Privacy Policy

Effective 1 August 2026

Our privacy policy is in two halves, and this is one of them. Together they are the whole picture; neither is complete on its own.

This half is about you as a customer — your Apilium account, your payments, our websites, who processes data for us, how long we keep it and how to have it erased. It is the company-level document, and your rights under it apply to everything we do.

The other half is about your notes — what the Altretta application holds, what synchronisation and hosted publishing do, and where an AI request goes. That is the Altretta Privacy notice, and it is where you find out what leaves your computer and what does not.

They are split this way because the answers are genuinely different. Almost everything about your account reaches us; almost nothing you write in Altretta does. Putting both in one document would make the second sound less true than it is.


1. Who we are

Apilium Technologies OÜ, a private limited company registered in Estonia under registry code 17409213, in Tallinn. We are the controller of the personal data described here.

We have not appointed a Data Protection Officer and are not required to. Privacy questions are answered by the company at [email protected].

2. Your account

You need an account to buy a paid plan and for nothing else. Our websites can be read, and Altretta can be downloaded and used, without one.

What we hold: your email address; your name, if you gave one; a hash of your password, or the identifier from the provider you used to sign in; your subscription and what you paid; and, for each device you activate, its fingerprint, host name, operating system and architecture, with the IP address and browser identifier of the request.

Why: to give you what you bought, to stop one licence being used on unlimited machines, to invoice you, and to answer you when you write to us. Most of that is performing our contract with you. Where it is not — keeping the service secure and working — it is our legitimate interest, and you can object to it.

3. Payments

Payments are handled by Stripe. We never receive or store your card details.

Stripe holds your name, your billing address and your payment method, and issues your invoices. Those invoices are also the accounting record we are required to keep.

4. When you write to us

Our contact, support and bug-report forms send us what you type: your name, your email address and your message. We use it to answer you and for nothing else, and we do not add you to a mailing list because you asked a question.

If you subscribe to our newsletter, we record your address, the date you subscribed and the wording you agreed to, so that we can show what you consented to. Every message carries a link that removes you.

5. Our websites

Our websites log what any web server logs — the page requested, the time, the IP address and the browser identifier — for security and to keep the site working.

Analytics run only if you accept them. The scripts are not loaded until you do, declining is as easy as accepting, and we honour Global Privacy Control and Do Not Track without asking you again. We do not use session recording, heatmaps or advertising trackers, and we do not sell or share anything with advertisers.

Your choice is stored in your browser and is per site, so a decision made on one of our domains does not carry to another. You can change it at any time from the cookie notice. The Cookie notice lists what is set and what it is for.

6. Who else processes data for us

ProcessorForWhere
DigitalOceanHosting, database, and storage for published sitesGermany
CloudflareServing and protecting every one of our domainsWorldwide edge network
StripePayments and invoicesIreland and the United States
BrevoThe emails the service needs: address confirmation, password reset, invitations, receiptsFrance

Cloudflare sits in front of every domain we run and terminates the encrypted connection, which means it handles every request to us. Stripe transfers to the United States under the European Commission's standard contractual clauses.

No AI provider is a processor of ours, because none of them receives anything through us.

7. How long we keep it

Your account and everything attached to it lives as long as your account does.

You can close your account from your settings, and we erase your personal data immediately — not on a schedule. We confirm the request with your password and a single-use code sent to your address, because being signed in is not on its own proof that it is you.

Two things survive, and only these: the invoices and accounting records Estonian law requires us to keep for seven years, held by our payment processor and still carrying the name and address they were issued to; and a one-way marker recording that an account at your address was closed, which cannot be turned back into your address and does not stop you signing up again.

Closing your account also takes down any sites you published. Anything in your vault is on your own computer and has never been ours to delete.

8. Your rights

You can ask us for a copy of your data, to correct it, to erase it, to restrict or object to what we do with it, and to receive it in a portable form. Where we rely on your consent, you can withdraw it as easily as you gave it.

Export and closure are both in your account settings. For anything else, write to [email protected] and we will answer within one month.

We do not charge for this. We may ask you to confirm your identity, so that we do not hand your data to somebody else.

If you think we have handled your data wrongly, please tell us — but you do not have to. You can complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), or to the supervisory authority where you live or work.

9. Children

Our services are not directed at children under 16, and we do not knowingly collect their data. If you believe a child has given us personal data, write to us and we will remove it.

10. Changes

If we change this policy in a way that affects your rights, we will tell you at least 30 days before it takes effect, at the address on your account. Every version carries the date it took effect.

11. Contact

[email protected] for anything in this policy.

Apilium Technologies OÜ · Tallinn, Estonia · Registry code 17409213