Third Party Index

Snapshot 56682

Document
Privacy policy
URL
https://apiant.ai/privacy
Fetched
HTTP status
200
Content type
text/html; charset=utf-8
Fetch mode
static
Size
29328 bytes
SHA-256 (raw)
cf66db58dfc694def32683410c0bbbf580cd36bd1d288ad8a30271c7c1f42894
SHA-256 (normalized text)
5a3023d72e7cedae152e308a0357b72ea0dc9ba3921e00ab7da3e831091595a5

Normalized text

Scripts and page chrome removed; this is what change detection compares.

This Privacy Notice explains how APIANT, Inc. ("APIANT", "we", "us" or "our") collects, uses, shares and protects personal information when you:
visit apiant.ai or any website of ours that links to this notice (the "Site");
create or use an account on the APIANT.ai platform at app.apiant.ai (the "Platform"), including the in-app assistant;
connect an AI client, such as Claude Code, to the APIANT MCP server at mcp.apiant.ai;
fill in a form on the Site, apply for the beta, ask about Enterprise or Managed, or request an app; or
otherwise deal with us, for example by email, text message, WhatsApp or our Discord community.
It should be read with our Terms of Service. If you have questions, write to privacy@apiant.com.
1. Our two roles
Where we decide. For your account, billing, the Site, our forms, our sales and support conversations and our marketing, APIANT decides why and how personal information is processed. For that information we are the controller, and this notice describes what we do.
Where you decide. When you build and run automations, the Platform moves data between the apps you connect, on your instructions. That data can include personal information about your own customers, staff or contacts ("Customer Data", which our Terms of Service include in "User Data"). For Customer Data you decide what is processed and why, and we act on your behalf as a processor or service provider. You are responsible for having the right to process it and for telling the people concerned. Customers who need a data processing agreement can ask for one at legal@apiant.com.
2. What we collect
Information you give us
Account details: name, email address, password (stored only as a salted argon2id hash), company, and your multi-factor authentication settings.
Billing details: the plan you choose, your billing history and billing address. Card numbers are entered on Stripe's pages and held by Stripe. We do not receive or store full card numbers.
Connections: the credentials you give us to connect your apps, such as OAuth tokens and API keys. We store them encrypted (see Section 9) and use them only to provide the Platform to you, including checking that they still work.
Automations and their data: the automations you build, their settings, and the data that passes through them when they run, including the execution history you can see in the Platform.
Assistant conversations: what you type to the in-app assistant and what it answers, including the results of the actions it takes for you (see Section 4).
AI model keys: if you bring your own AI provider key, we store it encrypted and show only its last four characters.
Forms on the Site: what you enter, which depends on the form:
notify me: your email address;
beta application: name, email, company, job title, company website, and your answers about what you would like to build;
Enterprise inquiry: name, email, company, job title, phone number and message;
Managed: name, email, company, phone number and a description of what you want built;
request an app: the app's name, website and documentation link, your name, email, job title, mobile number, whether you work at the company that makes the app or use it, and what you want to build.
Communications: emails, text messages, WhatsApp messages and Discord messages you send us, and our replies.
Terms acceptance: when you create an account we record the date and time you accepted our terms, the address of the version you accepted, your IP address, your browser's user agent and how you signed up.
Information collected automatically
Usage and device data: IP address, browser and device type, pages viewed, links clicked, and the date and time of your visit.
Where you came from: on your first visit to the Site we record the campaign tags in the link you followed, the website that referred you, the page you landed on, one advertising click identifier if the link carried one (for example Google's gclid or LinkedIn's li_fat_id), and the page you left from when you went to sign up. We pass these to your account when you sign up, together with your HubSpot visitor identifier, so we know which pages and campaigns bring people to APIANT and can connect your earlier visits to your account in our CRM.
Tests of our pages: we may show you one of several versions of a page and record which one, to learn which works better.
Cookies and similar technologies: see Section 7.
Information from other sources
Sign-in providers: if you sign in with Google or GitHub, they tell us your verified email address, name and account identifier.
Public company information: when you apply for the beta, we may read the public website of the company you name and prepare a short summary of it, to help us review your application.
Payment processor: Stripe tells us whether a payment succeeded and the status of your subscription.
Some of this is treated as sensitive personal information under some US state laws: your account password and the credentials for the apps you connect. We use them only to provide the Platform. We do not ask for other sensitive information such as health data, and our Terms of Service do not allow you to send health or medical information through the Platform.
3. How we use it
to create and run your account, provide the Platform and the assistant, and run the automations you build;
to bill you, manage your plan, and apply your task and credit limits;
to answer your inquiries, review beta applications and app requests, and, for Managed, check whether what you describe can be built before you pay;
to let our team know promptly about an inquiry: we send ourselves a text message with the details you entered and a link to your record in our CRM;
to send you service messages, such as usage warnings when you approach your plan's limits, and, where the law allows, news about APIANT that you can opt out of at any time;
to understand how the Site and the Platform are used, measure which pages and campaigns lead to sign-ups, and test versions of our pages;
to keep the Site and the Platform secure, prevent spam and abuse, and investigate problems; and
to meet legal obligations and to enforce our terms.
We do not sell your personal information.
We do not make decisions with legal or similarly significant effects about you solely by automated means. When our automated check cannot confirm that a Managed request can be built, a person reviews it.
4. The assistant, AI clients and AI steps
The in-app assistant. The assistant in the Platform is powered by models from Anthropic. When you use it, we send Anthropic your messages and the information the assistant works with to answer you. That includes the automations it reads or edits, and execution data from your connected apps that it looks up for you. Anthropic processes this information to provide the assistant on our behalf. We store your conversations in your account until you delete them or close your account.
Your own AI client. If you connect an AI client, such as Claude Code, to the APIANT MCP server, the client acts on your account with your authorization. The results of what it asks the Platform to do are returned to that client, and from there to its AI provider under your own agreement with that provider. We do not see your conversations with your AI client, only the actions it asks the Platform to take, including any problem report it files with us about the Platform.
AI steps in your automations. If an automation you build includes a step that calls an AI model through your own Anthropic or OpenAI connection, the data in that step goes to that provider under your account with them.
Your key or ours. Depending on your account, the assistant runs on APIANT's own AI provider account or on a key you supply. Your own key is stored encrypted.
Accuracy. AI output can be wrong. Review what the assistant or your AI client builds before you turn it on.
Google user data
When you connect a Google account to the Platform (for example Google Ads, Analytics, Search Console, Forms, Contacts, Blogger, Tag Manager, Merchant Center, BigQuery and other Google Cloud services, Chat, Classroom, Meet, YouTube or Photos), we access only the data needed for the automations and requests you set up. That can include reading reports and records from your account, and creating or updating items in it when you ask.
How we use it: only to run the automations and assistant requests you start. We do not use Google user data for advertising, we do not sell it, and we do not use it to train AI models.
Who sees it: APIANT staff do not read your Google data unless you ask us to for support, it is needed for security, or the law requires it.
Sharing: we do not transfer Google user data to anyone, except the services you direct an automation to send it to, or where the law requires it.
Storage and deletion: your Google connection tokens are stored encrypted. Data passing through an automation is kept in your execution history only for the period your plan sets (see Section 8), then deleted. You can disconnect a Google account at any time on the Connections page, and you can also revoke our access at myaccount.google.com/permissions.
APIANT's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Legal bases (EEA, UK and Switzerland)
Where the GDPR or a similar law applies, we rely on:
contract, to provide the Platform and the services you sign up for;
legitimate interests, to run and secure our business, answer inquiries, understand how our Site is used and market our services to businesses, where those interests are not outweighed by your rights;
consent, where we ask for it, for example for analytics cookies, which you can withdraw at any time; and
legal obligation, where the law requires us to keep or disclose information.
6. Who we share it with
We share personal information with service providers that help us run APIANT, only for the purposes in this notice:
Provider	What it does for us	What it receives
Amazon Web Services	Hosts the Platform, stores its data and backups, sends our system email, and scans uploaded files for malware	All Platform data, including account data and Customer Data
Anthropic	Provides the AI models behind the assistant, and helps us assess Managed requests, summarize public company websites named in beta applications, and write example requests on our app pages	Assistant messages and the data the assistant works with; the text of a Managed request; public company website content; app catalog information
Stripe	Takes payments and manages subscriptions	Name, email, billing address, payment details you enter, subscription status
Vercel	Hosts the Site and its forms, and stores Managed requests and site data	Site visits, form submissions, request logs
HubSpot	Our CRM and email, and page-visit tracking on the Site	Contact and company details from forms and sign-ups, where you came from, pages you visit, emails we exchange
Google	Site analytics (Google Analytics)	Usage and device data, and sign-up events with the page and campaign that led to them
Cloudflare	Turnstile, which checks that form submissions and sign-ups come from people, not bots	A challenge token and your IP address
Twilio and Supabase	Send our team text messages about inquiries	The details you entered in a form
Atlassian	Tracks problem reports about the Platform, including reports an AI client files for you	The description in the report
Firecrawl	Reads the public website of a company named in a beta application	The company's website address
Services you choose to use, and page components. Some services handle your information under their own privacy policies rather than on our instructions: Google or GitHub, if you sign in with them; WhatsApp, if you message us there; Discord, if you join our community; and Google Fonts and Elfsight, which serve the fonts and the reviews shown on our pages and receive your IP address and browser details when those load.
Apps you connect. When you connect an app and run automations, data goes to and from that app because you told the Platform to send it. What the app's provider does with it is governed by your agreement with them.
Our staff. Our staff may access your account and automation data to support you, investigate problems or keep the Platform secure.
Business transfers. We may share or transfer personal information in connection with a merger, acquisition, financing or sale of all or part of our business, including during negotiations, under confidentiality obligations.
Legal reasons. We may disclose information if the law requires it, to respond to valid legal process, or to protect the rights, property or safety of APIANT, our customers or others.
7. Cookies and similar technologies
The Site uses cookies and browser storage for the purposes below. A small notice on the Site lets you accept or decline the analytics cookies (Google Analytics, HubSpot and our own apiant_attr). If your browser is set to a European time zone, they stay off until you accept. Elsewhere they are on unless you decline. You can change your choice at any time with the "Cookie settings" link at the foot of every page. We store your choice in a cookie called apiant_consent for 180 days.
Name	Set by	Purpose	Lasts
apiant_attr	APIANT	Remembers where you first came from (campaign tags, referring site, landing page, one ad click identifier), the page you left from to sign up, and your HubSpot visitor identifier, so your account records where you came from and our CRM can connect your earlier visits to it	90 days
apiant_ab	APIANT	Remembers which version of a page you were shown, so you see the same one each visit	90 days
_ga, _ga_*	Google Analytics	Counts visits and measures how the Site is used	Up to 2 years
hubspotutk, __hstc, __hssc, __hssrc	HubSpot	Tracks visits so our CRM can connect them to an inquiry	Up to 6 months
Sign-in and security cookies	APIANT (Platform)	Keep you signed in, protect forms against forgery, and complete sign-in with Google or GitHub	For your session, or until sign-in completes
Form drafts	APIANT (browser storage)	Keeps what you typed into a form on this device until you send it	Until the form is sent or you clear it
You can also block or delete cookies in your browser's settings. The Site still works without them, although we will not be able to tell where you came from. We do not currently respond to browser "Do Not Track" signals.
8. How long we keep it
Information	How long
Account details	While your account is open. After you close it, it is deleted from the Platform about 30 days after your last sign-in, or within one day if you ask us to wipe your data when you close it. Copies in our CRM and billing records are kept as described below.
Execution history	For the period your plan sets, shown on our pricing page, then deleted automatically.
Deleted automations	30 days, then permanently deleted. They cannot be restored from the Platform.
Webhook deliveries	Until they run, then 7 days.
Uploaded and temporary files	30 days.
Assistant conversations	Until you delete the conversation or close your account.
Connections to your AI clients	Until you sign the client out, you close your account, or its authorization lapses, which can take up to ten years if it is never used.
History of AI steps in your automations	Until 90 days pass without the step running.
Sign-up attempts	90 days.
Records of terms acceptance	As long as we need them to show what you agreed to.
Form submissions and CRM records	As long as they are useful for our relationship with you. We delete them from our CRM and other systems on request, except where the law requires us to keep them.
Billing records	As long as tax and accounting law requires.
Other operational records, such as logs and messages to our team	For the periods our providers set, and deleted when no longer needed.
Backups	We keep backups of the Platform so we can recover from failures. Information deleted from the Platform remains in backups until those backups are deleted under our backup practices. Backups are used only to restore the Platform, and deleted information restored from a backup is deleted again.
We may keep some information after you ask us to delete it where we need it to prevent fraud, troubleshoot problems, assist with investigations, enforce our terms or comply with the law.
9. How we protect it
Connections to the Site, the Platform and the MCP server use encrypted HTTPS.
App credentials, multi-factor secrets and AI keys are encrypted with AES-256-GCM under per-field keys, which are themselves encrypted with a tenant key.
You can turn on multi-factor authentication for your account.
AI clients connect through OAuth, only after you approve them by name. You can sign a client out, and we will revoke one on request.
Uploaded files are scanned for malware.
Forms and sign-ups are protected against bots and spam.
No system is perfectly secure. Keep your password and your AI client's access to yourself, and tell us at once at support@apiant.com if you think your account has been compromised.
10. Where your information is processed
APIANT is based in the United States, and the Platform is hosted in the United States. If you use APIANT from outside the United States, your information is transferred to and processed in the United States, where data protection law may differ from yours.
11. Your rights and choices
In your account. You can update your details at any time. You can export your automations and your execution history. You can close your account from its settings and ask us to wipe your data when you do.
Marketing. You can unsubscribe from marketing emails with the link in any of them. We will still send messages about your account and your use of the Platform.
By request. Depending on where you live, you may have the right to know what personal information we hold about you and to get a copy, to correct it, to delete it, to object to or restrict certain uses, to withdraw consent, and to take your information elsewhere. To make a request, write to privacy@apiant.com. We may need to confirm your identity first. We will not treat you differently for exercising your rights.
US state rights. Residents of California, Virginia, Colorado, Connecticut, Texas and other US states with privacy laws have the rights above as those laws provide. In the past twelve months we collected the categories of information described in Section 2: identifiers, commercial information, internet and network activity, professional information, and inferences drawn from public company information in beta applications. We used and disclosed them for the purposes in Section 3, to the recipients in Section 6. We do not sell personal information. You may use an authorized agent to make a request on your behalf; we may ask the agent for proof of authority and ask you to confirm your identity. If we deny your request, you can appeal by replying to our decision.
Complaints. If you are in the EEA, the UK or Switzerland, you can complain to your data protection authority. We would appreciate the chance to address your concern first.
Customer Data. If your information is in an APIANT customer's automations, please contact that customer. We will help them respond.
12. Children
APIANT is for businesses and for people aged 18 or over. We do not knowingly collect information from children. If you believe a child has given us personal information, write to privacy@apiant.com and we will delete it.
13. Changes to this notice
We will update this notice when our practices change and show the date of the latest version at the top. If a change is significant, we will tell you in the Platform or by email before it takes effect.
14. Contact us
APIANT, Inc.
196 West Ashland Street
Doylestown, PA 18901
United States
privacy@apiant.com