ExArca

Privacy Policy

Last revision: 9 October 2026

This policy explains what personal data Exarca collects, why, who we share it with, how long we keep it, and the rights you have over it.

Who we are

Exarca (exarca.io) is run by INTESO d.o.o., Kidričeva ulica 25, 3000 Celje, Slovenia. We are the controller of your personal data.

For any privacy question or request, email us at support@exarca.io.

What we collect

Your account

Your email address, first and last name, and your password, which we store only as a salted hash. We also keep your language, time zone, notification settings, whether you show your online status and read receipts, and when you last logged in and were last seen.

Profile details you choose to add

A profile photo, background image, introduction, education, CV, organisation, and links to your Facebook, Twitter and LinkedIn profiles.

Content and messages

The discussions, comments, news, wiki pages, tasks, polls, calendar entries and board cards you create, your chat and private messages, read receipts, and whether you are online.

Files

Files you upload are stored on our servers.

Video calls

Video calls run on our own Jitsi server at meet.exarca.io. Your display name and the room name are sent to it, and your audio and video pass through it to the other participants.

Event registrations

When you register for an event we collect your name, email, organisation, country and the sessions you pick, and share them with the event's organisers.

Paid plans

When you subscribe, we send Stripe your name, email address and account id, and we keep the Stripe customer id, your subscription, plan, status and renewal date. You enter card details on Stripe's pages and we never see them.

Emails

We keep a copy of each email we send you: the recipient, subject, content and time. We keep these copies for 180 days. If you reply to a notification email, our reply mailbox receives it and we post the text as your reply in that conversation.

Signing in with Google, LinkedIn or Facebook

If you choose to sign in with one of these services, we receive your email address, whether it is verified, your name and your profile photo. We copy the photo to use as your avatar.

Technical data

For every request, our server logs your IP address, your account id if you are signed in, the address requested, the response and the time.

Platform visit statistics

When you are signed in and open pages of a platform you belong to, we record the platform, the page, your account and the time. The platform's administrators see totals (views and unique visitors), not who viewed what.

We use no third-party analytics, advertising or tracking tools, and we do not sell your data.

Contract (Art. 6(1)(b) GDPR)

  • Running your account and signing you in, including login codes and password resets.
  • Showing your profile to other members.
  • Storing and delivering your content, messages and files.
  • Video calls.
  • Event registrations you submit.
  • Paid plans.
  • The notification emails you have switched on, and reply-by-email.

Legitimate interests (Art. 6(1)(f) GDPR)

  • Security and fault-finding, using server logs, rate limits and the Cloudflare Turnstile bot check.
  • Visit totals for platform administrators.
  • Records of sent emails, to show delivery and handle replies.

You can object to processing based on legitimate interests.

Legal obligation (Art. 6(1)(c) GDPR)

  • Billing and tax records.

Consent (Art. 6(1)(a) GDPR)

  • Optional profile details.
  • Choosing to sign in with Google, LinkedIn or Facebook.

You can withdraw your consent at any time by contacting us. Withdrawing it does not affect what was done before.

Who we share it with

What you post is visible to the members of the space you post it in. Platform owners can make a platform public. Its published content, discussions included, can then be read by anyone, even people who are not signed in. Working groups are visible only to their members. Platform administrators see their members and, for events, the registration details.

These services process data for us:

  • Hosting: DigitalOcean, Amsterdam (AMS3) data centre, Netherlands.
  • Amazon Web Services (Amazon SES, London region eu-west-2) sends our emails.
  • Reply mailbox: NEOSERV (neoserv.si), a hosting provider in Slovenia. Replies reach it through our domain registrar Namecheap's email forwarding.
  • Stripe handles payments.
  • Cloudflare Turnstile is a bot check on the sign-in and sign-up pages. It loads a script from challenges.cloudflare.com and sends Cloudflare your IP address and technical details of your browser.
  • Google, LinkedIn and Facebook (Meta) handle sign-in, only if you choose them. Facebook is used only where the sign-up page offers it. Google's sign-in script loads only on the sign-in and sign-up pages. LinkedIn is contacted only when you click its button.
  • jsDelivr (cdn.jsdelivr.net) serves the emoji list the first time you open the emoji picker, so it receives your IP address.
  • Our own Jitsi server at meet.exarca.io runs video calls.

Members can embed content from YouTube, Vimeo, Google (Forms, Maps, Docs), Spotify, SoundCloud, Padlet, Canva, Figma, Miro, Loom, CodePen, CodeSandbox, Microsoft Forms and Sway, Mentimeter, Airtable, Typeform and Notion, and posts can show images and link previews hosted elsewhere. When you open such content, your browser loads it from that service, which receives your IP address and may set its own cookies under its own policy. YouTube videos load from YouTube's privacy-enhanced youtube-nocookie.com domain, and Vimeo videos use Vimeo's Do Not Track option; both limit the tracking those services do. Fonts are served from our own server.

International transfers

Our servers are hosted by DigitalOcean, Amsterdam (AMS3) data centre, Netherlands, so your data is stored in the EU. DigitalOcean is a US company; any access to the data from outside the EU relies on an adequacy decision or on standard contractual clauses. Emails are sent through AWS in London, United Kingdom. Stripe, Google, LinkedIn, Meta, Cloudflare, Namecheap and jsDelivr may process data outside the EU/EEA, including in the United States. Such transfers rely on an adequacy decision or on standard contractual clauses.

How long we keep it

  • Your account data stays while your account exists.
  • Deleting your account: in Account settings you can ask to delete your account. It is deactivated at once, and logging in again within 30 days cancels the request. After 30 days we anonymise it. We erase your name, email and profile details. We delete your memberships, settings, notifications, the copies of emails we sent you, and personal images (avatar, background, sign-up photo and the images in your introduction), and remove you from chat member lists. Content you posted in shared spaces stays and shows as "Deleted user", so the people you talked with keep the conversation. If you are the only owner of a platform or group, you need to hand it over or delete it first.
  • Visit statistics are kept. After your account is deleted they are no longer linked to you.
  • Copies of the emails we send you are kept for 180 days, then deleted, and sooner if your account is anonymised. Once a copy is deleted, the unsubscribe link in that email stops working. Replying to a notification by email already stops working 30 days after it was sent.
  • Server logs are rotated into a new file every day, and each file is deleted after 90 days.
  • The database is backed up every night and each backup is kept for 30 days. Our hosting provider also keeps a weekly backup of the whole server for 4 weeks. Data you delete can therefore remain in backups for up to about two months before it is overwritten.
  • Stripe keeps payment records as tax law requires.
  • Event registrations stay with the event for its organisers.

Cookies and browser storage

We use only cookies and browser storage that are strictly necessary to sign you in, keep the service working, or remember choices you made. That is why we do not ask for cookie consent; the notice at the bottom of the page is for your information. We use no tracking or advertising cookies.

NameTypePurposeDuration
jwtExCookieKeeps you signed in.30 days (1 day when you join through a group sign-up link). Removed when you log out.
exarca_rail_wCookieRemembers the width you set for the platform side panel.1 year.
reqMemIdCookieRemembers which group you asked to join while you sign in.10 minutes.
newMemberIdCookieRemembers a group invitation while you confirm your email and finish signing up.10 minutes.
themeLocal storageRemembers your light, dark or system theme choice.Until you clear it.
explore-viewLocal storageRemembers whether you chose grid or list view on Explore.Until you clear it.
workspace-viewLocal storageRemembers whether you chose grid or list view in Workspace.Until you clear it.
exarca-recent-groups:{user id}Local storageLists the groups you opened recently. It is kept per account so the next person on a shared browser does not see them.Until you clear it.
exarca-favorite-groups:{user id}Local storageLists the groups you marked as favourites, kept per account.Until you clear it.
exarca:cookie-notice-dismissedLocal storageRemembers that you closed the cookie notice.Until you clear it.
frimousse/data/en/…Local storageCaches the emoji list after you first open the emoji picker.Until you clear it.
frimousse/metadata/enSession storageChecks which version of the emoji list is cached.Until you close the tab.
exarca:chunk-reloadSession storageStops the page reloading in a loop after we release an update.Until you close the tab.

The video call window from meet.exarca.io keeps its own call settings in that site's browser storage. The sign-in and sign-up pages also load Google's sign-in script and Cloudflare Turnstile, as described above. Embedded content from other services may set those services' own cookies.

Your rights

Under the GDPR you can ask us to:

  • give you access to your personal data;
  • correct it (rectification);
  • erase it;
  • restrict how we process it;
  • give it to you in a portable format.

You can also object to processing based on legitimate interests, and withdraw any consent you gave. You can edit your profile and delete your account yourself in the app.

To make a request, email support@exarca.io. We reply within one month. We make no decisions about you based solely on automated processing.

You can complain to the data protection authority in the EU country where you live or work, or where you think the problem happened. As we are established in Slovenia, our lead authority is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec, www.ip-rs.si).

Contact

Email: support@exarca.io

Post: INTESO d.o.o., Kidričeva ulica 25, 3000 Celje, Slovenia

Changes to this policy

When this policy changes we update the date at the top. We tell account holders by email about significant changes.