Privacy Policy
This page may be automatically translated. Only the English version is legally binding. In case of any discrepancies, the English version shall prevail.
1. Data Controller
exployt Software GmbH, Lange Gasse 30, 8010 Graz, Austria is responsible for processing your personal data on this website.
2. Data We Collect
For full transparency, the four views below separate private local statistics, optional Gamification sharing, anonymous analytics, and account-linked operational data. Open any category for the complete current inventory.
Four clear data boundaries
Choose a category to see every current data group, how it is created, where it lives, whether it is linked or shared, and how long it is kept.
The same live inventory is also available on the dedicated Data Collection page. It is maintained from the same product catalog so the two views cannot drift apart.
3. Purpose of Processing
We use your data to:
- Provide and maintain our service
- Process your account registration and authentication
- Process payments for subscriptions
- Send service-related emails (verification, notifications)
- Generate invoices upon request
- Improve our service and user experience
4. Data Storage and Data Residency
The primary production web service is hosted on Microsoft Azure in the West Europe region (Netherlands). Customer source code, local project files, local project databases, local agent history, local credentials, and AI-provider API keys are not stored in the exployt cloud during ordinary desktop-app operation. Project content leaves that local boundary only through explicit user actions: you select a cloud AI provider or external tool and send task context to it, you publish selected files and metadata as a Marketplace item for sharing or sale, or you submit a support/bug report after reviewing the submission preview and confirming what will be sent. Marketplace items can include integrations, modules, standalone apps, settings sets, workflows, connector packages, or other reusable assets; you choose what goes into the package, and we recommend minimization plus obfuscation where appropriate. Some third-party providers listed below may process limited data outside the EEA under their own transfer mechanisms, such as Standard Contractual Clauses or equivalent contractual safeguards.
We retain your data as long as your account is active or as needed to provide services, comply with legal obligations, resolve disputes, enforce agreements, and protect the service against fraud or abuse.
5. Your Rights (GDPR)
Under the General Data Protection Regulation, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Request deletion of your data
- Restrict processing of your data
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise these rights, contact us at office@exployt.ai.
6. Cookies
We use essential cookies for authentication and session management. These are necessary for the website to function and cannot be disabled. Optional website analytics uses local browser storage and provider scripts only where the public analytics config is enabled and, when consent is required, only after you accept analytics in the website prompt.
7. Third-Party Services and Subprocessors
We use the following service providers to operate the website, account service, billing, transactional email, security, and optional website analytics stack. Customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter, and local Ollama models used by the desktop app are chosen or configured by you; they are not exployt cloud subprocessors for local project content, and exployt's cloud does not need to store your AI-provider API keys or source code for ordinary desktop-app operation.
Marketplace publishing is separate from ordinary desktop-app operation. If you intentionally upload a Marketplace item to share or sell it, the files and metadata you choose for that item are transmitted so they can be reviewed, hosted, shared, sold, or delivered to buyers. For Marketplace items that contain code, connector packages, integration modules, standalone apps, settings sets, workflows or reusable project assets, we recommend minimizing the package and using obfuscation where appropriate; exployt can support that workflow.
- Microsoft Azure: Hosting, storage, managed database, runtime infrastructure, and Azure Key Vault.
- Stripe: Payment processing (Privacy Policy).
- Resend: Transactional service emails such as verification, password reset, and security notifications.
- MaxMind: IP geolocation for security and trial-abuse prevention through an offline database; no runtime user data is shared with MaxMind for those lookups.
- Google Analytics 4 and Microsoft Clarity: Website analytics and product-improvement signals only where enabled under the website privacy notice and applicable consent settings.
7.1 Website Analytics and Cookie Consent
This section covers the public website and admin analytics dashboard. It is separate from the privacy rules for the desktop app and for local project content, which stay local during ordinary desktop-app operation.
- Google Analytics 4: Aggregate website traffic reporting such as page views, active users, approximate region, device category and referral channel. Google states that GA4 uses IP addresses only at collection time to derive location metadata and does not log or store them.
- Microsoft Clarity: Website behavior analytics such as heatmaps, session replay, click and scroll interactions, page rendering information and device/browser aggregates. We do not intentionally record source code, passwords, payment details, account secrets or desktop-app project content through Clarity.
- Blazor-ApexCharts: Client-side chart rendering for admin dashboards. It is an open-source charting library, not a separate analytics provider, and does not receive website-visitor data from exployt by itself.
Legal basis and control. For optional analytics and behavior scripts we rely on consent under GDPR Article 6(1)(a). Where consent is required, GA4 and Clarity load only after you accept analytics. Declining stores that choice locally and no analytics scripts load for that browser decision. Your decision is stored as exployt_analytics_consent in local browser storage; clearing this site's browser storage resets it.
Source basis. This section was checked on 25 August 2026 against GDPR Articles 6, 12, 13 and 21, EU cookie-consent guidance, Google Analytics Help and Microsoft Clarity FAQ. Provider documentation and retention settings can change; provider notices apply for their independent processing.
8. Trial Abuse Prevention
To prevent abuse of our free trial offer, we collect and process the following additional data when you start a free trial through our desktop application:
- Reduced device identifiers: The desktop app may derive stable device-fingerprint signals from hardware and operating-system attributes such as SMBIOS UUID, processor ID, machine GUID, BIOS serial, and baseboard serial. We reduce these signals to hashes/HMAC values for matching and abuse-prevention; they are used only for account security, license integrity, and trial-abuse prevention.
- IP address at signup: Used for rate limiting and risk assessment. Automatically anonymized after 90 days.
- Risk assessment data: A numerical risk score (0-100) and the signals that contributed to it, used to detect duplicate trials. Retained for 1 year for audit purposes, then deleted.
Legal basis: Legitimate Interest per GDPR Article 6(1)(f). Preventing trial abuse and protecting account/license integrity are legitimate business interests. We have balanced this against your privacy rights and determined that using reduced device identifiers only for security, licensing, and abuse-prevention purposes is proportionate and minimally invasive.
Data retention:
- Reduced device records: Retained for the lifetime of your account plus 90 days after deletion
- IP addresses: Anonymized after 90 days
- Risk assessment events: Deleted after 1 year
Your rights: You can request deletion of your device records at any time by contacting us at office@exployt.ai or by deleting your account. Note that after deletion, the same device may be eligible for a new trial after the 90-day grace period.
9. Account Security: Sign-In Notifications & Known Devices
To protect your account against unauthorized access, we record the devices from which you successfully sign in and send you a security email when a sign-in comes from a device we have not seen before. For this purpose we process:
- IP address: The IP address of each sign-in. In security emails the IP is always shown masked (e.g. 156.146.61.x) — we deliberately minimize what the email itself exposes.
- Approximate location: The country and, where resolvable, the city derived from the sign-in IP address using an offline MaxMind GeoIP database on our servers. No data is shared with MaxMind. Location is approximate (IP-based) and used for display in the security email only.
- Device information: Browser, operating system, and device type parsed from your browser's User-Agent header, or the application name when you sign in from the exployt desktop app.
- Reduced device identifiers (desktop app only): When you sign in from the desktop application, it may send the reduced device-identification signals described in Section 8. We use them solely to recognize that a sign-in comes from a computer you have already used — this keeps the recognition reliable when your network, VPN, or browser changes.
Purpose limitation: All of the above — including the hardware fingerprint — is used exclusively for account security and abuse prevention (recognizing known devices, alerting you to unknown sign-ins, and preventing trial abuse per Section 8). It is never used for analytics, marketing, advertising, or any form of cross-service tracking.
Legal basis: Legitimate Interest per GDPR Article 6(1)(f). Recital 49 GDPR explicitly recognizes processing necessary for network and information security as a legitimate interest. You do not need to opt in, and the security notification email is a transactional service message, not marketing.
Data retention:
- Known-device records: Deleted automatically 12 months after the last sign-in from that device. After deletion, the next sign-in from that device is simply treated as new again (you receive one security email).
- Sign-in history (session records incl. IP address and User-Agent): Deleted automatically 12 months after the session expires.
- Reduced device identifiers follow the retention rules in Section 8.
Your rights: You can view your active devices and sign-in history in your account area and revoke devices there at any time. You can also request deletion of your device records by contacting office@exployt.ai or by deleting your account.
10. AI-Assisted Subscription Compliance Check
On non-commercial subscriptions, we use a lightweight AI signal to help us check that the subscription tier you hold matches how you actually use the Service. (Commercial subscriptions are not subject to this check at all.) This section explains exactly what that means for your data, why we do it, and how you can object.
What we collect
While the AI agents carry out the work you have assigned them, they carry a single short instruction: if they happen to notice clear signs that the project is being used commercially (for example, clear signs of commercial monetisation that would not fit a non-commercial subscription), they record one compliance signal through a simple internal API call. There is no separate scan or analysis of your project, and none of your paid AI budget is spent on this check — the agent merely reports an incidental observation. When such a signal is recorded, it consists of:
- an opaque project identifier that lets us address a follow-up message to the right project, and
- a numeric flag count for that project.
That is all. No source code, no file content, no project metadata, no chat history, and no personal identifiers beyond the project identifier leave your device as part of this check.
Why we collect it
To detect, in a privacy-respecting way, situations where a project's use may exceed the scope of your current subscription tier — so we can offer you a clear, upfront upgrade option instead of a billing dispute later. The full mechanism, including the consequences, is described in § 11 of the Terms of Service.
Legal basis
We rely on Article 6 (1) (f) GDPR — legitimate interest. Our legitimate interest is to protect our software and contractual rights from unauthorised commercial use. We have completed a written Legitimate-Interest Assessment (LIA) under the EDPB Guidelines 1/2024 framework and weighed our interest against your rights and reasonable expectations. The assessment is available on request via office@exployt.ai.
Use of AI
In the spirit of Article 50 of the EU AI Act, we explicitly disclose that the compliance signal is produced by the AI agent as an incidental observation during the work you requested — not by a dedicated analysis of your project. No human reviews your project content. Flagging is advisory only: a flagged project is never automatically suspended, billed differently, or otherwise affected. Any concrete action (such as a suggested upgrade) is reviewed by exployt staff before reaching you.
Your right to object (Article 21 GDPR)
You can stop this processing for your account at any time. There are two equivalent paths:
- Email office@exployt.ai with subject "Object: AI Compliance Check" and your account email. We confirm within five business days.
- Toggle "AI Compliance Telemetry" to off in your Account area under Privacy.
Once you object, we cease collecting these signals for you, unless we can demonstrate compelling legitimate grounds that override your rights — a deliberately high bar that we do not anticipate meeting for ordinary use of the Service.
Your other GDPR rights
You also retain — for this processing as for all our processing — the rights to access (Article 15), rectification (Article 16), erasure (Article 17), restriction (Article 18), data portability (Article 20), and to lodge a complaint with a supervisory authority (Article 77), in Austria the Österreichische Datenschutzbehörde (dsb.gv.at). To exercise any of these, contact office@exployt.ai.
Retention
- Raw compliance counts are retained for at most twelve (12) months.
- After twelve months the per-project link is dropped and only aggregated, non-personal statistics remain.
- If you object under Article 21, your existing counts are deleted within thirty (30) days.
Recipients
Compliance counts are processed exclusively by exployt Software GmbH within the European Union. They are not shared with third parties.
No Article 22 decision
This processing is not a decision based solely on automated processing that produces legal effects on you within the meaning of Article 22 GDPR. The compliance count is one input that may prompt an exployt staff member to review your account; it never decides anything on its own.
11. Integrity Signal
To detect license violations and fraud, exployt may receive an automated technical signal indicating that a licensed project has been executed or distributed. Such a signal transmits only a non-descriptive project identifier together with the fact and time of the event. It never transmits your source code, file contents, or other project data. This processing is based on our legitimate interest in enforcing our license terms and preventing abuse.
12. Data We Collect When You Request a Payout
If you request a payout from your User Budget under § 20 of the Terms of Service, we collect the additional identifying data needed to execute the payout and to meet our payor-side reporting obligations:
- legal name (or legal form + commercial registry number, for legal entities);
- primary address;
- tax identification number (TIN) of your country of tax residence;
- VAT identification number, if you hold one;
- IBAN or other supported payout-identifier;
- date of birth (natural persons);
- country of tax residence.
Legal basis. Article 6 (1) (c) GDPR — compliance with a legal obligation to which we are subject. The Austrian tax-records retention requirement (§ 132 BAO) requires us to keep these records for seven (7) years; the EU DAC7 directive (transposed in Austria as the Digitales Plattform-Meldepflichts-Gesetz) requires us to transmit identifying data and payout totals annually to the Austrian Federal Ministry of Finance, which onward-shares it with the tax authority of your country of tax residence.
Purpose limitation. We use this data only to execute the payout, to compute deductions, and to meet our tax-reporting and record-keeping obligations. We do not use it for marketing, profiling, or any other purpose.
Recipients. exployt Software GmbH (controller), the chosen payment-provider for the specific payout (processor, as data minimisation requires — only the data needed for that transfer), the Austrian Federal Ministry of Finance (recipient under DAC7), and the tax authority of your country of tax residence (recipient via the DAC7 exchange).
Retention. Tax/accounting records: seven (7) years per Section 132 BAO, and longer where law requires it for specific records or ongoing proceedings. Where DAC7/DPMG reporting applies, the reporting dataset follows the DPMG retention/deletion rule, currently deletion ten (10) years after the relevant reporting period.
Your rights. Article 21 GDPR (right to object) is not available against processing required to comply with a legal obligation. Your other GDPR rights (access, rectification, restriction, complaint to a supervisory authority — in Austria the Österreichische Datenschutzbehörde) apply in full. To exercise them, contact office@exployt.ai.
13. DPA, Subprocessors and International Transfers
Business and enterprise customers can request a Data Processing Agreement (DPA) by contacting office@exployt.ai. We are preparing a public DPA package and will publish it when it is ready. The DPA is intended to document controller/processor roles, confidentiality, technical and organizational measures, subprocessor use, deletion/return after termination, and cross-border transfer safeguards.
Our current cloud subprocessors for the public website and account service are Microsoft Azure, Stripe, Resend, MaxMind offline geolocation data, and optional website analytics providers where enabled and consented where required. We do not treat customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter, or local Ollama models as exployt cloud subprocessors for local project content; those providers and tools are selected, configured, or invoked by you and governed by the accounts, licenses, and terms you choose.
Where a provider processes personal data outside the EEA, we rely on the provider's published transfer mechanisms and contractual safeguards, including Standard Contractual Clauses where applicable.
14. Data Security
We implement appropriate technical and organizational measures to protect your data, including HTTPS with modern TLS 1.2/1.3 in transit, platform encryption for Azure-hosted storage, bcrypt password hashing, AES-GCM encryption for selected sensitive server-side fields, DPAPI protection for local secrets in the Windows desktop application, signed entitlement tokens, and regular security updates. Local project databases and agent history stay on your machine. Local project database encryption is available through the desktop app's encryption settings; when you do not enable it, the SQLite database remains under your own device and file-system security.
Security and compliance details are duplicated for human readers and AI crawlers on the Trust & Security page, /llms.txt, /trust.txt, and /faq-security.txt.