content and viewer data in the demos you publish, your organization is the controller and we process it for you under our Data Processing Agreement.
What we collect
- Account data: your name, email, password (stored as a hash), workspace and role.
- Billing data: plan, invoices and billing contact. Card details go straight to Stripe and we never see them.
- Your content: the demos, screenshots, HTML captures, recordings and assets you create.
- Viewer data: for demos you publish, we record views, step progress, approximate location from IP address, referrer, device type, and anything a viewer types into your forms.
- Usage and technical data: product analytics for signed-in creators, plus logs we need to run and secure the Service.
The Chrome extension
When you use the ArcDemo Chrome extension, it can collect the page URLs and titles you choose to record, browsing activity needed to connect captured states, website content and resources needed to reproduce those states, screenshots, HTML snapshots, video, and visible screen or application-window pixels.
A capture can also include click, pointer, keyboard, selector, element-geometry, scroll, navigation, and transition metadata. If you select them, it can include tab audio, microphone audio, webcam video, and device identifiers supplied by Chrome. Browser-internal pages, Chrome Web Store pages, and other restricted/native UI are not supported capture targets.
The extension first keeps capture data in Chrome extension storage and IndexedDB while you record. Screenshot steps upload as soon as you confirm them; if a screenshot upload fails, the step remains locally for retry or discard. Video recordings upload automatically when you stop; if that upload fails, the recording remains locally for retry or discard. HTML and sandbox recordings stay local until you choose Upload. Uploads are sent over HTTPS to ArcDemo and may be stored in Cloudflare R2 and processed by ArcDemo services to create, edit, share, and export your demo.
HTML capture applies configured form-value masking and supports authored privacy rules, but masking HTML values does not erase sensitive information already visible in a screenshot, video, or screen/window recording. Review the visible pixels before uploading and avoid recording secrets, passwords, payment data, or information you are not authorized to share.
The macOS recorder
The recorder asks macOS for Screen Recording permission and captures only the windows you pick. Recordings stay on your Mac until you upload them to your workspace. You can turn the permission off any time in System Settings.
How and why we use it
- To provide the Service (contract): sign-in, hosting and sharing demos, analytics, email.
- To keep it secure (legitimate interests): detecting abuse, bots and fraud.
- To improve ArcDemo (legitimate interests): aggregated product analytics for creators. We never use analytics on public demo pages.
- To bill you and meet legal duties (contract and legal obligation): invoices, tax and accounting.
- To send product news (consent): only if you opt in, and you can unsubscribe at any time.
International transfers
Some of our providers process data outside the EU and EEA. When they do, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision such as the EU–US Data Privacy Framework.
How long we keep it
We keep account and content data while your account is active. Raw analytics events are kept for a limited period and then deleted. When you delete a demo or your workspace, we delete the data, and copies in backups expire on their own schedule.
Pending recordings remain locally until they upload or you discard them, subject to Chrome storage limits and browser or extension removal. Uploaded demos and their media remain while your workspace retains them; you can delete demos in ArcDemo and request account-data deletion at privacy@arcdemo.io. Backups and provider retention may take additional time to age out.
Your rights
Under the GDPR you can access, correct, export or delete your personal data, object to or restrict how we use it, and withdraw consent. Email privacy@arcdemo.io and we'll reply within 30 days.
If you watched a demo or filled in a form in one, contact the company that shared it, because they control that data. You can also complain to the Finnish Data Protection Ombudsman at tietosuoja.fi.
Security and Chrome Limited Use
We protect data with encryption in transit, access controls and the other measures on our Security page.
Chrome Limited Use commitment: ArcDemo uses extension data only to provide or improve the user-requested capture, editing, storage, sharing, and support features. We do not use captured data for personalized advertising, sell it, or transfer it for unrelated purposes. We limit human access to support requested by you, security and abuse investigation, legal obligations, or service-provider operations, with access controls. We protect data in transit and at rest where supported, but no system is completely secure. The use of information received from Chrome extension APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Children
ArcDemo is a business tool. It isn't meant for anyone under 16, and we don't knowingly collect their data.
Changes and contact
We'll post any updates here and change the date at the top. For significant changes we'll also email you. Questions? Email privacy@arcdemo.io.