Apragya ("Company," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at apragya.ai ("Service"). This policy is compliant with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and other applicable data protection laws.
By using the Service, you consent to the data practices described in this Privacy Policy. If you do not agree with this policy, please do not use the Service.
1. Information We Collect
1.1 Information You Provide
- Account Information: Name, email address, password, and profile details when you create an account
- Billing Information: Payment method details, billing address, and transaction history (processed securely through Stripe)
- User Content: AI agent configurations, workflow definitions, uploaded documents, and any other content you create or input through the Service
- Communications: Messages, feedback, and support requests you send to us
1.2 Information Collected Automatically
- Usage Data: Pages visited, features used, actions taken, time spent, and interaction patterns
- Device Information: Browser type, operating system, device identifiers, and screen resolution
- Log Data: IP address, access timestamps, referring URLs, and error logs
- Agent Execution Data: Execution logs, performance metrics, token usage, and cost data related to AI agent runs
1.3 Information from Third-Party Services
If you choose to log in using a third-party service (such as Google OAuth or Microsoft OAuth), we may receive your name, email address, and profile picture from that service, as authorized by your privacy settings with the respective provider.
2. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Service
- Process transactions and manage your subscription
- Personalize and improve your experience on the platform
- Send you transactional emails, security alerts, and service updates
- Respond to your comments, questions, and support requests
- Monitor and analyze usage trends and platform performance
- Detect, prevent, and address fraud, abuse, and technical issues
- Comply with legal obligations and enforce our Terms of Service
We do not use your User Content (such as AI agent configurations or processed data) to train machine learning models or for any purpose other than providing the Service to you.
3. Data Storage & Security
Your data is stored on secure, encrypted servers. We implement industry-standard security measures including:
- Encryption of data in transit (TLS 1.3) and at rest (AES-256)
- Regular security audits and vulnerability assessments
- Access controls with role-based permissions
- Automated backup and disaster recovery procedures
- SOC 2 Type II compliant infrastructure
While we strive to protect your personal information, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but will promptly notify you of any data breach that may affect your personal information, as required by applicable law.
4. Third-Party Services
We integrate with the following third-party services to provide the Service. Each has its own privacy policy governing the use of your information:
Stripe
Payment processing. Stripe collects and processes your payment information directly. We do not store your full credit card number on our servers. Stripe Privacy Policy
Google OAuth
Authentication. When you sign in with Google, we receive your name, email, and profile picture. Google Privacy Policy
Microsoft OAuth
Authentication. When you sign in with Microsoft, we receive your name, email, and profile picture. Microsoft Privacy Statement
Anthropic AI (Claude)
AI processing. User prompts and agent configurations may be sent to Anthropic's API for AI inference. Anthropic does not use API data to train its models. Anthropic Privacy Policy
5. Cookies
We use the following types of cookies:
- Essential Cookies: Required for authentication, security, and basic platform functionality. These cannot be disabled.
- Functional Cookies: Remember your preferences such as theme settings, language, and layout options.
- Analytics Cookies: Help us understand how you use the Service so we can improve it. These are anonymized and aggregated.
You can manage your cookie preferences at any time through the cookie consent banner or your browser settings. Disabling certain cookies may affect the functionality of the Service.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specifically:
- Account Data: Retained for the duration of your account and for 30 days after account deletion to allow for data export
- Agent Execution Logs: Retained for 90 days by default, configurable per your plan
- Billing Records: Retained for 7 years as required by financial regulations
- Support Communications: Retained for 2 years after resolution
You may request earlier deletion of your data by contacting us. Certain data may be retained longer if required by law or legitimate business purposes.
7. Your Rights
Under GDPR, CCPA, and other applicable data protection laws, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of all personal data we hold about you
- Right to Rectification: You can update or correct inaccurate personal data through your account settings
- Right to Deletion: You can request deletion of your personal data and account. We will process deletion requests within 30 days
- Right to Data Portability: You can export your data in a machine-readable format (JSON/CSV) through the GDPR Data Export feature available in your account Settings
- Right to Restrict Processing: You can request that we limit how we use your data
- Right to Object: You can object to our processing of your data for certain purposes
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing
GDPR Data Export: You can export all your personal data at any time by navigating to Settings → Privacy & Data in your account dashboard. The export includes your profile, agent configurations, execution history, and all associated metadata in JSON format.
To exercise any of these rights, please contact us at privacy@apragya.ai. We will respond to your request within 30 days.
8. International Data Transfers
Your data may be transferred to and processed in countries other than your country of residence. When we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including Standard Contractual Clauses (SCCs) approved by the European Commission, or reliance on the recipient's participation in a recognized framework.
9. Children's Privacy
The Service is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal data from a child under 18, we will take steps to delete that information promptly. If you believe that a child under 18 has provided us with personal data, please contact us at privacy@apragya.ai.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. We will notify you of material changes by posting the updated policy on the Service with a revised "Last updated" date. For significant changes, we may also send you a notification via email or through the platform.
We encourage you to review this Privacy Policy periodically. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
11. Contact Us
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us:
If you are located in the European Union, you also have the right to lodge a complaint with your local data protection authority if you believe we have not adequately addressed your concerns.