Privacy Policy
Ark Companion for iOS and Android
Dark Bio AG (“we,” “us,” or “our”) operates the Ark Companion mobile application (the “App”). This Privacy Policy describes how information is collected, used, and protected when you use the App.
1. What the App Does
The Ark Companion app pairs with Dark Bio Ark hardware devices. It enables you to authorize operations on your Ark (such as unlocking, executing analysis tasks, and managing device settings) and to review a tamper-evident audit journal of device events.
The App may display and locally cache analysis results produced by third-party applications running on your Ark, but does not generate or transmit your personal data. All source data remains exclusively on your Ark device.
2. Information Stored on Your Device
The following data is stored locally on your phone using encrypted secure storage and a local database. This data never leaves your device except as described in Section 3.
- Device pairing data. Cryptographic keys, shared secrets, and your Ark’s serial number, hardware revision, and firmware version, generated during the pairing process.
- Custom device name. A name you choose for your Ark.
- Audit journal entries. A local copy of your Ark’s tamper-evident event log (boots, pairings, unlocks, renames), synced directly from your Ark over an end-to-end encrypted channel.
- User preferences. Whether you have enabled biometric authentication and push notifications.
3. Information Transmitted to Our Servers
- Push notification token. When you enable push notifications, a Firebase Cloud Messaging (FCM) registration token is sent to our relay server so your Ark can notify you of pending authorization requests. This token is deleted from our server when you unpair your device. Push notifications contain only a generic prompt that your attention is needed; no personal data, device identifiers, or operation details are included in the notification payload.
- Pairing association. After pairing, the relay stores the cryptographic public identities of your Ark and Companion app so it can route messages between them. These are opaque key identifiers with no link to your personal identity. They are deleted when you unpair.
- Relay message metadata. Our relay server routes end-to-end encrypted messages between your Ark and the App. The relay can observe that communication occurred (connection metadata) but cannot read or modify message content. Messages from the App are delivered in real time or dropped immediately. Messages from the Ark may be briefly cached for delivery if the App is not yet connected, after which they are discarded.
4. Information We Do Not Collect
The App does not collect personal data stored on your Ark, location data, contacts, photos, browsing history, personal identifying information, or financial information. We do not use any analytics, crash reporting, advertising, or behavioral tracking services.
5. How We Use Information
- Push notification tokens are used solely to deliver authorization request notifications from your Ark to your phone.
- Relay infrastructure is used solely to route encrypted messages between your Ark and the App. We cannot decrypt these messages.
- Locally stored data is used solely to operate the App’s pairing, authorization, and audit journal features on your device.
We do not sell, rent, or share your information with third parties for marketing or advertising purposes.
6. Device Permissions
- Camera. Used to scan QR codes during device pairing. The camera feed is processed on-device and is never recorded, uploaded, or stored.
- Biometrics (Face ID / Touch ID / Fingerprint). Used for optional local authentication. Biometric data is handled entirely by your device’s operating system and is never accessed, collected, or transmitted by the App.
- Push Notifications. Used to alert you when your Ark requests authorization. You may disable notifications at any time.
7. Third-Party Services
We use Firebase Cloud Messaging (operated by Google) exclusively for delivering push notifications. No other Firebase services are used, including analytics, crash reporting, and performance monitoring. Google’s handling of FCM data is governed by Google’s Privacy Policy.
8. Data Security
- All communication between the App and your Ark is end-to-end encrypted using post-quantum cryptographic primitives.
- Sensitive data on your phone is stored using platform-provided encrypted secure storage (iOS Keychain / Android Keystore).
- The pairing process uses a cryptographic key exchange, with an additional visual color verification step to confirm the connection has not been intercepted.
- Our relay server operates on a zero-knowledge basis: it transports encrypted data it cannot read.
9. Data Retention and Deletion
- Local data. All pairing data, preferences, and audit journal entries are stored locally on your device. Unpairing your Ark deletes all associated data from the App. Uninstalling the App removes all remaining data.
- Push notification tokens. Deleted from our server upon unpairing.
- Pairing association. The stored link between your Ark and Companion identities is deleted from our server upon unpairing.
- Relay messages. Messages from the App are delivered in real time or dropped immediately. Messages from the Ark may be briefly cached for delivery, after which they are discarded.
- Pairing sessions. Temporary coordination data is deleted upon completion or shortly after if abandoned.
The App does not require an account. To remove all your data, unpair your device within the App and then uninstall it.
10. Children’s Privacy
The App is not directed at children under 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect information from children.
11. Your Rights
Depending on your jurisdiction, you may have rights regarding your personal data, including the right to access, correct, delete, or port your data. Because we store virtually no personal data on our servers (only a transient FCM token while you are paired), these rights are satisfied by the App’s built-in unpair and uninstall functionality.
For any data-related requests, contact us at privacy@dark.bio.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by updating the effective date at the top of this document. Continued use of the App after changes constitutes acceptance of the revised policy.
13. Contact
If you have questions about this Privacy Policy, contact us at privacy@dark.bio.