Skip to the policy

Legal

Privacy Policy

What we collect, why we hold it, who else sees it, and what you can make us do about it. Written to be read rather than to be survived.

Effective 5 August 2026

Who we are, and what this policy covers

ArboRule operates a platform for automated workflows and automated decisions. This policy explains what personal data we collect, why we use it, who we share it with, and what you can ask us to do about it.

ArboRule is a product of Murilo Zaffalon Marra Tecnologia da Informação Ltda., a company registered in Brazil under CNPJ 36.586.187/0001-02. That company is the controller of the personal data described here, and “we” means that company throughout this policy.

The policy covers our public website at arborule.com, the product application, and the API. It does not cover the third-party services you connect to a flow. Those services have their own policies, and you choose which of them to use.

If you want to exercise a right, or if you have a question about anything below, write to us at hello@arborule.com. We answer within 30 days.

Two kinds of data, and two different roles

The distinction below decides which parts of this policy apply to you, so we state it before anything else.

We are the controller of your account data. When you create an account, visit the website, or write to us, we decide why and how we use that data. Everything in this policy applies.

We are the processor of your workspace content. The flows you build and the decisions you run can contain personal data about your own customers. We only act on your instructions there. Your own privacy policy governs that data, and our agreement with you sets our obligations. If you are the subject of a decision that one of our customers ran, contact that customer — they can answer for the decision, and we cannot.

The words used here

Personal data means any information about an identified or identifiable person.

Processing means anything done with personal data — collection, storage, use, disclosure, or deletion.

Controller means the party that decides why and how personal data is processed. Processor means the party that processes it on the controller’s instructions.

These terms carry the meaning given to them in the General Data Protection Regulation (GDPR) and in the Brazilian General Data Protection Law (LGPD, Law 13.709/2018).

What we collect

Account data
Your name, your email address, your password in hashed form, the name of your organization, the country you bill from, and the product you chose at sign-up.
Workspace content
The flows, versions, decision tables, connections, cases, and files that you and your colleagues create. This content can contain personal data about your own customers.
Decision records
The input, the output, and the step-by-step trace of every run your flows perform. These records exist so that you can explain a decision after the fact.
Usage and technical data
Your IP address, your browser type, the pages you open, the API keys you use, and the entries in your workspace audit log.
Billing data
Your plan, your subscription status, and your invoices. Stripe processes the payment itself and holds the card details.
Contact and support data
The demo requests, the support messages, and the sales conversations you send us, together with what you write in them.

We do not ask for special categories of data, such as health data or biometric data. Do not send them to our support address. What you choose to process inside your own workspace is your decision and your responsibility.

Where the data comes from

Most of it comes from you: you type it into the sign-up form, into the product, or into an email to us.

Some of it comes from your device as you use the service — your IP address, your browser type, and the pages you open.

Some of it comes from a colleague. An administrator who invites you to a workspace gives us your email address before you have used the product at all.

Some of it comes from a provider that acts for us. Stripe tells us whether a payment succeeded. Cloudflare tells us whether a sign-up looks automated. An identity provider tells us who signed in, when your organization uses single sign-on.

Why we use it

  • To give you the platform, to run your flows, and to keep your decision records available to you.
  • To create and administer your account, and to let your colleagues join your workspace.
  • To bill you, to collect payment, and to keep the accounting records the law requires.
  • To answer your questions, and to give you technical support.
  • To keep the service secure: to detect abuse, to block automated sign-ups, and to investigate incidents.
  • To measure how the product and the website perform, so that we can improve them.
  • To tell you about changes to the service, and — where you agreed to it — to send you marketing email.
  • To comply with the law, and to defend a legal claim.

Who we share it with

We do not sell personal data, and we do not rent it. We share it with the providers below, each of which processes it for us and under contract.

ProviderWhat it doesWhere
Amazon Web ServicesHosting, databases, and file storage for the platform.United States
StripePayments and subscription billing. Stripe receives your card details directly; we never hold them.United States
CloudflareBot protection on the public sign-up and demo forms.Global network
ResendTransactional email, such as invitations and password resets.United States
WorkOSSingle sign-on and directory sync, for the organizations that turn them on.United States
PostHogProduct analytics: which features an account uses, and where a workflow fails.United States
GoogleGoogle Analytics 4 on the public website. See the section on cookies.United States
SentryError monitoring. Configured to exclude personal data from reports.United States
OpenAI, Anthropic, and GoogleAI model calls, and only for the workspaces that use an AI node, an Agent, or the Copilot.United States
SlackInternal alerts to our own team when an account or a demo request is created.United States

We also share personal data when the law requires it, when we have to defend a legal claim, and — if the company is ever sold or merged — with the buyer. We will tell you before your data becomes subject to a different policy.

The providers that handle AI model calls receive only what a flow sends them, and only for the workspaces that use an AI node, an Agent, or the Copilot. A workspace that uses none of those features sends them nothing.

International transfers

We host the platform in the United States, in the AWS region us-east-1. Our providers are listed in the table above, with the country each one operates in.

If you are in the European Economic Area, in the United Kingdom, or in Switzerland, your data leaves that area when you use the service. We rely on the European Commission’s Standard Contractual Clauses for those transfers, and we keep a copy of the clauses we have signed.

If you are in Brazil, we transfer your data abroad under Article 33 of the LGPD, on the basis of contractual clauses that carry the protection the law requires.

Cookies and analytics

Strictly necessary storage. The product keeps your session in your browser so that you stay signed in, and it keeps a per-tab identifier so that two of your own tabs do not fight over the same draft. The service does not work without them, so they carry no choice.

Bot protection. Cloudflare Turnstile sets a short-lived token on the sign-up and demo forms. It tells a person from a script, and it protects the forms from automated abuse.

Analytics. We use Google Analytics 4 on the public website, and PostHog inside the product. Both record which pages and features are used, and both are configured for measurement rather than for advertising. We do not use advertising cookies, we do not run remarketing, and we do not share personal data for cross-context behavioural advertising. If that changes, we will update this policy and offer you a choice before the change takes effect.

You can block cookies in your browser, and you can install Google’s opt-out add-on for Google Analytics. Blocking the strictly necessary storage will sign you out.

How we protect it

We encrypt data in transit with TLS, and we encrypt it at rest. We store passwords as salted hashes, never in a form we can read.

We store an API key as a SHA-256 digest. The key itself is shown to you once, at the moment you create it, and it is never written to our database — which is also why we cannot recover a lost key for you.

We encrypt the credentials you save in a connection at the application layer, so a database backup does not carry the secrets for your other systems in readable form.

Access to production is restricted to the people who need it, and every administrative action inside a workspace is written to that workspace’s audit log.

No system is perfectly secure. If a breach affects your personal data, we will notify you and the competent authority within the time the law allows.

How long we keep it

We keep your account data and your workspace content while your account is open.

After you close your account, we delete the workspace content within 30 days, except where you have asked us in writing to hold it longer.

We keep technical logs for 12 months, so that we can investigate an incident that is reported late.

We keep invoices and accounting records for as long as tax law requires, which is normally five years in Brazil and seven years in other countries where we operate.

We keep a record of a support conversation for two years after it ends.

Your rights

You have the rights below over your own account data. Write to hello@arborule.com to use any of them. We may ask you to confirm who you are before we act, because handing your data to the wrong person is the worse mistake.

Access
You can ask for a copy of the personal data we hold about you.
Rectification
You can ask us to correct data that is wrong or incomplete.
Erasure
You can ask us to delete your data, unless the law requires us to keep it.
Restriction
You can ask us to stop using your data while a dispute about it is open.
Portability
You can ask for your data in a machine-readable format, or ask us to send it to another provider.
Objection
You can object to processing that rests on our legitimate interests. See the next section.
Withdrawal
You can withdraw a consent at any time. The withdrawal does not undo what we did before it.
Complaint
You can complain to your data protection authority. You do not have to contact us first.

Using a right costs nothing. We will only charge a fee, or refuse, if a request is clearly excessive or repeated without reason — and we will explain which of the two we think it is.

Your right to object

Where we process your personal data on the basis of our legitimate interests, you can object to that processing at any time, on grounds that arise from your particular situation.

If you object, we stop — unless we can demonstrate compelling legitimate grounds that override your interests, or unless we need the data to establish or defend a legal claim.

If you object to direct marketing, we stop without exception, and we stop immediately.

If you are in Brazil

The LGPD applies to you, and it gives you the rights listed above. It also gives you two more.

You can ask us to confirm that we process your data at all, and you can ask which public and private bodies we have shared it with.

You can ask us to review a decision that was taken purely automatically and that affects your interests. If the decision was run by one of our customers, ask that customer: they built the policy, and they hold the record.

You can also complain to the Autoridade Nacional de Proteção de Dados (ANPD), at gov.br/anpd.

If you are in California

The California Consumer Privacy Act gives you the right to know what we collect, the right to delete it, the right to correct it, and the right not to be discriminated against for using those rights.

The categories we collect are listed in the section on what we collect. We collect them for the purposes listed in the section on why we use them, and we disclose them to the providers listed in the section on sharing.

We have not sold personal information in the last 12 months, and we have not shared it for cross-context behavioural advertising. We do not sell the personal information of anyone under 16.

Write to hello@arborule.com to make a request. You can name an authorised agent to act for you.

Children

The service is sold to businesses, and it is not directed at children. We do not knowingly collect data from anyone under 18. If you believe a child has given us personal data, write to us and we will delete it.

Changes to this policy

We update this policy when the service changes, when we add a provider, or when the law changes. The effective date at the top always tells you which version you are reading.

If a change materially affects your rights, we will tell you by email before it takes effect.

How to contact us

The controller is Murilo Zaffalon Marra Tecnologia da Informação Ltda., registered in Brazil under CNPJ 36.586.187/0001-02.

Write to hello@arborule.com for anything in this policy: a question, a request, a complaint, or a report of a security problem.

Tell us which right you want to use and which email address your account uses. That is enough for us to find you.