Draft — pending legal review

This document is a working draft and has not yet been reviewed by legal counsel. Last updated: 2026-06-12

Privacy Policy

Last updated: 2026-06-12

1. Data controller

The data controller for personal data processed in connection with the Anchras platform (anchras.com, the host agent, CLI, APIs, and related services — the “Service”) is Anchras, a company established in Belgium.

Contact for all privacy matters: privacy@anchras.com.

Where your organization uses the Service to manage its own infrastructure and the data flowing through it (for example workload contents, prompts sent through the AI gateway, or data stored on your machines), your organization is typically the controller of that data and Anchras acts as a processor on its behalf.

2. What data we process

Account data

  • Name, email address, password hash, organization name and membership, roles, and SSO identifiers when your organization uses single sign-on.
  • API key metadata and session/refresh-token records.

Infrastructure metadata and telemetry

  • Data reported by the Anchras agent installed on your machines: hostname, hardware and OS details (CPU, memory, storage, network interfaces), agent version, heartbeat and health status, and the state of resources managed through the platform (VMs, clusters, containers, volumes, networks).
  • Tailscale device names and tailnet addresses used to connect your machines.
  • Logs and metrics collected for the operation of resources you manage through the platform.

Billing data

  • Subscription, plan, and usage-metering records held by us; payment card and bank details are collected and processed directly by Stripe — we do not store full payment card numbers.

Audit logs

  • Records of actions taken in the platform (who did what, when, and from where — including user ID, action, resource, IP address, and timestamp), kept for security and accountability.

Support and communications

  • Messages you send us (email, support requests) and transactional emails we send you.

3. Why we process it (legal bases, art. 6 GDPR)

PurposeDataLegal basis
Providing the Service (accounts, control plane, agent)Account data, infrastructure metadata/telemetryPerformance of a contract (art. 6(1)(b))
Billing and invoicingBilling data, account dataPerformance of a contract (art. 6(1)(b)); legal obligation — tax/accounting (art. 6(1)(c))
Security, abuse prevention, audit loggingAudit logs, account data, IP addressesLegitimate interests (art. 6(1)(f))
Service communications and supportAccount data, communicationsPerformance of a contract (art. 6(1)(b)); legitimate interests (art. 6(1)(f))
Product improvement (aggregated/de-identified analysis)Telemetry, usage dataLegitimate interests (art. 6(1)(f))

We do not use your data for third-party advertising, and we do not sell personal data.

4. Sub-processors and recipients

We share personal data only with service providers needed to run the platform:

  • Stripe — payment processing and billing.
  • Tailscale — mesh networking between your machines and the control plane (device identifiers, tailnet metadata). If you bring your own Tailscale account, Tailscale processes that data under your own agreement with them.
  • Email delivery provider — transactional email (account, billing, and security notices).
  • AI model providers — only when you route requests through the Anchras AI gateway to an external model, the content of those requests is transmitted to the provider you selected. You control which providers are used and what is sent.
  • Hosting and infrastructure providers for the control plane.

Where sub-processors are located outside the European Economic Area, we rely on appropriate safeguards under chapter V GDPR (in particular the European Commission’s Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework). We may also disclose data where required by law.

5. Retention

  • Account data — kept while your account is active and deleted or anonymized within 90 days of account deletion, except where longer retention is legally required.
  • Infrastructure metadata and telemetry — kept while the related resource or organization exists; operational logs and metrics are retained for limited rolling windows.
  • Billing records — retained as required by Belgian tax and accounting law (generally up to 10 years).
  • Audit logs — append-only and retained for up to 2 years for security and accountability, unless a longer period is required for an ongoing investigation or by law.

6. Your rights (art. 15–22 GDPR)

You have the right to:

  • access the personal data we hold about you;
  • rectification of inaccurate or incomplete data;
  • erasure(“right to be forgotten”), subject to legal retention duties;
  • data portability — receive your data in a structured, commonly used, machine-readable format;
  • restriction of processing and objection to processing based on legitimate interests;
  • lodge a complaint with a supervisory authority — in Belgium, the Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données, www.dataprotectionauthority.be), or the authority of your habitual residence.

To exercise any of these rights, email privacy@anchras.com. Deletion and export requests are currently handled manually via that address — self-service tooling is not yet available. We will respond within one month, as required by the GDPR, and may need to verify your identity first.

7. Security

We apply technical and organizational measures appropriate to the risk, including encryption in transit, encryption of stored secrets and credentials (sealed with a key-management system), role-based access control, scoped and hashed API keys, short-lived session tokens, and append-only audit logging. Connectivity between your machines and the control plane runs over an encrypted Tailscale mesh. No system is perfectly secure; please report suspected vulnerabilities to security@anchras.com.

8. Cookies and similar technologies

The web application uses strictly necessary cookies and similar storage for authentication and session management (access and refresh tokens). We do not use third-party advertising or cross-site tracking cookies.

9. Automated decision-making

We do not make decisions producing legal or similarly significant effects about you based solely on automated processing. Content you choose to send through the AI gateway is processed by the model provider you select, under your control.

10. Children

The Service is a B2B product and is not directed at children. We do not knowingly process personal data of anyone under 16 except as incidental to business use by their employer.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced by email or in-product notice before they take effect. The “last updated” date at the top reflects the latest revision.

12. Contact

Anchras (Belgium) — privacy contact: privacy@anchras.com. See also our Terms of Service.