ARBOR
Privacy Policy
Effective August 22, 2026
This Privacy Policy explains how Arbor (“Arbor”, “we”, “us”) collects, uses, and protects your information when you use an Arbor app — including Thrive, our personal productivity and habit app, and Nura, our personal finance app — together with related services (the “Service”).
Arbor is a UK-based company and is the controller of your personal information under UK data protection law (the UK GDPR and the Data Protection Act 2018).
This policy covers what every Arbor app has in common: your account, and how we handle data across the platform. Data practices that are specific to one app — for example, Thrive keeping most of what you create on your device rather than our servers, or Nura connecting to your bank — are covered in that app’s own supplementary policy, linked from within the app.
1. Information you provide
When you create an Arbor account and sign in, we collect your email address and a password (handled by our authentication provider), and an optional display name. One Arbor account signs you in across the Arbor family of apps.
2. Content you create (stored on your device)
The tasks, routines and habits, projects, life areas, time blocks, focus sessions, reminders and notes you create in Thrive are stored locally in the app’s on-device database. This content is not uploaded to our servers except as described in “Information used by AI features” below.
3. Information used by AI features
When you use Thrive’s AI features — daily planning, natural-language capture, the coach and assistant, and auto-scheduling — Thrive sends the content needed to fulfil your request to our backend (Arbor Core), which uses a third-party AI provider (Anthropic) to generate a response.
This can include, for example, the titles and details of the tasks being planned, the messages you send to the coach, and the time ranges of your commitments. This data is processed to produce your result and is not used to train the AI provider’s models. If you do not use AI features, this data is not sent off your device.
4. Calendar access
With your permission, Thrive reads events from your device calendar to show your existing commitments and plan around them. Calendar data is used on your device; when you use auto-planning, the time ranges of events may be sent to our scheduling service so it can avoid conflicts. Thrive does not create, modify, or delete your calendar events. You can revoke calendar access at any time in your device settings.
5. Notifications
With your permission, Thrive schedules reminders and alerts as local notifications on your device. You can turn notifications off at any time in your device settings.
6. Cross-app presence
Thrive is part of the Arbor family of apps. When you sign in, we record that your account uses Thrive so that cross-app features can work across the Arbor apps tied to your account.
7. Analytics and advertising
We do not currently use third-party analytics, advertising, or cross-app tracking technologies, and we do not sell your personal information. If this changes, we will update this policy and, where required, ask for your consent.
8. How we use your information
We use the information above to:
- provide and operate the Service;
- authenticate you and keep your account secure;
- deliver the AI features and notifications you choose to use;
- maintain, troubleshoot, and improve the Service; and
- comply with legal obligations and enforce our terms.
9. Legal bases for processing
Under the UK GDPR, we rely on the following legal bases to process your personal information:
- Performance of a contract — to create and secure your account and provide the core features of the Service;
- Legitimate interests — to maintain, troubleshoot, secure and improve the Service and enable cross-app features, in ways you would reasonably expect and that do not override your rights;
- Consent — for optional device permissions such as notifications and calendar access, and when you choose to use AI features; you can withdraw consent at any time in your device settings or by not using those features; and
- Legal obligation — where we must process information to comply with the law.
10. How your information is shared
We share information only with service providers (processors) that help us run the Service, and only as needed for them to perform that role:
- Supabase — account authentication and database;
- Anthropic — AI processing for AI features you use;
- Railway — backend hosting; and
- Apple — app distribution and system notification delivery.
11. Data retention and deletion
Account data is retained until you delete your account. Content you create in Thrive is stored on your device and remains until you delete it or uninstall the app.
You can delete your account at any time in the app (Settings → Delete account). This permanently deletes your Arbor account and erases Thrive’s data on that device, and cannot be undone.
12. Security
Data is transmitted over encrypted connections (HTTPS), and your session credentials are stored securely on your device (for example, in the iOS Keychain). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Children
Thrive is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us information, please contact us and we will delete it.
14. Your rights
If you are in the UK or the EEA, you have rights under the UK GDPR / EU GDPR to access, correct, delete, or receive a portable copy of your personal information, to object to or restrict certain processing, and to withdraw consent where we rely on it. You can exercise many of these directly in the app (for example, by deleting your account); for anything else, contact us at vinc3.parker@gmail.com.
You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk, or to your local supervisory authority. We would appreciate the chance to address your concerns first. If you are elsewhere, you may have similar rights under your local laws.
15. International data transfers
Arbor is based in the United Kingdom. Some of our service providers process data outside the UK — for example, our AI provider (Anthropic), hosting (Railway), and authentication and database (Supabase) may process data in the United States. Where personal data is transferred outside the UK, we rely on appropriate safeguards, such as the UK’s International Data Transfer Agreement (IDTA) or an adequacy decision, to keep it protected.
16. Changes to this policy
We may update this Privacy Policy from time to time. We will revise the “Effective” date above and, for material changes, provide additional notice where appropriate.
17. Contact us
If you have questions about this policy or your information, contact us at vinc3.parker@gmail.com.