1. Who is responsible for your information
Everyday Arc Ltd operates Let It Be Known and is the controller of the personal information described in this policy. The Department of Small Matters is the ceremonial identity presented within Let It Be Known. It is not a government body, authority or public office.
Privacy questions and rights requests may be sent to correspondence@everydayarc.com, the dedicated Let It Be Known correspondence address.
2. What the app is
Let It Be Known turns a matter submitted by a claimant into a ceremonial certificate. Its certificates and notices have no legal force. The app is not a court, regulator, dispute-resolution service, medical service or crisis service.
The app can be used with an anonymous Firebase account. A claimant may instead create or secure a file using email and password, Sign in with Apple or Google Sign-In. An email-and-password file must be verified before it can lodge a matter.
3. Information we process
Depending on how the app is used, we process:
- Account and file information: an internal Firebase user identifier; account type; email address and display name where supplied by the claimant or sign-in provider; verification state; claimant number; standing; filing allocation; settings; permission and consent records; blocked-account list; and account-security information.
- Matters and certificates: matter text while it is being considered; the generated certificate, including its title, body, closing, desk, case number, claimant name, date and public summary; file visibility; publication-safety and moderation status; and interaction and report counts.
- Interactions and reports: certificates witnessed or marked likewise aggrieved; the acting account identifier; reports of offensive content, personal information or spam; the reason for a report; moderation actions; and related timestamps.
- Notifications and correspondence: a push token if notifications are enabled; notices, directives and their read state; email-verification and account-security correspondence; and private support requests, including the message, category, reply address, reference and status.
- Usage and security data: app events, limited counts and categories, feature outcomes, durations, character counts, an app-instance or device identifier, device-integrity attestations, approximate location derived from a masked IP address, IP address and operational logs needed to deliver, secure and diagnose the service. Authentication troubleshooting uses a random support reference and bounded provider, phase, checkpoint and failure-category fields. It does not include the claimant's email address, Firebase user identifier, credential, token, provider response, URL or raw error message.
We do not sell personal information. We do not show advertising, use advertising identifiers or track people across other companies' apps or websites for advertising.
4. Drafts and original matter text
An unfinished draft may be stored locally on the device so that the claimant can return to it. It is not uploaded to the Department as a draft. A claimant can clear the draft in the app.
When a matter is presented, the text is transmitted to our server and to Anthropic for the processing described below. We do not intentionally write the claimant's original matter text to the Department's Firestore database or application logs. The certificate becomes the lasting record. Anthropic's separate retention is described in section 5.
The requests made to Anthropic do not append the claimant's name, email address, Firebase user identifier, purchase status or device identifier. The words a claimant chooses to submit may themselves contain personal information. Claimants should not include details that are unnecessary for the matter.
5. AI processing and permission
With the claimant's explicit permission, Let It Be Known uses Anthropic, a third-party artificial-intelligence provider, to:
- classify and route the submitted matter;
- prepare a certificate when the matter is accepted for filing; and
- conduct a publication-safety review of every generated certificate, including a certificate that is currently private, so that it can remain safe if the claimant later opens the file to public inspection.
The Department asks for permission when the claimant first enters the Counter under the current disclosure, before a statement is entered or transferred. Choosing Decline and Return sends nothing to Anthropic. This processing is necessary for the Department to consider a matter and issue a certificate.
Permission is recorded locally for that claimant and disclosure version. It can be turned off in Department Records under Privacy. While it is off, the claimant may continue to consult the Bulletin, witness certificates and manage the file, but cannot present a matter or receive a certificate. Entering the Counter presents the permission notice again. Turning permission off cannot recall processing that has already taken place.
Everyday Arc determines the purposes of this processing and remains the controller. Anthropic processes the API requests as a service provider acting on Everyday Arc's instructions, subject to the applicable commercial terms and data-processing agreement.
Under Anthropic's standard API retention terms, API inputs and outputs are deleted from its systems within 30 days of receipt or generation, except where Anthropic and Everyday Arc agree a different period, where longer retention is required by law, or where material is retained to enforce Anthropic's Usage Policy. Anthropic states that inputs and outputs flagged as Usage Policy violations may be retained for up to two years and related trust-and-safety classification scores for up to seven years. Let It Be Known does not submit API feedback. Anthropic does not use commercial API inputs or outputs to train its models by default unless the customer opts in or submits them as feedback. Everyday Arc does not opt in.
6. Routing and automated decisions
Before a matter leaves the device, the app performs a narrow local check for urgent crisis phrases. A local match routes the claimant to a welfare notice and does not send the statement to Anthropic.
If the local check does not match and AI permission has been given, Anthropic classifies the matter as suitable for filing, outside the Department's scope, unsuitable for filing, or uncertain. A matter whose subject is serious harm, danger or crisis is routed to the welfare notice. A serious circumstance mentioned only as background to an ordinary small grievance may still be filed. Content used to threaten, target, demean or expose another person may be refused. A refusal or uncertain decision receives a second automated review before it can prevent a filing or count as a failed attempt.
This process determines only whether the app's ceremonial service can receive a submission. It does not make a legal finding, medical assessment or other decision with legal or similarly significant effect. No certificate is issued for a matter routed to welfare or refused.
7. Public inspection
Visibility is set for the claimant's whole file, not certificate by certificate.
When a file is open to public inspection, eligible certificates may appear on the Bulletin, in the Registry and in featured areas. A public certificate may show the claimant name recorded on it, certificate title and text, public summary, case number, date, desk, classification and public interaction counts. The original statement is not published. A certificate withheld by publication-safety or moderation review remains private even when the rest of the file is open.
When a file is restricted, its certificates remain on the claimant's own record but do not appear in public views. A claimant can change the file setting in Department Records. Other signed-in claimants can report a public certificate or block its claimant. Blocking hides that claimant's public certificates from the person who applied the block; it does not remove the certificates for everyone.
Before a file is first opened publicly, the app presents a public-filing notice and content policy. Public certificates may be removed or withheld where needed to enforce that policy, protect people, investigate reports or comply with law.
8. Analytics and device security
We use Google Firebase Analytics to understand whether app features work and how the service is used. Analytics events contain event names and limited counts, categories, desks, outcomes, durations and character counts. Google Analytics derives approximate location from a masked IP address. The events do not contain grievance text, certificate text or claimant names. Analytics may be associated with a pseudonymous internal user identifier or app-instance identifier, so it should not be described as anonymous.
We use Firebase App Check with Apple's DeviceCheck and Google's Play Integrity services to help distinguish genuine app requests from abuse. They process device or app-integrity information and security tokens. Cloud Functions and authentication systems may also process IP addresses, user-agent information and operational logs for security and service delivery.
9. Notifications
Notifications are optional. If a claimant enables them, we use Firebase Cloud Messaging and the device's notification service to deliver notices about certificates, witness or likewise-aggrieved milestones, changes in Department standing and other correspondence. We store a push token for this purpose. A claimant can withdraw notification permission in Department Records or in device settings. Notices are also kept in the app where the relevant feature provides an in-app copy.
10. Why we use the information
Under UK data-protection law, we rely on the following lawful bases:
- Performance of a contract: to open and maintain a file, authenticate a claimant, consider a matter, carry out the AI processing necessary to provide the requested filing service, issue and store certificates, apply visibility settings, record interactions and provide requested service functions.
- Consent: for optional notifications. Where submitted matter text contains special-category information and explicit consent is the applicable additional condition under data-protection law, the claimant's express AI-processing choice is also relied upon for that information. Consent may be withdrawn for future processing.
- Legitimate interests: to secure the app, prevent misuse, enforce filing and content rules, moderate public records, investigate reports, maintain limited audit records, diagnose failures, measure product use and improve the service. Our interests are operating a safe, reliable and proportionate service. We use limited event data and do not include grievance or certificate text in analytics.
- Legal obligation and legal claims: where processing is needed to comply with law, respond to a lawful request or establish, exercise or defend legal claims.
Providing a name and permanent sign-in method is optional because an anonymous file is available. Matter text is required if the claimant asks the Department to consider and file a matter. AI permission is a separate, explicit product control rather than the Article 6 lawful basis for processing ordinary matter text. It may be declined or turned off, but without it the Department cannot perform the filing service or issue a certificate.
11. Service providers and recipients
We use:
- Google Firebase: Authentication, Cloud Firestore, Cloud Functions, Analytics, App Check and Cloud Messaging;
- Anthropic: classification, routing, certificate preparation and certificate publication-safety review;
- Apple: app distribution, Sign in with Apple if selected, DeviceCheck and notification delivery on Apple devices;
- Google: Google Sign-In if selected and the Firebase services listed above;
- Resend: delivery of service email to a claimant who has supplied an email address. Resend receives the recipient address, the subject and body of the message, and ordinary delivery metadata such as timestamps, message identifiers and the resulting delivery status. A support receipt includes the support message the claimant has just asked the Department to receive. Resend does not receive original matter text submitted for a certificate, certificate text, display name, Firebase user identifier or device identifiers. Other service email is limited to messages the Department must send about a claimant's own file, including verification of a correspondence address, a password amendment the claimant has requested, and notices that a certificate of theirs has left or returned to public inspection; and
- professional advisers, regulators, courts or public authorities where disclosure is reasonably necessary or legally required.
These providers process information under their own terms and, where they act for Everyday Arc, under applicable data-processing terms. We do not use RevenueCat or collect purchase history in the free-only version 1.0 release. This policy must be updated before a paid arrangement is enabled.
12. International transfers
Some providers process information in the United States and other countries outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, Everyday Arc relies on an applicable UK adequacy regulation or approved contractual safeguards, together with relevant supplementary measures. A claimant may contact us for further information about the safeguard used for a particular provider.
13. How long information is kept
We apply the following retention rules and criteria:
- local drafts remain on the device until submitted, cleared, replaced, the file is reset or the app is removed;
- account, preference, certificate, interaction, notice and report records remain while needed to provide the file and public record, and are placed into the account-deletion process when closure is requested;
- when closure begins, a one-way hash of the Firebase account identifier is retained for up to seven days solely to prevent an already-authorised request from recreating the deleted file; the raw identifier is not stored in that lock and the lock is then purged;
- push tokens remain while notifications are enabled and the device or account remains registered for them;
- Anthropic API inputs and outputs follow the period in section 5;
- for service email other than a support receipt, the Department keeps a record that an email was requested and its delivery outcome, so a message is not sent twice and a failure can be answered; that record holds the notice type, the account it belongs to and the outcome, and it does not hold the message body. Resend retains each message and its delivery metadata under its own published schedule. Support receipts follow the support-request period below;
- private support requests, including their message and reply address, are retained for up to twelve months so the Department can answer and audit the request, then removed by a Firestore expiry policy. The support record does not store a Firebase user identifier and is not removed automatically when an account is closed;
- Firebase Authentication may retain logged IP addresses for a short security period and removes other authentication information from live and backup systems under Google's published deletion schedule after Everyday Arc initiates deletion;
- analytics data follows the retention period configured for the production Firebase property; and
- limited security, moderation, fraud-prevention, legal and operational records may remain for as long as reasonably required for those purposes. Moderation evidence may include a one-way pseudonymous fingerprint rather than the original account identifier.
We delete or anonymise information when it is no longer needed for the stated purpose, subject to provider backup cycles and legal requirements.
14. Account closure and deletion
A claimant can request account closure in Department Records. The request starts deletion of the authentication account, user file, certificates, interactions, reports, notices, directives, stored preferences and push token attributable to that account. Public certificates are withdrawn as part of that process.
Some limited information may remain where needed to complete deletion, operate security and fraud controls, preserve proportionate moderation evidence, answer a support request, meet a legal duty or establish, exercise or defend legal claims. A private support request is retained for the period stated in section 13 and does not store the deleted Firebase account identifier. Provider backups and security logs may expire on the provider's own schedule. Account closure cannot be undone after it completes.
A claimant may also request erasure by email. We may need proportionate evidence that the requester controls the file. An anonymous claimant should tell us that the file has no email address; we will explain a verification method without asking for the original grievance text.
15. Your rights
Depending on the law that applies, a person may have the right to:
- receive information about how personal information is used;
- request access to, correction of or deletion of personal information;
- request restriction of, or object to, certain processing;
- receive information provided to us in a portable form where applicable;
- withdraw consent for future processing; and
- complain to a data-protection regulator.
To exercise a right, contact correspondence@everydayarc.com. We may ask for proportionate evidence that the requester controls the relevant file. In the United Kingdom, a person may complain to the Information Commissioner's Office at ico.org.uk.
The app also provides a self-service JSON copy from Department Records. That copy contains the account details, certificates, claimant-authored interactions and reports, and Department correspondence held in the file. Original submitted matter text is not retained by the Department, and an unfinished matter remains on the device where it was begun, so neither appears in the server copy. Security credentials, internal abuse controls, provider logs and third-party personal information are not reproduced in the automated copy. A claimant may still use the correspondence address above for a wider access or portability request.
16. Children
Let It Be Known is for people aged 13 or over. The app asks a person opening or securing a new account to confirm that they are at least 13. We do not ask for a date of birth. If we learn that an account belongs to a child under 13, we will take appropriate steps to close it and delete the associated personal information, subject to the limited retention described above.
17. Changes and contact
We may update this policy when the app or law changes. Material changes will be brought to claimants' attention where appropriate, and the date above will be updated.
Questions about this policy or Let It Be Known data may be sent to:
Everyday Arc Ltd correspondence@everydayarc.com
No personal contact name, personal address or personal telephone number is to appear on the public policy.