Privacy Policy
Last updated: August 9, 2026
This policy explains what ArborCloud, Inc. ("ArborCloud," "we," "us") collects when you use our API, dashboard, and related services (the "Service"), and how we use, share, and protect that information.
1. Information We Collect
Account & identity.
- Email address and name, collected via our authentication provider (Clerk) when you sign up or sign in
- Organization details if you create or join a team account — organization name, membership role, and member list
Billing.
- Payment card details are entered directly into forms hosted by our payment processor, Stripe. We never see or store your full card number — Stripe returns us a token and limited metadata (such as card brand and last 4 digits) that we use to reference your payment method
- Transaction and credit history (amounts, dates, and status of top-ups, auto-recharges, and refunds)
API and usage data.
- Request counts, token counts, model selected, and spend, for billing and displaying your usage dashboard
- The content of prompts you send and completions you receive is transmitted to the model you selected (run on our own infrastructure or a model provider we operate) solely to generate your response. We do not use the content of your API requests to train our own models, and we do not sell it. See Section 4 for how long this content is retained
- Activity logs for security and support purposes (e.g. sign-ins, API key creation, organization changes), tied to your account ID and a timestamp
Technical data.
- Our hosting provider (Vercel) and authentication provider (Clerk) automatically log standard request metadata — including IP address, browser/device information, and timestamps — for security, fraud prevention, and abuse detection. We do not run separate marketing analytics or ad-tracking on the Service
2. How We Use Your Information
We use the information above to:
- Authenticate you, provision your account, and enforce usage limits and billing
- Process payments, auto-recharges, and refunds through Stripe
- Route your API requests to the model you selected and return the result
- Detect and prevent fraud, abuse, and security incidents
- Send service-related emails (e.g. billing receipts, security alerts, material changes to this policy or our Terms)
- Respond to support requests you send us
We do not use your account data or API request content for advertising, and we do not sell personal information to third parties.
3. Third-Party Processors
We rely on the following processors, each under its own privacy policy and a data processing agreement with us:
- Clerk — authentication and session management
- Stripe — payment processing; Stripe is PCI-DSS compliant and handles your card data directly
- Vercel — application hosting
- Neon — database hosting for account, organization, and billing records
We do not permit these providers to use your data for their own purposes beyond providing the service to us.
4. Data Retention
We retain account, billing, and usage-summary records for as long as your account is active and for a reasonable period after closure to satisfy tax, accounting, and legal obligations. API request content (prompts and completions) is processed to generate your response and is not retained by us beyond what is operationally necessary to serve that request and to produce the aggregate token/spend totals shown on your usage dashboard. Deleting your account triggers deletion of your account record from our identity provider; associated usage and billing history may be retained in de-identified or aggregate form for accounting purposes.
5. Data Security
All connections to the Service use HTTPS/TLS encryption. Payment card data never touches our servers — it is collected and stored by Stripe. Sensitive account-linked credentials we do store (such as API keys used by our own dashboard features) are encrypted at rest. No method of storage or transmission is 100% secure, and we cannot guarantee absolute security.
6. Your Rights
Depending on where you live, you may have the right to request access to, correction of, deletion of, or a copy of your personal data, and to object to or restrict certain processing. You can manage most of this yourself from your account settings, or contact us using the details below. We will respond to verified requests within a reasonable time and as required by applicable law.
7. International Data Transfers
Our infrastructure and processors may store and process data in the United States and other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for transfers of personal data across borders.
8. Children's Privacy
The Service is not directed to individuals under 18, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us and we will delete it.
9. Changes to This Policy
We may update this policy as our Service evolves. We will update the "Last updated" date above and, for material changes, provide additional notice (such as an email or in-product notice) before the change takes effect.
10. Contact
Questions about this policy or your data can be sent to support@arborcloud.ai.