Privacy

This isn't a legal document — it's a plain description of what CheckMyARM actually does with your data today, based directly on how the app is built. See About for how compatibility classification works, or How CheckMyARM Thinks for the reasoning behind the recommendation itself.

Privacy by design, not by promise

We don't want — or need — to see anything that would invade your privacy. CheckMyARM was designed with a privacy-first mindset: before anything else was built, the question was "what's the least we could possibly look at and still answer this honestly?" Everything below follows from that answer, not the other way around.

That's why CheckMyARM intentionally avoids collecting documents, passwords, browsing history, personal communications, file contents, and other sensitive information — not because we promise to handle them carefully, but because none of it helps answer the question you're actually asking: will my stuff work on Windows on ARM? The technical observations we do use exist for one purpose — building your assessment — and nothing else.

We never retain your assessment. If you choose to save your work — exporting it to continue later — that's your decision, not ours; nothing about how CheckMyARM works requires us to keep a copy on our end. Real privacy by design is achieved by minimizing what's collected and how long it's kept, not by building bigger locks around ever-growing stores of data. We can't promise perfect security — no one honestly can — but we can, and do, promise there's simply less here to protect.

What we collect

When you run a scan, the scanner sends your browser (and then our server) a list of your installed applications, some basic device information, and the compatibility results we look up for them:

Sharing your own compatibility findings with the community is optional, and signing in with Google or GitHub is optional too — CheckMyARM works fully anonymously if you never do either.

What we do NOT collect

CheckMyARM currently:

Site analytics

We use GoatCounter, a small, privacy-focused analytics service, to see basic aggregate site-usage statistics — which pages get visited, and roughly how often. It's the same philosophy as everything else on this page: understanding how CheckMyARM is actually being used, without tracking who's using it.

Scan retention

The detailed scan itself is temporary. Your session — the list of applications and devices we found, and the report built from it — exists primarily so we can generate that report and let you refresh it later without re-scanning. It's automatically deleted after about a day, and it's never kept as a standing record of your machine.

Your personal assessment notes — decisions, priorities, and comments you add in your Workspace — are never sent to our server at all; they live only in your browser, and you can export them anytime to save your progress or continue later.

Anonymous aggregate learning

Separately from your temporary session, CheckMyARM keeps a small amount of anonymous, aggregate information about which applications and devices are commonly encountered, and on which kind of computer — an x64 machine considering the move, or an ARM64 machine already running it. This happens automatically, for every scan, whether or not you sign in or share anything.

Its only purpose is understanding the ecosystem and directing volunteer research toward applications and devices that come up often but aren't resolved yet — never toward deciding whether any specific application actually works. How common something is doesn't make it more or less compatible; that's decided separately, from real compatibility research.

This aggregate layer does not preserve a historical inventory of your machine, and it does not record which applications or devices appeared together on the same scan — only that a given application, or a given generic device type, was encountered somewhere, at some point, on some kind of computer. There's no session, browser, account, or IP address attached to it, and nothing about it can be traced back to any one person's computer.

We don't offer an opt-out for this specific layer, because there's nothing here that identifies you or your machine to opt out of — it's a running count, not a record of you.

Community contributions

CheckMyARM also learns from what you tell it, in two different ways.

When you record a compatibility answer — Native, Emulated, or Unsupported — in your Workspace, that answer is automatically retained as an anonymous community indication, with nothing extra for you to click. It's a starting point for research, not a final word: it's never described as though you'd necessarily used the application yourself, and it can never, on its own, automatically change what CheckMyARM tells the next person about that application.

Submit Findings is the deliberate version of the same idea — when you choose to share a finding, along with any notes about limitations or workarounds, that's a richer contribution you're actively choosing to make. Both kinds of answers are anonymous by default: we recognize your browser with a cookie so you don't end up submitting the same app twice, not by anything tied to your identity. Signing in is entirely optional, and never required to use the scanner or contribute. If you sign in after already contributing anonymously, your prior contributions move to your account automatically.

A structured Compatibility answer can only ever become part of the trusted compatibility database after a human researcher reviews it — never on its own. A deliberately shared Submit Findings answer can additionally be accepted automatically, but only when a strict, unanimous agreement is reached among several signed-in contributors — never from a single answer, and never from anonymous ones alone.

If you change your mind about an app, resubmitting updates your existing answer in place — it doesn't create a second, conflicting entry. Community contributions are stored on our server (unlike your private Workspace notes above), and we don't yet have self-service export or delete tooling for that specific data. That's a real gap, and something we intend to address in a future update.

Feedback

CheckMyARM's Feedback form is open to anyone, anonymous by default — you don't need to sign in, and nothing about submitting feedback requires an account. Leaving your email or another way to reach you is entirely optional, and only worth doing if you'd like a reply.

The form includes one explicit checkbox, off by default, to attach the assessment/session information currently available in your browser — the same information Save/Export would produce. It's only ever included if you actively check that box; we never attach it automatically. When included, it exists for exactly one purpose: helping us understand or reproduce the specific thing you reported. It's kept only as long as that investigation is open, and is deleted once the feedback is marked resolved — the feedback text itself, and our notes on it, may be kept longer.

Feedback, including any diagnostic data you choose to attach, is kept completely separate from CheckMyARM's community-learning system described above. It's never added to the compatibility database, never counted as a community finding, and never affects any app's confidence or prevalence numbers — it's read by us, for investigating your report, and nothing else.

Third-party services

CheckMyARM relies on a small number of outside services, only where the app actually needs them:

In short

We believe compatibility information is valuable, but personal inventories are not. CheckMyARM collects only what's needed to generate your report and improve the shared compatibility database — nothing more.