Privacy Policy

Last updated: August 11, 2026

The short version

Your content stays on your device. Ariv and Adoro product analytics are optional. AuraFi 1.4 sends limited automatic, pseudonymous usage analytics to PostHog, but does not send station choices, audio, favorites, or listening history. We only have your email if you purchase or contact support.

This policy covers every product Ariv Studios makes. Each product handles data differently, so the policy is grouped by product below - jump straight to the one you're using:

Ariv

Personal knowledge management (macOS, Windows, Linux)

In one paragraph

Ariv is a local-first note-taking app. Your notes, documents, attachments, tasks, and tags live on your computer as plain Markdown files. Nothing is uploaded to Ariv's servers unless you explicitly opt in to end-to-end encrypted sync. AI features and the Google Calendar integration are off by default and only activate when you turn them on.

What we don't collect

  • Your notes, documents, or file contents - All content stays on your device.
  • Location data - We never track where you are.
  • Device fingerprints - No unique device identification.
  • Personal identifiers beyond what's needed for purchase or support.

Local data

  • Notes are stored as Markdown files in a vault folder you choose.
  • Tasks, tags, backlinks, and search indexes are kept in a local SQLite database in your application data folder.
  • Attachments (images, PDFs) sit in the vault alongside your notes.

Anonymous usage analytics (opt-in)

Ariv can send anonymous product analytics through PostHog so we can understand which features get used and where users get stuck. Off by default; toggle in Settings > Privacy > Help Shape Ariv.

When enabled, we collect:

  • App opens and feature usage events (e.g. "command palette opened", "task created")
  • Setting changes (which key changed - never the value)
  • Anonymous app version, OS platform, theme/accent color

What we never send: note content, note titles, file paths, tag names, task text, attendee names, calendar event content, or anything else identifiable. All events are tied to a random anonymous ID generated locally.

Website acquisition and download measurement

When you visit an Ariv download page, the website may store a random first-party acquisition ID and normalized source context in browser local storage for up to 30 days. This is limited to a controlled channel, campaign and asset identifiers, the landing-page path without query parameters, and the referring host. We do not store search terms, note content, email addresses, or arbitrary query values in this context.

For a desktop download, the normalized context is sent to dl.ariv.one with the requested installer. If you choose the displayed Open Ariv with source link after installation, a signed handoff can connect that download to the first desktop open. The handoff contains no personal information, expires after 24 hours, can be redeemed once, and its server record is purged after 30 days. Ariv sends the joined first-open event to PostHog only if you enabled Help Shape Ariv analytics in the app.

Global Privacy Control or Do Not Track suppresses PostHog on instrumented website pages, creates no persistent acquisition ID, and disables the signed handoff. The installer download still works and is recorded without a causal acquisition identifier.

AI features (optional)

Ariv supports AI-powered features (Ask Brain, auto-tagging, note summaries). These features are off by default and can run in two modes:

Bring Your Own Key (BYOK) mode:

  • You provide your own API key for Google Gemini, OpenAI, Anthropic, or a local Ollama model.
  • Queries flow directly between your device and the provider you chose. We never see your API key, your prompts, or the AI's responses.
  • API keys are stored encrypted in your operating system's secure keystore (macOS Keychain, Windows DPAPI, or Linux libsecret).

Managed AI mode (included with Sync + AI plans):

  • Your AI queries are routed through Ariv's proxy server to the AI provider on your behalf.
  • The proxy sees your prompts and responses in transit but does not store, log, or retain them. They exist in server memory only for the duration of the request.
  • We record only token counts, cost, and latency for billing and quota purposes. No prompt content, response content, or note text is persisted.
  • The AI provider's own privacy policy governs how they handle the content of your queries.

Google user data (Google Calendar integration)

Ariv offers an optional Google Calendar integration that surfaces the user's meetings on a "Today at a Glance" dashboard section and lets them turn any meeting into a pre-filled note in their local vault. This integration is off by default and only activates when the user explicitly clicks Connect in Settings > Integrations.

What Google user data Ariv accesses:

  • Profile basics via the openid and https://www.googleapis.com/auth/userinfo.email scopes - just the user's email address, used solely to display "Connected as <email>" in Settings so the user knows which account is linked.
  • Calendar events via the https://www.googleapis.com/auth/calendar.events.readonly scope - read-only access to events on the user's primary calendar for the current day.

How Ariv uses this data:

  • Display the user's events for the current day in the "Today at a Glance" dashboard section.
  • When the user clicks "Take notes" on an event, create a markdown note in the user's local vault titled with the meeting name, date, and time. The note body is pre-filled with the event's title, start/end time, attendees (names where available), location, and conferencing link.
  • Maintain a local mapping between Google event IDs and the resulting note paths so the dashboard can flip the action from "Take notes" to "Open notes" once a note already exists for that meeting.

How Ariv stores this data:

  • Event content (titles, attendees, descriptions, etc.) is held in memory only for the duration of the user's session. It is not written to disk or any database.
  • Meeting notes the user creates live as ordinary markdown files inside the user's local vault, on the user's device. They are the user's own data and are no different from any other note in Ariv.
  • The OAuth refresh token is stored encrypted at rest using the operating system's secure keystore (macOS Keychain, Windows DPAPI, or Linux libsecret) on the user's device. Access tokens are kept in memory only.

How Ariv shares this data:

  • Ariv does not share Google user data with anyone. Calendar event data is fetched directly from Google to the user's desktop and never transits, transits through, or is stored on Ariv's infrastructure.
  • Ariv does not have a backend that processes user calendar data. There is no server-side cache, no analytics pipeline that touches event content, and no third-party processor.
  • Ariv does not use Google user data to train, develop, or improve any AI/ML models.
  • Ariv does not sell, rent, or transfer Google user data to any third party.

How users can revoke access:

  • From inside Ariv: Settings > Integrations > Google Calendar > Disconnect. This calls Google's token revocation endpoint and wipes the locally-stored refresh token from the OS keystore.
  • From the user's Google Account: Apps with access to your account > remove Ariv.
  • Meeting notes the user has already created are theirs - they remain in the local vault after disconnecting and can be deleted by the user at any time.

Limited Use compliance. Ariv's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

End-to-end encrypted sync (optional)

If you opt in to sync, your vault is encrypted on your device with a key derived from your password before anything leaves your computer. Our sync server stores only opaque ciphertext - no filenames, paths, or content are visible to us. If you lose your password, we cannot recover your data.

Purchases

Ariv Pro is sold through our payment processor, acting as Merchant of Record. They collect your email, payment information, billing address, and any tax-relevant details required by your jurisdiction. We receive only your email and the subscription/purchase confirmation - we never see or store your payment card details. Their processing of your data is governed by their own privacy notice, which is presented at checkout.

Adoro

Focus timer (macOS, iOS, Android)

In one paragraph

Adoro is a local-first focus timer. Your sessions, tags, and stats live on your device. Optional anonymous analytics help us understand how the app is used. Mobile purchases are handled by Apple, Google, and RevenueCat.

What we don't collect

  • Tag names, session notes, or descriptive text you type into the app - these stay on your device.
  • Location data.
  • Device fingerprints.
  • Personal identifiers beyond what your platform's app store needs to deliver the app.

Local data

  • Timer sessions, tag assignments, and statistics are stored locally.
  • Tag names and any session notes you write are never transmitted off-device.

Anonymous usage analytics (opt-in)

Adoro can send anonymous product analytics through PostHog. Off by default; toggle in Settings > Privacy.

When enabled, we collect:

  • App opens, session starts/completions
  • Feature usage (which settings changed - never the values)
  • Pro conversion events

All analytics data is anonymous and aggregated. We use it to understand usage patterns and improve the product.

Purchases

Mobile purchases are processed through the Apple App Store, Google Play Store, and RevenueCat (for subscription management). We receive an anonymous subscriber ID and your subscription status. We do not receive your payment details.

App Store privacy labels

Apple App Store:

  • Data Linked to You: None
  • Data Used to Track You: None
  • Data Not Linked to You: Usage Data, Diagnostics (when analytics are enabled)

Google Play Store:

  • Data shared: None
  • Data collected: App activity, App info (when analytics are enabled)
  • Security: Data encrypted in transit

AuraFi

Internet radio player (macOS)

In one paragraph

AuraFi 1.4 sends limited product analytics automatically through PostHog. It uses a stable, pseudonymous device identifier derived by hashing your Mac's hardware UUID. AuraFi does not send the station you choose, the audio stream, your favorites, mood, volume, timer, or listening history. The app is free and requires no account or purchase.

What AuraFi sends to PostHog

  • A 32-character pseudonymous device identifier created by hashing the Mac hardware UUID with SHA-256. This identifier is stable for that Mac and is not anonymous.
  • An app_heartbeat event no more than once every 24 hours, with the app name, AuraFi version, and macOS version.
  • A player_opened event when you open the expanded player, with the app name and full_player view name.
  • Standard SDK and request metadata may include app, device, operating-system, locale, network, and approximate location information derived from the network request. The current PostHog project does not anonymize source IP addresses.

What we don't collect

  • Station names, station URLs, audio, or listening history
  • Favorites, mood, volume, or sleep-timer selections
  • Account, email, payment, or support information unless you contact us separately

Analytics control

AuraFi 1.4 sends these events automatically and does not include an in-app analytics switch. Contact support@ariv.one to ask questions, object to this processing, or request access or deletion where applicable.

What stays on your Mac

Your favorite stations, selected mood, volume, sleep-timer state, and app preferences are stored locally. AuraFi is free and does not require an account or purchase.

Network requests

Radio Browser and the station you play receive the IP address and connection details normally required to answer a network request or stream audio. Sparkle checks the AuraFi update feed on ariv.one, and approved updates are downloaded from dl.ariv.one. Their infrastructure providers may process standard server logs under their own policies.

Applies to all products

The following terms apply across Ariv, Adoro, AuraFi, and any future Ariv Studios product.

Your rights

  • Access: Your data is on your device.
  • Delete: Delete the app and its data folder.
  • Export: Data is stored in standard formats (Markdown, JSON, SQLite).
  • Opt-out of analytics: Where a product offers optional analytics, disable it in Settings > Privacy. AuraFi 1.4 does not have an in-app analytics control; contact support@ariv.one to object or make an applicable data-rights request.
  • Disconnect integrations: Where a product connects to a third-party account, its Settings page lets you disconnect it. Disconnecting revokes the relevant tokens with the third-party provider and wipes them locally.

Rights for users in the EU/UK (GDPR) and California (CCPA/CPRA)

If you are in the European Economic Area, the United Kingdom, or California, you have additional rights regarding personal data we hold about you (typically your email and any subscription/billing records):

  • Right to access: request a copy of the personal data we hold.
  • Right to rectification: ask us to correct inaccurate information.
  • Right to erasure ("right to be forgotten"): ask us to delete personal data, subject to legal retention requirements (e.g. tax records).
  • Right to data portability: receive your data in a machine-readable format.
  • Right to object / restrict processing: ask us to stop or limit certain processing.
  • Right to opt out of "sale" or "sharing" of personal data (CCPA/CPRA): we do not sell or share personal data for cross-context behavioral advertising. Nothing to opt out of.
  • Right to lodge a complaint: with your local supervisory authority (e.g. the ICO in the UK, your national DPA in the EU, the California Attorney General).

How to exercise your rights: email support@ariv.one from the email address associated with your account. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.

Lawful basis for processing (GDPR): we process your email and billing details to perform our contract with you (Article 6(1)(b)), to comply with tax and accounting obligations (Article 6(1)(c)), and to protect our legitimate interests in operating and improving the service (Article 6(1)(f)). Optional Ariv and Adoro analytics are processed with your consent (Article 6(1)(a)) and can be withdrawn in Settings. AuraFi 1.4's limited automatic analytics are processed under our legitimate interests in understanding basic app use and maintaining the free app (Article 6(1)(f)), subject to your right to object.

Data retention

  • Account email and subscription records: kept for as long as your account is active, plus the period required by Canadian tax law for accounting records (currently six years from the end of the tax year to which they relate).
  • Encrypted sync blobs: retained as long as your sync subscription is active. Deleted vault items go to a 15-day Trash window before permanent removal. Closing your account deletes all encrypted blobs from our infrastructure within 30 days.
  • PostHog analytics events: our PostHog project currently reports an 84-month event-retention setting, with automatic retention enforcement disabled. This applies to website analytics, opt-in Ariv and Adoro analytics, and AuraFi's automatic analytics. We may delete events earlier when they are no longer needed or when an applicable request requires it.
  • Support correspondence: retained for up to 24 months after the last interaction.

Subprocessors

We use a small number of subprocessors to operate Ariv Studios products. None of them ever receive your note content or local file contents.

  • Cloudflare, Inc. - hosts our website (Cloudflare Pages) and the encrypted sync infrastructure (Workers, D1, R2). Encrypted sync blobs are stored at rest in Cloudflare R2; we use the EU/Auto region routing where applicable. Cloudflare also provides our website analytics in cookieless aggregate form.
  • Payment processor (Merchant of Record) - handles payment processing, billing, tax collection and remittance, and subscription management for desktop subscriptions. Receives your email, payment details, and billing address. We will identify the specific provider on request.
  • PostHog Inc. - website interaction analytics on instrumented pages, opt-in product analytics inside Ariv and Adoro, and limited automatic analytics from AuraFi 1.4. AuraFi sends the pseudonymous identifier and events described above, but not station choices, audio, favorites, or listening history.
  • RevenueCat, Inc. - subscription management for mobile apps that offer paid plans. Receives anonymous subscriber IDs only.
  • Resend - transactional email (account, billing, support). Receives your email address and the message content.
  • Apple, Google - mobile app distribution and in-app purchase processing for our mobile apps. Governed by their respective privacy policies.

If you have opted in to AI features with your own API key, your prompts and responses flow directly between your device and the AI provider you chose (Google, OpenAI, Anthropic, or a local model). Those providers are not our subprocessors - you have a direct relationship with them governed by their terms.

International data transfers

Ariv Studios operates from Canada. Some of our subprocessors process data in the United States, the European Union, or other regions. Where personal data of EU/UK users is transferred outside those jurisdictions, we rely on standard contractual clauses (SCCs) and our subprocessors' approved transfer mechanisms. Encrypted sync blobs are end-to-end encrypted before they leave your device, so even when stored or routed across regions, the content is unreadable to us, our subprocessors, or anyone in transit.

Cookies and similar technologies

We do not use advertising cookies or cross-site tracking. We do use limited first-party browser storage for website measurement:

  • Website analytics: Cloudflare Web Analytics is cookieless and aggregates traffic data. Instrumented pages also use PostHog with a random first-party browser identifier.
  • Acquisition context: a random acquisition ID and normalized first-touch fields may remain in local storage for up to 30 days so a download can retain its source. Global Privacy Control or Do Not Track disables this storage and PostHog capture.
  • Checkout pages: when you proceed to checkout, our payment processor may set cookies necessary for processing the transaction. Their cookie use is governed by their privacy notice, which is presented at checkout.
  • In-app analytics: Ariv and Adoro analytics are optional. AuraFi 1.4 sends the limited automatic events described in its section using a stable pseudonymous identifier derived from the Mac hardware UUID. In-app analytics do not use browser cookies.

Children's privacy

Our products are not intended for children under 13. We do not knowingly collect information from children.

Data security

  • All data stays local on your device by default.
  • Any network requests use HTTPS encryption.
  • Secrets (API keys, OAuth refresh tokens) are stored encrypted in your operating system's secure keystore (macOS Keychain, Windows DPAPI, or Linux libsecret).
  • We recommend encrypting your device.
  • We can't be breached for data we don't have.

Changes to this policy

We may update this policy occasionally. We'll notify users of significant changes via email (if we have your address), an in-app notification, or our website. The "Last updated" date at the top of this page reflects the most recent revision.

Contact

Questions about this policy? Reach us at support@ariv.one.