Privacy at arbe
arbe is a small, free alpha. We collect what is needed to give you an account, run the service, and keep it reliable. We do not sell personal data, show ads, or send marketing email.
Last updated 29 July 2026.
Who is responsible
The data controller (the person who decides how your data is used, and who is answerable for it) is Oskar Roug Mosumgaard (Invisible Touch), based in Germany.
For privacy questions or requests, email oskar+arbe@rough.dk.
What arbe knows about you
- Account data: your email address, sign-in provider, provider profile details such as a GitHub name, account dates, and authentication records.
- What you and your house members create: profile details, houses, memberships, agents, threads, messages, files, workflows, environments, and their history.
- Agent work: prompts and replies, tool inputs and results, files sent for indexing, and work performed in remote sandboxes. This may include data you place in a prompt, file, repository, or command.
- Credentials: metadata for API tokens and house secrets. We encrypt secret values in storage and pass them to a runtime or provider only when the work you request needs them.
- Operations and usage: app IDs, request and run IDs, timestamps, errors, model and tool usage, token counts, cost, and security logs. We keep these to run and bill the service, so they are recorded whether or not you turn on telemetry. Telemetry controls a separate layer of product analytics, described below.
Most of this comes directly from you. Some comes from your sign-in provider, other members of your houses, agents acting on your instructions, and the systems that run arbe.
Why we use it
- Provide arbe
- To authenticate you, keep your houses and history, run agents and sandboxes, and return the work you request. The legal basis is performance of our agreement with you.
- Run it safely
- To secure accounts, prevent abuse, diagnose failures, enforce usage limits, and understand what the service costs. The legal basis is our legitimate interest in operating a safe, reliable alpha.
- Improve it
- If you turn on telemetry, PostHog also receives product analytics about how you use arbe, without email, names, prompt content, or message content. The legal basis is your consent, which you can withdraw for future analytics at any time. Turning it off does not stop the operational and usage records above, which we keep to run and bill the service.
- Meet obligations
- We may keep or disclose limited records when required by law or needed to establish, exercise, or defend legal claims.
arbe uses models to generate replies and agents may take actions you ask for. arbe does not make solely automated decisions about you that produce legal or similarly significant effects.
Who receives data
People and agents in a house receive the content and member information shared in that house. We also use service providers to run arbe:
- Cloudflare for the website, API, network security, and short-lived logs.
- Supabase for sign-in, the database, file storage, and encrypted secrets.
- Electric SQL for live data sync and durable thread streams.
- OpenRouter and the selected model provider for model prompts and replies. If a house selects a direct model provider, that provider receives the request instead.
- Daytona, or the legacy Sprites runtime, when an agent opens a remote computer to do work.
- ragthis (hosted on Fly.io) for file extraction and search. To describe images and scanned documents it may send file pages to a model provider listed above.
- PostHog EU for product analytics you opt into, plus a limited always-on record of agent runs and paid usage: identifiers, timings, outcomes, models, token counts, and cost. These events exclude emails, names, prompts, messages, and file content.
- GitHub if you choose GitHub sign-in.
We do not give personal data to advertisers or data brokers. We may disclose it if legally required, or to protect arbe and its users.
Where data is processed
arbe is operated from Germany, and we select EU regions where a provider offers them, including PostHog's EU service. Some providers, and some model providers a house selects, may process data outside the European Economic Area. Those locations and safeguards depend on the provider and model in use; safeguards may include an adequacy decision or the European Commission's standard contractual clauses. arbe is an alpha, so do not put sensitive data in it, and email us if you need current transfer details first.
How long data stays
- Account and product data stays while your account or the relevant house exists, unless it is needed longer for security, legal claims, or a legal obligation.
- Cloudflare's application logs are normally retained for about 72 hours.
- Thread history and the primary usage ledger are durable product records. They stay with the relevant house until that house is deleted. Limited operational copies in PostHog follow that service's project retention and may outlive house deletion.
- Deleting a house removes its database records and starts deletion of its thread streams, stored files, and derived file index. Provider backups and queued cleanup may take longer to expire.
- Deleting your account removes your sign-in, API access, and memberships. Content already shared with other people can remain in their houses, attributed to a deleted account, because removing it would alter their shared history. If you want that content removed too, email us and we will look at it case by case.
Cookies and local storage
Signing in sets essential cookies that keep your session active. arbe does not work without them while you are signed in.
If you turn on telemetry, PostHog stores an analytics identifier in your browser. We keep that narrow: no session recording, no automatic capture of clicks or page views, and no location lookup from your IP address. With telemetry off, the browser analytics client never loads.
Your choices and rights
Once you are signed in, Account lets you download a copy of your data, edit your profile, and delete your account, and Telemetry lets you turn optional analytics on or off.
You can also ask us to access, correct, erase, restrict, or port your personal data; object to processing based on legitimate interests; or withdraw consent. Some of these rights apply only in certain circumstances. Email oskar+arbe@rough.dk. We may need to verify your identity and will normally respond within one month.
You can also complain to a data protection authority where you live or work, or where you think a breach happened. Germany's federal authority explains how to find the right German authority.
Changes
As the alpha changes, this notice will change too. We will update the date above and, where practical, announce material changes in arbe before they take effect.