PRIVACY

Last updated: August 17, 2026

This page describes the information the current AStack application and control plane are designed to process and store. It does not claim certifications or controls that have not been independently verified.

INFORMATION STORED BY THE CONTROL PLANE

Account and access

  • Email, name, company, account status, and authentication identifiers
  • Billing plan, credit balance, and payment reference identifiers
  • API-key name, prefix, permissions, status, limits, and a one-way key hash
  • Account creation, update, and last-login timestamps

Sessions and usage

  • Session, customer, worker, and optional end-user identifiers
  • Session status, connection type, timestamps, duration, cost, and credits consumed
  • Usage records, service logs, errors, security events, and performance telemetry
  • Browser and request information included in application or security logs

CONVERSATION PROCESSING

During an active session, the runtime can receive audio, text, and images from the browser. It uses that input for speech recognition, voice activity detection, language generation, speech synthesis, and rendered facial animation.

  • The database schema stores session and usage metadata; it does not define a customer media library.
  • Runtime and evaluation tools can create temporary recordings and diagnostic artifacts when those tools are enabled.
  • Do not send secrets or information that is not required for the conversation.

HOW INFORMATION IS USED

  • Create, authenticate, route, expire, and clean up sessions
  • Run the conversational and rendering pipeline
  • Measure usage, calculate charges, apply credits, and display dashboard records
  • Diagnose failures, enforce API-key permissions and rate limits, and investigate abuse
  • Respond to messages submitted through the support form

CURRENT RETENTION SETTINGS

Session records90 days before archive and deletion
Usage records180 days before archive
Non-critical security events90 days before archive
Security events365-day hard deletion limit

Account, credit-ledger, and payment-reference records do not currently have an automatic deletion deadline documented in the application schema. An account can record a deletion request for administrative handling.

SECURITY BOUNDARIES

  • Long-lived API keys are intended for server-side use and are stored as hashes.
  • Browsers receive time-limited session credentials and signed renderer player URLs.
  • Database access is restricted through service roles, authenticated operations, and row-level policies.
  • AStack has not published a SOC 2 report, uptime SLA, or independent penetration-test result.

SERVICE PROVIDERS AND CONTACT

The application uses external providers for authentication and database services, website hosting, payment processing, email delivery, container storage, and GPU runtime capacity. The selected runtime provider can change between development, evaluation, and launch deployments.

To ask what data is associated with your account or request an account action, use the support form. Do not include API keys or session secrets.