Effective date: August 25, 2026
arlo ("we", "us", "our") operates the arlo mobile application and website at followarlo.com. This Privacy Policy explains what data we collect, how we use it, and your rights.
The data controller for arlo is João Pedro Martinho Bento (individual developer), operating the arlo app and followarlo.com. For any privacy question or request, contact support@followarlo.com.
We process your data on the following legal bases (GDPR art. 6):
We also use your own favorites, follows, and views to order the pieces and artists shown in your own Pieces and Artists feeds. This does not change what anyone else sees.
Images uploaded to arlo are screened automatically before they appear: an image-classification model runs on our servers and can flag or refuse an upload, and media served through our content delivery network is matched against known-illegal-image hash lists by Cloudflare’s CSAM Scanning Tool. Screening runs on the image itself and builds no profile of you. Account-level consequences — a takedown, a suspension — are decided by a person, never by the classifier alone. We rely on our legitimate interest in keeping the service safe, and on our legal obligations.
If media is matched as known child sexual abuse material, it is reported onward to the National Center for Missing & Exploited Children (NCMEC) or the competent regional hotline, along with the account details needed to act on it. This is a legal obligation, and it is the only circumstance in which we disclose your content to a recipient outside the processors listed below. Nothing is transmitted to any such recipient in the absence of a match.
If you sell on arlo, your artist profile is public: anyone can open it, signed in or not, and see your display name, profile photo and banner, your bio, your Instagram handle, your city, your published pieces and events, and how many people follow or save your work. The shop, market and event locations you add are public too, including their street addresses and map coordinates. Your email address and phone number are never published, and a buyer account has no public profile at all.
Three switches in the app change what is shared, alongside the analytics choice described in section 2. Show exact address, on each shop or market location, hides the street when you turn it off — the public listing then shows the surrounding area only, and the map pin is rounded to roughly 110 metres. In Profile > Privacy & security, Show my location to artists decides whether an artist looking up your buyer profile sees your city (an artist’s own city stays public, because browsing by city depends on it), and Allow messages from anyone decides whether someone you have never messaged can start a conversation with you.
Chat messages are never public. They are visible to you, to the person you are writing to, and — where a message is reported or moderated — to us.
We share data with the following processors, solely to operate the service. Each processor receives only the data necessary for its function and is bound by a data processing agreement.
| Processor | Purpose | Data Shared | Data Location |
|---|---|---|---|
| Supabase | Database and authentication | Account data, all app content | EU (Frankfurt) |
| Stream | In-app messaging | User IDs, display names, chat messages | EU (EU West) |
| Cloudflare | Image storage and share pages | Uploaded media, object metadata | EU |
| Sentry | Crash and error reporting | Device info, stack traces, user IDs, per-install and device identifiers | EU |
| BetterStack | Logging and uptime monitoring | Server logs, including user IDs | EU |
| Apple (APNs) | Push notification delivery | Device push token, notification content | Apple infrastructure |
| Apple (Maps) | Address and place search in the location pickers | Typed search text, general map area being searched | Apple infrastructure |
| Resend | Transactional email | Recipient name and email address, message content — artist application updates and moderation notices | United States |
| PostHog | Product analytics | In-app usage events and device info — only with your consent. Server-side records of account, marketplace and moderation actions, with a pseudonymous user ID — regardless of that choice (see section 2) | EU |
Signing in with Apple, Google or Facebook involves those providers as independent controllers under their own privacy policies. For a detailed breakdown of data flows and retention per processor, contact support@followarlo.com.
We retain your data for as long as your account is active. Deleting your account (in the app: Profile > Delete account, the last row of the profile screen) immediately and permanently removes your profile, listings, messages and uploaded media from our systems, and deletes your analytics identity — the pseudonymous profile PostHog holds for you, together with the events recorded on it. Residual copies in encrypted backups expire within 30 days. Data we are legally required to keep is retained for the mandated period only.
Analytics events — both the in-app ones you consent to and the server-side records described in section 2 — are retained for up to one year. An event sent just before you delete your account — from your device, or from our servers as the deletion runs — can reach PostHog after that erasure has run; by then it belongs to no account, and it expires on the same one-year schedule.
Under the GDPR, you have the right to:
To exercise any of these rights, contact us at support@followarlo.com. We respond within one month. We may ask you for information that lets us confirm the request comes from you, so we never act on someone else’s account by mistake. If we cannot act on a request, in whole or in part, we will tell you why.
The arlo mobile app does not use cookies. Our website does not use cookies at all — not even essential ones. We do not use third-party advertising trackers. In-app analytics run only after you opt in (see section 2), and no arlo analytics — in-app or server-side — is ever used for advertising.
arlo does not track you. We never link what you do in arlo with data collected about you in other companies’ apps, websites or offline properties; we never share your data with advertisers or data brokers; and we never sell it. The app does not use Apple’s advertising identifier (IDFA) and shows no App Tracking Transparency prompt, because it has nothing to ask for.
arlo is not intended for children under 15. Where the law of your country sets a lower digital consent age, a user aged 13 or 14 may use arlo only with parental consent — the same threshold as our Terms of Service. We do not knowingly collect data from children below these ages. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We use industry-standard measures to protect your data, including encryption in transit (TLS) and at rest. However, no method of transmission over the internet is 100% secure.
Our services are hosted in the European Union. Where a transfer outside the EU occurs — when you sign in with Apple, Google or Facebook, when you search for a place with Apple’s Maps service, or when we send you a transactional email — it is protected by appropriate safeguards such as adequacy decisions, the EU–U.S. Data Privacy Framework, or Standard Contractual Clauses. You can ask us which safeguard covers a particular transfer, and for a copy of it, at support@followarlo.com.
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. Continued use of the service after changes constitutes acceptance.
If you have questions about this Privacy Policy, contact us at:
support@followarlo.com