Sign in

Privacy Policy

Last updated: August 6, 2026

Overview

Ark Agency ("we", "us", or "the Service") is a content operations platform for video production teams. This Privacy Policy explains what information we collect, how we use it, and the choices you have. It applies to the Ark Agency web application and any related services we provide.

Information we collect

Account information. When you create an account we collect your name, email address, password (stored in hashed form by our authentication provider), and any profile details you choose to add, such as an avatar or job title.

Workspace content. Information you and your team enter while using the Service, including clients, content briefs, scripts, content pieces, tasks, shoot and meeting schedules, feedback, time-tracking entries, and notifications.

Usage and technical data. Basic technical information needed to operate the Service securely, such as log data and error reports.

Google user data (optional). If you choose to connect your Google account, we access the Google data described in the next section. Connecting Google is entirely optional — the Service works without it.

Google user data

Ark Agency offers an optional Google Calendar integration. If you connect your Google account, we request the following OAuth scopes:

  • Basic profile and email (userinfo.email, userinfo.profile) — used to identify which Google account is connected to your Ark Agency profile.
  • Read your calendars (calendar.readonly) — used to display events from your primary Google Calendar alongside your Ark Agency schedule so nothing gets booked twice.
  • Manage events (calendar.events) — used to create and update events on your primary Google Calendar for shoots and meetings you schedule in Ark Agency, and to keep those events in sync when they change.

We only use Google user data to provide the calendar features described above. We do not use Google user data for advertising, we do not sell it, and we do not allow humans to read it except with your explicit consent, where necessary for security purposes, to comply with applicable law, or where access is limited to aggregated, anonymized data for internal operations as permitted by Google's policies.

OAuth tokens for your Google account are stored encrypted and are used solely to make the calendar requests described above on your behalf. You can disconnect Google Calendar at any time from the Settings page in the app, which removes the stored connection, or revoke Ark Agency's access from your Google Account permissions page.

Ark Agency's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use information

  • To provide, operate, and improve the Service.
  • To authenticate you and keep your account secure.
  • To power collaboration features — showing your name and avatar to teammates in your workspace, sending in-app notifications, and syncing schedules.
  • To respond to support requests and communicate about the Service.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use it for advertising.

How information is shared

Your workspace content is visible to other members of your workspace according to their roles. Beyond that, we share information only with the service providers that host and operate the platform on our behalf:

  • Lovable Cloud — application hosting and authentication.
  • Supabase — database and file storage.
  • Google — only if you connect Google Calendar, to sync events as described above.

These providers process data solely to provide their services to us. We may also disclose information if required by law or to protect the rights, safety, or security of the Service and its users.

Data retention and deletion

We retain your information for as long as your account is active or as needed to provide the Service. If you disconnect Google Calendar, the stored connection and tokens are removed. If you want your account and associated personal data deleted, contact us at filipbonce@gmail.com and we will process the request within 30 days, except where retention is required by law.

Security

We take reasonable technical and organizational measures to protect your information, including encrypted connections (HTTPS), encrypted storage of third-party access tokens, and role-based access controls within workspaces. No method of transmission or storage is completely secure, but we work to protect your data against unauthorized access, alteration, or loss.

Children's privacy

The Service is intended for business use and is not directed to children under 16. We do not knowingly collect personal information from children.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. Material changes will be communicated through the Service.

Contact

If you have questions about this Privacy Policy or how your data is handled, contact us at filipbonce@gmail.com.