Skip to content
ArchiAppArchiApp

Legal

Privacy policy

How ArchiApp collects, uses and protects personal data, written to be read rather than skimmed past.

Last updated 15 January 2026

Who is responsible for your data

ArchiApp is operated by JCastIT, a company registered in Belgrade, Serbia. In data-protection language we are the controller: we decide why and how your personal data is processed.

You can reach us about anything in this document at hello@thearchiapp.com. We answer data-protection requests within 30 days, and usually far sooner.

We process personal data under the Serbian Personal Data Protection Act (Zakon o zaštiti podataka o ličnosti). Where we offer the service to people in the European Economic Area, we also apply the GDPR.

What we collect

Account data. If you create an account: your name, email address, an optional phone number, your language preference, and a hash of your password. We never store the password itself.

Photos you scan. The images you upload or capture in order to identify a material, plus the colour and texture fingerprint we compute from them and the results that were returned.

Favourites and history. The decors you save and the searches you have run, so both are available on your next device.

Business data for partners. If you work for a distributor: your company name and legal name, branch addresses, contact details, the articles you stock, prices per square metre, availability and lead times. Prices you publish are shown to everyone using ArchiApp — that is the point of the portal.

Technical data. IP address, browser and device type, and timestamps in our server logs. On mobile, crash diagnostics if you have allowed your operating system to share them.

What happens to the photos you scan

A photo is used to produce a numeric fingerprint — a short vector describing colour distribution, texture and pattern. The match is calculated from that fingerprint, not from the picture itself.

We keep the image so you can reopen a past search, and we keep a small thumbnail for your history screen. You can delete any individual search, or your whole history, from the app at any time; the image and its fingerprint are removed with it.

We do not run face recognition, we do not attempt to identify people or places in your photos, and we do not sell or license them. If a photo happens to contain something personal, that is a good reason to use the delete controls — they work immediately.

Anonymous, aggregated counts of which decors get matched are shared with distributors and manufacturers as demand statistics. These contain no personal data and cannot be traced back to you or to a single photo.

Why we use it, and on what legal basis

To provide the service — matching an image, returning decors, showing distributors and prices, keeping your favourites and history. Legal basis: performance of a contract with you.

To keep accounts secure — signing you in, rotating session tokens, rate limiting, and investigating abuse. Legal basis: our legitimate interest in a service that is not trivially attacked.

To improve matching accuracy — measuring how often results are useful and tuning the engine. Legal basis: legitimate interest, using aggregated data wherever it is sufficient.

To contact you — replying to an enquiry, sending a password-reset link, or telling you about a change to this document. Legal basis: contract or, for the launch waitlist, your consent, which you can withdraw at any time.

To meet obligations — accounting and tax records for paying partners. Legal basis: legal obligation.

How long we keep it

Account data: for as long as the account exists, then deleted within 30 days of closure.

Searches, images and favourites: until you delete them, or until the account is closed.

Server logs: 90 days, then discarded.

Waitlist email addresses: until launch, or until you unsubscribe, whichever comes first.

Invoicing records for partners: as long as Serbian accounting law requires, currently ten years.

Who else sees it

We do not sell personal data. We share it only with the service providers that run ArchiApp for us, each bound by a data-processing agreement: Vercel (hosting and image storage), Neon (the database), and Resend (transactional email such as password resets).

Distributors see the demand statistics described above and any enquiry you deliberately send them. They do not receive your account details, your photos or your search history.

We disclose data to authorities only where a valid legal request obliges us to, and we tell you when we are allowed to.

Transfers outside Serbia

Our infrastructure runs in the European Union, primarily in Frankfurt. Some providers are established in the United States and may access data for support purposes.

Those transfers rely on the European Commission's Standard Contractual Clauses and the equivalent instruments recognised under Serbian law. You can ask us for a copy of the safeguards that apply to a particular provider.

Your rights

You can ask for a copy of the data we hold about you, correct anything inaccurate, or have it deleted. You can ask us to restrict or stop a particular use, and you can request your data in a portable, machine-readable format.

Where processing rests on consent, you can withdraw it at any time — that does not affect anything done before you withdrew it.

Most of this is available directly in the product: profile fields are editable in settings, and searches and favourites have delete controls. For anything else, email hello@thearchiapp.com.

If you think we have handled your data badly, you can complain to the Serbian Commissioner for Information of Public Importance and Personal Data Protection (poverenik.rs), or to your local supervisory authority in the EEA. We would rather you told us first.

Cookies and local storage

The marketing site sets no analytics or advertising cookies. It stores your theme and language choice in your browser so the site does not flash the wrong colours on your next visit.

The distributor portal and the admin console set two strictly necessary cookies that hold your session. They are httpOnly, so no script on the page can read them, and they disappear when you sign out.

Because we use no tracking cookies, there is no consent banner to click away.

How we protect it

Passwords are stored as salted hashes. Session tokens are short-lived, rotated on every refresh, kept out of reach of JavaScript, and revoked whenever a password changes.

Traffic is encrypted in transit, access to production data is limited to the people who need it, and every administrative action is written to an audit log.

No system is perfect. If a breach ever affects your personal data, we will notify the supervisory authority within 72 hours and tell you directly where the risk to you is high.

Children

ArchiApp is a professional tool and is not directed at children. We do not knowingly create accounts for anyone under 15, the age of digital consent in Serbia. If you believe a child has registered, tell us and we will remove the account.

Changes to this policy

When we change something meaningful we update the date at the top of this page and, if you have an account, we email you before the change takes effect. Continuing to use ArchiApp after that means you accept the updated policy.

Something here unclear?

Write to us and a person will answer — no ticket queue, no template reply.

hello@thearchiapp.com