Back to Arbutus

Studio-wide policy

Privacy Policy

This is the privacy policy for Arbutus Investment LLC and every app we make. It explains what we collect (as little as we can), how we handle it (on your device wherever possible), and the rights you always keep. We've written it to be protective of you by default.

Effective: 30 May 2026 Last updated: 30 May 2026 Applies to: this website & all Arbutus apps

The short version

We collect the bare minimum, we process it on your device whenever we can, and we never sell it.

You decide, feature by feature, what each app may access. You can export your data or delete everything, permanently, at any time. We don't run third-party advertising or tracking. If a court ever forces our hand, we'll tell you unless the law forbids it.

The sections below say all of this more precisely. Plain-language summaries don't replace the full text, but where the two seem to conflict, we'll always interpret the policy in the way most protective of your privacy.

1. Who we are

Arbutus Investment LLC ("Arbutus", "we", "us", "our") is an independent software studio based on the Pacific coast of Canada. We are the data controller responsible for the personal information described in this policy. You can reach us any time at privacy@arbutus.studio.

This policy covers this website and every app we publish. Individual apps — because they do very different things — may add a short supplemental notice describing data handling specific to that app. A supplement can only ever add detail or extra protections; it can never weaken the commitments made here.

2. Our privacy principles

Every decision we make about data is measured against five commitments:

  • Data minimisation. We collect only what a feature genuinely needs, and nothing "just in case".
  • On-device by default. Where it's technically possible, your information is processed on your phone and never leaves it.
  • Purpose limitation. We use information only for the purpose you gave it to us for.
  • Your control. Access is granted feature-by-feature and can be withdrawn at any time. Export and deletion are always available.
  • No surveillance economy. We don't sell data, don't rent it, and don't embed third-party ad or tracking networks.

3. What we collect

The exact data depends on which app you use and which features you turn on. In general it falls into a few buckets:

Information you provide

  • Content you create — journal entries, expense records, meals you log, notes, and similar.
  • Account details, if an app offers an optional account (for example, an email address for cloud backup or sync). Many features work with no account at all.
  • Messages you send us for support or feedback.

Information a feature needs to function

  • Device permissions you explicitly grant — such as location, photos, camera, motion, or notifications — used only for the feature you enabled them for.
  • Basic device information needed to run reliably (operating-system version, device model, app version, language).

Diagnostics (optional)

  • Crash reports and aggregate, non-identifying usage statistics — only if you opt in. These are designed so they can't be tied back to you, and the apps work fully with them switched off.

We do not buy personal information about you from data brokers, and we don't build advertising profiles.

4. On-device processing

This is the heart of how we build. Several of our apps interpret personal signals — places you visit, photos on your phone, what's on your screen, your meals. Wherever the technology allows, that interpretation happens entirely on your device, and the raw signals never reach our servers.

When a feature genuinely cannot run on-device and needs to send something to a server (ours or a carefully vetted processor), we will:

  • tell you clearly, in context, before it happens;
  • send the smallest amount of data necessary, and strip identifiers where we can;
  • process it for that single request and not retain the raw content beyond what's needed to return your result, unless you've asked us to store it (for example, to sync across your devices).

5. Sensitive signals (location, photos, screen & health-adjacent data)

Some Arbutus apps can draw on especially personal inputs to do their job — for example, an auto-journaling app that understands your day from your location history, your photo library, on-device activity, or what's on your screen; or a nutrition app that reads a photo of your plate.

For any such signal:

  • It's strictly opt-in. Nothing sensitive is accessed until you explicitly grant that specific permission, and the app works (in a reduced form) if you don't.
  • It's interpreted on-device wherever possible, and the underlying photos, screen contents, and precise location are not uploaded to us as a matter of course.
  • It's purpose-bound. A signal you enabled for one feature is never quietly repurposed for another.
  • You can revoke it instantly from the app or your device settings, and delete anything already derived from it.
  • We don't use it to advertise to you or share it for anyone else's advertising.

The supplemental notice for each app spells out exactly which sensitive signals it can use, what it derives from them, and where any processing takes place.

6. How we use information

We use information only to:

  • provide, maintain, and improve the features you actually use;
  • sync or back up your data across your devices, where you've turned that on;
  • respond to your support requests;
  • keep the apps secure and prevent fraud or abuse;
  • comply with legal obligations that genuinely apply to us.

We do not use your content to build advertising profiles, and we do not use your private content to train machine-learning models without your separate, explicit, revocable consent.

7. Sharing & disclosure

We share personal information only in these limited situations:

  • Service providers (processors) who help us run the apps — such as cloud hosting or crash reporting — strictly under contract, only for the purposes we set, and never for their own use. We choose providers who meet a high privacy bar.
  • At your direction — for example, when you export or share your own content.
  • Legal requirements — when we're compelled by valid legal process. We review each request, push back on overbroad or improper ones, disclose only the minimum required, and notify you unless we're legally prohibited.
  • Protecting people — to address an imminent risk to someone's safety, or a real security threat.
  • Business changes — if Arbutus is ever involved in a merger or acquisition, your data stays governed by a policy at least as protective as this one, and we'll give you notice and a choice where the law provides one.

8. What we never do

To be unambiguous, we will never:

— sell, rent, or trade your personal information;
— embed third-party advertising networks or cross-app trackers;
— use your private content for ads;
— train models on your private content without separate, explicit, revocable consent;
— access a sensitive signal you haven't explicitly permitted for that purpose.

9. Storage & retention

Most of what our apps create lives on your device (and in your own cloud backup, if you use one). Where we do hold data on our servers — for sync or an optional account — we keep it only as long as your account is active or as needed to provide the feature.

When you delete content, we remove it from our active systems promptly and from routine backups within a short, defined window. We retain a minimal amount of information only where the law requires it (for example, limited records for tax or fraud-prevention), and only for as long as that obligation lasts.

10. Security

We protect information with encryption in transit and at rest, scoped access controls, and a practice of keeping the least data possible — the safest data is the data we never collect. No system is perfectly secure, but if a breach ever affects your personal information, we will notify you and the appropriate authorities as required by law, without undue delay.

11. Your rights & choices

Wherever you live, every Arbutus app gives you practical control:

  • Access & portability — view and export your data in a usable format.
  • Correction — fix anything inaccurate.
  • Deletion — erase specific items, or wipe everything permanently, in a tap.
  • Withdraw consent — revoke any permission at any time, without losing access to features that don't need it.
  • Object & restrict — limit certain processing.

Depending on where you are, you may have additional rights under laws such as Canada's PIPEDA (and provincial equivalents), the EU/UK GDPR, and the CCPA/CPRA in California — including the right not to be discriminated against for exercising them. We honour these rights for everyone, regardless of location, and we don't charge you to use them. To make a request, email privacy@arbutus.studio; you also have the right to complain to your local data-protection authority.

12. Children

Our apps are not directed to children under 13 (or the minimum age in your region), and we don't knowingly collect their personal information. If you believe a child has provided us data, contact us and we'll delete it.

13. Where your data lives

We're a Canadian studio and prefer to keep data in Canada or with providers offering comparable protection. If information is ever processed in another country, we use appropriate safeguards (such as standard contractual clauses) so it stays protected to the standard described here, wherever it travels.

14. Per-app supplemental notices

Each app ships with its own short notice covering anything specific to it — the exact permissions it can request, what it derives from them, where processing happens, and any optional cloud features. Read that notice alongside this policy. If anything in a supplement ever appeared to reduce your protections below this document, this document governs.

15. Changes to this policy

If we update this policy, we'll change the "last updated" date above and, for material changes, give you prominent notice in the app or by email before they take effect. We'll keep prior versions available so you can see what changed. We will never apply a materially less-protective change to data we already hold without giving you a meaningful choice.

16. Contact us

Questions, requests, or concerns about privacy are always welcome:

We read every message and aim to respond within 30 days, usually much sooner.