Privacy Policy
What the service collects, why, who it reaches, and what you can ask us to do about it.
Last updated 2 August 2026
1. Scope
This policy covers the ApexCorp service and this website. Where the Service is deployed inside your own environment under a separate agreement, you are the controller of the data it processes, and this policy then applies only to the website and to support data you send us.
2. Who is responsible
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], is the controller of personal data processed through the hosted Service. Contact: contact@apexcorp.app.
3. What we collect
Today, on a deployment you run
This is the only way the Service currently runs. Everything it produces — briefs, tasks, notes, memory, spend records — is written to a database file on your own machine or server. It is never sent to us, and we have no ability to read it.
Your model provider key is read from that deployment’s environment when the orchestrator starts. It is never written to the database, never sent to the browser, and there is deliberately no way to set one through the control panel.
If you create an account
Accounts exist for one reason: a subscription needs something to attach to. We hold your email address, a hash of your password — never the password itself — and the dates you created the account and last signed in. Your session is a random token, and we store only a hash of that too, so our database cannot be used to sign in as you.
Card details never reach us. Paddle is the merchant of record: they take the payment, calculate and remit tax, and issue the invoice. We receive your subscription’s plan and status, and nothing about your card.
When the hosted service launches
Not built yet The hosted orchestrator does not exist yet, so nothing below is collected today. Your company’s work runs on a machine you control.
- Company content — the briefs, tasks, notes and memory your company produces.
- Model provider credentials — encrypted at rest and used only to make calls on your behalf.
- Operational logs — IP address, browser type, timestamps, and the requests you make, kept to run and secure the service.
- Usage metering — task counts and token spend, used for limits and billing.
We do not collect
- Advertising identifiers, cross-site tracking, or data brokered from third parties.
- Special category data. Please do not put it into task briefs.
4. Why we process it, and on what basis
- To provide the Service — performance of our contract with you.
- To bill you — performance of a contract, and legal obligation for tax records.
- To keep the Service secure and abuse-free — our legitimate interests.
- To contact you about service changes — legitimate interests, or consent for anything promotional.
5. Where your content goes
The important one: task briefs and the context agents assemble are sent to the model provider you configure, under your own account with that provider. Their handling of that data is governed by their terms and privacy policy, not ours. We do not use your content to train any model, and we do not sell it.
6. Who else sees it
Paddle is our merchant of record. They process your payment and billing address for that purpose under their own privacy notice, which is the one to read about your card details — we never hold them.
Not built yet The processors below come with the hosted service, and there is not one yet.
- Cloud hosting and database providers.
- Error monitoring and operational logging.
Each is bound by a data processing agreement. We disclose data to authorities only where legally required, and will tell you unless prohibited.
7. International transfers
Where data leaves [JURISDICTION], we rely on an adequacy decision or on standard contractual clauses with appropriate supplementary measures.
8. How long we keep it
- Account data — while your account is open, then up to 30 days.
- Company content — until you delete it, or 30 days after termination.
- Billing records — as long as tax law requires, typically six to seven years.
- Operational logs — up to 90 days, except where retained for a specific security investigation.
9. Your rights
Subject to local law, you may request access to your data, correction, deletion, restriction, portability, or object to processing based on legitimate interests. Write to contact@apexcorp.app; we respond within one month. You may also complain to your local data protection authority.
On a deployment you run, we hold nothing, so there is nothing for us to produce or erase — the database file is yours and you may copy or delete it at will. We would rather say that than imply a request to us would accomplish anything.
Not built yet There is no self-service export or delete-my-account button yet. Write to us and we will do it by hand within the month the law allows. Exercising a right should not depend on a person reading an inbox, and building that properly is part of launching the hosted service.
10. Cookies
No analytics and no advertising cookies, anywhere. If you sign in we set one cookie,apexcorp_session, which keeps you signed in and does nothing else. It is strictly necessary, so it needs no consent banner; it is HttpOnly so scripts cannot read it, and Secure so it never travels over plain HTTP. Signing out clears it.
Paddle’s checkout sets its own cookies when you open it, under their domain and their policy. The demo keeps its sample company in local storage, which never leaves your device.
Not built yet Anything beyond that session cookie — analytics, product telemetry — would get a banner before it is set. There is nothing of the kind today.
11. Security
On a deployment you run, the security that matters is the deployment’s: the orchestrator binds to loopback so only that machine can reach it, agents are confined to the project root and to an allowlist of read-only commands, and the provider key stays in the environment rather than in the database or the browser.
For accounts: passwords are hashed with scrypt and a per-password salt, sessions are stored only as a hash, sign-in is rate limited, and the form gives the same answer whether or not an address is registered — so it cannot be used to find out who has an account.
Not built yet The orchestrator’s own API still has no authentication, which is why it binds to loopback and why the hosted service does not exist yet. Encryption at rest for provider credentials, least-privilege access, and an administrative audit log all have to be built before anyone else’s work runs on our infrastructure.
No system is perfectly secure; if a breach affects your personal data we will notify you and the relevant authority as required. See our security page for what is enforced today.
12. Children
The Service is not directed at children under 16, and we do not knowingly collect their data. Tell us if you believe we have.
13. Changes
We will post updates here and, for material changes, give notice by email at least 30 days in advance.
Questions about this document go to contact@apexcorp.app, or via the contact page.
Related: Terms · Privacy · Refunds · Acceptable Use