Aupretor Privacy Policy

Last updated: September 28, 2026

1. Overview & Privacy Commitment

At Aupretor Inc. (“Aupretor,” “we,” “our,” or “us”), we take your privacy and the confidentiality of your business operations seriously. This Privacy Policy describes how we collect, process, store, and safeguard personal and business data when you use the Aupretor website (aupretor.com), mobile or desktop interfaces, and AI operator features (the “Service”).

Our fundamental commitment is straightforward: Your business data belongs to you. We do not sell your personal data, and we do not use your customer communications or business graph records to train public artificial intelligence models.

2. Information We Collect

We collect information necessary to operate your business workspace, facilitate customer communications, and orchestrate automated business actions:

2.1 Account & Identity Information

  • Your name, email address, password hash, and profile image.
  • Authentication identifiers provided by third-party sign-in providers (e.g., Google OAuth).
  • Business profile details: workspace name, business category, currency, and operating preferences.

2.2 The Business Graph (Operational Data)

To serve as your AI business operator, Aupretor stores a structured representation of your daily business activities:

  • Customers: Contact names, phone numbers, email addresses, and client notes.
  • Conversations: Inbound and outbound message transcripts across connected channels (WhatsApp and Instagram).
  • Work Items: Quotes, jobs, tasks, appointments, orders, and delivery statuses.
  • Financial Records: Transaction logs, recorded payments, outstanding balances, and invoice records (payment card data itself is handled directly by Bachs).
  • Business Memory: Guidelines, operating rules, price lists, and workflow policies you save to guide the AI operator.

2.3 Usage & Diagnostic Telemetry

We collect technical diagnostics to ensure platform reliability and measure feature adoption:

  • Device type, browser version, operating system, and IP address.
  • Application interaction events (e.g. pages visited, features opened, actions dispatched).
  • Aggregated error logs and diagnostic stack traces.

3. How We Use Information

We process collected data exclusively for valid business purposes:

  • Powering Your AI Operator: Providing real-time situational awareness (“Today” surface), surfacing overdue work, drafting customer replies, and executing delegated actions.
  • Channel Integration: Routing customer messages between Aupretor and external platforms (such as WhatsApp and Instagram).
  • Workspace Security: Authenticating users, verifying tenant boundaries, and preventing fraudulent or unauthorized activities.
  • Customer Support & Billing: Managing subscriptions, processing billing cycles, and resolving technical inquiries.
  • Product Quality: Monitoring platform performance, preventing regressions, and identifying workflow bottlenecks.

4. AI Model Processing & Zero-Training Policy

Aupretor leverages large language models (LLMs) and intelligent reasoning algorithms to analyze business data and execute delegated tasks. We enforce strict data protection controls:

  • No Foundation Model Training: Your business records, customer transcripts, and operational documents are never used to train, retrain, or improve public foundation models (such as models from OpenAI, Anthropic, or Meta).
  • Transient Processing: Data submitted to AI models for inference is handled securely via commercial APIs with zero-data-retention agreements where available. The LLM processes the immediate context and discards the prompt payload after completing the request.
  • Tenant Isolation: Your business memory, customer data, and work items are strictly partitioned in our database using tenant-scoped identifiers (businessId). AI prompts are only provided context from your explicit workspace.
  • Human-in-the-Loop Confirmation: Any high-consequence operation (such as processing payments or broadcasting messages) requires your explicit review before the operator takes action.

5. Cookies & Tracking Technologies

We use cookies and standard web storage mechanisms to provide a secure and seamless application experience:

5.1 Essential Session Cookies

Strictly necessary for security and authentication. Managed through Better Auth to identify active user sessions, prevent cross-site request forgery (CSRF), and enforce tenant permissions. These cannot be disabled as the Service cannot function without them.

5.2 Privacy-Preserving Analytics (PostHog)

We use PostHog for product telemetry and user flow analysis. To maximize data privacy:

  • Reverse Proxy Ingestion: Telemetry is routed through our first-party proxy (/ingest/*) hosted on EU Cloud infrastructure.
  • Full Input Masking: PostHog Session Replay enforces strict client-side input masking (maskAllInputs: true). Text entered into password fields, sensitive inputs, and forms is masked on your device and never transmitted in plain text.
  • No Cross-Site Ad Tracking: We do not deploy third-party advertising cookies, data brokers, or retargeting pixels on your workspace dashboard.

6. Data Sharing & Third-Party Processors

We do not sell, rent, or trade your data. We share data only with trusted infrastructure subprocessors bound by strict data processing agreements:

  • Convex Inc.: Real-time reactive backend and multi-tenant database infrastructure.
  • Bachs: Subscription billing engine and payment processing. Aupretor does not store credit card numbers.
  • PostHog (EU Cloud): Self-hosted proxy analytics and product observability.
  • Meta (WhatsApp & Instagram APIs): Facilitates direct customer communications when you connect your social business accounts.
  • Cloudflare & Vercel: Edge routing, web hosting, DDoS protection, and secure SSL/TLS termination.

7. Tenant Isolation, Security & Data Retention

We maintain technical and organizational measures to safeguard your business information:

  • Multi-Tenant Isolation: Every database query and mutation verifies session authenticity and tenant membership before executing, preventing cross-tenant data access.
  • Encryption: Data in transit is encrypted using TLS 1.3. Data at rest is encrypted using industry-standard AES-256 encryption.
  • Data Retention: We retain your business graph and customer records for as long as your workspace remains active. When you delete your account or specific records (e.g. customers, work items), they are promptly scrubbed from primary storage in accordance with our deletion protocols.

8. Your Rights & Data Choices

Depending on your jurisdiction (such as under the GDPR or CCPA), you possess specific rights regarding your personal and business data:

  • Access & Export: You can request a machine-readable export of your customer database, work records, and transaction history.
  • Correction: You can edit and update business details, customer profiles, and team members at any time via your workspace.
  • Deletion: You can request full deletion of your account, business workspace, and associated records by contacting [email protected].
  • Opt-Out of Non-Essential Communications: You can unsubscribe from product updates and marketing emails via the unsubscribe link in any promotional message.

9. International Data Transfers

Aupretor operates globally and utilizes distributed cloud servers in the United States and the European Union. If you access the Service from outside these regions, your data may be transferred, stored, and processed internationally in accordance with standard contractual clauses and recognized transfer mechanisms.

10. Updates to This Policy

We may update this Privacy Policy periodically to reflect enhancements to our service or evolving legal requirements. Material changes will be highlighted with an updated “Last updated” timestamp and notified via email or an in-app notice. We encourage you to review this page regularly.

11. Contact Information

If you have questions, data protection requests, or inquiries regarding our privacy practices, please contact our team: