Privacy policy
Last updated October 5, 2026
In short
Actual Robot (Arloa, PBC, a Delaware public benefit corporation, doing business as Actual Robot) runs actualrobot.com: a workspace for your home robotics lab and a set of hands-on lessons. This policy explains what we keep about you, why, who else handles it, how long we keep it, and what you can do about it.
We use your data to run the service for you. We do not sell it, we do not show ads, and we do not use third-party analytics or advertising trackers.
What we collect
- Your account. Your name, email address and password when you create an account. The password is stored only as a one-way hash, so we cannot read it. If you sign in with GitHub or Google instead, we receive your account ID there, your name, email address and profile picture link, and the sign-in tokens that service issues.
- Sign-in sessions. Each time you sign in we record a session: when it expires, your IP address and your browser's user agent (its name and version).
- Your lab. Your lab profile (name, experience, interests, budget and notes), your equipment (models, part numbers, quantities, costs, links, technical details and setup notes) and your experiment notebook (questions, methods, observations, outcomes, where your evidence is kept, and next steps). Recordings stay on your own storage; we only store where you say they are.
- Suggestions. Changes to your lab suggested by the AI helper or a tool, and whether you applied or rejected each one. We keep them after you decide, as a record of what changed your lab.
- Lesson progress. For each lesson: your checklist, your quiz answer, your notes and form entries (such as where a recording is kept and your test results), and whether you completed it.
- Tailored lessons. Lesson text the helper wrote for your equipment, and the list of equipment it was based on. We keep the latest versions for each lesson and delete older ones.
- The AI helper. Your agreement to the helper's notice (which version, and when), and the helper history described below.
- Billing, if you upgrade. Your Stripe customer ID and your subscription's plan, status and billing period. We never see or store your card details.
- Usage records. One record for each use of the AI (a helper message, a check-in, a tailored lesson): what kind it was, the model, how many tokens and tool calls it took, its cost, and record IDs. We use them for plan limits and to track costs. They contain no messages or lab content.
- The helper's safety log. One record for each action the helper takes and each safety block: record IDs, the time, the tool's name, an outcome code, the model and instructions version, and short redacted summaries of the action's shape. It never contains your messages, the tool's inputs or results, or your lab content. It is how a pause after repeated safety blocks works.
- Product events. When you are signed in, we record a short, fixed list of events in our own database to learn which steps people reach, for example that a check-in started, that suggestions were approved, or that an upgrade link was clicked. Each event holds your account ID, the event's name, the time and at most a few counts or fixed labels (such as a lesson number or where an upgrade prompt appeared). It never holds what you wrote, your lab's contents, the helper's answers, your email address, your IP address or your browser details. If your browser sends Global Privacy Control or Do Not Track, we record none of these events. No third-party analytics or session-recording tool is involved, and we record nothing before you sign in.
- Technical logs. Our server logs each request with a request ID, the kind of page or API called, the result and how long it took, plus error details when something fails. Our logging rules leave out email addresses, passwords, tokens, cookies, request contents, query strings and lab or lesson content. If a page crashes in your browser, it sends us where in our code it failed, not the error message.
When you use "Autofill from a link", our server fetches the product page you gave it and passes it to the helper (see the next section). The website sees a request from our servers, not from your browser. We do not store the page: only the suggestion it produces is kept, like any other suggestion.
How we use it
- To run the service: store your lab, lessons and suggestions, and show them to you on any device you sign in on.
- To sign you in and protect accounts, for example by limiting repeated sign-in attempts from one IP address or for one email address.
- To answer you with the AI helper, only after you agree to its notice.
- To bill Pro subscriptions and apply each plan's limits.
- To understand which steps of the app people reach, from the product events above, and improve them.
- To find and fix problems.
We do not sell your data, use it for advertising, or train AI models on it.
The AI helper
The helper is built on OpenAI. To answer you, what you send and the parts of your lab it reads are sent to OpenAI. The helper only runs after you agree to this notice, and asks again whenever it changes (current version: 2026-10-05).
What is sent to OpenAI
- Your messages to the helper.
- Lab data the helper reads to answer: your display name, lab profile, equipment and its notes, experiments, and pending suggestions.
- Your lesson progress and lesson notes, when the helper reads them for a lesson question.
- The product page you ask equipment autofill to read, and your lab profile and equipment when you tailor a lesson or project plan (Pro).
The helper reads only your own lab. It cannot change your lab: it suggests changes, and nothing is saved until you review and apply it.
Who receives it, and why
OpenAI stores it in the United States (US data residency). The OpenAI Agents API does not offer zero data retention. It is used only to answer you and to suggest changes you can review. Nothing is saved to your lab until you apply it. See OpenAI's Agents API overview for its data residency and retention.
How long it is kept
- OpenAI keeps each conversation until we delete it, and may take some time to finish removing it after that. Your helper conversations stay in your history so you can go back to them: we delete each one 30 days after you last used it, when you delete it, and when you delete your helper history. A check-in is deleted when it is replaced.
- OpenAI's documentation says it also keeps abuse-monitoring logs, which may include messages, for up to 30 days, and does not use this data to train its models.
- OpenAI may keep traces of a conversation (its messages and the lab data the helper read) under its own policy; whether deleting a conversation removes them is not yet confirmed.
These points follow OpenAI's published data controls, read on October 2, 2026. OpenAI's own policy governs what it keeps.
What we keep
We keep no copy of the messages. For your helper history we keep each conversation's title (the start of your first message, or a name you give it) whether you started it in the lab or a lesson, and, when you asked the helper about a lesson, piece of equipment, experiment or project idea, the id of that item (never its content); they are deleted with the conversation. We keep usage records (counts and costs, for billing) and a safety log of what the helper did (ids and outcome codes, never your messages or lab content).
Your choices
- Delete a single conversation from the helper's history, or your whole helper history, at any time (Lab setup, under "Helper & privacy"). We delete your conversations at OpenAI (where the removal may take some time to finish) and here, the helper's pending suggestions, the helper's "why it fits" notes on your build suggestions, and the gap analyses it wrote. A deleted conversation can no longer be continued. If OpenAI cannot be reached, we tell you and keep retrying automatically.
- Withdraw your agreement in the same place. The helper then sends nothing more to OpenAI, and your helper history is deleted.
- Your lab, your lessons and the suggestions you applied are yours and stay until you change them.
Who else handles your data
- Cloudflare hosts the site and runs our server code, database and logs.
- OpenAI runs the AI helper, only after you agree (see above).
- Stripe handles payments, only if you upgrade. To create your customer record we send Stripe your email address and your account ID; you enter your card details on Stripe's own checkout page. Stripe keeps its own records under its own privacy policy.
- Resend sends our emails, such as the link to verify your address or reset your password. We send Resend your email address and the email itself. It keeps its own delivery records under its own privacy policy.
- GitHub or Google, only if you choose to sign in with them.
We share your data with others only as this policy describes, or where the law requires it.
Not live yet
- Ordering parts. Ordering through Actual Robot is switched off. Before it is switched on, this policy will describe what an order shares, and with whom.
- Supplier prices. Parts research is not available yet. Our plan is to fetch supplier prices and stock from the supplier when you look at them, without storing them, and to keep only your own references, such as the supplier, part number, link and quantity.
Cookies and browser storage
- The sign-in cookie (
better-auth.session_token;__Secure-better-auth.session_tokenon the live site) keeps you signed in. Your browser's scripts cannot read it. It lasts 7 days and is renewed while you keep using the site; signing out ends it. - While you sign in with GitHub or Google, a short-lived security cookie (
better-auth.state) protects that step for a few minutes. sidebar_stateremembers whether the lessons sidebar is open, for 7 days.- Your browser also stores three things locally, never as cookies:
- which version of each lesson you chose to view (the example or your tailored one): just that choice, kept until you clear your browser's site data;
- your unsaved edits to the helper's equipment suggestions on the Lab check-in page, which are lab content (such as equipment names, models and notes): kept until you approve or reject the suggestion, and not removed when you sign out, so clear your browser's site data on a shared computer;
- the ID of the helper conversation open in the current tab, used to reopen that conversation: cleared when you close the tab.
We use no advertising or analytics cookies.
How long we keep it
- Your account, lab, lesson progress, suggestions and tailored lessons: for as long as you have an account.
- Sign-in sessions, with their IP address and user agent: deleted when you sign out, and soon after they expire.
- Helper conversations: as described in How long it is kept.
- Usage records (for cost accounting), the helper's safety log (record IDs and outcome codes, to protect the service from abuse) and purchase history: kept after you delete your account, as explained below.
- Product events: deleted 13 months after they are recorded, and all of yours when your account is deleted. Deleting your helper history does not remove them, because they hold no conversation content.
- Your Stripe customer link and subscription records are deleted with your account. Stripe keeps its own records.
- Our logs are kept by Cloudflare's Workers Logs for 3 to 7 days, depending on our Cloudflare plan.
When you delete your account, we delete your account, your lab, your lesson progress and your helper conversations. We keep a few records without your name or email address: usage records (ids, counts and costs), the helper's safety log, and purchase history with your shipping address removed. We keep these for accounting, safety and legal reasons, and we don't currently delete them after a fixed period.
Your choices and rights
- See and export your data. In Lab setup, "Export lab record" downloads your lab profile, equipment, experiment notebook and pending suggestions as a JSON file. Your lesson progress and notes are shown in the lessons.
- Correct it. Edit your lab records and lesson notes at any time.
- The AI helper. Delete conversations or your whole helper history, or withdraw your agreement, at any time (see Your choices).
- Product events. Turn on Global Privacy Control or Do Not Track in your browser and we record none (see What we collect).
- Delete your account. There is no self-service account deletion yet: email us at privacy@arloa.ai from the address on your account, and we delete it for you. We first cancel any Pro subscription. We then delete your account and sign-in sessions, your lab, lesson progress, suggestions and tailored lessons, your agreement to the helper's notice and your helper conversations (here and at OpenAI, where the removal may take some time to finish; if OpenAI cannot be reached, we keep retrying automatically), your product events and your billing links. Usage records, the helper's safety log and purchase history (with your shipping address removed) are not deleted with your account: they hold record IDs, counts, amounts, and the part numbers, product names and links of anything you ordered, not your name, email address or content. See How long we keep it. Stripe keeps its own records. You can also ask us for a copy of data the export does not include.
Depending on where you live, you may have more rights over your data, such as objecting to how we use it or complaining to a data protection authority. Contact us to use them.
Security
Passwords are stored only as hashes, the live site is served over HTTPS, every record is tied to your account and checked on each request, and sign-in attempts are rate limited. No system is perfectly secure, so please use a strong password that you do not use anywhere else.
Children
Actual Robot is not meant for children under 13, and we do not knowingly collect their personal data. If you believe a child under 13 has given us personal data, contact us and we will delete it.
Where your data is processed
Actual Robot is launching in the United States. Cloudflare runs the site on its global network, so a request may be handled in a data center outside your country. OpenAI stores the helper's data in the United States.
Changes to this policy
When this policy changes we update this page and its date. If a change affects what the helper sends to OpenAI, the helper asks for your agreement again before it sends anything more. We will tell you about other important changes in the app before they take effect.
Contact
Arloa, PBC, a Delaware public benefit corporation, doing business as Actual Robot. Privacy questions and requests: privacy@arloa.ai.