ARXAK
Make it real · Early access
HomeEN
ARXAK / PRIVACY

Your plans, with clear boundaries.

This notice describes the ARXAK Make it real early-access app operated by Arxak Pte Ltd, Singapore. Contact contact@arxak.com with privacy questions.

Class matching and location

Match me uses your selected city. If you choose Use my location, your browser asks for permission. Your coordinates are rounded on your device to two decimal places before a nearby search. The server and search provider receive that approximate search area, not your exact device coordinates. City and region searches use the place you enter. City, class interests, saved class IDs and hidden class IDs are kept in this browser. Booking links lead to independent providers, which apply their own privacy policies.

Sign-in and private records

Available sign-in methods identify your account. The service uses the site-specific user identifier to associate plans, recipes and group responses with you. Saved plans can include your goal, location, spending cap, dates, notes, quotes, booking references, experience feedback and your explicit personal priorities, kept options and dismissed option links. Shortlist choices remain private and are excluded from public recipes and group invitations. They can be removed or changed in the plan. Do not enter passwords, full payment-card details or unnecessary sensitive information.

What stays in your browser

Your appearance, language, preferred location and new-plan currency preferences are stored on this device. These preferences do not change existing quotes or payment currencies. An unsaved draft may be temporarily kept in session storage so it survives a sign-in redirect. It is cleared after a successful initial save. Saved records use server storage rather than this temporary draft.

Invitations

Creating an invitation requires your consent to share its title, city, style, dates, group size, spending cap and selected components with anyone holding the link. The invitation expires after seven days and can be disabled. Guests sign in and consent before sharing a chosen display name and date responses with the organizer. Other guests cannot see individual responses. Private notes, quotes and booking references are not included.

People discovery and invitations

Adults can choose a profile name, city, bio, interests, invitation preferences and optional photo. Discovery is opt-in and expires after the chosen 24 hours or seven days. The first three available profiles form a visitor preview; signed-in users can browse further. Readiness is self-declared, not proof that someone is online, age-verified or identity-verified. Pause discovery or delete your profile from My profile. Photos are resized on your device and stored in object storage.

Invitations store the sender and recipient display names and cities, proposed date, public meeting place, message and decisions. Only the two participants can read them. Creating an invitation sends it inside ARXAK, not by email or SMS. Accepted event invitations do not automatically grant a seat. Blocks prevent further discovery and invitations between signed-in accounts; they cannot prevent a blocked person from seeing a public visitor preview while signed out. Reports are recorded and also block the person. Contact support for urgent follow-up. Deleting your profile withdraws pending invitations you sent and removes your photo; existing invitation and report records remain for participants and safety handling.

Your personal account profile

You can optionally add a display name, city, interests, self-selected personality words, social preferences and an optional personal answer. These choices are saved privately to your account. Your city and interests can tailor class suggestions; personality words are self-descriptions, not a psychological assessment. You can edit them in You Personalise my suggestions. Creating this profile does not publish you in people discovery. Any details copied to your separate people profile require your review and explicit discovery consent.

Public events and wishlists

Event publication requires the host’s explicit consent to share the displayed listing details and provider quote terms. Guests consent before requesting a place; pending and declined requests are visible only to the host and requester. Accepted participants’ chosen display names appear publicly on the event. Exact meeting details are limited to the host and accepted participants. Public listing copies remain separate from their source plan. Cancellation and withdrawal records remain available in the event.

Photo wishlists use server object storage for images and database records for descriptions, delivery regions, spending caps and buying commitments. Personal wishes are private until you create a shared link. Event wishes can be viewed by the host and accepted participants. Shared links expose the photo, wish details and buyer’s chosen display name to anyone holding the link; you can turn the link off. Images sent for matching are shared with OpenAI only when you request that search. Removing a wish deletes its photo and coordination record, not an external merchant order. Account identifiers are not exposed on public listings.

Recipes

Publishing a recipe makes its limited plan details available to anyone with its link. The preview identifies those details before publication. Removing the recipe disables future access to that link; it cannot recall copies already made by other users.

Supplier search

When you choose Find & compare, ARXAK sends the visible request, location, group size, spending cap, currency, preferred date, selected personal priorities and starting-point category to OpenAI for web research. It does not send private notes, guest names or booking references. Responses API storage is disabled; OpenAI may retain data under its applicable service policies. Search results are cached for your account for 30 minutes. Hashed account identifiers, query hashes and result records support usage limits. Records older than 24 hours are removed on subsequent successful searches; inactive records may remain until that cleanup runs. Contact us for earlier removal. Personal shortlist refinements can rank the existing dated catalogue without an external search. Fresh search requires ARXAK’s search connection and a signed-in request.

External websites

Provider links open independent websites under their own privacy and payment terms. ARXAK does not send your private plan to a provider simply because you open its link. Copying an enquiry produces text for you to review and send yourself. Interface fonts are served directly by Arxak without a third-party font request.

Export and deletion

Export your private plans from You, or download a brief within a plan. Delete a plan to remove its plan data, invitation and group responses. Remove published recipes separately in Studio. Guests can withdraw their response using a still-active invitation. Contact us for help with a response after a link closes or for broader account-data requests. Provider bookings are separate and cannot be cancelled by deleting ARXAK records.

Existing account records

Records created in earlier versions remain subject to their existing access controls. Contact us for access, export or deletion help.

Opt-in gathering suggestions

Next up stores the name, city, interests, time zone, free-time windows, budget, frequency and calendar busy periods you choose. Calendar exports are parsed in your browser; titles, attendees, descriptions and meeting links are not uploaded. Only time intervals for the next 32 days are retained. Imported intervals are snapshots, not a live calendar connection. Free time you enter is a preference, not a confirmed commitment.

Private circles are joined through an invitation and consent. Matching compares opted-in members’ city, interests, budgets and available times. Members see a proposed plan and response counts, not other members’ calendars or contact information. Public source research receives the city, activity interests and budget needed to suggest a place; individual calendar records and account identifiers are not sent to the research model.

Device notifications require a separate permission and store your push endpoint and encryption keys. Notifications show a general message. Push providers process delivery; delivery is not guaranteed. Pause suggestions to stop matching and remove notification devices. Leave a circle to stop group matching, or delete your suggestions data from Next up. Closing a circle stops matching for all members. No external booking, payment or calendar change occurs when you respond.

Gathering and host setup requests

The request form stores your name, contact email, city, format, preferred date, group size, per-person budget, company preference, notes and the terms accepted with your request. These records are private and are used by Arxak to review and respond to the request, not to enrol you in marketing. Do not submit colleagues' details or sensitive information.

A secure browser cookie links you to your private receipt for up to 30 days. A daily hashed network address is used for abuse limits. You can delete an unpaid request that has no checkout from its receipt in that browser, or contact contact@arxak.com with the reference for access, cancellation, refunds or deletion. Requests with payment records are retained for fulfilment and financial recordkeeping. Cookie expiry does not delete the stored request. Requests are retained until deleted or removed in an operational retention review. Request follow-up is manual; payment is recorded from verified Stripe status. Contact details are not posted publicly or passed to hosts simply by submitting this form.

Additional sign-in methods

Google and Apple sign-in are available only when their account setup is complete, as shown on the sign-in page. They share an identity response with ARXAK; we keep the provider's stable account identifier and its link to your ARXAK account. We do not request your email inbox, contacts or AI subscription. Sign-in sessions use secure, HTTP-only cookies, expire after seven days and can be ended by signing out. Temporary sign-in challenges expire after ten minutes. Accounts are linked only through an explicit link action; matching email addresses are not used to merge accounts.

Payments and refunds

Where an event has an enabled checkout, The configured payment provider (Stripe or Revolut) handles card and payment details. ARXAK stores the event, payer account, agreed amount and currency, provider order references, status and refund records. These records support receipts, cancellation handling and reconciliation. Payment information is not published on the event roster. New live checkouts require a reviewed tax treatment as well as the merchant connection. ARXAK stores the subtotal, applicable tax and final collected total; the provider collects the address needed for tax calculation. No saved card or automatic host debit is implemented.

Destination photographs

Some attributed destination photographs load from Wikimedia. Your browser contacts its image servers when you view them; these requests use no referring page address. Each photograph links to its author and reuse licence.

Google Maps place results

When Google Places is enabled, ARXAK sends your selected city or your device-rounded approximate search point, language and search category to Google Maps Platform to retrieve place names, addresses, coordinates and Google Maps links. The server keeps the API credential private. Google-supplied place content is displayed live with Google Maps attribution and is not written into ARXAK’s shared discovery cache or your browser’s saved-picks list. A place can still be added to an ARXAK plan through the details you choose to keep. Google processes these requests under the Google Privacy Policy.

Nearby discovery and email verification

Device location is optional and permission-based. The browser rounds it to about two decimal places for nearby searches. Arxak does not continuously track location. Approximate search coordinates may be sent to OpenAI for discovery and to the Wikimedia Foundation for nearby public geographic references. Local public-place results can be cached without an account identifier. Wikipedia references are geographic suggestions, not verified opening hours or live availability.

When email sign-in is enabled, Resend receives the email address and a short-lived verification message. Arxak stores a secret-keyed digest of the code, expires it after ten minutes and limits attempts. Codes are not marketing subscriptions. Email open and click tracking are disabled for sign-in delivery.

Partner offers and service threads

Host and venue profiles can optionally share their business offer and contact email privately with campaign buyers matching their stated city and group capacity. This permission is separate from promotional updates and can be turned off in the workspace profile. Offers and contact details are self-reported; publication does not verify the supplier. Private service threads store buyer questions, revisions, cancellation requests, progress and prepared deliverables for the buyer and Arxak operations. Avoid sensitive information in these threads. Saving a cancellation request does not itself issue a refund. Contact us for access, correction or deletion requests.

Saved commercial selections

Optional offer selections are private account records containing the offer, seller, quoted price, currency, recurrence and chosen quantity. They are not purchases, subscriptions or reservations. You can remove them from Saved selections. Event hosts publish their own offer descriptions and terms; selection records are not shared with those hosts in this release. Hosts can export their own event participation names and statuses. Digital pack previews are generated on your device; names and menu text entered in a preview are not sent to ARXAK.

Community campaigns and workspace registrations

Workspace registration stores your name, contact email, roles, organization, city, public website, interests, consent choices and optional referral tag. Email is not verified by saving a profile. A secure HTTP-only cookie provides access from this browser for up to 30 days; expiry does not delete stored data. Signing in can connect that browser workspace to your account. Campaigns store briefs, supplier budgets, references, management payment records and participant responses. Arxak operations can read these records to review and deliver the service. Optional promotional updates require a separate choice.

A campaign invitation exposes its description, sponsor, proposed places and times to anyone with the link. Unlike personal plan invitations, these campaign links stay active until replaced or the gathering is cancelled. The private host link grants attendance access; keep it private. Guests may respond without an account and share their name, option, availability and optional email with the campaign organizer. Other guests cannot view those responses. Hosts see participant names, status and check-in state, but no sponsor contact list. The organizer records physical attendance with a participant code. Attendance is not independently audited.

Sponsor contact permission is optional and separate from joining. Only non-withdrawn, opted-in names and emails appear in the sponsor export. Guests can revoke permission or withdraw in the same browser through an active invitation; withdrawal removes their response details and check-in from the workspace. Copies already exported cannot be recalled by this action. Repeating a campaign creates a new draft without copying participants or payments. Request profile or campaign export, deletion, cancellation or help after losing browser access at contact@arxak.com. Financial records may remain for required recordkeeping; other records remain until deleted or reviewed for retention. No automatic supplier payment, booking or marketing subscription is created by registration.

AI requests and verification codes

When you search, your description, selected city or approximate device location and language are sent to OpenAI to research public sources. Responses API storage is disabled. Avoid entering personal or sensitive details. Source-backed results are cached to reduce repeated searches; your request is represented by a hashed cache key. External search links open Google and carry the search text and selected area in their URL.

When email or mobile sign-in is enabled, Twilio Verify receives your email address or phone number to deliver and validate a code. Email delivery uses the configured SendGrid sender. Arxak stores the verified address or number as an account sign-in identifier. Temporary verification records expire after ten minutes and are removed during subsequent verification starts; they cannot be reused after expiry. Hashed network and destination identifiers support short-term abuse limits. Arxak does not store the verification code. These channels remain unavailable until their provider connection is complete.

Anonymous side quests, environment and Arxie Radar

The homepage works without sign-in. Optional browser GPS is rounded to three decimals before OpenStreetMap Nominatim and server-side WeatherAPI lookups. Precise GPS is not sent to OpenAI or saved in passes. A denied location prompt uses a labelled suggested city from timezone or language, not a detected location. You can change it.

Public OpenStreetMap area names are cached for 24 hours using hashed lookup keys. Nearby venue entries come from a server-side Foursquare Places search on a venue-cache miss, inside a selected radar horizon of 1–100 km (2.5 km default) around approximate GPS or a selected area center. Approximate search coordinates and radius reach Foursquare. Up to 15 listings are considered, subject to coverage and filters; no background venue searches run; nearby venue pools are cached for up to one minute. These source records do not establish current popularity, opening hours, equipment, access or availability. A failed lookup stops generation; no merchant, address or nearby distance is invented. Public area center coordinates can be cached; raw visitor GPS is not stored. Geocoder map data is © OpenStreetMap contributors; their privacy policy applies at https://osmfoundation.org/wiki/Privacy_Policy. Venue data is provided by Foursquare; its privacy policy applies at https://foursquare.com/legal/privacy-policy.

WeatherAPI.com provides current area conditions when its server-side key is configured. Coordinates and weather responses are not persisted. Weather is general information only; conditions are uncertain and may differ at your exact location or time. Never rely on them alone for safety-critical decisions. Consult official meteorological services and relevant authorities. WeatherAPI.com is not liable to our end users for their decisions using weather data. Provider terms apply at https://www.weatherapi.com/terms.aspx. When WeatherAPI is unavailable or unconfigured, MET Norway provides a labelled hourly forecast under CC BY 4.0. Shared coarse forecast cells are cached until provider expiry. When both sources fail, the interface displays weather unavailable.

Nearby public venue names, addresses, types, photo URLs, local hour and atmosphere summary enter OpenAI. Recent-title history is used only to exclude repeat venues and is not shared with the model. Nearby source pools and generated suggestions may be cached for up to three minutes under hashed coarse-cell context keys. Exact source venue pins are retained for navigation; visitor GPS is not saved in these caches. Eligible enterprise partners below their monthly allotment may be prioritized; partner-prioritized suggestions are labelled. Visitor GPS is not sent to the model. Photos are shown only when supplied in the Foursquare result. Otherwise category artwork is a labelled placeholder. Displayed photos are requested from Foursquare’s image CDN with no referrer, which receives normal network information including viewer IP. Map routing shares the selected native venue name and source address with Google. API response storage is disabled, but provider service and abuse-monitoring records may still apply. Arxie Passes are generated on this device. The active pass watches precise GPS locally and pauses watching when the page is hidden. Checking in sends one fresh location fix to check the 30-meter distance against the source venue pin. Supabase saves the venue, internal pseudonymous profile ID, arrival time, calculated distance and reported GPS accuracy; no coordinate trail is retained in the arrival ledger. A repeat arrival at the same venue within 24 hours is not counted again. Browser GPS is device-reported location, not proof of a purchase or a merchant-confirmed visit. Venues with an explicit arrival-billing agreement may pay the agreed fee; visitors are not charged for pinging. Merchant billing records are private and accessible only to the server. Copying an invitation does not send it to anyone. Downloads work offline; map links and GPS arrival check-in need the live site.

Arxie Radar counts open tabs, not verified people. It shows aggregate neighborhood counts, hiding nonzero counts below three. When Supabase anonymous sign-in is enabled, a random UUID and anonymous authentication credentials persist in browser storage. Supabase stores an internal pseudonymous profile, a hashed device token, short-lived tab presence in a hashed neighborhood cell and pulse events. Profiles and presence rows are readable only by their owner; pulse reads require live membership in the same cell. No name, photo, bio or GPS coordinate is stored in these records. Until this connection is ready, the existing radar uses a random tab-memory token with short-lived hashed server presence. Presence expires after 35 seconds without a visible-tab heartbeat. Pulse signals expire after 30 seconds. Expired rows are cleared on later radar requests. Visual pulse reception is enabled while the matrix is open and can be switched off. Pulse feedback is an 800-millisecond noninteractive screen aura, with reduced-motion support. Neighborhood radar exposes no direct messages, profiles or visible identities.

Normal hosting and provider logs still apply. Short-lived network abuse counters control requests and costs; complete untrackability is not promised. No GPS, quest or pass is saved in browser storage. Anonymous session identifiers and authentication credentials may be saved; clearing browser data removes local access but does not itself delete server records. Contact contact@arxak.com for deletion requests. Radius and energy preferences remain in tab state and are supplied to the generation engine. Profiles are internal session records, never public social profiles.

Optional venue photos and moments

Photo sharing is a separate, explicit choice. After a fresh device GPS check within 30 meters of a source venue pin, you may consent to show a small photo to people viewing that venue in Arxak. Photos are cropped and re-encoded on your device, with location metadata removed, and stored in private object storage. No name or public profile is created. This confirms a device-reported nearby position, not a person’s identity or attendance inside a building. A secure HTTP-only cookie connects your venue photo and outing feedback for one day. Only its digest is stored server-side.

Visible-tab location checks renew photo sharing every 15 seconds. Sharing expires after 45 seconds without renewal. Hiding the page, leaving GPS range, hiding your photo or finishing the moment requests immediate removal. Expired photos cannot be requested and are physically cleared on later venue requests. Short-lived quiet hello events last 30 seconds, require current nearby photo-sharing membership, and exclude the sender. You can switch reception off. Check-in and completion records contain the venue, arrival time and optional worth-it feedback, with an internal cookie digest and pass identifier; precise coordinate trails are not saved. Contact contact@arxak.com to request deletion.

Self-service merchant gateway

Merchant registration stores the business name, contact email, geocoded storefront address and pin, selected off-peak periods, and private Stripe customer and subscription mappings. Address lookup uses OpenStreetMap Nominatim and can be cached for 24 hours. The merchant confirms its pin; registration does not verify ownership. A secure, HTTP-only browser cookie provides workspace access for 30 days, with only its one-way digest stored in Supabase. Contact support after losing browser access. Stripe hosts payment-method collection; Arxak does not receive card numbers. Saving a card alone does not activate arrival billing. A matched venue needs a separate approved subscription before charges begin.