Arden
← Back to Arden

Privacy Policy

Effective Date: July 20, 2026

Contact: support@ardentime.com

Arden ("Company," "we," or "us") is committed to protecting your privacy. This Privacy Policy explains what information we collect, how we use it, and your rights with respect to that information. By installing or using the Arden application or web application (together, the "Software"), you agree to the practices described below.

1. Overview of How Arden Works

Arden is a cloud-based passive timekeeping platform for legal professionals. Activity signals are collected from the sources you connect — the Arden desktop tracker ("ArdenTrack") and, if you enable them, your Microsoft 365 and Google Workspace accounts — and are transmitted to and stored in Company's cloud database (hosted on Supabase), scoped to your firm's workspace and protected by row-level security. Arden's processing engine organizes these signals into work sessions, attributes them to your clients and matters, and drafts time entries for your review.

Arden collects activity metadata — application names, window titles, timestamps, durations, email subjects and participants, calendar event details, and file names and paths. Arden does not collect the body content of your emails, the contents of your documents or files, or screenshots of your screen. The one exception is documents you explicitly upload to Arden's pre-bill assistant, as described in Section 2.4.

2. Information We Collect

2.1 Account and Authentication Data

When you create an Arden account, we collect:

  • Your email address and hashed password (via Supabase Auth), or your Google or Microsoft account identifier if you choose OAuth sign-in
  • Your name, firm name, and timekeeper profile information
  • Your subscription and billing status

This data is stored in Arden's Supabase-hosted backend and is used to authenticate you, manage your subscription, and provide account support.

2.2 Activity Data from ArdenTrack

ArdenTrack, Arden's desktop activity tracker, collects the name of the application in the foreground, its window title, timestamps and durations, idle/away status, and file-activity events (file names and paths) within folders you designate for monitoring. ArdenTrack does not capture screenshots, keystrokes, or the contents of your files. Collected activity events are transmitted directly to Company's Supabase-hosted backend, authenticated with your account credentials; ArdenTrack does not maintain a local database of your activity on your device.

2.3 Activity Data from Connected Integrations

If you connect the following integrations, Arden collects activity metadata from them via their official APIs:

  • Microsoft 365 (Microsoft Graph): email metadata (subject lines, sender and recipient addresses, timestamps), calendar events (subject, attendees, start and end times), and OneDrive/SharePoint file activity (file names and paths). Arden does not read email bodies, attachments, or file contents.
  • Google Workspace: Gmail message metadata (subject lines, participants, timestamps), Google Calendar events (subject, attendees, start and end times), and Google Drive file activity (file names and paths). Arden does not read email bodies, attachments, or file contents.
  • Clio: your matters, clients, and billing code configuration are imported from Clio to power attribution and billing workflows.

Each integration is optional and requires your explicit OAuth consent. OAuth access and refresh tokens are stored in our Supabase backend encrypted at the application layer with AES-256-GCM, in addition to Supabase's encryption at rest. You may disconnect an integration at any time, which deletes the stored tokens and stops collection from that source.

2.4 Customer Content

Time entry narratives, work sessions, classifications, client and matter records, billing codes, pre-bill documents, and profile information ("Customer Content") are stored in Company's Supabase-hosted backend, scoped to your firm's workspace. Row-level security ensures Customer Content is accessible only to authenticated members of your firm, according to their roles. If you upload a document to Arden's pre-bill assistant, its text is extracted and processed by our AI provider (Section 4.3) for the duration of that conversation; uploaded document text is used only to answer your request.

2.5 Usage Telemetry

Arden automatically collects limited usage telemetry to monitor application health and improve the product, including app open and close events, session uptime, counts of activity events collected and sessions processed, and a device-level UUID (randomly generated) alongside your user ID. Telemetry is transmitted to Arden's servers (hosted on Supabase). We do not use telemetry data to train large language models (LLMs) or generative AI features.

3. How We Use Your Information

  • Account data is used to authenticate you, manage your license and billing, and provide customer support.
  • Activity data and Customer Content are used solely to generate, attribute, and manage your time entries and billing documents.
  • Telemetry data is used to monitor application stability, measure feature engagement, and prioritize product improvements.
  • We do not sell, rent, or share your personal information with third parties for marketing purposes, and we do not use your data to train AI models.

4. Third-Party Service Providers

Arden relies on the following third-party providers to operate. Each receives only the minimum data necessary for its function:

4.1 Supabase

Supabase (supabase.com) hosts Arden's authentication backend, database, and all cloud-stored Customer Content, activity data, and telemetry. All data is scoped to your firm's workspace using row-level security and encrypted at rest. Supabase's privacy practices are governed by their Privacy Policy at supabase.com/privacy.

4.2 Render

Render (render.com) hosts Arden's processing engine — the background workers that ingest activity from your connected sources, organize it into sessions, and generate draft time entries. Matter attribution is performed by deterministic matching within Arden's own engine; no third party receives your data for attribution. Arden does not connect external log drains in Render, and our services are configured not to log request or response content. All data in transit is encrypted via TLS. Render's privacy practices are available at render.com/privacy.

4.3 Anthropic

Anthropic (anthropic.com) provides the AI models (Claude) used to draft time entry narratives and to power Arden's pre-bill assistant. To perform these functions, Anthropic receives session summaries consisting of activity metadata (app names, window titles, email and calendar subjects and participants, file names, timestamps, and durations), your client and matter names, and — only for the pre-bill assistant — your time entries and the text of documents you explicitly upload. This is the minimum information required to draft accurate narratives. Arden's API traffic with Anthropic is subject to zero-data-retention terms: data submitted via the API is not stored by Anthropic and is not used to train its models. Anthropic's privacy practices are available at anthropic.com/legal/privacy.

4.4 Stripe

Stripe (stripe.com) processes subscription payments. Stripe receives your email address and payment card details; Arden never stores your full payment card information. Stripe's privacy practices are available at stripe.com/privacy.

4.5 Microsoft, Google, and Clio

When you connect these integrations, data flows between Arden and the provider as described in Section 2.3, and time entries you choose to send to Clio are transmitted to and stored by Clio. Your use of each provider's services is governed by that provider's own privacy policy and your agreement with them.

5. Data Storage and Retention

5.1 Customer Content and Activity Data

Customer Content and activity data are stored in Company's Supabase-hosted backend, scoped to your firm's workspace using row-level security, and retained for as long as your account is active. Upon account deletion, Customer Content and activity data are removed from Company's servers within 30 days.

5.2 Account Data

Account credentials and subscription status are retained for as long as your account remains active, and for a reasonable period thereafter to resolve billing disputes or legal obligations.

5.3 Telemetry Data

Telemetry records are retained for 12 months, after which they are automatically deleted. To request early deletion of your telemetry data, email support@ardentime.com and we will process it within 30 days.

5.4 Integration Tokens

OAuth tokens for connected integrations are retained, encrypted, only while the integration is connected. Disconnecting an integration deletes its tokens.

6. Data Security

Arden takes the following measures to protect your data:

  • All data in transit between your devices, Arden's services, and our providers is encrypted using TLS.
  • All cloud-stored data is encrypted at rest; OAuth integration tokens are additionally encrypted at the application layer using AES-256-GCM.
  • Access to Customer Content is restricted by row-level security to authenticated members of your firm. Company personnel do not access Customer Content except as required for technical support at your request or to comply with valid legal process.
  • Arden's API traffic with Anthropic is subject to zero-data-retention terms, and Arden's processing services are configured not to log request or response content.

The security of the devices on which you run the Software remains your responsibility. Arden recommends enabling Full Disk Encryption and strong local authentication on any device running ArdenTrack.

7. Your Privacy Rights

7.1 California Residents (CCPA)

If you are a California resident, you have the following rights under the California Consumer Privacy Act:

  • Right to Know: You may request a description of the categories and specific pieces of personal information we have collected about you.
  • Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
  • Right to Opt Out of Sale: Arden does not sell your personal information.
  • Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.

To submit a CCPA request, contact us at support@ardentime.com. We will respond within 45 days.

7.2 All Users

  • Account deletion: You may request deletion of your Arden account and associated data at any time by contacting support@ardentime.com.
  • Integration control: You may disconnect Microsoft 365, Google Workspace, or Clio at any time from within the Software, which stops collection from that source and deletes its stored tokens.
  • Telemetry opt-out: To opt out of usage telemetry collection, email support@ardentime.com with the subject line "Telemetry Opt-Out" and we will disable collection for your account within 5 business days.

8. Children's Privacy

Arden is a professional productivity tool intended for use by adults. We do not knowingly collect personal information from individuals under the age of 18. If we become aware that we have collected information from a minor, we will delete it promptly. If you believe a minor has created an account, please contact us at support@ardentime.com.

9. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email (at the address associated with your account) or via an in-app notice at least 14 days before the changes take effect. Your continued use of the Software after the effective date of the updated policy constitutes your acceptance of the changes.

10. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy, please contact us:

Arden

Email: support@ardentime.com

Address: 2108 N St Ste N, Sacramento, CA 95816

Response time: We aim to respond to all privacy-related inquiries within 3 business days.

© 2026 Arden. All rights reserved. Privacy · EULA