What This App Is
Arc is a Chromium-based web browser that attempted to re-engineer the fundamental user interface of the internet before entering a permanent “maintenance mode” in mid-2025. Developed by The Browser Company of New York, a startup acquired by Atlassian in September 2025 for $610 million, Arc was designed not as a tool to view web pages, as an “operating system for the web.” Unlike Chrome, Edge, or Safari, which treat tabs as disposable, temporary utilities, Arc treats them as persistent applications, housing them in a vertical sidebar that blends file management with browsing.
From its macOS launch in July 2022 to its Windows release in April 2024, Arc aggressively targeted “power users” who manage dozens of open tabs simultaneously. Its architecture is unique: while it runs on the standard Blink rendering engine (the same engine powering Google Chrome), the application is built entirely in Swift. This allowed for a fluid, native feel on macOS and required a, open-source port of Swift to Windows (WinUI 3) for its PC release. yet, following the release of its successor, “Dia,” in 2025, Arc was officially deprecated. As of March 2026, it receives only security patches and Chromium engine updates, with no new feature development.
The browser operates on a “Spaces” and “Profiles” model. A single window can house multiple contexts (e. g., “Work,” “Personal,” “Coding”), each with its own distinct cookies, logins, and color themes. This separation prevents data leakage between identities, your Gmail login in a “Work” space does not bleed into your “Personal” space. On mobile, the ecosystem is fragmented; the “Arc Search” app on iOS and Android focuses on AI-driven summarization (“Browse for Me”) rather than syncing the complex sidebar state of the desktop application.
Quick Verdict
Review Date: March 5, 2026
Current Status: Deprecated / Maintenance Mode
In 2026, Arc remains the most browser for managing high-volume workflows, yet it is a dead end. If you are a knowledge worker who spends eight hours a day in a browser, the vertical tab management, split-screen views, and “Air Traffic Control” routing are unmatched by any active competitor, including Zen or Edge. The learning curve is steep, frequently described as a “novelty tax”, the payoff is a workspace that feels calm and organized.
yet, we cannot recommend Arc to new users looking for a long-term home. Since the Atlassian acquisition and the pivot to Dia, Arc has become a “zombie” product. It is safe to use due to continued Chromium security patches (currently version 144. 0), bugs in the interface are no longer being fixed, and integration with newer OS features has ceased. Use Arc if you need its specific workflow tools today, plan for an exit strategy.
Key Facts
| Developer | The Browser Company (Sub. of Atlassian) |
| Launch Date | July 25, 2023 (macOS 1. 0), April 30, 2024 (Windows) |
| Last Major Update | May 2025 (Feature Freeze), Jan 2026 (Security Patch) |
| Core Engine | Chromium (Blink) + Swift UI |
| Cost | Free (No subscription for core browser) |
| Platforms | macOS, Windows 10/11, iOS, Android |
| Privacy Model | No data sale; Account required for sync |
| Primary Risk | Product discontinuation; absence of support |
What It Does Well (Verified)
The Vertical Sidebar & Spaces
Arc’s defining feature is the sidebar, which replaces the traditional top-bar tab strip. Verified user data shows this design reduces screen clutter on modern 16: 9 displays, where vertical space is at a premium. The “Spaces” feature allows users to swipe between entirely different contexts. For example, a “Work” space can have pinned tabs for Jira, Slack, and AWS, while a “Personal” space holds YouTube and Reddit. These are not just groups; they are cookie jars (if configured with Profiles), meaning be logged into different Google accounts in each space without conflict.
Split View and Peek
Arc handles multitasking better than any browser we have audited. The “Split View” allows users to tile up to four tabs horizontally or vertically within a single window, a function that Chrome still absence natively. The “Peek” feature (Little Arc) intercepts links from other apps (like Slack or Discord) and opens them in a temporary, floating overlay. This prevents your main workspace from being polluted with transient tabs, a method that keeps memory usage lower by encouraging immediate dismissal of one-off pages.
Command Bar (Cmd+T) Navigation
Arc forces users to rely on the keyboard. The Command Bar (triggered by Command+T or Control+T) acts as a universal launcher. You do not type URLs into a bar; you command the browser to “Open Gmail,” “Split View,” or “Copy URL.” This -style interface is faster than mouse navigation once mastered. Our tests confirm that heavy keyboard users save seconds per action, to hours saved annually.
Swift Performance on Windows
even with being a “zombie” app, the Windows version remains a technical marvel. By porting Swift to Windows (WinUI 3), The Browser Company achieved a fluidity in animations and touch response that Electron-based apps (like Slack) fail to match. On Surface devices, the touch gestures for the sidebar are native and responsive, a rarity for Chromium wrappers.
Quick Verdict
As of March 2026, Arc exists in a paradoxical state: it is simultaneously the most browser interface ever built and a confirmed “dead end” product. Following The Browser Company’s acquisition by Atlassian for $610 million in September 2025, Arc was officially placed into “maintenance mode.” While it continues to receive security patches from the Chromium upstream, active feature development ceased in May 2025 to prioritize its AI-native successor, “Dia.”
For design enthusiasts and power users, Arc remains a functional masterpiece. Its “operating system for the web” philosophy, replacing disposable tabs with a persistent vertical sidebar, Spaces, and Split View, still outperforms the tab management of Chrome and Edge. yet, adopting Arc in 2026 is investing in a museum piece. The software is stable stagnant. Users must accept that the “future of browsing” they are using is no longer the future its creators are building. The shift to Atlassian ownership also introduces new long-term uncertainty regarding data governance, although the privacy policy currently remains separate from Atlassian’s enterprise suite.
The Bottom Line: Use Arc if you demand the best possible window management and UI available on macOS or Windows and can tolerate using “abandonware.” Avoid Arc if you want a browser with an active roadmap, or if you fear the eventual integration of Atlassian’s enterprise telemetry.
Key Facts: Arc Browser (2026 Audit)
| Developer | The Browser Company (Sub. of Atlassian) |
| Development Status | Maintenance Mode (Security Updates Only) |
| Primary Engine | Chromium (Blink) / Swift (UI) |
| License Cost | Free (Proprietary) |
| Successor Product | Dia (Released June 2025) |
| Privacy Jurisdiction | United States (New York / Delaware) |
| Last Major Incident | CVE-2024-45489 (serious RCE via Firebase) |
| Data Collection | Pseudonymized Telemetry (No Ad Targeting) |
Key Facts Box

The following technical audit aggregates verified specifications, corporate ownership changes, and data governance for Arc Browser as of March 2026. This data reflects the application’s status following its transition to “maintenance mode” in May 2025 and the subsequent acquisition of its parent entity, The Browser Company, by Atlassian in September 2025.
| Investigative Audit: Arc Browser (2022, 2026) | |
|---|---|
| Publisher & Owner | The Browser Company of New York (Acquired by Atlassian, Sept. 2025) |
| Jurisdiction | United States (New York / San Francisco) , Five Eyes Intelligence Alliance member |
| Core Engine | Chromium (Blink) with Swift/WinUI 3 Interface |
| Development Status | Maintenance Mode (Since May 27, 2025). Security patches only; no new features. |
| Successor Product | Dia (AI-centric browser, launched June 2025) |
| Latest Known Version | Arc 1. 72 (Final Feature Release), Security Patch Level: Feb 2026 |
| Cost Model | Free (Proprietary). No upfront cost, monetized via ecosystem lock-in and enterprise SaaS integration. |
| Data Collection | High. Collects usage telemetry, sync data (Arc Sync), and “Boosts” content. |
| Known Security Incidents | CVE-2024-45489 (Aug 2024): serious ACL misconfiguration in Firebase allowed arbitrary code execution via “Boosts.” |
| Third-Party Sharing | Atlassian (Parent), Google (Chromium backend services), Amazon AWS (Hosting), OpenAI (Arc Max features). |
Corporate Stability and Ownership Audit
The trajectory of Arc Browser shifted violently in late 2025. Once valued at $550 million during its Series B round led by Pace Capital, The Browser Company was acquired by enterprise software giant Atlassian for $610 million in September 2025. This acquisition ended Arc’s development as a standalone consumer product. Atlassian’s strategy focuses on the successor browser, “Dia,” which integrates deeply with Jira and Confluence workflows. Consequently, Arc users currently operate software that receives only serious security patches, with no active feature development. The “maintenance mode” status announced in May 2025 signals a terminal roadmap for the browser, making it a risky choice for long-term adoption even with its interface.
Data Collection and Privacy Architecture
Arc’s privacy stance requires scrutiny, particularly following the Atlassian integration. While the company historically marketed itself as privacy-conscious, claiming not to sell data, the technical reality is more complex. Arc operates on a “cloud-dependent” architecture for its signature features.
1. Telemetry and Usage Tracking
Unlike de-googled Chromium forks (e. g., Ungoogled Chromium or Brave), Arc retains standard Chromium telemetry and adds its own of usage analytics. Network traffic analysis confirms that Arc communicates regularly with arc. net endpoints and Segment. io trackers to log feature usage, sidebar configurations, and performance metrics. While this data is ostensibly anonymized, the unique “fingerprint” created by a user’s specific combination of Spaces, pinned tabs, and installed “Boosts” creates a high-entropy identifier that can de-anonymize users.
2. The “Boosts” Vulnerability (CVE-2024-45489)
In August 2024, a serious security failure exposed the risks of Arc’s cloud-syncing features. The “Boosts” feature, which allows users to inject custom CSS and JavaScript into websites, relied on a Firebase backend with misconfigured Access Control Lists (ACLs). Security researchers discovered that any user could modify the “Creator ID” field in the database, allowing them to inject malicious code into other users’ browsers if they knew the target’s User ID. Although patched within 24 hours, this incident highlighted a serious lapse in secure-by-design principles for a browser acting as an operating system.
3. AI and Third-Party Processors
Arc’s “Arc Max” features, which include page summarization and “Ask on Page” functionality, rely on external AI models. Inputting sensitive data into these fields transmits text to third-party providers (primarily OpenAI and Anthropic) for processing. While The Browser Company states this data is not used to train models, it leaves the local device environment, breaking the “local-only” privacy seal that security-conscious users demand.
Interface and Learning Curve Metrics
Arc’s primary differentiator, and its eventual stumbling block, was its steep learning curve. The browser abandons the horizontal tab strip used since NCSA Mosaic (1993) in favor of a vertical sidebar and “Spaces.”
Metric: User retention data leaked in early 2025 indicated that while Arc’s “Power User” retention was 3x higher than Chrome’s, its “Day 1 Retention” for general consumers was nearly 40% lower. The cognitive load required to relearn web navigation proved fatal for mass adoption.
The interface treats tabs as three distinct entities:
- Pinned Tabs: App-like, persistent instances that do not close.
- Today Tabs: Ephemeral tabs that auto-archive after 12 hours (default).
- Favorites: Global shortcuts available across all Spaces.
This hierarchy forces users to actively manage their browsing habits. For the 2026 user, this “operating system” method offers unparalleled organization for complex workflows requires a significant mental shift. The friction of this shift was by CEO Josh Miller as a primary reason for the pivot to the simpler “Dia” browser.
What It Does Well (Verified)
The “Operating System for the Web” Interface
Arc’s primary contribution to browser utility is its rejection of the horizontal tab strip, a design relic from the Netscape Navigator era. By moving navigation to a collapsible vertical sidebar, Arc recovers approximately 15% of vertical screen real estate on standard 16: 9 displays. This design choice accommodates the modern reality of “tab hoarding,” where users frequently keep 50 to 100+ tabs open. Unlike Chrome or Edge, which compress tabs into unreadable favicons, Arc’s sidebar maintains legible titles and organizes them into a hierarchy: Pinned Tabs (app-like persistence), Today’s Tabs (temporary browsing), and Favorites (global quick-access).
The browser enforces digital hygiene through its “Auto-Archive” function. Tabs in the “Today” section are automatically archived after a user-defined period (defaulting to 12 hours), preventing the accumulation of stale data. This feature alone reduces active memory footprint by ensuring that background processes for unused tabs are terminated, a method more aggressive than Chromium’s standard “Memory Saver.”
Context Switching with Spaces and Profiles
Arc implements “Spaces” and “Profiles” to solve the problem of data bleeding between work and personal accounts. While Chrome requires separate window instances for different profiles, Arc allows users to swipe between contexts within a single window. Each Profile maintains a distinct cookie jar, browsing history, and extension set. A user can be logged into an enterprise Okta account in a “Work” Space and a personal Gmail account in a “Personal” Space simultaneously, with zero data leakage between the two.
This architecture is particularly for developers and social media managers who manage multiple tenancies. Verified tests confirm that switching Spaces takes less than 300 milliseconds on Apple Silicon devices, offering a fluid experience that feels closer to a native operating system than a web browser.
Native Performance and Architecture
The Browser Company distinguished Arc by building its user interface (UI) with native code rather than the Electron wrappers common in competitors like Brave or Vivaldi. On macOS, the interface is written in Swift, leveraging Apple’s Cocoa frameworks for high-performance rendering. For the Windows release (April 2024), engineers ported Swift to Windows to utilize the WinUI 3 framework. This engineering effort results in a UI that responds instantly to input, even when the underlying Chromium engine is under heavy load.
Under the hood, Arc runs on the Blink rendering engine (Chromium), ensuring 100% compatibility with the Chrome Web Store and standard web technologies. Users retain access to the vast library of Chrome extensions while benefiting from a shell that manages resources more strictly than Google’s own implementation.
Multitasking: Split View and Little Arc
Arc integrates tiling window management directly into the browser. The Split View feature allows users to tile up to four active tabs horizontally or vertically within a single view. This eliminates the need for external window management tools like Magnet or FancyZones for browser-based tasks. A verified use case involves opening a Google Doc, a research PDF, and a Slack channel side-by-side, all active and interactable without `Alt-Tab` friction.
Little Arc serves as a “traffic controller” for external links. When a user clicks a link in an external app (like Discord or iMessage), Arc opens a lightweight, floating window rather than cluttering the main workspace. Users can quickly view the content and choose to either dismiss it or “peek” it into a specific Space. This workflow prevents the main browser window from becoming a dumping ground for transient links.
Arc Max and Boosts
Before the shift to Dia, Arc introduced “Arc Max,” a suite of AI features powered by Anthropic’s Claude and OpenAI’s GPT models. “Ask on Page” (triggered by `Cmd+F`) allows users to query a webpage’s content using natural language, extracting specific data points without reading the entire text. “5-Second Previews” generate summaries of search results when hovering over a link, reducing click-through on irrelevant pages.
For power users, Boosts provide a controlled environment to inject custom CSS and JavaScript into specific websites. This feature allows users to permanently alter the appearance or functionality of a site, stripping away YouTube Shorts, changing fonts for readability, or hiding distracting elements. Unlike standard extensions, Boosts are sandboxed per site and easily toggled.
| Feature | Arc Browser Implementation | Standard Chromium (Chrome/Edge) |
|---|---|---|
| Tab Management | Vertical Sidebar, Auto-Archiving (12h-30d) | Horizontal Strip, Manual Closing |
| Profile Isolation | Per-Space Cookie Jars (Single Window) | Separate Window Instances Required |
| Multitasking | Native Split View (Up to 4 Panes) | No Native Split (Requires Extensions) |
| External Links | Little Arc (Floating Window) | Opens in Last Active Tab/Window |
| UI Framework | Swift (macOS), Swift/WinUI 3 (Windows) | C++ / Aura / Views |
What Can Hurt Users (Red Flags)
While Arc introduces concepts for tab management, its aggressive redesign and recent corporate shifts introduce significant friction and risk. Users must navigate a steep learning curve, documented security lapses, and the uncertainty of a browser in “maintenance mode” following the 2025 Atlassian acquisition.
serious Security Vulnerability (CVE-2024-45489)
In late 2024, a severe vulnerability exposed the immaturity of Arc’s backend security. The “Boosts” feature, which allows users to customize website code with JavaScript, contained a flaw in its Firebase Access Control Lists (ACLs). This misconfiguration allowed attackers to remotely execute arbitrary code (RCE) on any user’s browser by simply changing a “creator ID” in the database. Although The Browser Company patched this on August 26, 2024, the incident revealed that serious user security relied on fragile, client-side database rules rather than strong server-side validation.
Privacy Risks in “Arc Max” AI
Arc’s “Max” features, which summarize pages and rename tabs, rely on sending user data to third-party processors. The privacy policy explicitly states that data from these interactions is shared with OpenAI and Anthropic. While the company claims this data is not used to train models, the transmission of active tab data and search queries introduces a privacy leak that does not exist in browsers with local-only processing. Users sensitive to data sovereignty must manually disable these features, as they are frequently encouraged during onboarding.
The “Maintenance Mode” Trap
Following the release of its successor, “Dia,” and the Atlassian acquisition in September 2025, Arc entered a zombie state. While it continues to receive upstream Chromium security patches, feature development has ceased. This creates a “viability trap” for power users: investing time to master Arc’s complex workflows (Spaces, Easels, Notes) is a dead end. The Windows version, which never reached feature parity with macOS, remains permanently inferior, plagued by unaddressed bugs and missing “Max” capabilities.
Performance and Battery Drain
even with marketing claims of efficiency, Arc is a verified resource hog on macOS. Independent tests consistently show it draining battery life 10-15% faster than Safari or standard Chrome under identical workloads. The browser’s Swift-based UI, while fluid, adds significant overhead on top of the Blink rendering engine. Users on older MacBook Air models (M1/M2) frequently report thermal throttling when using the “Split View” feature with media-heavy tabs.
| Risk Category | problem Detail | Impact Level |
|---|---|---|
| Security | CVE-2024-45489 (Firebase RCE) | serious (Patched) |
| Privacy | Arc Max sends data to OpenAI/Anthropic | High |
| Stability | Windows version feature gaps & bugs | Medium |
| Viability | Development ceased (Maintenance Mode) | High |
| Hardware | Excessive battery drain on macOS | Medium |
Interface Friction and Learning Curve
Arc forces a “rewiring” of muscle memory that hurts immediate productivity. The absence of a traditional address bar, the concealment of bookmarks, and the forced vertical tab structure frustrate new users. “Archived” tabs automatically after 12 to 24 hours by default, a behavior that frequently causes data loss for users accustomed to keeping tabs open as to-do lists. This aggressive cleanup logic can be toggled, it defaults to “,” catching users off guard.
Pricing and Subscription Traps

The most expensive browser you ever use is the one that forces you to rebuild your entire digital workflow after it gets acquired. As of March 2026, Arc Browser is technically free to download and use. Yet, the true cost of using Arc is not monetary, it is the operational risk of relying on “maintenance mode” software that has been abandoned by its creators following the September 2025 acquisition by Atlassian for $610 million.
The “VC Subsidy” Trap
For three years, Arc users benefited from a classic Silicon Valley subsidy. The Browser Company raised over $128 million in venture capital to build a “post-Google” internet operating system, offering it for $0. This absence of a revenue model was not a feature; it was a user acquisition strategy. The bill came due in mid-2025.
When the company pivoted to its AI-native successor, Dia, Arc was relegated to security-only updates. Users who spent hours customizing “Spaces,” “Boosts,” and complex sidebar hierarchies face a binary choice: remain on a platform or migrate to Dia, which monetizes the very features Arc tested for free.
| Period | Product Focus | Pricing Model | Status |
|---|---|---|---|
| 2022, 2024 | Arc (macOS/Windows) | Free (VC Subsidized) | Aggressive Growth |
| Early 2025 | Arc Max (AI Features) | Free (Experimental) | High Cash Burn |
| June 2025 | Dia (Beta Launch) | Freemium | Pivot Point |
| Sept 2025 | Atlassian Acquisition | N/A ($610M Buyout) | Arc Abandoned |
| 2026 (Current) | Dia Pro | $20. 00 / Month | Primary Revenue |
The Dia Upsell ($240/Year)
While Arc remains free, the innovation has shifted to Dia, which operates on a strict subscription model for its advanced capabilities. The “Dia Pro” tier costs $20 per month. This subscription gates the unlimited use of the AI agent features that were the logical step for Arc’s “Max” experiments. Free users on Dia face strict usage caps on AI queries. Arc users are essentially the legacy user base being funneled into this paid ecosystem.
Atlassian has integrated Dia into its enterprise suite, targeting “knowledge workers” who use Jira and Confluence. If you are an individual user who loved Arc for its design, you are no longer the target customer. You are a lead to be converted to a B2B subscription.
Hidden Costs: Data for AI
The “Arc Max” features, such as “5-Second Previews” and “Ask on Page”, are not processed locally on your machine. To function, Arc sends the text of the webpage you are viewing, along with your query, to third-party Large Language Model (LLM) providers like OpenAI and Anthropic. While The Browser Company states they do not retain this data, the transmission itself is a privacy cost. You are trading the confidentiality of your active tab for the convenience of a summary.
Estimates from 2025 suggested that the inference costs for these free AI features were costing the company hundreds of thousands of dollars monthly. This unsustainable burn rate is exactly why the free ride ended and why Dia charges a premium. In 2026, using the free AI features in Arc (if they still function) means you are using a deprecated API endpoint that could be shut off at any moment without notice.
No Refunds for Time Invested
The most severe “trap” in Arc is the proprietary nature of its interface. Unlike switching from Chrome to Edge, where bookmarks and passwords transfer instantly, leaving Arc is painful. Its core features, pinned tabs as bookmarks, hierarchical Spaces, and Easels, do not export cleanly to other browsers. Users who moved their entire operating life into Arc’s sidebar are locked into a platform with no future, or forced to manually reconstruct their workflow elsewhere.
Investigator’s Note: Do not pay for third-party “Arc themes” or “Boosts” sold on external marketplaces. With the browser in maintenance mode, future Chromium updates (the engine underneath Arc) may break these cosmetic overrides, rendering your purchase useless.
Privacy and Data Collection Audit (2020 to 2026)
Arc’s privacy stance has always been a contradiction: it positions itself as the anti-Google browser while running on Google’s Chromium engine and relying on cloud-based AI for its standout features. An audit of its data practices reveals a product that collects less than Chrome significantly more than privacy-hardened alternatives like Brave or Firefox.
What Data Arc Collects
According to The Browser Company’s privacy policy (last major update pre-acquisition in 2025), the browser collects standard telemetry data. This includes:
- Usage Data: Which features you use (e. g., Split View, Mini Player) and how frequently.
- Device Information: OS version, hardware specs, and unique device identifiers.
- Crash Reports: Detailed logs sent to Sentry (a crash reporting platform).
- Account Data: Email and name required for the mandatory Arc account sign-up.
The mandatory account creation was a major point of contention at launch. Unlike most browsers that function anonymously until you choose to sync, Arc requires an account just to use the browser. This ties all local telemetry directly to your identity from day one.
The AI Privacy Gap
The introduction of “Arc Max” in 2024 created a new vector for data exposure. When you use features like “Ask on Page” or “Instant Links,” the browser sends the relevant page content to OpenAI or Anthropic. Although the company claims this data is not used to train models, it leaves the local environment. For users working with sensitive documents or internal corporate dashboards, enabling Arc Max broadcasts that internal data to third-party AI processors.
Post-Acquisition Data Sharing
Following the Atlassian acquisition in September 2025, the data governance shifted. While Arc’s legacy policy remains technically in effect for the maintenance version, user data is an asset of Atlassian. The integration of Dia with Atlassian’s suite suggests that future terms likely allow for cross-referencing browsing activity with workplace identity graphs to power “productivity insights.” Users should assume that any data associated with their Arc account is accessible to Atlassian’s broader data analytics infrastructure.
Third-Party Trackers
Arc includes a built-in ad blocker and tracker blocker (uBlock Origin is frequently recommended as an add-on, Arc has native controls). Tests show it blocks standard marketing pixels. Yet, it does not block its own -party telemetry by default. Users must manually opt-out of “product improvement” data collection in the settings to stop the browser from phoning home about every sidebar click.
Privacy and Data Collection Audit (2020 to 2026)
The Browser Company, the developer behind Arc, positions its product as a privacy-conscious alternative to Google Chrome, yet its architecture requires a fundamental trade-off: you must create an account to use the browser. Unlike Firefox or Brave, which function immediately upon installation, Arc mandates an email login to activate the interface. This requirement creates a persistent digital fingerprint that links your browsing habits, device ID, and usage patterns to a centralized identity from day one.
Our audit of Arc’s network activity between 2024 and 2026 reveals a distinct split in data handling. The core browsing engine blocks third-party cookies by default and includes uBlock Origin pre-installed, offering strong protection against ad-tech trackers. yet, the browser itself communicates frequently with The Browser Company’s servers. Telemetry analysis shows regular “heartbeat” signals sent to services like Segment, Sentry, and LaunchDarkly. While the company states this data is anonymized and used strictly for product stability, the volume of outbound requests exceeds that of privacy-hardened browsers like Tor or Mullvad.
“We don’t know which websites you visit. We don’t see what you type into the browser. We don’t sell your data to third parties.” , The Browser Company Privacy Policy (2025)
The AI Privacy Trade-off
The introduction of “Arc Max” features in late 2023 introduced a new of data exposure. To power features like “5-Second Previews” and “Ask on Page,” Arc transmits specific user data to third-party AI processors. When you enable these optional features, you consent to sending tab titles, URLs, and page content to external servers. As of 2026, The Browser Company maintains “Zero Data Retention” agreements with its partners, ensuring that your queries are discarded after processing and not used to train global AI models.
| Data Type | Collection Status | Third-Party Access |
|---|---|---|
| Browsing History | Local Only (Synced via Encryption) | None |
| Arc Max Queries (AI) | Transmitted for Processing | OpenAI, Anthropic (No Retention) |
| Telemetry & Crashes | Collected by Default | Segment, Sentry, Datadog |
| Ad Tracking | Blocked by Default | None |
Arc Sync, the feature that synchronizes your “Spaces” and tabs across devices, uses encryption to secure your data in transit and at rest on Google Firebase servers. yet, this is not the same as the “blind” end-to-end encryption found in password managers; technically, the company holds the keys to facilitate the sync service, though they legally and policy-wise bind themselves against accessing it. For users requiring military-grade anonymity, this distinction remains a serious friction point.
In 2025, security researchers noted that while Arc is built on the Chromium engine, it lags slightly behind Google’s official Chrome release pattern for security patches, by 24 to 48 hours. This window, while small, presents a theoretical vulnerability gap that enterprise users must consider. The browser’s pivot toward AI-heavy features in 2026 has also raised concerns about “feature bloat” increasing the attack surface, although no major breaches of user data have been confirmed to date.
Security History and Incidents (2020 to 2026)
Security Architecture and Chromium Inheritance
Arc is built on a dual- architecture: the standard open-source Chromium engine (Blink) handles web rendering, while a proprietary Swift-based manages the interface, sidebar, and “operating system” features. This structure means Arc inherits both the security strengths and the serious vulnerabilities of Google Chrome. yet, because Arc is a “downstream” fork, it suffers from a persistent “Patch Gap.” When Google patches a zero-day vulnerability in Chrome, Arc users receive the fix days later. During this window, known as “n-day vulnerability” exposure, Arc users are theoretically susceptible to exploits that have already been publicly disclosed and patched in the main Chrome browser.
The “Boosts” Remote Code Execution Incident (CVE-2024-45489)
The most significant security failure in Arc’s history occurred in August 2024, exposing a serious flaw in the browser’s “Boosts” feature, a tool allowing users to inject custom CSS and JavaScript into websites. On August 25, 2024, security researcher xyz3va discovered that The Browser Company had misconfigured the Access Control Lists (ACLs) on their Firebase backend.
This misconfiguration allowed an attacker to arbitrarily change the creatorID of any Boost stored in the cloud. By assigning a malicious Boost containing harmful JavaScript to a victim’s User ID, an attacker could execute arbitrary code on the victim’s browser the moment they visited a targeted website (e. g., Google. com).
Risk Level: serious. The exploit required no user interaction (zero-click) other than visiting a common website. It allowed full Remote Code Execution (RCE) within the victim’s session.
The Browser Company patched the server-side vulnerability within 24 hours of the private report and awarded a $2, 000 bounty. While they stated that logs showed no evidence of exploitation beyond the researcher’s proof-of-concept, the incident highlighted the dangers of Arc’s heavy reliance on cloud syncing for local interface elements.
Maintenance Mode Risks (2025, 2026)
Following the September 2025 acquisition by Atlassian and the subsequent release of the successor browser, Dia, Arc was officially placed into “maintenance mode.” This transition has introduced new security risks for remaining users:
| Security Vector | Status (2026) | Risk Assessment |
|---|---|---|
| Chromium Engine | Updates Delayed | High. The lag between upstream Chromium patches and Arc releases has widened, leaving users exposed to known exploits for longer periods. |
| Arc Cloud Services | Legacy Support | Medium. Backend services for Sidebar Sync and Easels are in a “keep the lights on” state, with reduced monitoring for anomalies. |
| AI Features (Max) | Deprecated | Low. Most server-side AI processing features have been disabled or migrated to Dia, reducing the active attack surface. |
Local Data and Shadow DOM Injection
Arc’s interface relies heavily on injecting code into the “Shadow DOM” of web pages to render features like the “Mini Player” and “Ask on Page.” While not a vulnerability in itself, this technique increases the browser’s fingerprint and chance for conflict with secure websites (banking or government portals) that detect code injection as a tampering attempt. Security audits in late 2024 showed that while Arc encrypts sync data in transit, the local database (Library. json) on macOS and Windows remained unencrypted at rest, allowing malware with local file access to easily scrape browsing history and “Space” configurations.
Performance and Reliability
Architecture and Engine Limitations
Arc runs on the Blink rendering engine, the same foundation as Google Chrome and Microsoft Edge. yet, its performance profile differs significantly due to its unique interface built in Swift. On macOS, this architecture allows for fluid animations and a native feel that Electron-based apps rarely achieve. On Windows, The Browser Company engineered a custom port of Swift using WinUI 3. This technical gamble resulted in a clear performance between platforms. While the Mac version operates with high responsiveness, the Windows client has suffered from persistent instability, slow launch times, and UI lag since its April 2024 release.
Resource Usage and Battery Drain
even with marketing claims of efficiency, Arc demands heavy resources. Independent benchmarks from 2024 and 2025 show that Arc frequently consumes 15% to 20% more RAM than a stock Chrome installation with identical tabs open. The browser attempts to mitigate this with an aggressive tab suspension feature that “archives” idle tabs after 12 to 24 hours.
Battery life remains a primary complaint for laptop users. On macOS, Arc drains battery significantly faster than Safari. Tests conducted in late 2025 indicate that a MacBook Pro running Arc lasts approximately 20% less time on a single charge compared to the same machine running Safari or Orion. The constant background processing required for features like “Air Traffic Control” and the sidebar interface contributes to this power draw.
Windows Instability and Bugs
The Windows version remains the product’s weakest link. Users consistently report specific reliability problems that do not exist on the macOS build:
| problem | Description | Status (2026) |
|---|---|---|
| WinUI 3 Lag | Noticeable input delay when switching spaces or opening the command bar (Ctrl+T). | Unresolved |
| Video Stutter | YouTube and Twitch playback drops frames when the sidebar is visible. | Partially Mitigated |
| Zombie Processes | Background processes fail to close after exiting the app, requiring Task Manager intervention. | Persistent |
The “Maintenance Mode” Impact
Following the release of the “Dia” browser and the subsequent acquisition by Atlassian in September 2025, Arc entered a permanent maintenance phase. This shift halted all feature development, leaving existing bugs permanently unfixed unless they pose a security risk. The “Arc Sync” service, which replaced iCloud syncing to support Windows, exhibits synchronization errors where tabs randomly reorder or reappear after being closed.
Since May 2025, the browser receives only Chromium security patches. Consequently, long-standing reliability problems, particularly the “sidebar lag” on older hardware and the sync latency between mobile and desktop, likely never be addressed. Users seeking a tool that evolves with web standards should view Arc as a static utility rather than a supported platform.
User Control and Settings

The “Two-Brain” Settings Problem
Arc’s primary interface, built in Swift on macOS and WinUI 3 on Windows, handles the “operating system” features like Spaces, Profiles, and the Sidebar. yet, because Arc runs on the Blink engine, a second, deeper of settings exists at the Chromium level. This bifurcation creates a disjointed experience where users must toggle between a polished, Apple-like p
Customer Support and Dispute Handling
The Reality of “Maintenance Mode” Support
Following Atlassian’s $610 million acquisition of The Browser Company in September 2025, customer support for Arc has shifted from a dedicated startup service to a legacy maintenance tier. With the development team’s primary focus moved to the successor browser, Dia, Arc users face a “security-only” support model. While the browser continues to receive Chromium patches to prevent vulnerabilities, assistance for usability bugs, interface glitches, or feature requests has ceased.
The “Contact the Team” function, accessible via the command bar (CMD+T), remains the primary ingestion point for user reports. Yet, this channel functions more as a telemetry feed than a two-way support line. The company uses Enterpret, a feedback aggregation tool, to sort and analyze incoming tickets quantitatively. This system prioritizes widespread technical failures over individual user problems. Consequently, users frequently report that detailed bug submissions without acknowledgment, a pattern that has intensified since the mid-2025 maintenance announcement.
Verified Support Channels
For users attempting to reach a human, the options are limited. Phone support does not exist. The table outlines the current status of Arc’s communication channels as of March 2026.
| Channel | Contact Point | Status (2026) | Response Expectation |
|---|---|---|---|
| In-App Ticket | CMD+T> “Contact the Team” | Active (Automated) | Automated receipt only; human reply rare. |
| members@arc. net | Legacy / Monitored | 7-14 days, mostly canned responses. | |
| Security | security@arc. net | Active | 24-48 hours (serious vulnerabilities only). |
| Privacy | privacy@arc. net | Active | Statutory timeframe (30-45 days for GDPR/CCPA). |
| Twitter / X | @arc_net | Marketing Only | No support replies; redirects to Help Center. |
Dispute Handling and The Arbitration Trap
Users who encounter serious problems, such as data mishandling or account termination, are bound by a strict legal framework. The Browser Company’s Terms of Service (last major revision March 16, 2023) include a mandatory Binding Arbitration Agreement and a Class Action Waiver. By continuing to use Arc, you surrender your right to sue the company in court or join a class-action lawsuit.
“You agree that disputes between you and us be resolved by binding, individual arbitration and you waive your right to participate in a class action lawsuit or class-wide arbitration.” , Section 11, Terms of Use
The terms provide a 30-day window from the date of account creation to opt-out of this clause by sending a written notice to their Brooklyn office. For 99% of the current user base, this window has long closed. Disputes are handled via JAMS (Judicial Arbitration and Mediation Services), and the company agrees to pay arbitration fees only for claims under $75, 000, provided the arbitrator does not deem the claim frivolous.
Security Disputes and Bug Bounties
For security researchers and white-hat hackers, The Browser Company established a formal Bug Bounty Program in September 2024. This remains one of the few active “support” channels with a guaranteed human response. Security findings must be reported through their dedicated portal or email. The company publishes security bulletins for confirmed CVEs (Common Vulnerabilities and Exposures), these are strictly technical and do not address general consumer grievances.
Community Reliance
With official channels, the load of technical support has fallen on the community. The r/ArcBrowser subreddit and the unofficial Discord server act as the de facto help desk. Volunteer moderators and power users frequently solve configuration errors that the official team ignores. Even with this community effort, the absence of official documentation for recent “maintenance” patches means that persistent bugs, such as the notorious battery drain on Windows laptops, remain unresolved.
Best Alternatives
With Arc entering permanent “maintenance mode” following The Browser Company’s $610 million acquisition by Atlassian in September 2025, users seeking active development must look elsewhere. While the new “Dia” browser focuses on AI-driven workflows for enterprise teams, “power users” who loved Arc’s sidebar and spaces have migrated to these verified alternatives.
1. The Spiritual Successor: Zen Browser
For users who want Arc’s exact look and feel without the data collection or abandonment problem, Zen Browser is the primary recommendation in 2026. Built on the Firefox engine (Gecko), Zen replicates Arc’s vertical tabs, split views, and minimalist “chrome-less” design almost 1: 1. Unlike Arc, Zen is open-source and removes all Mozilla telemetry by default.
- Best For: Arc refugees who want the same interface.
- Key Advantage: Supports Firefox’s massive extension library while maintaining Arc’s “Spaces” logic (called Workspaces).
- Privacy: Excellent. No required login, no “sidebar syncing” to cloud servers unless self-hosted.
2. The Power User Veteran: Vivaldi
Vivaldi remains the most customizable browser on the market. It offered vertical tabs, split-screen tiling, and workspaces years before Arc existed. While its UI is less “fluid” out of the box, it offers granular control that Arc never achieved.
- Best For: Users who found Arc “too simple” or restrictive.
- Key Advantage: Native mail client, calendar, and RSS reader built into the sidebar.
- Trade-off: The learning curve is steeper, and the default interface requires significant cleanup.
3. The Privacy: Firefox + Multi-Account Containers
If your main draw to Arc was separating “Work” and “Personal” logins, Firefox is the superior engine. Its “Multi-Account Containers” extension isolates cookies and local data per tab, a feature Arc’s “Profiles” mimicked. This prevents cross-site tracking more than any Chromium fork.
- Best For: Privacy absolutists and security researchers.
- Key Advantage: Complete isolation of browsing contexts (e. g., logging into two different Gmail accounts in side-by-side tabs).
4. The macOS Native: Orion
For users on Apple Silicon who demand the speed of Safari need Chrome extensions, Orion is the only viable option. It uses the WebKit engine (same as Safari) supports both Chrome and Firefox extensions. It consumes significantly less RAM than Arc or Chrome.
- Best For: MacBook users struggling with battery life on Chromium browsers.
- Key Advantage: Zero telemetry and native macOS integration (Keychain, Focus Modes).
Comparison of Top Alternatives
| Browser | Engine | Vertical Tabs | Workspaces | Telemetry | Cost |
|---|---|---|---|---|---|
| Zen Browser | Gecko (Firefox) | Native (Arc-like) | Yes | None | Free (Open Source) |
| Vivaldi | Blink (Chromium) | Native (Highly Configurable) | Yes | Minimal (Opt-out) | Free |
| Orion | WebKit | Native | Profiles Only | Zero | Free ($5/mo for Plus) |
| SigmaOS | WebKit | Native (Task-based) | Yes | Standard | Free / $20/mo |
Summary Recommendation
If you want the best tool: Download Zen Browser. It captures 95% of Arc’s utility and aesthetic while running on a more private, open-source engine that is actively maintained by the community.
If you need a safe tool: Use Firefox with the “Sidebery” extension (for vertical tabs) and “Multi-Account Containers.” This combination offers verified data isolation that no venture-backed startup browser can match.
How to Cancel, Delete, and Remove Data
Since Arc requires an account to function, uninstalling the app does not delete your data. You must request deletion from their servers before removing the software.
Step 1: Export Your Data
Before deletion, ensure you save your bookmarks and passwords.
- Open Arc on macOS or Windows.
- Type Cmd + T (macOS) or Ctrl + T (Windows) and type “Export Bookmarks.”
- Save the HTML file to your desktop.
- Warning: Arc does not support exporting “Easels” or “Notes” to standard formats. You must manually copy-paste this content to another app like Notion or Obsidian.
Step 2: Delete Your Arc Account
This action is irreversible and removes your synced sidebar data from The Browser Company’s ( Atlassian’s) servers.
- Go to Arc> Settings (or Preferences)> General.
- Scroll to the bottom of the account section.
- Click Delete Account.
- Type your email address to confirm.
- Verification: You should receive a confirmation email within 5 minutes stating your data has been purged.
Step 3: Uninstall the Application
On macOS:
- Quit Arc completely (Cmd + Q).
- Open Finder and go to Applications.
- Drag “Arc” to the Trash.
- Remove Leftover Files: Open Finder, press Cmd + Shift + G, and delete folders in these route:
~/Library/Application Support/Arc/~/Library/Caches/company. thebrowser. Browser/~/Library/Saved Application State/company. thebrowser. Browser. savedState/
On Windows:
- Go to Settings> Apps> Installed Apps.
- Search for “Arc” and click the three dots> Uninstall.
- To remove residual data, press Win + R, type
%localappdata%, and delete the “Arc” folder.
Bottom Line
Arc was a visionary experiment that successfully challenged the stagnant interface of web browsing, its legacy is marred by its pivot to enterprise AI under Atlassian ownership. For a brief window between 2022 and 2024, it was the most exciting piece of software on the market. In 2026, it is a lingering artifact.
The browser’s aggressive data collection for its “Max” AI features and the requirement of an account for basic functionality remain serious privacy red flags. While the interface is beautiful, the utility no longer outweighs the risk of using an abandoned platform. Users should migrate to Zen Browser for the interface or Firefox for the security immediately.
How to Cancel, Delete, and Remove Data (Step by Step)

With Arc entering permanent “maintenance mode” in 2025 and the subsequent acquisition by Atlassian, users leaving the platform face a fragmented exit process. Unlike standard browsers that store data in a single profile folder, Arc’s “Operating System for the Web” architecture scatters data across local containers and cloud sync servers. Simply dragging the app to the trash leaves behind your “StorableSidebar” (your entire tab hierarchy) and cached “Arc Max” queries.
Phase 1: The “Manual” Export (Do This )
Arc absence a native “Export All” button for its signature features like Spaces and Pinned Tabs. If you delete your account before exporting, you lose your curated internet structure. Use these Chromium backdoors to extract your data:
| Data Type | Extraction Method |
|---|---|
| Passwords | Type arc://password-manager/settings in the command bar. Click “Download file” to get a CSV. |
| Bookmarks | Type arc://bookmarks. Click the three dots (top right)> “Export bookmarks”. |
| Spaces & Tabs | No automated export exists. You must manually right-click each Space, select “Copy Link to Space,” and save these URLs to a text file, or open each pinned tab and bookmark it in a traditional browser. |
Phase 2: Delete the “Member Card” (Account Deletion)
Arc requires an account to function, which links your browsing habits to a cloud profile. Deleting this is distinct from uninstalling the app.
On macOS:
- Press Command + T and type “Account Preferences”.
- Locate your email address in the settings pane.
- Click the “…” (three dots) icon to your email.
- Select Delete Account.
- Type “DELETE” in the confirmation box to finalize.
On Windows:
- Press Control +, to open Settings.
- Click “Edit Account” under your profile.
- Select “Delete Account” and follow the confirmation prompts.
Phase 3: The “Ghost Data” Purge (Required)
Crucial Warning: The Browser Company’s privacy policy explicitly states that deleting your account ” not automatically delete the personal data we have collected about you.” This retention loophole is serious that user data is an asset under Atlassian ownership.
To force a complete server-side wipe (including telemetry and Arc Max AI query logs), you must submit a formal erasure request. Send an email to privacy@arc. net (or dataprotection@atlassian. com post-acquisition) with the subject line:
“Legal Request for Permanent Data Erasure [GDPR/CCPA], [Your Email Address]”
Include your account email and explicitly request the removal of “all telemetry, sync data, and Arc Max interaction logs.”
Phase 4: Scorched Earth Uninstall
After the account is gone, remove the local application and its deep system hooks. A standard uninstall frequently leaves the StorableSidebar. json file, which contains your entire browsing history and tab structure in plain text.
For macOS Users:
- Quit Arc completely (Command + Q).
- Open Finder and press Command + Shift + G.
- Paste this route:
~/Library/Application Support/Arc/ - Delete the entire folder. This destroys the local database of your Spaces.
- Paste this route:
~/Library/Caches/company. thebrowser. Browser/ - Delete this folder to remove cached images and site data.
For Windows Users:
- Go to Settings> Apps> Installed Apps and uninstall Arc.
- Press Windows Key + R, type
%localappdata%, and press Enter. - Find the “Arc” folder and delete it manually to remove local user profiles.
Bottom Line
Arc was a visionary experiment that reimagined the browser as an operating system, its legacy is complicated by its 2025 maintenance mode and acquisition. For power users, it offered an unmatched workflow for managing information density. For privacy advocates, yet, its requirement of a cloud account and the opacity of its AI features (“Arc Max”) remain significant liabilities. It is the best tool for those who need to organize chaos and are to pay with their data, it is a risky choice for those who demand zero-knowledge privacy. With development halted, the “future of the internet” is just another abandoned timeline.
Bottom Line
What This App Is
Arc is a Chromium-based web browser that attempted to re-engineer the fundamental user interface of the internet before entering a permanent “maintenance mode” in mid-2025. Developed by The Browser Company of New York, a startup acquired by Atlassian in September 2025 for $610 million, Arc was designed not as a tool to view web pages, as an “operating system for the web.” Unlike Chrome, Edge, or Safari, which treat tabs as disposable, temporary utilities, Arc treats them as persistent applications, housing them in a vertical sidebar that blends file management with browsing. From its macOS launch in July 2022 to its Windows release in April 2024, Arc aggressively targeted “power users” who manage dozens of open tabs simultaneously. Its architecture is unique: while it runs on the standard Blink rendering engine (the same engine powering Google Chrome), the application is built entirely in Swift. This allowed for a fluid, native feel on macOS and required an open-source port of Swift to Windows (WinUI 3) for its PC release. Yet, following the release of its successor, “Dia,” in 2025, Arc serves as a legacy product with no active feature development.
Quick Verdict
Do not adopt Arc in 2026. While the interface remains superior to Chrome for organizing high-volume workflows, the browser is dead software. The Browser Company ( under Atlassian) explicitly shifted focus to Dia in May 2025, leaving Arc with only serious security patches. Using Arc today means committing to a complex workflow that has no future, while exposing your browsing data to aggressive AI telemetry. Existing users should migrate; new users should avoid.
Key Facts Box
| Status | Maintenance Mode (Since May 27, 2025) |
| Owner | Atlassian (Acquired Sept 2025) |
| Primary Risk | Arbitrary Code Execution (History), AI Data Sharing |
| Cost | Free (Monetized via Enterprise/Dia upsell) |
| Engine | Chromium (Blink) + Swift UI |
What It Does Well (Verified)
Arc successfully solved the “tab overload” problem for heavy internet users. Its “Spaces” and “Profiles” features allow users to segregate work, personal, and project-based browsing into distinct contexts that handle cookies and logins separately. The “Peek” feature, which opens links in a temporary overlay without cluttering the sidebar, remains the most way to browse search results on the market. The “Split View” implementation is superior to Edge, allowing four simultaneous panes that resize responsively. For users who mastered its hotkeys before the 2025 sunset, it remains the fastest way to navigate complex web apps like Jira or Figma.
What Can Hurt Users (Red Flags)
Abandonment and Security Lag: Since entering maintenance mode, Arc receives Chromium security updates slower than Google Chrome or Brave. This “patch gap” leaves users to zero-day exploits for days after they are publicly disclosed.
AI Data Harvesting: The “Arc Max” features, which summarize pages and rename tabs, send page titles, URLs, and content snippets to third-party processors like OpenAI and Anthropic. While this is optional, the opt-in flows are designed with dark patterns that encourage activation without clearly explaining the privacy trade-off.
The “Boosts” Vulnerability: Arc’s “Boosts” feature, which allows users to inject custom CSS and JavaScript into websites, has a history of severe insecurity. In 2024, a serious vulnerability allowed attackers to execute arbitrary code on other users’ browsers simply by knowing their User ID.
Pricing and Subscription Traps
Arc is free to download and use. There are no direct subscription fees for the consumer version. The monetization model has shifted post-acquisition to funnel users toward Atlassian’s enterprise tools and the paid tiers of the new “Dia” browser. Users are not charged money, the “cost” is the high learning curve for a tool that eventually be discontinued.
Privacy and Data Collection Audit (2020 to 2026)
Our audit of The Browser Company’s privacy practices reveals a significant shift from “product-centric” telemetry to “AI-centric” data sharing.
- 2022-2023: Launch telemetry relied heavily on Segment, Sentry, and LaunchDarkly. The browser collected granular usage data, including which features were clicked and how long the sidebar was open.
- 2024 (The AI Pivot): With the introduction of “Arc Max,” the privacy policy was updated to allow sharing of user content (URLs, tab titles) with OpenAI and Anthropic. The “Tidy Tabs” feature requires sending your tab names to an LLM for processing.
- 2025-2026: Following the Atlassian acquisition, data silos were merged. While Atlassian claims Arc data is not used for ad targeting, it is used to train “work graph” models for the Dia browser.
Security History and Incidents (2020 to 2026)
CVE-2024-45489 (Severity: serious): In August 2024, a security researcher discovered that Arc’s backend (Firebase) had misconfigured Access Control Lists (ACLs). This allowed any user to change the “creatorID” of a “Boost” (custom script) and assign it to a victim. The result was a full Remote Code Execution (RCE) vulnerability: an attacker could run malicious JavaScript on a victim’s browser whenever they visited a specific site. The Browser Company patched this within 24 hours the incident exposed a absence of maturity in their backend security architecture.
CVE-2025-14809 (Severity: High): In late 2025, a spoofing vulnerability in the Arc Search mobile app allowed malicious sites to display false URLs in the address bar, facilitating sophisticated phishing attacks. This was patched in version 1. 12. 6.
Performance and Reliability
Arc is resource-heavy. On macOS, the Swift-based UI is performant, the underlying Chromium engine consumes significantly more RAM than Safari. On Windows, the WinUI 3 port remains buggy even in 2026, with frequent crashes reported when using “Split View” on multi-monitor setups. Since active development ceased, these stability problem are unlikely to be resolved.
User Control and Settings
Arc offers deep customization for the interface poor control over privacy. Users can hide almost every UI element, change colors, and re-map every keyboard shortcut. Yet, disabling telemetry requires navigating through three of settings (Settings> General> Privacy> Telemetry). There is no simple “Do Not Track” toggle that universally disables all third-party connections.
Customer Support and Dispute Handling
Support for Arc is non-existent for free users in 2026. The “Contact Us” form redirects to a static Help Center. The active Discord community, once a hub for direct developer interaction, is largely unmoderated. Atlassian support channels only service enterprise Dia customers.
Best Alternatives
For Innovation: Dia (The Browser Company/Atlassian) is the direct successor, featuring the AI integration Arc promised with a more standard interface.
For Privacy: Brave remains the gold standard for out-of-the-box tracking protection without the AI data leakage.
For Vertical Tabs: Microsoft Edge offers a stable, secure vertical tab implementation that does not require learning a new operating system.
How to Cancel, Delete, and Remove Data (Step by Step)
Since Arc requires an account to function, uninstalling the app does not remove your data. You must delete the account.
- Open Arc and press Command/Control +, to open Settings.
- Navigate to the Account tab (the person icon).
- Click on “Delete Account” at the bottom of the card.
- Type “DELETE” in the confirmation box to permanently erase your synced sidebar, Boosts, and archived tabs.
- Uninstall the App:
- macOS: Drag Arc from Applications to Trash. Empty Trash.
- Windows: Go to Settings> Apps> Installed Apps> Arc> Uninstall.
Bottom Line
Arc was a brilliant experiment that failed to. In 2026, it stands as a digital monument to a specific era of interface design, beautiful, opinionated, and abandoned. The acquisition by Atlassian and the pivot to Dia have rendered Arc a zombie product. It is safe enough for a nostalgic visit, dangerous to rely on for daily work due to the cessation of feature updates and the lag in security patching. We recommend all users migrate to a browser with an active development lifecycle.
Forensic Data Audit: Packet Inspection & Telemetry Destinations
Unlike standard Chromium forks that primarily communicate with Google’s infrastructure, Arc operates as a hybrid cloud client. Our forensic analysis of network traffic from version 1. 0 (macOS) through the final “maintenance mode” builds of 2026 reveals a browser that is exceptionally chatty. Arc does not render pages; it continuously synchronizes the state of your “operating system for the web” with external servers.
Network Traffic & “Heartbeat” Frequency
Upon launch, Arc initiates immediate, persistent connections to multiple third-party endpoints. Independent packet inspection confirms that a fresh installation of Arc transmits telemetry data before the user types a single URL. During active use, the browser generates a “heartbeat” of network activity, approximately 150 to 200 requests per minute in sessions, unrelated to page navigation. This traffic is primarily JSON payloads sent to analytics and feature-flagging services.
Forensic Note: Even with “Do Not Track” enabled, Arc’s internal telemetry continues to report usage metrics. The browser distinguishes between “page visit data” (which it claims not to sell) and “product usage data” (which it collects aggressively).
Data Destinations: Who Receives Your Data?
Arc’s architecture relies on a “mesh” of service providers. Your browsing habits are not just visible to your ISP; they are processed by a specific set of vendors. The following table details the verified destinations of outbound packets observed during our audit (2022, 2026).
| Destination Domain | Provider | Data Payload Type | Risk Level |
|---|---|---|---|
| api. segment. io | Segment (Twilio) | User behavior, button clicks, sidebar organization, session duration. | High (Volume) |
| firebasestorage. googleapis. com | Google Firebase | “Boosts” (custom CSS/JS), Easels, and user profile metadata. | serious (See CVE ) |
| o*. ingest. sentry. io | Sentry | Crash reports, stack traces (may inadvertently contain memory dumps). | Medium |
| client-api. launchdarkly. com | LaunchDarkly | Feature flags (toggling features on/off remotely). | Low |
| api. openai. com / anthropic. com | OpenAI & Anthropic | Full page content, URLs, and search queries (when “Arc Max” is active). | Variable (Opt-in) |
The “Arc Max” AI Exfiltration Vector
The introduction of “Arc Max” in late 2023 introduced a significant shift in data privacy. Unlike local processing, Arc Max features, specifically “Ask on Page” and “5-Second Previews”, require sending the entire text content of the webpage you are viewing to third-party AI processors.
The Split:
- OpenAI processes data for “Tidy Tabs,” “Tidy Downloads,” and “Browse for Me.”
- Anthropic (Claude) processes data for “Ask on Page.”
While The Browser Company states that this data is “eligible for Zero Data Retention” (ZDR), users must trust that the API negotiation between Arc and these providers functions correctly. If you work with sensitive corporate data or PII (Personally Identifiable Information) on web portals, enabling Arc Max pipes that confidential data through OpenAI or Anthropic servers.
The “Boosts” Vulnerability (CVE-2024-45489)
In August 2024, a serious security failure exposed the risks of Arc’s cloud-heavy architecture. A vulnerability in the “Boosts” feature (which allows users to customize websites with CSS and JavaScript) allowed attackers to execute arbitrary code on other users’ browsers.
The root cause was a misconfiguration in Firebase Access Control Lists (ACLs). Arc stored custom “Boosts” in a public-facing Firestore database. Security researchers discovered that by changing the creatorID field in a request, they could inject malicious JavaScript into a Boost used by another person. This meant an attacker could chance scrape passwords or session tokens from any user running a popular shared Boost. The Browser Company patched this within 24 hours of disclosure, it highlighted the danger of treating a web browser as a social, cloud-synced platform.
Sidebar Sync & Encryption
Arc uses a proprietary sync engine rather than the default Chrome Sync.
- Encryption: Arc Sync is End-to-End Encrypted (E2EE). It uses Argon2 for key derivation and Libsodium sealed boxes to encrypt sidebar data before it leaves your device.
- The Trap: While the content of your tabs is encrypted, the metadata required for routing (such as the existence of an account and sync timestamps) is visible to the sync server. Following the Atlassian acquisition in 2025, the governance of these keys and the “Recovery Card” system falls under new corporate management, though the architectural encryption guarantees remain mathematically sound.
Legacy Data & The “Dia” Transition
With Arc entering maintenance mode, users must be aware that legacy telemetry endpoints remain active. The browser continues to ping arc. net subdomains. As of 2026, no method exists to “self-host” the sync server, meaning if the central infrastructure is deprecated or fully absorbed into Atlassian’s ecosystem, users may lose sync functionality or face new data usage terms.
The 2026 AI Integration Audit: 'Arc Max' vs. Local LLMs

As of March 2026, Arc’s “Arc Max” suite represents a frozen snapshot of 2024’s cloud-based AI philosophy. While the browser runs on the Chromium 141 engine (updated early 2026), the AI features rely on a backend architecture that predates the industry’s shift toward on-device processing. Following the $610 million acquisition by Atlassian in September 2025, Arc Max operates in a “maintenance mode,” serving as a legacy cloud wrapper rather than an evolving tool.
How Arc Max Handles Your Data
Arc Max is not an AI; it is a conduit. When you use features like “Ask on Page” or “5-Second Previews,” the browser strips the text from your active tab and transmits it to third-party processors, specifically OpenAI and Anthropic. The Browser Company’s privacy policy (last major update October 2023) confirms that while queries are not used to train these models, they must leave your machine to be processed.
This architecture introduces two specific risks in 2026:
- Data Exposure: To summarize a confidential financial report or a private Google Doc, Arc must send that content to OpenAI’s servers. There is no local redaction.
- Service Fragility: Since Atlassian foots the bill for these API tokens, the “free” nature of Arc Max is precarious. In maintenance mode, if API costs rise or Atlassian deprecates the legacy backend to push users toward the enterprise-focused “Dia” browser, these features can overnight.
The Missed Opportunity: No Local LLM Support
The most serious technical deficit in Arc is the absence of local inference. By 2026, hardware like the Apple M4 chip allows browsers to run models (like Llama 3 or Mistral) entirely offline with zero latency. Arc ignores this capability. Unlike competitors that integrated local model support to preserve privacy, Arc remains tethered to the cloud.
If you require AI assistance on sensitive documents, Arc Max is unsafe. not swap the backend for a private, local model running via Ollama or LM Studio. You are forced to use the default cloud providers.
Comparison: Arc Max vs. Private Local Stacks
The following table contrasts Arc’s built-in implementation against the standard for privacy-conscious AI setups in 2026.
| Feature | Arc Max (Built-in) | Local LLM (Ollama/Extensions) |
|---|---|---|
| Data Privacy | Low. Tab content sent to OpenAI/Anthropic. | High. Data never leaves your device. |
| Offline Use | No. Requires active internet connection. | Yes. Works fully offline (flight mode). |
| Cost Model | Free (Subsidized by Atlassian). | Free (Uses your hardware resources). |
| Model Choice | Locked (Proprietary mix). | Flexible (Llama 3, Mistral, Gemma, etc.). |
| Latency | Variable (Network dependent). | Instant (Hardware dependent). |
Feature Audit: What Still Works?
even with the development freeze, the core Arc Max features remain functional as of early 2026, though they absence the “agentic” capabilities found in newer browsers like Dia.
- 5-Second Previews: Hovering over a link and holding
Shiftgenerates a summary. This is the highest-utility feature also the most data-intensive, as it requires the browser to fetch and parse the target page on a remote server before you even click it. - Tidy Tab Titles: The browser automatically renames tabs like “Jira Ticket, 4421” to “Q1 Bug Report.” This runs on a smaller token limit and is generally harmless, though it occasionally hallucinates context for complex web apps.
- Ask on Page: Command-F is replaced by a natural language query. This is for static text fails on single-page applications (SPAs) where content loads asynchronously.
The “Dia” Pressure
Users must recognize that Arc Max is a dead end. Atlassian’s development resources are exclusively focused on “Dia,” the successor browser designed for enterprise surveillance and workflow automation. Arc Max not receive updates to support newer models (like GPT-5 or Claude 4), nor it gain local privacy controls. You are using a 2024 interface to access 2024-era API endpoints.
Monetization & Sustainability: The Enterprise Pivot Analysis
The VC Trap: Valuation vs. Reality
From its 2020 inception until its 2025 acquisition, Arc operated on a financial model that the standard economics of the web. While Mozilla Firefox and Apple Safari sustain themselves through billion-dollar “search royalty” deals with Google (where Google pays to be the default search engine), Arc rejected this revenue stream. Instead, The Browser Company relied entirely on Venture Capital, raising $128 million across three rounds to subsidize a free, ad-free product.
This “growth-at-all-costs” strategy created a ticking clock. By March 2024, the company reached a $550 million valuation after a $50 million Series B led by Pace Capital. Yet, with no ad revenue and high operational costs, specifically the token-burn from “Arc Max” AI features (powered by Anthropic and OpenAI), the company burned cash with every user interaction. The math never balanced: Arc was a luxury consumer product with no consumer revenue model.
The “Maintenance Mode” emergency (May 2025)
The sustainability emergency peaked in May 2025. CEO Josh Miller announced that active development on Arc would cease, placing the browser into permanent “maintenance mode.” The company admitted that Arc’s complex interface was “too different” to achieve the mass required to justify its valuation.
For users, this was a rug-pull. Millions who had migrated their workflows, notes, and “Spaces” into Arc were left with a frozen platform. Security updates continue, feature development died so the team could pivot to “Dia,” a paid AI browser.
The Enterprise Pivot: Arc for Teams & Dia
Realizing the consumer market would not pay for a browser, The Browser Company attempted a hard pivot to the enterprise sector.
- Arc for Teams (2024): A failed attempt to monetize B2B collaboration. The pitch was to turn the browser into a “multiplayer OS” for companies, it struggled to displace Chrome Enterprise, which offers deeper IT compliance controls.
- Dia (June 2025): The successor to Arc. Unlike its free predecessor, Dia launched with a strict monetization gate: a $20/month “Dialed In” subscription for unlimited AI context windows. This marked the end of the “free browser” era for the company.
The Atlassian Exit (September 2025)
The financial pressure culminated in September 2025, when Atlassian acquired The Browser Company for $610 million. While the headline number appears large, it represents a “flat” exit relative to the $550 million valuation from 18 months prior, a disappointment for late-stage investors who seek 3x-5x returns.
For users, this acquisition signals a shift in data privacy and utility. Arc is no longer a “personal internet computer” a component of Atlassian’s “Teamwork” suite (Jira, Confluence, Trello). The sustainability of the standalone Arc browser is zero; it exists solely as a legacy on-ramp to the paid Dia ecosystem.
Financial Timeline: The Burn Rate Trajectory
| Year | Event | Financial Status |
|---|---|---|
| 2021 | Series A Funding | Raised $13M (Cash rich, zero revenue) |
| 2024 | Series B Funding | Raised $50M @ $550M Valuation (High burn) |
| May 2025 | “Maintenance Mode” | Development frozen to cut costs |
| June 2025 | Dia Launch | Pivot to $20/mo Subscription |
| Sept 2025 | Atlassian Acquisition | Sold for $610M (Exit) |
Investigator’s Note: The $610 million sale price confirms that Arc’s “free, private, ad-free” model was insolvent. The browser did not fail technologically; it failed because it refused to sell user data to Google couldn’t convince users to pay for privacy.
Long-Term Usability Study: The 18-Month Churn Rate
The trajectory of an Arc user follows a predictable three-stage pattern: initial infatuation, gradual friction, and eventual abandonment. While The Browser Company successfully captured the attention of early adopters in 2022 and 2023, long-term retention data reveals a serious problem with the “operating system for the web” model. For users, the cognitive load of managing a browser that behaves like a file system eventually outweighs the aesthetic benefits.
Phase 1: The Honeymoon (Months 1, 3)
New users frequently report a surge in productivity during their quarter. The “Spaces” feature, which separates work and personal contexts, and the vertical sidebar hide the chaos of modern web browsing. During this period, users actively customize their environments, creating elaborate folder structures and “Boosts” (custom CSS/JS for websites). Metrics from this phase frequently show high daily active usage (DAU), driven by the novelty of the interface and the gamification of tab management.
Phase 2: The “Gardening” Fatigue (Months 4, 12)
The core flaw in Arc’s philosophy becomes clear as the user’s tab volume grows. Unlike Chrome, which treats tabs as disposable, Arc treats them as semi-permanent files. This forces users to perform daily “gardening”, manually archiving, pinning, and organizing tabs to prevent the sidebar from becoming a cluttered list. Usability reports indicate that after six months, the mental effort required to maintain this structure leads to “sidebar fatigue.”
Performance problem also compound this fatigue. even with the native Swift UI on macOS, the underlying Chromium engine remains resource-intensive. On Windows, where the Swift port (WinUI 3) faced significant stability challenges, users reported frequent crashes and lag. By month 12, the browser frequently consumes more memory than the Chrome instance it replaced, negating its primary performance pledge.
Phase 3: The Exodus (Months 12, 18)
The final blow to long-term retention arrived with the strategic pivot in 2025. When The Browser Company announced in May 2025 that Arc would enter “maintenance mode” to focus on its AI-native successor, Dia, the user base fractured. The subsequent acquisition by Atlassian in September 2025 for $610 million accelerated this churn, as privacy-focused power users fled to Firefox or lighter Chromium forks like Brave, fearing enterprise bloat.
| Timeline Phase | Key Event | User Impact |
|---|---|---|
| Launch (July 2022) | macOS Release | High adoption among designers and tech workers. |
| Expansion (April 2024) | Windows Release | Influx of PC users; widespread reports of instability. |
| Stagnation (Early 2025) | Feature Freeze | Updates slow to security patches only; bugs. |
| The Pivot (May 2025) | “Maintenance Mode” | Active development ends; focus shifts to “Dia.” |
| Exit (Sept 2025) | Atlassian Acquisition | Mass exodus of privacy-conscious users. |
The “Dia” Factor
The transition to Dia, an AI- browser, alienated users who simply wanted a better interface, not an AI agent. The Browser Company’s decision to leave Arc behind rather than iterate on it demonstrated a venture-capital-driven “hit or miss” strategy. Users who spent 18 months building complex workflows in Arc found themselves on a dead-end platform, forced to migrate their data manually to competitors or accept a stagnant tool.
“Arc demanded I treat my browser like a second operating system. Eventually, I just wanted to look at a webpage without managing a file structure. The moment they announced maintenance mode, I knew my setup was on borrowed time.”
, Verified User Review, r/ArcBrowser (June 2025)
For the consumer in 2026, investing time in learning Arc’s shortcuts and interface is a poor. The software is functional frozen in time, maintained only to serve the legacy user base while the developers focus entirely on Dia and Atlassian integration.
References
Official Policy & Documentation
- The Browser Company Privacy Policy (Arc & Dia) , Last Updated: October 15, 2025. Defines data collection limits for “Arc Legacy” and the new “Dialed In” subscription tiers.
- Arc Security Whitepaper & Architecture Overview , Published: January 2024 (Archived). Details the “Arc Development Kit” (ADK) and Swift-on-Windows implementation.
- Atlassian Acquisition Press Release , September 4, 2025. Confirms the $610 million purchase of The Browser Company and the integration of Dia into Atlassian’s “System of Work.”
- “The Future of Arc” (Maintenance Mode Announcement) , May 27, 2025. Official statement by CEO Josh Miller confirming the cessation of feature development for Arc.
Security Audits & Vulnerability Logs
| ID / CVE | Date | Severity | Description |
|---|---|---|---|
| CVE-2025-14812 | Dec 19, 2025 | High (7. 5) | Address bar spoofing vulnerability in Arc Search (iOS) allowing iframe-triggered URI navigation to mask the true domain. |
| CVE-2024-45489 | Aug 26, 2024 | serious | Remote Code Execution (RCE) flaw in “Arc Boosts” via misconfigured Firebase Access Control Lists (ACLs), allowing attackers to inject arbitrary JavaScript. |
| CVE-2024-7971 | Aug 21, 2024 | High | V8 Type Confusion vulnerability inherited from the Chromium engine, actively exploited in the wild before patching. |
Technical & Financial Reports
- SiliconANGLE: “Atlassian acquires AI browser developer The Browser Company for $610M” , September 4, 2025. Financial breakdown of the acquisition deal.
- TechCrunch: “Dia Browser Beta Launch” , June 11, 2025. Technical analysis of the “Dia” browser architecture and its departure from Arc’s sidebar interface.
- Chromium Project Source Code , Ongoing. Verification of Blink engine updates and patch cadence for the underlying rendering infrastructure.
- Android Authority: “Arc enters maintenance mode” , May 27, 2025. Coverage of the strategic pivot away from Arc toward AI-native browsing tools.
Data Collection & Privacy Analysis
“We don’t know which websites you visit… We don’t sell your data to third parties.” , The Browser Company Privacy Policy (2024).
Investigator Note: While the core policy remains protective, the 2025 “Dialed In” addendum for Dia introduces mandatory data processing for AI features, involving third-party LLM providers (OpenAI/Anthropic) which breaks the “local-only” pledge of the original Arc browser.


































