Last updated: 2026-06-06
When you connect your GitHub account, Arbor reads your public repository metadata (names, languages, commit activity, star counts) via the GitHub REST API. We never read private repositories or repository contents beyond what the GitHub public API returns.
We store your GitHub login, display name, email address (from your GitHub profile), and avatar URL.
When a peer submits feedback on your work, we store their attestation responses linked to your account. Rater identity is kept private from your public profile.
For every rater session we record a salted, irreversible HMAC of the IP address and the User-Agent string for abuse prevention. The raw IP address is never stored. These hashed values are not shared with other users and are purged after 360 days.
We log every call made to our AI provider (Anthropic) — including the prompt and response — for debugging and billing purposes. These logs are retained for 90 days.
When another user visits your public profile, we record a daily salted HMAC of their IP, User-Agent, and the current date for view-count deduplication. The raw IP is never stored, and each hash covers only a single calendar day.
When we send you an email we record delivery status, bounces, and unsubscribe events.
We record the date and policy version you accepted at the time you connected your GitHub account.
Your GitHub data is used to generate a skill assessment and public developer profile. Peer attestations are used to cross-validate and strengthen that assessment. Nothing is sold or used for advertising.
The hashed IP and User-Agent data is used only to detect and block abuse of the peer feedback system.
Profile-view hashes are used only to count unique daily visitors to your profile page.
public_repo scope — Arbor cannot read your private repositories.We do not use analytics, advertising, or social tracking pixels.
Vercel, Supabase, Anthropic, Resend, and GitHub are US-based companies. If you are located outside the United States, your data is transferred to and processed in the United States. These transfers are made under Standard Contractual Clauses or equivalent safeguards as required by applicable law.
You may request access to, correction of, or deletion of your account data at any time. To delete your account, go to Settings and use the "Delete account" option — this removes your profile, assessments, attestations, and associated data immediately.
If you are in the EU or UK, you have additional rights under the GDPR, including the right to data portability and the right to lodge a complaint with your local supervisory authority. Contact us to exercise these rights.
Categories of personal information collected (and purpose of collection):
We do not sell or share your personal information with third parties for cross-context behavioral advertising or any other commercial purpose.
As a California resident you have the right to know what personal information we collect, the right to delete your personal information, the right to correct inaccurate personal information, and the right to opt out of the sale or sharing of personal information. You may exercise these rights by using the self-service deletion in Settings or by contacting us at the address below. We will not discriminate against you for exercising your rights.
Arbor is operated by Drew Seward, an individual operating as Arbor ("we", "us", "our"). For questions about this policy or to exercise your rights, contact us at the address below.
Questions or requests: support@arbor.fyi