Sarala AI

Legal

Privacy Policy

Last updated:

In short: we collect only what we need to run your account and the services you ask us to run. We do not sell your data, we show no ads, and we do not train AI models on your content. You can ask us to correct or erase your data at any time by writing to team@sarala.ai.

Who we are

This policy is issued by Sarala AI (OPC) Private Limited (CIN U62011AP2026OPC128608), referred to as “we” or “us”. For the personal data described here we act as the “Data Fiduciary” under India’s Digital Personal Data Protection Act, 2023 (the DPDP Act). Our contact point for privacy questions, requests and grievances is team@sarala.ai.

What this policy covers

This policy covers:

  • the Apex Community cockpit, the hosted, multi-tenant workspace where you sign in, create organisations and run agents (the “cockpit”);
  • the design tool we host alongside it for those organisations;
  • our websites at sarala.ai and getapex.dev (the “websites”).

Software you download and run yourself, on your own machines or in your own cloud account, does not send data to us unless you set it up to. This policy does not cover third-party services you connect, such as your cloud provider, your code host or your model provider. Their own policies apply to them.

What we collect and why

Account and sign-in

  • What: your name, email address, profile picture, and the identifier your sign-in provider gives us (GitHub, or Google where we have enabled it). If you sign in with an email and password, we also keep a salted hash of the password, never the password itself.
  • Session records: a session token, the IP address and browser details (user agent) of each session, and when it expires.
  • Why: to identify you, keep you signed in, and protect the account. If a sign-in provider confirms an email address that matches an existing account, we link the two sign-ins to the same account.

Organisations, products and the work you do in them

  • What: the organisations, products, agents, tasks, comments, conversations with agents, run outputs and logs, and settings that you or your teammates create in the cockpit.
  • Why: to provide the service you asked for. This is your content, and we treat it as yours.

Keys, credentials and connections

  • What: secrets you choose to store, such as a model provider key or a cloud credential, and the connection tokens issued when you connect GitHub or Google Cloud (see the sections below). These are stored encrypted. A connection record also holds the account email, the scopes granted, its status and expiry times.
  • Why: so that agents and workflows can act with the access you give them, and only as you.

Usage, cost and audit records

  • What: for each model call, the provider, model, token counts and cost; for each run, metadata such as when it started, how long it ran, the resources it used and which organisation it belongs to; and an activity log recording who did what, and when, inside an organisation. When a stored connection is used, that use is logged.
  • Why: to show you what your organisation spent and did, to keep the work inspectable, to enforce usage limits, and to detect and investigate abuse or errors. We may look at run metadata for abuse detection, but not at the content of your runs unless one of the reasons in the “Who can see your data” section applies. We do not collect usage data about you from your browser for advertising or product analytics.

Design tool

When an organisation uses the design tool, we create a matching team and account for its members in it, using their names and email addresses, and it stores the designs they make.

Telemetry you send us

If you connect your own application to our evaluation service, it receives the traces, logs and metrics that your application sends. What is in them is decided by your application, so please do not send personal data you do not need to. Each connection uses a key scoped to one organisation, product and project.

The websites

The websites are static pages. They set no cookies and run no analytics or advertising tools. Like any web service, our hosting provider handles ordinary request information (such as your IP address and the page requested) to deliver the pages and keep them secure.

Getting in touch

If you email us, we keep the message and your address so we can reply and keep a record of the conversation.

Google user data

We use Google in two separate ways, each with its own OAuth client.

Signing in with Google

Where Google sign-in is enabled, we request the scopes openid, email and profile. These give us your name, email address, profile picture and a Google account identifier. We use them only to create and sign you in to your account. We do not keep the access, refresh or ID tokens Google issues for sign-in.

Connect Google Cloud (optional)

If you choose to connect a Google Cloud account, we ask for the scopes openid, email and https://www.googleapis.com/auth/cloud-platform, and ask Google for offline access so that the connection keeps working. What we do with it:

  • What we store: your Google account email, the scopes granted, and the access and refresh tokens, encrypted. We store nothing else from your Google account.
  • What we use it for: only to act as you, in your own Google Cloud projects, on actions you ask for. Today that means listing the projects you can reach, checking your permissions on a project, and creating secrets (and new secret versions) in your project’s Secret Manager. Each use is recorded in the activity log.
  • What we do not keep: the list of your projects is shown to you and is not stored by us. We do not read your cloud resources or data for any other purpose.
  • Disconnecting: you can disconnect at any time. When you do, we ask Google to revoke the tokens and we clear them. A record that the connection existed, with the account email, remains (see Retention). You can also remove our access in your Google Account settings.

Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: we use Google user data only to provide or improve the features you ask for, we do not transfer it to others except as needed to run the service or as the law requires, we do not use it for advertising, and no person at Sarala AI reads it except where you ask for support, where it is needed for security or abuse investigation, or where the law requires.

GitHub

Signing in with GitHub gives us your name, email address, profile picture and GitHub identifier (the sign-in requests the read:user and user:email scopes). If you install our GitHub App on an account or organisation, we record the installation, the repositories you selected and the permissions GitHub reports. Repository contents are read from GitHub when you use a feature that needs them and are not copied into a separate store beyond what the work in the cockpit produces. If you authorise the app to act as you, we keep the resulting token encrypted, and use it only for actions you ask for, such as setting a secret in your repository. You can revoke access at any time in your GitHub settings.

What we do not do

  • We do not sell your personal data or your content, and we do not share it for advertising.
  • We show no ads and use no advertising or analytics trackers.
  • We do not use your content, your keys or your Google user data to train AI models.
  • We do not send your content to a model provider on our own account. Model calls made for your work use the provider and key your organisation chose, and what that provider does with the content is covered by your agreement with it.
  • We do not read your content as a matter of routine (see the next section).

Who can see your data

  • Members of your organisation see what its roles allow them to see.
  • Our service providers process data on our behalf, as listed below.
  • Us. The people who operate the service have the technical ability to reach data stored in it. We use that ability only to run and secure the service, to give support you ask for, to investigate abuse or a security problem, or because the law requires it. Stored secrets are encrypted, and each time one is used the use is logged.
  • Authorities. We may disclose data if a valid legal request or obligation requires it.

Cookies and local storage

We use only what is needed to make the cockpit work. We use no analytics, advertising or tracking cookies, so there is no cookie banner to dismiss.

Cookies and local storage used by the cockpit
NamePurposeLifetime
Session cookie (name begins with apex- and ends in session_token)Keeps you signed in. Marked HTTP-only and same-site, and secure on HTTPS.Up to 7 days, renewed while you use the service
apex_github_connect, apex_google_connectProtect the flow when you connect GitHub or Google Cloud, so the response is matched to your request.15 minutes
Browser local storageRemembers preferences such as theme, sidebar state, the product you selected, unsent drafts and a pending invitation.Until you clear it

The design tool is a separate application and sets its own cookies to keep you signed in. The websites set no cookies.

Service providers

We share data only with providers that help us run the service, or that you choose to connect.

Service providers that receive data
ProviderWhat forData involved
Google CloudHosting, database, file storage, secret storage, load balancing, DNS and logs, in its India regionAll data described in this policy
GitHubSign-in and the repositories you connectProfile details; repository data you choose to use
Google (identity)Sign-in with Google, where enabled, and Connect Google CloudAs described in the Google user data section
The model provider you choose (for example OpenRouter or Anthropic, through your own key)Running the agents of your organisationThe prompts, code and context your agents send
Penpot, the design tool, hosted by us on Google CloudDesign work for organisations that use itMember names and emails; designs

We do not use an email delivery service, a content delivery network or an advertising network.

Where data is kept and transfers

The cockpit’s database and storage are in Google Cloud’s India region (asia-south1). Some providers above, such as GitHub and your chosen model provider, process data in other countries. When your agents call a model provider you selected, or when you connect GitHub, the relevant content leaves India because you have asked it to. The DPDP Act permits transfers to other countries unless the Government restricts them, and we will follow any such restriction.

How we protect data

  • Secrets, such as model keys and connection tokens, are encrypted before they are stored, and the encryption key is held in a managed secret store separate from the database.
  • Sign-in tokens issued by Google and GitHub for the sign-in itself are not kept.
  • Secret values and sign-in headers are redacted from our application logs.
  • Traffic to the service is encrypted in transit with HTTPS. The database uses managed identity-based access.
  • Each use of a stored secret or connection is recorded.

No system is perfectly secure. If you find a weakness, please tell us as described on our Security page. If a personal data breach affects you, we will notify you and the Data Protection Board of India as the law requires.

Agents run code in sandboxes. A sandbox sees the keys and secrets given to that run, and the code in it can reach the internet. Please read the rules on compute and sandboxes in our Terms of Service.

Retention and deletion

  • Account and organisation data is kept while your account or organisation is active.
  • Run logs stored in file storage expire automatically after 90 days.
  • Backups of the database are kept for a short period for recovery, currently 7 days. Data you delete can remain in backups until they expire.
  • The activity log is kept as a permanent record of who did what in an organisation. Entries about governance, including each use of a connected account, are not deletable inside the product.
  • Disconnected connections: after you disconnect Google Cloud, the tokens are cleared, but a record with the account email and the status “revoked” remains.
  • Design files are stored until they are deleted; they do not expire automatically.

How to ask for deletion

Some deletion is available inside the cockpit today: you can delete your own stored secrets and API keys, agents, tasks and comments, disconnect connections, and a product’s owner can delete the product together with its data. The product does not yet let you delete a whole account or an organisation that has history, so for those, please write to team@sarala.ai from the email address on the account, with the subject “Deletion request”.

  • We will acknowledge your request within 7 days and tell you what we have done within 30 days.
  • What we remove: your profile details, sessions, linked sign-ins, stored secrets and connection tokens, and the content that belongs only to you. For an organisation that asks to close, we remove its products and their data.
  • What may remain: entries in the activity log and records that other members of an organisation rely on, which may refer to your account identifier; backups until they expire; and records we must keep by law. Where an account cannot be fully erased because of such records, we will disable it, revoke its access and remove the personal details we can, and tell you plainly what remains.

We may need to confirm that a request comes from you before acting on it.

Your rights and grievances

Under the DPDP Act you have the right to:

  • ask for a summary of the personal data we hold about you and how we use it;
  • ask us to correct or complete it;
  • ask us to erase it, subject to what the law lets us keep;
  • withdraw consent where we rely on it, which does not affect what we did before you withdrew;
  • nominate another person to exercise your rights if you die or cannot act for yourself;
  • have a grievance addressed.

To use any of these rights, or to raise a grievance, email team@sarala.ai. We aim to respond within 30 days. If we have not resolved your grievance, you may complain to the Data Protection Board of India.

Children

The service is not directed at anyone under 18, and you must be at least 18 to create an account. We do not knowingly collect personal data from children. If you believe a child has given us personal data, email us and we will delete it.

Changes to this policy

We may update this policy, for example when we add a feature that handles data differently. We will change the date at the top and, for material changes, show a notice in the service or on our websites before they take effect. Earlier versions are available on request.

Contact

Sarala AI (OPC) Private Limited, CIN U62011AP2026OPC128608. Email team@sarala.ai for any question about this policy or your data.