Arborbeta
Sign in with GitHub

Privacy Policy

Last updated: 2026-06-06

What we collect

When you connect your GitHub account, Arbor reads your public repository metadata (names, languages, commit activity, star counts) via the GitHub REST API. We never read private repositories or repository contents beyond what the GitHub public API returns.

We store your GitHub login, display name, email address (from your GitHub profile), and avatar URL.

When a peer submits feedback on your work, we store their attestation responses linked to your account. Rater identity is kept private from your public profile.

For every rater session we record a salted, irreversible HMAC of the IP address and the User-Agent string for abuse prevention. The raw IP address is never stored. These hashed values are not shared with other users and are purged after 360 days.

We log every call made to our AI provider (Anthropic) — including the prompt and response — for debugging and billing purposes. These logs are retained for 90 days.

When another user visits your public profile, we record a daily salted HMAC of their IP, User-Agent, and the current date for view-count deduplication. The raw IP is never stored, and each hash covers only a single calendar day.

When we send you an email we record delivery status, bounces, and unsubscribe events.

We record the date and policy version you accepted at the time you connected your GitHub account.

How we use it

Your GitHub data is used to generate a skill assessment and public developer profile. Peer attestations are used to cross-validate and strengthen that assessment. Nothing is sold or used for advertising.

The hashed IP and User-Agent data is used only to detect and block abuse of the peer feedback system.

Profile-view hashes are used only to count unique daily visitors to your profile page.

How we protect your data

  • Your GitHub access token is encrypted at rest (AES-256-GCM) and is never exposed to other users or written to logs.
  • We only ever request the public_repo scope — Arbor cannot read your private repositories.
  • All traffic between you, Arbor, and our providers is encrypted in transit over HTTPS/TLS.
  • IP addresses are never stored in raw form — only as salted, one-way HMACs that cannot be reversed.
  • Rater abuse data (hashed IP and User-Agent) is automatically purged after 360 days.
  • You can delete your account and associated data at any time (see Your rights below).

Third parties

  • Vercel — hosting and serverless functions. Data transits their infrastructure.
  • Supabase — PostgreSQL database. All account and assessment data is stored here.
  • Anthropic — AI skill assessments. We send derived signals from your public activity, your repository names, and a small sample of your public commit-message text, alongside our taxonomy prompts, to their API. Anthropic does not use data submitted through their API to train their models.
  • GitHub — OAuth authentication and public repository data.
  • Resend — transactional email delivery.

We do not use analytics, advertising, or social tracking pixels.

Vercel, Supabase, Anthropic, Resend, and GitHub are US-based companies. If you are located outside the United States, your data is transferred to and processed in the United States. These transfers are made under Standard Contractual Clauses or equivalent safeguards as required by applicable law.

Retention

  • AI/LLM call logs: 90 days
  • Abuse metadata (salted IP hash + User-Agent on attestations): 360 days
  • Profile-view hashes: daily-window basis (each hash covers one calendar day)
  • Email delivery events: retained while your account is active
  • Account data: retained until you delete your account

Your rights

You may request access to, correction of, or deletion of your account data at any time. To delete your account, go to Settings and use the "Delete account" option — this removes your profile, assessments, attestations, and associated data immediately.

If you are in the EU or UK, you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with your local supervisory authority. Contact us to exercise these rights.

CCPA — California residents

Categories of personal information collected (and purpose of collection):

  • Identifiers (GitHub login, display name, email, avatar URL) — to create and display your developer profile.
  • Internet or other electronic network activity (salted HMAC of IP address and User-Agent, repository metadata) — to detect abuse and generate your skill assessment.
  • Professional or employment-related information (peer attestations, skill assessments) — to produce your credentialing profile.

We do not sell or share your personal information with third parties for cross-context behavioral advertising or any other commercial purpose.

As a California resident you have the right to know what personal information we collect, the right to delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information. You may exercise these rights by using the self-service deletion in Settings or by contacting us at the address below. We will not discriminate against you for exercising your rights.

Data controller

Arbor is operated by Drew Seward, an individual operating as Arbor ("we", "us", "our"). For questions about this policy or to exercise your rights, contact us at the address below.

Contact

Questions or requests: support@arbor.fyi