Privacy Policy
Last updated: 2025-10-31
Introduction
anycast.io UG (haftungsbeschränkt) is committed to protecting your privacy. This policy explains our data collection and usage practices for our AI-powered anomaly detection service. We take a privacy-first approach: we do not store any files you upload for analysis.
Data We Collect
Account and Profile Data
- Account information (email, name, password hash)
- Profile settings (avatar, language preferences)
- Account status (confirmed, suspended, deleted flags)
- Role and permissions (user/admin)
- Marketing email preferences
- Beta feature access flags
- Two-factor authentication status (if enabled)
Usage and Activity Data
- File metadata (filename, size, type) - files themselves are deleted immediately
- Analysis results and anomaly reports
- AI model usage (tokens consumed, costs incurred)
- API usage statistics and rate limiting data
- Activity logs and audit trails
- Last sign-in time and IP address
- Session information and authentication tokens
Organization Data
- Organization name and identifier
- Team member relationships and roles
- Organization-level settings and preferences
- Invitation status and history
Technical and Analytics Data
- Browser type and version
- Device information and operating system
- Page views and navigation patterns
- Button clicks and form interactions
- Scroll depth and engagement metrics
- Error logs and performance data
- Feature usage analytics via Plausible Analytics
Payment and Billing Information
- Customer ID from payment processor (Stripe)
- Subscription status and plan details
- Billing history and invoices
- Usage-based billing events and meter data
- Payment method type (card brand, last 4 digits)
- We do NOT store full credit card numbers
Important: File Processing
- Files are analyzed in memory and immediately deleted
- We never store your uploaded files
- No file content is retained after analysis
- Analysis results contain only anomaly information, not raw data
How We Use Your Data
- Provide anomaly detection services
- Generate analysis reports
- Process payments and manage subscriptions
- Send service-related communications
- Improve our AI models and detection accuracy
- Ensure service security and prevent abuse
Data Storage and Security
- All connections use HTTPS encryption
- Zero file retention policy - files deleted immediately after processing
- Analysis results stored securely with encryption
- Regular security audits and updates
- Access limited to authorized personnel only
Third-Party Services
We integrate with the following third-party services:
Payment Processing
- Stripe: Payment processing, subscription management, and billing (see Stripe’s privacy policy)
AI and Machine Learning
- OpenAI: GPT models for text analysis and anomaly detection
- Anthropic: Claude models for advanced analysis capabilities These providers process data transiently and do not store your files.
Authentication Providers
- Google OAuth: Optional social login (if enabled)
- GitHub OAuth: Optional social login (if enabled)
Infrastructure and Analytics
- Plausible Analytics: Privacy-focused usage analytics (no cookies required)
- Postmark: Transactional email delivery
- Sentry: Error tracking and performance monitoring (anonymized)
Optional Storage Services
- Cloudinary: Profile avatar storage (if configured)
- Amazon S3: File storage for exports (if configured)
All third-party services are selected for their privacy practices and compliance with data protection regulations.
Cookies and Analytics
Essential Cookies
We use strictly necessary cookies for:
- User authentication and session management
- Security features (CSRF protection)
- Language preferences
- Temporary form data storage
Analytics
We use Plausible Analytics, a privacy-focused analytics tool that:
- Does NOT use cookies
- Does NOT track users across websites
- Does NOT collect personal information
- Is fully GDPR compliant
We track aggregated metrics including:
- Page views and visitor counts
- Traffic sources and referrers
- User interactions (clicks, form submissions)
- Feature usage patterns
- Conversion goals for service improvement
You can opt out of analytics by using browser privacy features or ad blockers.
Your Rights
Under GDPR and applicable laws, you have the right to:
- Access your personal data
- Correct inaccurate data
- Request data deletion
- Export your data
- Object to data processing
- Withdraw consent at any time
Data Retention
- Account data: Retained while account is active
- Analysis results: Available in your account history
- Uploaded files: Deleted immediately after processing
- Payment records: As legally required
International Data Transfers
We primarily process data within the EU. Any international transfers comply with GDPR requirements and appropriate safeguards.
Children’s Privacy
Our service is not intended for children under 16. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy from time to time. We will notify you of significant changes via email or website notification.
Contact Us
For privacy-related questions or to exercise your rights, please contact us at:
support@ainomaly.io