Privacy Policy
APODEXA turns messy bank and invoice files into validated, structured data. This policy explains what we collect, why, and your choices.
1. Information we collect
- Account information — your email address and name (if you use Google Sign-In) and an account identifier. We never receive your Google password.
- Files you upload — bank CSVs, invoices, and similar documents, which may contain financial and personal data (amounts, descriptions, vendor names).
- Processing results — validated output, confidence scores, validation checks, provenance, and a history of your runs and corrections.
- Billing information — payments are handled by Stripe. We receive subscription status and identifiers; we never receive or store your full card number.
- Usage & analytics — on our public marketing pages only, via Google Analytics (see §6). The signed-in dashboard is not analytics-tracked.
- Technical data — IP address, browser type, and server logs, for security and reliability.
2. How we use information
To provide and operate the service; to authenticate you and secure accounts; to process subscriptions; to maintain run history and the review/correction workflow; to improve reliability and prevent abuse; and to comply with legal obligations.
We do not sell your data, and we do not use your uploaded files to train AI models. Processing is deterministic; no file content is sent to an external AI provider.
Legal basis (where the GDPR applies). We process your account and file data to perform our contract with you (delivering the Service); we rely on our legitimate interests to secure the Service, prevent abuse, and keep it reliable; we use analytics only with your consent (see §6); and we process certain records to comply with legal obligations.
3. Where your data is processed and international transfers
Data is hosted on Amazon Web Services in the Tokyo region (ap-northeast-1), Japan. Depending on your location this may involve an international transfer. Where required, we safeguard such transfers as the law demands: for visitors in the EU/EEA and UK, transfers to Japan are covered by the European Commission's adequacy decision for Japan; for other regions we rely on appropriate contractual or legal safeguards.
4. Retention and deletion
- Uploaded files, results, and run history are retained for up to 90 days, or until you delete them or close your account, whichever is sooner.
- Self-service export and deletion. From your account settings you can export your data and permanently delete your account and all of its data yourself — your data is removed from our live systems immediately, and copies in our encrypted database backups expire automatically within 90 days. When we restore from a backup, recorded deletions are re-applied so a restore does not bring erased data back. The export contains your account, workspace, run history, corrections, and related metadata; it does not include your original uploaded source files or any secrets (passwords, API-key secrets).
- Security audit log. We keep a minimal, tamper-evident security log of account-level events (for example sign-in attempts, API-key creation or revocation, data exports, and deletion requests). Entries contain opaque internal identifiers, timestamps, and — for sign-in events — the IP address; they never contain your files, file contents, or email address. This log is retained for up to 365 days for security and abuse-prevention purposes and, because it is the record of the deletion itself, it survives account deletion.
- You can also request deletion by emailing us; we will delete your data within 30 days. Some records may be retained where the law requires it; the durable record of your payments is held by Stripe, our payment processor.
5. Sub-processors
| Provider | Purpose | Data |
|---|---|---|
| Amazon Web Services (Tokyo) | Hosting, storage, compute | All service data |
| Stripe | Subscription payments | Billing/contact data; card data goes directly to Stripe |
| Google (Sign-In) | Optional authentication | Email, name, Google account id |
| Google Analytics | Marketing-page analytics only | Pseudonymous usage data |
The current sub-processor list, with the role and data touched for each, is also published at /subprocessors.
6. Cookies and analytics
- Essential cookie — a session cookie (
apodexa_session, HttpOnly, Secure) that keeps you signed in. Required. - Analytics cookies — we use Google Analytics 4 on our public marketing pages only. Analytics runs under Google Consent Mode with analytics denied by default: no analytics cookies are set and GA stays in a cookieless state until you Accept on the cookie banner shown on your first visit. If you Decline, analytics stays off. Your choice is remembered; to change it, clear this site's storage in your browser (which brings the banner back) or decline. The signed-in dashboard is not analytics-tracked.
7. Security
Encryption in transit (TLS 1.2+) and at rest, access controls, generated storage filenames, upload validation, operational logging with per-request correlation IDs, run-level provenance on every result, and least-privilege infrastructure. No method is perfectly secure, but we work to protect your data. See our Trust & Security page for the current controls.
8. Your rights
Subject to your jurisdiction, you have the right to access your data, rectify inaccurate data, request erasure, obtain a copy for portability, and object to or restrict certain processing; where processing is based on consent, you may withdraw it at any time.
You can exercise the core rights yourself: export and permanent deletion are available in your account settings and take effect immediately on our live systems, with backup copies expiring within 90 days (see §4). For anything else, email agentsclaude@gmail.com. If you are in the EU/EEA or UK you also have the right to lodge a complaint with your data protection authority; in Japan this is the Personal Information Protection Commission (PPC).
9. Data breaches
If a breach affecting your personal data occurs, we will notify affected users and the relevant supervisory authority without undue delay, as required by applicable law (including the GDPR and Japan's Act on the Protection of Personal Information (APPI)).
10. United States privacy (California / CCPA)
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. If you are a California resident, you may exercise the access, deletion, and portability rights described above, and we will not discriminate against you for doing so.
11. Children and eligibility
APODEXA is a business tool, is not directed to children, and is not intended for anyone under 16. We do not knowingly collect data from children.
12. Changes
We may update this policy; material changes will be posted here with a new effective date.
13. Contact
Questions or requests: agentsclaude@gmail.com.