Privacy Policy
Effective date: August 11, 2026
1. Who we are
Apparae is a service operated by HumanAI Ventures Inc.("Apparae," "we," "us," "our"), a Delaware corporation. Contact: sharifocc@gmail.com. Mailing address: HumanAI Ventures Inc., 520 Douglas Street, Apartment 203, West Sacramento, CA 95605, United States. For GDPR inquiries, our Data Protection Officer contact is the same address and email.
2. What Apparae does
Apparae is an autonomous AI agency that runs marketing, product, engineering, and operations work on behalf of micro-SaaS founders. To do that, Apparae operates a team of AI agents that draft content, schedule social posts, generate documents, and execute tasks against third-party services that you connect (for example, your Facebook Page, Instagram Business account, X account, GitHub repository, or Stripe account).
3. Data we collect
3.1 Account data
- Email address and display name (via Google OAuth or email sign-up)
- Authentication tokens, hashed session identifiers
- Billing information (processed by Stripe; we store only the last four digits of your payment method and the Stripe customer identifier)
3.2 Business content you provide
- Your business idea, ICP worksheet, brand assets, uploaded documents
- Chat messages you send to Apparae agents
- Files stored in your Apparae working directory
3.3 Connected-service data
When you connect a third-party account (Facebook Page, Instagram Business account, X/Twitter, LinkedIn, GitHub, Stripe, Google Workspace, etc.), Apparae stores the OAuth access and refresh tokens needed to act on your behalf, plus metadata that account exposes (handle, display name, account identifier, page identifier, follower count where applicable).
Facebook, Instagram, and Threads data specifically: when you connect a Meta account, Apparae stores the Page/Business identifier, page access tokens, page name, and (for Instagram Business accounts) the account identifier and username. We use this data solely to publish, schedule, and analyze posts you or an Apparae agent explicitly initiate. We do not read your private messages, do not train models on Meta content, and do not sell or share Meta data with any third party except the sub-processors listed in Section 5.
3.4 Agent-generated content
Content that Apparae agents draft on your behalf (posts, emails, documents, code, analyses) is stored in your account and is your property.
3.5 Product telemetry
Standard product analytics: page views, feature usage, error reports. We use PostHog and Sentry as our analytics and error tracking sub-processors.
4. How we use your data
- To operate and provide the Apparae service
- To let Apparae agents execute tasks on your behalf against services you have connected
- To bill you and process payments
- To communicate with you about your account, product updates, and support
- To improve the service (aggregate analytics; not to train third-party foundation models)
- To comply with legal obligations
What we do NOT do: we do not sell your data. We do not use your business content or connected-service data to train third-party foundation models. We do not share your data with advertisers.
5. Sub-processors we share data with
Apparae uses the following categories of sub-processors. Each is contractually bound to process data only on Apparae's instructions and to maintain equivalent security standards:
- Cloud infrastructure: Google Cloud Platform (Cloud Run, Cloud Build, Secret Manager) — us-central1 and us-west1 regions
- Database and storage: Supabase (Postgres + Storage) — us-west-2 region
- Frontend hosting: Vercel — global edge network
- Large language models: Google Gemini (via Google AI Studio and Google Vertex AI) — prompts and completions transit these APIs to generate agent responses
- Social scheduling: Postiz (self-hosted by Apparae on Google Cloud) — never sends your data to Postiz-hosted infrastructure
- Payments: Stripe — payment method data lives with Stripe; we never touch full card numbers
- Email delivery: Resend — transactional emails only
- Analytics and error tracking: PostHog, Sentry, Langsmith (for LLM trace observability)
When Apparae acts against a connected third-party service (for example, publishing a post to your Facebook Page or your Instagram Business account), that service also receives your data in the course of the action, governed by that service's own privacy policy.
6. How long we keep your data
- Account data and business content: for as long as your account is active, plus 30 days after you request account deletion
- OAuth tokens for connected services: until you disconnect the service or delete your account
- Billing records: as required by applicable tax and accounting law (typically 7 years)
- Product telemetry and error logs: 90 days rolling
7. Your rights
Under GDPR (if you reside in the EEA, UK, or Switzerland) and CCPA (if you reside in California) — and as a matter of Apparae policy for all users — you have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Delete your account and personal data (see the Data Deletion page for instructions)
- Export your data in a machine-readable format
- Object to specific uses of your data
- Withdraw consent at any time
- Lodge a complaint with your local data protection authority
Email sharifocc@gmail.com to exercise any of these rights. We respond within 30 days.
8. Security
Data is encrypted in transit (TLS 1.3) and at rest. OAuth tokens are encrypted at the application layer with per-tenant keys. Access to production systems is restricted to authorized personnel and audited. If we become aware of a data breach affecting your account, we will notify you within 72 hours of discovery.
9. International transfers
Apparae is operated from the United States. If you access the service from outside the United States, your data will be transferred to and processed in the United States. For EEA/UK/Swiss users, transfers are covered by Standard Contractual Clauses where applicable.
10. Children
Apparae is not directed at children under 16 and we do not knowingly collect data from anyone under 16. If you believe a child has provided data to Apparae, please email us and we will delete it.
11. Changes to this policy
We may update this policy from time to time. Material changes will be announced by email to your account address at least 30 days before they take effect. The "Effective date" at the top of this page reflects the current version.
12. Contact
Questions about this policy or your data: sharifocc@gmail.com. Postal: HumanAI Ventures Inc., 520 Douglas Street, Apartment 203, West Sacramento, CA 95605, United States.
See also: Terms of Service · Data Deletion