# exployt.ai Privacy Summary Last updated: 2026-08-25 Canonical privacy policy: https://exployt.ai/privacy Legal page privacy section: https://exployt.ai/legal#privacy Website privacy section: https://exployt.ai/legal#website-privacy ## Controller exployt Software GmbH, Merangasse 53/3, 8010 Graz, Austria is responsible for processing personal data on the website and account service. Contact: office@exployt.ai. ## Data categories exployt cloud processes account and authentication data, billing and payment state, subscription/license state, account-security events, fraud-prevention signals, support/feedback records submitted by the user, consented website analytics and logs needed to operate and secure the public website, account service, billing, licensing, support and Marketplace cloud features. exployt does not collect Big Data from customer projects or build datasets from source code. ## Website analytics and cookies Website analytics is separate from app/project privacy. Optional public website analytics may use Google Analytics 4 for aggregate traffic metrics and Microsoft Clarity for behavior analytics such as heatmaps, session replay, click and scroll interactions, page rendering information and device/browser aggregates. Provider scripts are served only where the public analytics config enables them. Where consent is required, GA4 and Clarity load only after the visitor accepts analytics in the website prompt; declining keeps those scripts unloaded for that browser decision. The consent decision is stored locally as exployt_analytics_consent and can be reset by clearing this site's browser storage. Blazor-ApexCharts is used for client-side chart rendering in admin dashboards. It is not a separate analytics provider and does not receive website-visitor data from exployt by itself. ## Project content and AI provider keys Customer source code, file contents, local project databases, local agent history, local project files, local credentials and local AI-provider API keys are not collected by exployt cloud for ordinary desktop-app operation. Project content leaves that local boundary only through explicit user actions: the customer selects a cloud AI provider or external tool and sends task context to it, publishes selected files and metadata as a Marketplace item for sharing or sale, or submits a support/bug report after preview and confirmation. Marketplace items can include integrations, modules, standalone apps, settings sets, workflows, connector packages or other reusable assets; the customer chooses what goes into the package, and exployt recommends minimization plus obfuscation where appropriate. Support/feedback flows that include diagnostic data show the data first and send only what the customer confirms. ## Data residency The primary production web service is hosted on Microsoft Azure in the West Europe region (Netherlands). Some third-party providers may process limited data outside the EEA under their own transfer mechanisms and contractual safeguards. ## Third-party services and subprocessors Current providers for the public website, account service, billing, email, security and optional website analytics stack include Microsoft Azure, Stripe, Resend, MaxMind offline geolocation data, and optional Google Analytics 4 / Microsoft Clarity website analytics where enabled and consented where required. Customer-selected AI providers, Git services, tools, plugins, connectors, OpenRouter and local Ollama models used by the desktop app are chosen or configured by the customer and are not exployt cloud subprocessors for local project content. ## Payout and tax-reporting data When a user requests a payout, exployt may collect legal name, address, tax identification number, VAT identification number if held, IBAN or other supported payout identifier, date of birth for natural persons, and country of tax residence. This data is used only to execute payouts, compute deductions, and meet tax-reporting and record-keeping obligations. Recipients can include the selected payout provider, the Austrian Federal Ministry of Finance where DAC7/DPMG applies, and the tax authority of the user's tax-residence country through the DAC7 exchange. Tax/accounting records are generally retained for seven years under BAO section 132; DAC7/DPMG reporting datasets follow the DPMG retention/deletion rule, currently deletion ten years after the relevant reporting period. ## Security Traffic uses HTTPS with modern TLS 1.2/1.3. Passwords are bcrypt hashed. Selected sensitive server-side fields use AES-GCM encryption and lookup hashes. Local Windows secrets in the exployt credential stores use DPAPI. Local project databases and agent history are not sent to exployt cloud during ordinary desktop-app operation. Local project database encryption is available through desktop app settings; when it is not enabled, the local SQLite database remains under the customer's own device and file-system security. ## GDPR rights and DPA Users may request access, rectification, deletion, restriction, portability, objection or consent withdrawal where applicable by contacting office@exployt.ai. Business and enterprise customers can request a Data Processing Agreement at office@exployt.ai. exployt is preparing a public DPA package and will publish it when it is ready. Some data must be retained for legal, tax, accounting, fraud-prevention, dispute or security reasons.