Let It Be Known
A ceremony for small things
Notice of Information Practice

Privacy Policy

Last updated 4 September 2026

1. Who is responsible for your information

Everyday Arc Ltd operates Let It Be Known and is the controller of the personal information described in this policy. The Department of Small Matters is the ceremonial identity presented within Let It Be Known. It is not a government body, authority or public office.

Privacy questions and rights requests may be sent to correspondence@everydayarc.com, the dedicated Let It Be Known correspondence address.

2. What the app is

Let It Be Known turns a matter submitted by a claimant into a ceremonial certificate. Its certificates and notices have no legal force. The app is not a court, regulator, dispute-resolution service, medical service or crisis service.

The app can be used with an anonymous Firebase account. A claimant may instead create or secure a file using email and password, Sign in with Apple or Google Sign-In. An email-and-password file must be verified before it can lodge a matter.

3. Information we process

Depending on how the app is used, we process:

We do not sell personal information. We do not show advertising, use advertising identifiers or track people across other companies' apps or websites for advertising.

4. Drafts and original matter text

An unfinished draft may be stored locally on the device so that the claimant can return to it. It is not uploaded to the Department as a draft. A claimant can clear the draft in the app.

When a matter is presented, the text is transmitted to our server and to Anthropic for the processing described below. We do not intentionally write the claimant's original matter text to the Department's Firestore database or application logs. The certificate becomes the lasting record. Anthropic's separate retention is described in section 5.

The requests made to Anthropic do not append the claimant's name, email address, Firebase user identifier, purchase status or device identifier. The words a claimant chooses to submit may themselves contain personal information. Claimants should not include details that are unnecessary for the matter.

5. AI processing and permission

With the claimant's explicit permission, Let It Be Known uses Anthropic, a third-party artificial-intelligence provider, to:

  1. classify and route the submitted matter;
  2. prepare a certificate when the matter is accepted for filing; and
  3. conduct a publication-safety review of every generated certificate, including a certificate that is currently private, so that it can remain safe if the claimant later opens the file to public inspection.

The Department asks for permission when the claimant first enters the Counter under the current disclosure, before a statement is entered or transferred. Choosing Decline and Return sends nothing to Anthropic. This processing is necessary for the Department to consider a matter and issue a certificate.

Permission is recorded locally for that claimant and disclosure version. It can be turned off in Department Records under Privacy. While it is off, the claimant may continue to consult the Bulletin, witness certificates and manage the file, but cannot present a matter or receive a certificate. Entering the Counter presents the permission notice again. Turning permission off cannot recall processing that has already taken place.

Everyday Arc determines the purposes of this processing and remains the controller. Anthropic processes the API requests as a service provider acting on Everyday Arc's instructions, subject to the applicable commercial terms and data-processing agreement.

Under Anthropic's standard API retention terms, API inputs and outputs are deleted from its systems within 30 days of receipt or generation, except where Anthropic and Everyday Arc agree a different period, where longer retention is required by law, or where material is retained to enforce Anthropic's Usage Policy. Anthropic states that inputs and outputs flagged as Usage Policy violations may be retained for up to two years and related trust-and-safety classification scores for up to seven years. Let It Be Known does not submit API feedback. Anthropic does not use commercial API inputs or outputs to train its models by default unless the customer opts in or submits them as feedback. Everyday Arc does not opt in.

6. Routing and automated decisions

Before a matter leaves the device, the app performs a narrow local check for urgent crisis phrases. A local match routes the claimant to a welfare notice and does not send the statement to Anthropic.

If the local check does not match and AI permission has been given, Anthropic classifies the matter as suitable for filing, outside the Department's scope, unsuitable for filing, or uncertain. A matter whose subject is serious harm, danger or crisis is routed to the welfare notice. A serious circumstance mentioned only as background to an ordinary small grievance may still be filed. Content used to threaten, target, demean or expose another person may be refused. A refusal or uncertain decision receives a second automated review before it can prevent a filing or count as a failed attempt.

This process determines only whether the app's ceremonial service can receive a submission. It does not make a legal finding, medical assessment or other decision with legal or similarly significant effect. No certificate is issued for a matter routed to welfare or refused.

7. Public inspection

Visibility is set for the claimant's whole file, not certificate by certificate.

When a file is open to public inspection, eligible certificates may appear on the Bulletin, in the Registry and in featured areas. A public certificate may show the claimant name recorded on it, certificate title and text, public summary, case number, date, desk, classification and public interaction counts. The original statement is not published. A certificate withheld by publication-safety or moderation review remains private even when the rest of the file is open.

When a file is restricted, its certificates remain on the claimant's own record but do not appear in public views. A claimant can change the file setting in Department Records. Other signed-in claimants can report a public certificate or block its claimant. Blocking hides that claimant's public certificates from the person who applied the block; it does not remove the certificates for everyone.

Before a file is first opened publicly, the app presents a public-filing notice and content policy. Public certificates may be removed or withheld where needed to enforce that policy, protect people, investigate reports or comply with law.

8. Analytics and device security

We use Google Firebase Analytics to understand whether app features work and how the service is used. Analytics events contain event names and limited counts, categories, desks, outcomes, durations and character counts. Google Analytics derives approximate location from a masked IP address. The events do not contain grievance text, certificate text or claimant names. Analytics may be associated with a pseudonymous internal user identifier or app-instance identifier, so it should not be described as anonymous.

We use Firebase App Check with Apple's DeviceCheck and Google's Play Integrity services to help distinguish genuine app requests from abuse. They process device or app-integrity information and security tokens. Cloud Functions and authentication systems may also process IP addresses, user-agent information and operational logs for security and service delivery.

9. Notifications

Notifications are optional. If a claimant enables them, we use Firebase Cloud Messaging and the device's notification service to deliver notices about certificates, witness or likewise-aggrieved milestones, changes in Department standing and other correspondence. We store a push token for this purpose. A claimant can withdraw notification permission in Department Records or in device settings. Notices are also kept in the app where the relevant feature provides an in-app copy.

10. Why we use the information

Under UK data-protection law, we rely on the following lawful bases:

Providing a name and permanent sign-in method is optional because an anonymous file is available. Matter text is required if the claimant asks the Department to consider and file a matter. AI permission is a separate, explicit product control rather than the Article 6 lawful basis for processing ordinary matter text. It may be declined or turned off, but without it the Department cannot perform the filing service or issue a certificate.

11. Service providers and recipients

We use:

These providers process information under their own terms and, where they act for Everyday Arc, under applicable data-processing terms. We do not use RevenueCat or collect purchase history in the free-only version 1.0 release. This policy must be updated before a paid arrangement is enabled.

12. International transfers

Some providers process information in the United States and other countries outside the United Kingdom. Where UK data-protection law requires a transfer safeguard, Everyday Arc relies on an applicable UK adequacy regulation or approved contractual safeguards, together with relevant supplementary measures. A claimant may contact us for further information about the safeguard used for a particular provider.

13. How long information is kept

We apply the following retention rules and criteria:

We delete or anonymise information when it is no longer needed for the stated purpose, subject to provider backup cycles and legal requirements.

14. Account closure and deletion

A claimant can request account closure in Department Records. The request starts deletion of the authentication account, user file, certificates, interactions, reports, notices, directives, stored preferences and push token attributable to that account. Public certificates are withdrawn as part of that process.

Some limited information may remain where needed to complete deletion, operate security and fraud controls, preserve proportionate moderation evidence, answer a support request, meet a legal duty or establish, exercise or defend legal claims. A private support request is retained for the period stated in section 13 and does not store the deleted Firebase account identifier. Provider backups and security logs may expire on the provider's own schedule. Account closure cannot be undone after it completes.

A claimant may also request erasure by email. We may need proportionate evidence that the requester controls the file. An anonymous claimant should tell us that the file has no email address; we will explain a verification method without asking for the original grievance text.

15. Your rights

Depending on the law that applies, a person may have the right to:

To exercise a right, contact correspondence@everydayarc.com. We may ask for proportionate evidence that the requester controls the relevant file. In the United Kingdom, a person may complain to the Information Commissioner's Office at ico.org.uk.

The app also provides a self-service JSON copy from Department Records. That copy contains the account details, certificates, claimant-authored interactions and reports, and Department correspondence held in the file. Original submitted matter text is not retained by the Department, and an unfinished matter remains on the device where it was begun, so neither appears in the server copy. Security credentials, internal abuse controls, provider logs and third-party personal information are not reproduced in the automated copy. A claimant may still use the correspondence address above for a wider access or portability request.

16. Children

Let It Be Known is for people aged 13 or over. The app asks a person opening or securing a new account to confirm that they are at least 13. We do not ask for a date of birth. If we learn that an account belongs to a child under 13, we will take appropriate steps to close it and delete the associated personal information, subject to the limited retention described above.

17. Changes and contact

We may update this policy when the app or law changes. Material changes will be brought to claimants' attention where appropriate, and the date above will be updated.

Questions about this policy or Let It Be Known data may be sent to:

Everyday Arc Ltd correspondence@everydayarc.com

No personal contact name, personal address or personal telephone number is to appear on the public policy.