Sapilon becomes publicly available on 15 November 2026: 50 days to go. The core goes open source the same day →

Legal

Privacy Policy

We collect little, we don't sell it, and we don't train AI models on your data. Here is exactly what we do.

Last updated: September 17, 2026

Working draft. This document is pending formal legal review ahead of public availability on 15 November 2026. It reflects how we actually operate today, but wording may change once counsel signs off.

1. Who we are

Sapilon operates this website (sapilon.com) and the Sapilon platform. For personal data described in this policy, Sapilon is the controller, except for the content of your projects on the platform, where you are the controller and we act as your processor under the Data Processing Agreement. Contact us at we@sapilon.com with any privacy question or request.

2. What we collect

On the website

  • Contact details you send us: email address and, if you provide it, your name and company. This includes the email address and company of anyone who joined our former waitlist, which is now closed.
  • Anonymous analytics (Google Analytics 4), loaded only after you consent via the cookie banner.

On the platform

  • Account data: name, email, company, sign-in and billing records.
  • Project content: the code, prompts, artifacts, and data you bring to or create in your projects. We process this on your instructions as your processor; it may incidentally contain personal data you control.
  • Usage and audit records: actions taken by you and by the AI in your projects. Keeping this trail is a product feature: every AI action is logged, diffable, and reversible.
  • Payment data: wallet top-ups are handled by our payment provider (Stripe); we receive transaction confirmations, never full card numbers.

3. How we use it

  • To provide the service: operating your account, projects, environments, and the experts marketplace (performance of contract).
  • To respond to you: support and contact requests, and telling former waitlist members once Sapilon is publicly available (legitimate interest or pre-contractual steps).
  • To bill you: wallet, invoices, tax records (contract and legal obligation).
  • To keep the platform secure: audit trails, abuse prevention (legitimate interest).
  • To understand site usage: consent-gated analytics (consent).

We do not sell personal data, and we do not use your data for third-party advertising.

4. Cookies & analytics

We use Google Analytics 4 to understand website usage. Analytics cookies load only after you opt in through the cookie banner; declining does not limit the site in any way. We honor Google Consent Mode, and you can change your choice at any time by clearing the site's cookies. The platform sets the strictly necessary cookies needed to keep you signed in.

5. AI processing

AI work on the platform is performed by Anthropic's Claude models, run on Amazon Bedrock in AWS regions in the European Union. When you or the platform's agents run AI tasks, the relevant prompts and project content are processed by AWS inside those regions and are not shared with Anthropic. Amazon Bedrock does not store prompts or outputs and does not use them to train models. Neither Sapilon, AWS nor Anthropic trains AI models on your code or data. AI activity in your projects is recorded in your project's audit trail so you can inspect and reverse it.

6. Sharing & sub-processors

We share personal data only with the service providers needed to run Sapilon, under data-processing terms:

  • AWS: hosting for the platform and your environments, and AI model processing (section 5).
  • Stripe: payment processing.
  • Google: consent-gated website analytics.

The current list, purposes, and locations are maintained in the DPA. Beyond these, we disclose data only if the law requires it, and we will tell you when we are allowed to.

7. International transfers

Platform data is hosted in AWS regions in the European Union by default. Where a sub-processor processes data outside the EU/EEA (for example, parts of Stripe's infrastructure), the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision.

8. Retention

  • Contact data: as long as needed to respond to you, then deleted. Former waitlist entries are kept only to tell those people that Sapilon is publicly available, then deleted.
  • Account and project data: for the life of your account; after termination we keep project data available for export for at least 30 days, then delete it.
  • Billing records: as long as tax law requires.
  • Analytics: per the GA4 retention settings, capped at 14 months.

9. Your rights (GDPR)

If you are in the EU/EEA (and in many other places), you have the right to access, correct, delete, and export your personal data, to restrict or object to processing, and to withdraw consent at any time without affecting prior processing. Email we@sapilon.com and we will respond within one month. You also have the right to lodge a complaint with your local supervisory authority. For personal data inside your projects, where you are the controller, we will refer requests from your users to you and assist as the DPA describes.

10. Security

Data is encrypted in transit and at rest, environments are isolated, and AI actions are constrained by ownership zones and recorded in audit trails. The Trust & Security page describes our practices in detail, including how to report a vulnerability.

11. Changes & contact

We will update this policy as the product evolves and note the date at the top of the page; material changes are announced to account holders by email. Questions, requests, or concerns: we@sapilon.com.