Privacy
Effective September 11, 2026
Arbor is an AI-assisted learning app operated by Sriharsha Kanumilli in San Jose, California. This policy describes information handled through the Arbor Mac app and arborstudio.app. For privacy questions or requests, email skstudiohq@gmail.com.
Information Arbor handles
- Account information: information used to sign you in, such as your email, account identifier, and profile information provided through your chosen sign-in method.
- Learning content: uploaded files, source text and links, questions, answers, notes, highlights, citations, principles, flashcards, quiz responses, and learning progress. Arbor stores this content to provide your workspace and reopen saved work.
- Billing information: purchase identifiers, payment status, credits, usage deductions, and refund or dispute records. Stripe handles payment details during checkout.
- Operational information: AI operation type, outcome, token counts, estimated cost, latency, retry counts, and error categories associated with your account. This usage ledger does not store prompts, answers, source content, or email addresses. Your learning content is stored separately as described above.
- Service requests and support: hosting and service providers receive technical information such as IP addresses and request details when you connect. If you contact us, we receive the information you include in your message.
How information is used
Arbor uses information to authenticate accounts, store and retrieve learning materials, generate learning content, manage credits and payments, prevent abuse, diagnose failures, and respond to support requests.
AI processing and service providers
When you use AI features, Arbor sends questions and relevant source content to OpenAI. Source processing can also send content for extraction or create embeddings for retrieval. Generated results are saved in your workspace. Requests can include a hashed account identifier for provider safety handling. Avoid uploading information you do not want processed by these services.
- Supabase: account authentication, database, and uploaded-file storage.
- Railway: hosting Arbor's backend and processing requests.
- OpenAI: AI generation, extraction, and embeddings.
- Stripe: checkout, payment processing, and receipts.
- Vercel: hosting the website and Mac update downloads.
- AgentMail: delivery of internal billing-alert summaries; these alerts contain operational counts rather than learning content.
A sign-in provider receives information when you choose its sign-in flow. Services you choose for exports or sharing receive the content you send to them. Provider processing and retention can also be governed by their terms and privacy policies. This policy does not promise zero retention by AI or other service providers.
Local storage and updates
The Mac app stores preferences, cached content, and session information locally. A login session can be saved in macOS Keychain. Removing the app does not itself remove the Keychain session or delete your cloud account. Signing out clears sensitive app caches and temporary exports; files you export yourself remain under your control.
Arbor uses Sparkle for updates. Manual checks and enabled automatic checks contact the update host to discover or download releases. Automatic checks are optional. Sparkle system profiling and automatic installation are disabled by default.
Retention and deletion
Saved learning content is retained to make it available in your account. Use the available content-deletion controls or contact us to request account or data deletion. Self-service account deletion is not yet available in the released Mac app.
Deletion from active systems may not immediately remove backup copies. Some payment, security, and support records may be retained where needed for billing reconciliation, disputes, fraud prevention, or legal obligations. Retention depends on the record and service involved; we do not promise an immediate or fixed deletion period for every copy.
Your choices
You can choose what to upload, use the app's available export and deletion controls, sign out, and change automatic update checks in the Arbor menu. Contact us to request access, correction, or deletion of your information, or to ask about other privacy rights available where you live. We may need to verify your identity before acting on a request.
Security and international processing
Arbor uses account-scoped access controls to separate users' content. No service can guarantee absolute security. Arbor operates from the United States and uses cloud providers; information may be processed outside your country.
Changes and contact
We will update this page when our practices change and revise the effective date. For questions about this policy, contact skstudiohq@gmail.com.