We're open source. If actrone-memory has been useful to you, a star on GitHub means a lot to us.

Legal

Privacy policy

Last updated: September 24, 2026

1. Who we are

Apocalypse Technologies (“we”, “us”, “our”) owns and operates Actrone, including the actrone.com website and associated services. This Privacy Policy explains how we collect, use, disclose, and protect your personal data. We process data as a data controller under GDPR, POPIA, and applicable equivalent legislation.

2. Data we collect

We collect: (a) Account data: name, email address, organisation name, billing information provided at registration; (b) Usage data: API calls, task inputs/outputs, error logs, and performance metrics; (c) Technical data: IP addresses, browser type, session tokens stored in HTTP-only cookies; (d) Communication data: contents of emails, support tickets, and contact form submissions; (e) Waitlist data: the email address you give when joining the Founding 500 waitlist, and the name, company, and intended use if you choose to add them.

3. Legal basis for processing (GDPR)

We process your data on the following bases: (a) Contract performance: to deliver the Service you have subscribed to; (b) Legitimate interests: to improve our platform, detect abuse, and ensure security; (c) Legal obligation: to comply with tax, financial, and regulatory requirements; (d) Consent: for optional analytics cookies, marketing emails, and non-essential data uses. You may withdraw consent at any time.

4. How we use your data

We use your data to: provide and improve the Service; send transactional emails (account verification, password reset, billing receipts); send product update emails (you may unsubscribe at any time); detect and prevent fraud and abuse; comply with legal obligations; generate aggregated, anonymised platform statistics (never linked to individual users).

5. Data sharing

We do not sell your personal data. We share data only with: (a) Website hosting: Vercel, which serves actrone.com and processes request data such as IP addresses to do so; (b) Form storage: Baserow, hosted in Germany, which stores waitlist sign-ups and contact form messages; (c) Analytics: PostHog, in its US cloud, only after you accept analytics cookies; (d) Error monitoring: Sentry, which receives technical error reports from the website and is configured not to collect personal data; (e) Infrastructure providers: AWS, for the hosted platform, where data is stored in encrypted, access-controlled environments; (f) Payment processors: Stripe, for billing (they have their own privacy policy); (g) Email delivery: Resend, for transactional and product emails; (h) Legal authorities: where required by law or court order. We require all sub-processors to provide equivalent data protection guarantees.

6. Task data

Task inputs and outputs submitted to the Orchestrator are processed to deliver the Service. They are retained for 90 days by default (configurable per plan). We do not use task data to train shared models without your explicit written consent. Enterprise customers may request data isolation and shorter retention periods.

7. Data retention

Account data is retained for the duration of your subscription and for 7 years thereafter for legal and accounting purposes. Task data is retained for 90 days by default. Governance violation records are retained for 7 years (regulatory requirement). You may request deletion of personal data; some data may be retained where required by law.

8. Your rights

Under GDPR, POPIA, and equivalent regulations, you have the right to: access your personal data; correct inaccurate data; request deletion (“right to be forgotten”); restrict or object to processing; data portability; withdraw consent; lodge a complaint with your supervisory authority. To exercise these rights, contact legal@actrone.com. We respond within 30 days.

9. International transfers

We and the service providers listed above may process your data outside your jurisdiction, including in the United States. We use Standard Contractual Clauses (SCCs) approved by the European Commission for all such transfers. Enterprise customers may request data residency in specific AWS regions.

10. Security

We implement: TLS 1.3 encryption in transit; AES-256 encryption at rest; API key hashing (SHA-256, so raw keys are never stored); access controls with least-privilege principles; regular penetration testing; and SOC 2 Type II controls. See our Security Policy for details.

11. Contact

For privacy questions or to exercise your rights: legal@actrone.com. For security disclosures: security@actrone.com. Our registered address is available on request.