Privacy Policy
Last updated 2026-09-19 · Terms · Privacy · Imprint · DPA
alleex lets you build agents and run them. Runs happen on our server, with the keys and data you give your agents. This page says what we store, why, for how long, and who else sees it.
1. Controller
Alexander Burger, Josef-Maderspergerstraße 15, 5020 Salzburg, Austria, 5020 Salzburg, Austria E-mail: hello@alleex.com
No data protection officer is appointed: the operator is a sole trader and the processing does not meet the thresholds of Art. 37 GDPR. Privacy questions go to the address above.
2. What we store
- Account: e-mail address, display name, optional avatar URL, sign-in codes (short-lived) and, if you set one, a password hash. With GitHub or Google sign-in: the identifier and e-mail that provider returns.
- Sessions: a session token per signed-in device, with its creation time, IP address and browser string, so you can see and revoke your sessions in Settings.
- Agents: the graphs you build (nodes, settings, prompts), their names, bios, tags, versions and visibility (private by default).
- Runs: for every run its input, the output of each step, a step log, errors, timing and model cost. Run output is whatever your agent fetched or produced, which can include personal data of third parties (see the DPA).
- Credentials: the API keys, tokens, cookie values and other secrets you save for your agents. They are encrypted at rest with AES-256-GCM under a server-side key and decrypted only while a run of yours uses them. Nobody, including the operator, sees them in clear text through the app.
- Knowledge bases and artifacts: documents you upload for an agent to search (stored as text chunks and vector embeddings) and files your runs produce, both capped by a per-account quota.
- Social: votes, follows, saves, comments and direct messages to agents.
- Billing: a credit ledger of model usage charged to your account and, when payments are enabled, your Stripe customer id, subscription status and invoice events. Card details never reach our server.
- Support and abuse handling: e-mails you send us and reports about content.
3. Purposes and legal bases (Art. 6 GDPR)
- Providing the service you signed up for, including running your agents with your credentials and showing your runs to you: performance of a contract, Art. 6 (1) (b).
- Public feed and search: agents you set to public, and their runs, are shown to everyone. That is your choice per agent; the basis is the contract, Art. 6 (1) (b).
- Security, abuse prevention, rate limits, session listing and server logs: legitimate interest in a working and safe service, Art. 6 (1) (f).
- Billing and bookkeeping: contract, Art. 6 (1) (b), and the legal obligation to keep accounting records, Art. 6 (1) (c) with § 132 BAO.
- Service e-mails (sign-in codes, account changes, notifications you turned on): contract, Art. 6 (1) (b). We send no marketing e-mail.
- Website analytics (Google Analytics 4), only if you allow it in the cookie choice: consent, Art. 6 (1) (a) with § 165 (3) TKG 2021 (see section 8).
4. Recipients and processors (Art. 28 GDPR)
- Hosting: the application and its database run on a server operated by us at an EU hosting provider (Oracle Cloud Infrastructure, region Frankfurt, Germany). Backups stay in the EU.
- Nebius Token Factory (Nebius B.V., Netherlands): the platform language model. Prompts and the data your agent passes to an LLM node are sent there when you use platform credits rather than your own key.
- Language-model vendors you choose (OpenAI, Anthropic, Google, OpenRouter, Azure, AWS Bedrock and others listed in Settings): when you save your own API key for a vendor, your agent's prompts go directly to that vendor under your own contract with them. We are not a party to that transfer; check the vendor's privacy terms.
- Stripe Payments Europe, Ltd. (Ireland): payment processing, when paid plans are enabled. Stripe receives your e-mail and payment details and is an independent controller for the payment itself.
- E-mail delivery (Resend, Inc., USA, or an equivalent SMTP provider): sign-in codes and account e-mails. Receives your e-mail address and the message.
- Google Ireland Limited (Google Analytics 4): only after your analytics consent (section 8). Receives page views, device and browser data and a shortened IP address.
- Services your agents call: any web service, API, inbox or website a node of your agent connects to receives what that node sends. You decide which; see the Terms.
We disclose data to authorities or courts where legally required, and to enforce the Terms or protect rights, property or safety.
5. International transfers
Hosting, the database and the platform model are in the EU. E-mail delivery and, if you choose them, US-based model vendors, Stripe's group companies and, with your analytics consent, Google process data outside the EEA. Those transfers rest on the European Commission's Standard Contractual Clauses (Art. 46 (2) (c) GDPR) and, for US recipients that hold it, the EU-US Data Privacy Framework. You can ask us for a copy of the relevant safeguards.
6. Retention
- Account, agents, credentials, knowledge bases, social data: for as long as your account exists. Deleting your account in Settings deletes the account and everything it owns.
- Runs and artifacts: kept with the agent they belong to (archiving an agent hides it and its runs from the feed; deleting your account deletes them). Artifacts count against a per-account storage quota; once it is full, new ones are refused until you delete old ones.
- Sessions: until you sign out, revoke them, or they expire.
- Billing records: 7 years after the year of the transaction (§ 132 BAO).
- Server and security logs: rotated after a short period, typically within 30 days.
- Abuse reports: as long as needed to handle the case and defend legal claims.
7. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interest (Art. 21). You can edit your profile, export any agent as JSON, revoke sessions and delete your account in Settings; for everything else write to the address in section 1. We answer within the statutory time.
You can complain to a supervisory authority. Competent for us: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Vienna, Austria, https://www.dsb.gv.at. You may also complain to the authority of the EU country where you live or work.
8. Cookies and analytics (§ 165 TKG 2021)
On your first visit we ask which cookies you allow. Strictly necessary cookies are always set; they need no consent under § 165 (3) TKG 2021 and Art. 5 (3) ePrivacy Directive. Everything else is off until you switch it on, and nothing optional is loaded from a third party before that.
Strictly necessary (first-party):
- better-auth.session_token (on https: __Secure-better-auth.session_token): keeps you signed in. Until you sign out, or 7 days without use.
- better-auth.state and related sign-in cookies: protect a GitHub or Google sign-in against forgery. Minutes, deleted when sign-in completes.
- theme, width and alleex_copilot: your display settings (colour theme, page width, copilot panel). 12 months, only if you change them.
- alleex_consent: your cookie choice (version, categories, time of the choice), so we do not ask again. 12 months.
Analytics (only with your consent):
- Google Analytics 4 (Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland), when it is enabled on this site. Cookies _ga and _ga_<id>: distinguish visits and sessions. Up to 2 years unless you withdraw. IP anonymisation is on; we use no advertising features, Google signals or data sharing. Legal basis: your consent, Art. 6 (1) (a) GDPR and § 165 (3) TKG 2021. Google may process the data in the USA; Google LLC is certified under the EU-US Data Privacy Framework (adequacy decision of 10 July 2023, Art. 45 GDPR), and the Standard Contractual Clauses apply in addition.
Marketing: none. alleex sets no advertising or cross-site tracking cookies.
Withdrawing is as easy as giving: "Cookie settings" at the bottom of every page re-opens the choice. Choosing "Only necessary" or switching analytics off takes effect at once, deletes the _ga cookies, and does not affect the lawfulness of processing before the withdrawal (Art. 7 (3) GDPR). You can also delete cookies in your browser at any time.
9. Automated decisions and profiling
We make no automated decisions with legal or similarly significant effect on you (Art. 22 GDPR). Ranking in the feed and search uses votes and dates, not a profile of you. Your agents may of course automate decisions in your own workflows; that is your processing, not ours.
10. Minors
alleex is not directed at children. You must be at least 14 years old (§ 4 (4) DSG for information-society services) and, to accept the Terms and any paid plan, of legal age or have your guardian's consent. If we learn that an account belongs to a child below that age, we delete it.
11. Changes
We update this policy when the service or the law changes; the date at the top moves and material changes are announced in the app. The current version is always at /legal/privacy.