Aplite.ai

Privacy Policy

Last updated: July 8, 2026

Aplite is a personal AI workspace: hosted agents that read and write a markdown vault, chat with you, and run automations on your behalf. This policy explains what personal data we process when you visit our website or use the app, why we process it, who receives it, and what rights you have. It is written to be read, not just scrolled past.

The short version: your workspace lives on our own servers in the United States, run by an Estonian company under EU data-protection law. Your notes and chats go to the AI model you picked — under API terms that exclude training — and nowhere else. We run no advertising, no cross-site tracking, and no third-party analytics, and we never sell data.

1. Who is responsible

The controller within the meaning of the EU General Data Protection Regulation (GDPR) is:

PIKsolution OÜ
Nisu tn 25-25, Põhja-Tallinna linnaosa, 10317 Tallinn, Estonia
Email: support@aplite.ai

For anything in this policy — questions, requests, complaints — email us. We answer.

2. What data we process

Account data

When you register: your email address, display name, and either a password (stored as a bcrypt hash — we cannot read it) or, if you sign in with Google, the basic profile Google shares with us (name, email address, profile picture). We verify your email address before activating email/password accounts.

Workspace content

Your notes and uploaded files, agent configurations and prompts, chat history, agent memory, automations, and the activity log of what your agents did. This content may contain any personal data you choose to put into it — what goes into your vault is entirely up to you. Each workspace runs in its own isolated instance; no other customer's agents or account can reach it.

Billing data

Your plan, credit balance, and a ledger of credit grants, purchases, and usage. Payments are handled by our merchant of record (see section 5) — we never see or store your card number. We receive order confirmations and subscription status.

Technical data

IP address and request metadata in server logs and short-lived rate-limiting counters (abuse protection), error reports in our self-hosted error tracker, and the operational status of your workspace instance.

Product analytics

To see where people get stuck, we record our own page views and clicks on this website and in the app: the page, the button, a coarse country from the request, a truncated browser string, and two random ids — one kept in your browser's local storage, one for the current tab — that let us tell one visit from another. IP addresses are never stored in this record; only a salted hash, which we cannot turn back into an address. It runs on our own servers, the ids mean nothing outside Aplite, and nothing is shared with an advertising or analytics company.

3. Why we process it (legal bases)

PurposeDataLegal basis (GDPR)
Providing the service — hosting your workspace, running your agents, syncing your vault Account data, workspace content Art. 6(1)(b) — contract
Billing, invoicing, tax records Billing data Art. 6(1)(b) contract; Art. 6(1)(c) legal obligation
Security — rate limiting, abuse prevention, error monitoring Technical data Art. 6(1)(f) — legitimate interest in a secure, working service
Product analytics — understanding how the signup flow and the app are used Product analytics data Art. 6(1)(f) — legitimate interest in improving our own product; first-party only, no profiling
Transactional email — verification, receipts, service notices Email address Art. 6(1)(b) — contract
Product news (only if you opt in) Email address Art. 6(1)(a) — consent, withdrawable anytime

4. AI processing — where your prompts go

When you chat with an agent or one of your automations runs, the relevant content — your messages, the notes and files the agent reads, tool results — is sent to the AI model you selected. Requests are routed through OpenRouter (OpenRouter, Inc., USA) to the model's provider, such as Anthropic, OpenAI, or Google.

Web searches performed by your agents are proxied through our self-hosted search service; upstream search engines receive the query but no account identity.

5. Who receives data (processors)

We keep the list short and use our own infrastructure where practical. Error tracking and agent web search run on our own servers — no third party involved.

RecipientRoleLocation
Hetzner Online GmbH Server hosting — all workspace data, database, and backups live here USA (Oregon); provider established in Germany
OpenRouter, Inc. & the model providers behind it Routing agent requests to the AI model you chose (section 4) USA
Polar (polar.sh) Merchant of record — checkout, subscriptions, invoices, VAT. Card data is handled by Polar and its payment processors, never by us EU / USA
Resend, Inc. Delivery of transactional email (verification, notices) USA
Google Ireland Ltd. "Sign in with Google", if you use it. Nothing else — web fonts are served from our own domain, so a plain visit to this website contacts no Google server EU / USA

6. Integrations you connect

Aplite can connect to services like Telegram, Slack, Gmail, Google Calendar, Google Drive, Notion, or GitHub. These integrations are off until you connect them. When you do, data flows between Aplite and that service as required for the feature you configured — e.g. an agent sending your morning digest to Telegram — under that service's own privacy terms. You can disconnect any integration at any time in your settings.

Aplite's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

7. International transfers

We are established in Estonia (EU) and process your data under the GDPR, but the servers holding your workspace and its backups stand in the United States, as do several of the processors listed above. For every transfer outside the EU/EEA we rely on EU Standard Contractual Clauses and, where the provider holds one, an EU–US Data Privacy Framework certification. A European hosting region is planned; this page will say so on the day it exists, not before.

8. How long we keep data

9. How we protect it

10. Cookies and local storage

The app uses only cookies that are strictly necessary to keep you signed in (session cookies). This website sets no cookies at all. Both do store the two analytics ids described in section 2 in your browser's local storage — no cookie, nothing sent to anyone else, and clearing site data removes them.

We use no advertising cookies, no tracking pixels, and no third-party analytics, and we do not follow you across other websites — which is why you don't see a cookie banner. Fonts, scripts and images all load from our own domain.

11. Your rights

Under the GDPR you have the right to:

To exercise any of these, email support@aplite.ai. You also have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU member state of your residence or workplace.

12. Age

Aplite is not directed at children. You must be at least 18 years old (or the age of digital consent in your country) to use it.

13. Changes to this policy

When we change this policy, we update it here with a new date. For material changes we notify you in the app or by email before they take effect.