Privacy Policy

How we collect, process, and protect personal data — including specific protections for children's data under GDPR and COPPA.

Draft

Terms of Service

The terms governing use of Arc Sentinel's websites, Quest Guardian platform, and related services.

Draft

Compliance & Security

How Quest Guardian meets EU Cyber Resilience Act, GDPR, COPPA 2025, and EU AI Act requirements. Architecture-level compliance documentation.

Draft

Our Privacy Principles

No Cloud Processing

Child safety data is processed on decentralized infrastructure. We never use centralized cloud services for sensitive content.

Parent-Held Keys

Encryption keys are generated on the parent's device. Our server cannot decrypt child monitoring data — only the parent can.

Minimal Retention

Evidence data is retained only for the period necessary to serve its protective purpose, then permanently deleted.

Transparency First

Parents have full visibility into what data is collected, how it's processed, and the ability to delete it at any time.

Regulation by Design

GDPR, COPPA, CRA, and EU AI Act compliance is built into our architecture from day one — not retrofitted.

EU-Hosted Infrastructure

All backend services run in EU data centers. No child data is transferred to jurisdictions with weaker protections.