Privacy Policy
Last updated: July 14, 2026
Overview
ArcBrush is a desktop application that processes images locally on your device. Images leave your device only when you use the two optional Cloud nodes (Remove Background and Upscale): when you use them, the image is sent to a third-party service for processing and the result is returned to you. Cloud-node images are used only to perform the requested operation, are not used to train models, and are not intentionally retained after the result is delivered, except for transient processing needed to provide the service or as required by law or security controls. A Pro license is a signed file that is verified entirely on your device - it requires no account, no network connection, and no device fingerprint. If you sign in to an account holding a Trial or Studio license, the application contacts our servers periodically to verify that license; this sends a pseudonymous device fingerprint and your authentication token - no image data is included. See "Pro License Files" and "Trial and Studio License Verification and Device Binding" below for full details. We collect only the minimum data necessary to provide our services and improve the application.
Who We Are
ArcBrush LLC is responsible for the personal information described in this Policy (the "data controller" where that term applies under your local law). Contact: contact@arcbrush.com. Mailing address: 522 W Riverside Ave, STE N, Spokane, WA 99201, USA.
Pseudonymous Usage Telemetry
ArcBrush sends a pseudonymous usage heartbeat approximately every 30 minutes while the application is running, plus a final heartbeat when the application closes. This helps us understand how the app is used and prioritize improvements. Telemetry is enabled by default. The heartbeat contains:
- Install ID. A pseudonymous device identifier: a one-way SHA-256 hash of an operating-system device identifier (the same identifier described under "Trial and Studio License Verification and Device Binding" below). The raw identifier never leaves your machine, and the hash cannot be reversed to recover it. Where the operating system does not provide such an identifier, a randomly generated UUID is used instead. Installs upgraded from older versions may also send the previous random install ID so the old and new records can be merged rather than double-counted.
- App version. The version of ArcBrush you are running.
- Operating system. "windows", "macos", or "linux".
- Session duration. How many minutes the app has been open.
- Node count. The number of nodes in your current graph.
- Cloud usage count. How many Cloud-node operations were run this session.
- Registered status. Whether you have signed in to an account (true/false only, not your email), and whether the build is a development build.
- Network diagnostics. The number of failed network requests since the last heartbeat, the proxy mode selected in Settings ("direct", "auto", or "manual" - never the proxy address, username, or password), and whether a custom certificate authority is configured (yes/no only).
The application also sends short named telemetry events about the auto-update process (for example, that an update was offered, downloaded, or applied), with a brief qualifier such as the target version. These events follow the same telemetry opt-out.
Telemetry does not include your name, email address, images, prompts, project content, node parameter values, file names, file paths, or license-file contents. We do not use telemetry to identify you.
You can disable telemetry at any time in Settings; the setting is stored locally on your device. When disabled, no usage data is sent. Disabling telemetry does not affect licensing, updates, or any editor feature.
Send Feedback
The Send Feedback feature (Help menu) lets you report bugs, request features, or share general feedback. When you submit feedback, the following is sent:
- Your message. The text you write. It is stored as submitted and may contain personal information you choose to include, so do not include passwords, payment information, private keys, or sensitive personal information in feedback.
- System info. OS, app version, GPU model, and display resolution to help reproduce issues.
- Graph context. Node types and connection structure of your current graph (no image data or file paths).
Feedback submissions are stored on our servers for the purpose of improving ArcBrush and are retained for as long as they remain relevant to product development, security, or support. No images or file contents are included.
Cloud Nodes (Remove Background and Upscale)
ArcBrush includes two optional Cloud nodes, Remove Background and Upscale, that are processed in the cloud rather than on your device. They are free to use but require a signed-in account with a verified email. When you run one of these nodes:
- The input image is sent through ArcBrush's cloud service to a third-party image-processing provider over an encrypted (HTTPS) connection so the operation can be performed.
- The request also includes the account and session information needed to authenticate it, enforce rate limits and monthly usage limits, and prevent abuse.
- The processed result is returned to your device and stored in your project like any other node output.
- The image is used only to perform the requested operation, is not used to train models, and is not intentionally retained after the result is delivered, except for transient processing needed to provide the service or as required by law or security controls.
The processing is carried out by a third-party provider (see Third-Party Service Providers below), whose handling of the image is governed by its own terms. We may change providers from time to time and will update this Policy or the in-app disclosure before using a materially different provider. ArcBrush does not use Cloud-node images to identify people, create face templates or other biometric identifiers, or infer health information; do not upload images containing regulated health, biometric, or similarly sensitive data unless you have the rights and consents required to do so. Every other node in ArcBrush runs entirely on your device and sends no image data anywhere, so if you never use the Cloud nodes, your images never leave your machine.
Payment Processing
Pro license purchases are processed by Stripe, our third-party payment processor. When you buy a license, Stripe collects and processes your payment information (including card details and billing address) directly. ArcBrush LLC does not see or store your full card number. Stripe's handling of your data is governed by its own privacy policy at stripe.com/privacy.
ArcBrush receives and stores purchase metadata from the payment processor, such as the checkout session identifier, the email address provided at checkout, the product purchased, the amount and currency, the purchase time, refund and dispute status, and the resulting license identifier.
You do not need an account to purchase: a license can be bought as a guest with only an email address. After a successful purchase, a license email is sent to the email address provided at checkout or associated with your signed-in account; it contains the license file and a download link. These emails are sent only for completed purchases.
Account Data
If you create an account (including to start a Trial, manage or re-send licenses, or use the Cloud nodes), ArcBrush may process:
- Email address and account identifier. Used for authentication and account communication. Stored securely on our servers.
- Authentication data. Session tokens are stored in your operating system's secure credential storage (Windows Credential Manager, macOS Keychain, or libsecret on Linux). If you sign in through a third-party sign-in provider, we receive the account identifier and email address it supplies. If you sign in with a password, we store only a salted cryptographic hash of it - never the password itself.
- License, trial, purchase, refund, and dispute history. Stored on our servers for billing and licensing purposes.
- Terms acceptance. The version of the Terms you accepted and when.
- Cloud-node usage counters and rate-limit records.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose personal information to service providers and processors only as described in this Policy.
Pro License Files
An ArcBrush Pro license is delivered as a signed file (the "license file"), either emailed to you as an attachment and a download link at purchase, or installed automatically when you sign in to an account that purchased Pro.
What the license file contains and how it works:
- Name and email address. The license file contains, in plain readable text, the name and email address associated with your purchase. This is by design: it lets a lost license be traced back to your purchase for re-issue, and it discourages sharing the file. Editing this information invalidates the file's cryptographic signature. Keep in mind that anyone who receives a copy of your license file can read the name and email address inside it, and that if you store the file in a cloud backup or sync service, that service may process the file under its own terms.
- Local verification, no account or network required. The application verifies the license file's signature entirely on your device, using public cryptographic keys built into the Software. Installing and using a Pro license requires no account, no sign-in, and no network connection, and it never transmits a machine fingerprint or any other device identifier.
- Storage. The license file is copied to a location inside the application's data folder on your device, where you can find it, back it up, or move it yourself. It is an ordinary file, not a hidden or encrypted record.
- Opportunistic revocation check. When the application is online, it may send the random identifier contained in your license file to our servers, piggybacked on the existing update-check request, to ask whether that specific license has been revoked (for example, after a refund or a confirmed policy violation). The request does not include your name, email address, machine fingerprint, images, project files, file names, or file paths; like any network request, it necessarily involves ordinary network metadata (such as an IP address and timestamp), which is used only as described in the next bullet and in standard server security logs. This check never blocks the Software, never requires a network connection to keep working, and fails silently if the server cannot be reached. A license that has not been revoked keeps working offline indefinitely, even if our servers are permanently unreachable.
- Abuse detection on the revocation check. To detect a leaked or mass-shared license file, our server counts how many different networks a given license's revocation checks arrive from. For this count, network addresses are not stored: each address is reduced to a salted one-way hash that cannot be reversed, is used only to count distinct networks per license, and is deleted after 90 days. Standard server and security logs may process ordinary network metadata for a limited period (see Data Retention). No machine identity is collected, and this processing never affects whether the Software works.
- Re-issue. If you lose your license file, we can re-send it to the email address on the purchase at any time.
Trial and Studio License Verification and Device Binding
The free trial and Studio licenses use a different, time-boxed verification system; this section does not apply to Pro licenses, which are covered above and are never machine-bound. After you sign in and activate a Trial, or purchase a Studio license, the application receives a server-signed entitlement file that is stored in your operating system's secure credential storage (Windows Credential Manager, macOS Keychain, or libsecret on Linux). The application verifies this file locally at each launch; no network connection is needed to confirm your license once issued.
What this license system collects and sends:
- Machine fingerprint. ArcBrush computes a pseudonymous device identifier by applying a one-way SHA-256 hash to an OS-level device identifier (on Windows, a system registry identifier that is reset when Windows is reinstalled; on macOS, a hardware platform UUID; on Linux, the system machine identifier from /etc/machine-id). The hash cannot be reversed to recover the underlying identifier, and the raw identifier never leaves your machine. The hash is transmitted to our servers during the license refresh request (see cadence below) and is associated with your account solely to count the number of distinct devices using your Trial or Studio license and enforce the per-account device limit described below. It is not used to identify your images or project files, track your activity outside license verification, or personalize advertising; because it is associated with your account for licensing, we treat it as personal data where applicable law requires. It is never sent once your account is known to hold a Pro license.
- Authentication token. Your session token is included in the license refresh request to authenticate the request. Your password is never transmitted.
- Plan and entitlement data (received). Our servers return a signed entitlement file specifying your license tier (Trial or Studio) and the validity window. This file is stored in your credential storage and is verified locally on subsequent launches without a network connection.
License refresh cadence (offline-first)
Your Trial or Studio entitlement file is valid for 30 days from the most recent successful refresh. The application works without any network connection during that period. When the application launches and an internet connection is available, it contacts our servers once at startup to refresh the entitlement file and extend the window. If the server cannot be reached, the locally stored file continues to be used.
- A 7-day grace period follows the 30-day window. Trial and Studio features remain available during this period with a single, dismissible notification.
- The license refresh is independent of the pseudonymous usage telemetry. Disabling telemetry in Settings does not affect license verification.
Device limit (3 machines per account, Trial and Studio only)
A single Trial or Studio license can be active on up to three machines at the same time. The server counts the number of distinct machine fingerprint hashes associated with your account within each refresh cycle. If you reach the limit, you can remove individual devices or reset all active devices at Settings > Account > Active Devices without contacting support. Device records are retained while your account is active; when you remove a device or reset your device list, the removed records no longer count toward the limit, although limited security and fraud-prevention logs may be retained for a limited period. Pro licenses have no device limit and are not machine-bound.
Third-Party Service Providers
We use the following categories of third-party service providers to operate ArcBrush. Where required, we enter into data-processing terms or other appropriate agreements with them; some providers, such as payment processors, process certain information under their own terms and privacy policies:
- Payment processor. Stripe processes Pro license purchases (see Payment Processing above).
- Cloud hosting. Our account database is hosted with reputable cloud infrastructure providers.
- Email delivery. Purchase confirmation, license, and account emails are sent through a transactional email service.
- Image processing. The Cloud nodes (Remove Background and Upscale) send images to a third-party image-processing provider to perform the requested operation. The image is used only to fulfill your request (see Cloud Nodes above).
Website
- We do not use third-party tracking cookies or advertising analytics on our website.
- Our website's hosting provider, content delivery network, and security tools may process ordinary server-log information (such as IP address, user agent, requested URL, referrer, and timestamp) for security, diagnostics, and aggregate traffic measurement.
- Download counts are kept in aggregate and are not tied to your ArcBrush account.
Data Security
All communication between ArcBrush and our servers uses HTTPS encryption. Account credentials are managed through industry-standard authentication. API keys are never stored on the client. We use reasonable technical and organizational safeguards appropriate to the nature of the data we process; no system is perfectly secure, and we cannot guarantee absolute security.
Data Breach Notification
Where required by law, we will notify the relevant data protection authority of a reportable personal-data breach without undue delay and, where feasible, within 72 hours of becoming aware of it. We will notify affected individuals without undue delay where required by applicable law, including where a breach is likely to result in a high risk to their rights and freedoms.
Data Retention
- Raw telemetry events are retained for product analysis and then deleted or reduced to aggregate statistics; aggregate statistics that do not identify you may be kept indefinitely. Telemetry and website download counts are not tied to your account identity, so deleting your account does not change what these records contain.
- Feedback submissions are retained for as long as they remain relevant to product development, security, or support. If you delete your account, we remove the contact email address from any feedback you submitted with that address; the message text, system info, and graph context you included are kept, since they are bug-report and feature-request content rather than information about you.
- Account data is retained while your account is active, plus a limited period afterward for security, fraud prevention, and dispute resolution.
- License purchase records are retained for the period required by tax and accounting law.
- License file records (the license-to-email association used to re-send a lost license and to process a revocation) are retained to support re-issue and revocation, independent of whether you keep an account. Deleting your account detaches the license from your account but does not delete or unlink the purchase record itself.
- Machine fingerprint records (the pseudonymous device hashes used for device counting on Trial and Studio licenses) are retained while your account is active. Pro licenses do not generate machine fingerprint records.
- Network-count records from the license revocation check (the salted one-way hashes used to count distinct networks per license for leak detection) are deleted after 90 days.
- Server and security logs are retained for a limited period appropriate to security and diagnostics; backups are overwritten on a rolling schedule.
- If you had activated a free Trial before deleting your account, we retain a one-way cryptographic hash of your canonicalized email address together with the date the trial was consumed, under legitimate interest in preventing free-trial abuse. This hash cannot be reversed to recover your email address or any other account identifier, is not linked to any surviving record, and is used only to recognize a repeat sign-up attempting to claim another free Trial - it is never used to affect account creation itself or any paid license.
- If you had accepted our Terms of Service before deleting your account, we retain a separate one-way cryptographic hash of your canonicalized email address together with the Terms version you accepted, the date you accepted it, and the date of deletion. This hash uses its own dedicated key, distinct from the free-trial hash above, so the two records cannot be linked to each other. It cannot be reversed to recover your email address, name, or any other account identifier, and it is not used for any purpose other than to demonstrate, if you later bring a legal claim against us (which would necessarily reveal your email address to us), that a specific email address accepted a specific version of the Terms on a specific date. We retain it under our legitimate interest in, and to the extent necessary for, the establishment, exercise, or defense of legal claims.
- You may request deletion of your account and associated data at any time, either using the self-serve deletion form (which emails a confirmation link before anything is deleted) or by writing to contact@arcbrush.com. Requests are honored within one month either way. Deleting your account does not affect a Pro license file you have already installed, which continues to work offline and remains re-sendable to the purchase email at any time; a Trial or Studio entitlement instead lapses once its current verification window expires, since renewing it requires a signed-in account. An account with an active Studio term license is handled by contacting support rather than the self-serve form. We may retain limited license and purchase records after account deletion where needed to honor your license, re-issue a lost license, process refunds or disputes, prevent fraud or unauthorized distribution, comply with accounting and tax obligations, or establish or defend legal claims.
International Data Transfers
The third-party providers we use to operate the Software may be located in countries other than the one from which you access it. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with data transfer restrictions, your personal data may be transferred to and processed in countries that have different data protection laws than your own. Where required by applicable law, such transfers rely on appropriate safeguards, which may include adequacy decisions, the EU-U.S. Data Privacy Framework (where a provider is certified and eligible), the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or other lawful transfer mechanisms.
Your Rights
Depending on where you live, you may have specific rights regarding your personal data. We honor the following rights for all users, regardless of jurisdiction:
- Access. Request a copy of the personal data we hold about you.
- Rectification. Request correction of inaccurate or incomplete data.
- Erasure. Request deletion of your account and associated data (the "right to be forgotten"), using the self-serve deletion form or by emailing us. See "Data Retention" above for what this does and does not affect.
- Portability. Receive your data in a structured, commonly used, machine-readable format.
- Objection and restriction. Object to or restrict certain processing of your data.
- Disable telemetry in Settings at any time.
- Use most of the editor without an account. Every node except the two Cloud nodes (Remove Background and Upscale) works without any data collection beyond optional telemetry; the Cloud nodes require a free account and upload images for processing.
- Withdraw consent. Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, contact us at contact@arcbrush.com. We may need to verify your identity before fulfilling a request, and some requests may be limited where the information is needed for security, fraud prevention, licensing, accounting, legal compliance, or the establishment or defense of legal claims. We will respond within the timeframes required by applicable law (typically 30 days under the GDPR; 45 days under the CCPA).
Legal basis for processing (EEA/UK users)
If you are located in the European Economic Area or the United Kingdom, we process your personal data on the following legal bases:
- Performance of a contract. To provide your Pro, Trial, or Studio license and process its purchase, including issuing and verifying license files and, for Trial and Studio, license verification and device binding.
- Legitimate interests. To operate, improve, and secure the Software (including pseudonymous usage telemetry, when not disabled; the opportunistic Pro license revocation check; for Trial and Studio, license-abuse prevention via machine fingerprinting for device counting; and, on account deletion, retaining a one-way hash of a previously-consumed Trial's email address to prevent free-trial abuse, as described under "Data Retention").
- Consent. Where you have given consent for specific processing (for example, feedback submissions).
- Legal obligation. To comply with applicable laws and respond to lawful requests.
- Establishment, exercise, or defense of legal claims. On account deletion, retaining a separately-keyed one-way hash of your canonicalized email address, the Terms of Service version you accepted, and the acceptance and deletion dates, so that we can demonstrate acceptance of specific Terms if you later bring a legal claim, as described under "Data Retention".
You have the right to lodge a complaint with your local data protection authority if you believe we have not handled your data in accordance with applicable law. A list of EU supervisory authorities is available at edpb.europa.eu; UK users may contact the Information Commissioner's Office.
California residents (CCPA/CPRA)
If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), including the rights listed above. ArcBrush LLC does not currently meet the thresholds that make a company a "business" subject to the CCPA/CPRA; we honor the rights described in this Policy for all users voluntarily, and we will update this section with the required California-specific disclosures if that changes. In the preceding 12 months, we have collected the following categories of personal information: identifiers (email address, install ID, a random license file identifier, pseudonymous machine fingerprint hash for Trial/Studio devices), commercial information (purchase history), internet or other electronic network activity information (pseudonymous usage telemetry and network diagnostics), and user-provided content (feedback submissions). We do not sell or share your personal information for cross-context behavioral advertising, and we do not knowingly collect personal information from minors under 16 for the purpose of selling or sharing.
Children's Privacy
ArcBrush is not directed at children under 13. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 13 without required parental consent, we will delete it; parents or guardians may contact us at contact@arcbrush.com to request deletion.
Changes to This Policy
We may update this Privacy Policy from time to time. Updated policies will be posted at https://arcbrush.com/privacy. If we make material changes to how we collect, use, or disclose personal information, we will provide notice through the application, the website, email, or another appropriate method, and obtain consent where required by law.
Contact
For privacy questions or data requests, contact us at contact@arcbrush.com.