Legal

ApolloBot Privacy Policy

How ApolloBot handles account, workspace, research, provider, and billing data.

i
Effective and versioned

Effective August 3, 2026 · Version 2026-08-03. Save or print this page for your records.

Scope and operator

Effective August 3, 2026 · Version 2026-08-03. ApolloBot is operated by Frontier Science under the verified merchant identity shown in Stripe Checkout and billing receipts. Questions or privacy requests may be sent to thom@frontier-science.ai.

Data we process

We process identity and membership data; organization, project, investigation, approval, and audit records; customer questions and connected content; sources, checkpoints, outputs, and artifacts; provider usage receipts; service logs; and subscription, tax, and billing identifiers. Stripe receives payment details directly; ApolloBot does not store complete card numbers.

Why we process it

We use this data to authenticate users, enforce tenant and role boundaries, execute approved investigations, recover durable work, measure capacity, prevent abuse, provide artifacts, reconcile billing, support customers, protect the service, and meet legal obligations. We do not sell customer workspace content or use it for advertising.

OpenAI and web search

Hosted execution sends the investigation question and governed prior-phase output to OpenAI’s API using GPT-5.6 Luna. Requests set store=false and do not use background mode. OpenAI states that API inputs and outputs are not used for model training by default. Under standard API controls, abuse-monitoring data may be retained by OpenAI for up to 30 days unless a verified Zero Data Retention configuration applies. The OpenAI web-search capability is not HIPAA eligible and is not covered by a BAA.

Infrastructure and subprocessors

Cloudflare and OpenAI process data needed to operate identity, networking, durable control state, artifact storage, workflow execution, and research generation. Stripe processes checkout, payment, tax identifiers, subscriptions, portal access, and metered billing. A connected repository, data, email, publication, or compute provider receives data only after its integration and required approval are enabled.

Confidential and regulated data

Workspace content is private by default and is not published automatically. Customers must not submit protected health information, controlled data, export-controlled material, or other regulated or highly sensitive personal data unless a separate written agreement and required provider configuration expressly permit it.

Retention and deletion

ApolloBot retains workspace content while the account or subscription is active and as needed to provide the service. An organization owner may request export or deletion through the contact above. Deletion is not instantaneous: integrity, security, audit, billing, tax, dispute, backup, and legal records may be retained when reasonably necessary or required. Provider-held copies follow the provider terms described above.

Security and customer controls

Organizations control membership, roles, investigation privacy, hard caps, approvals, cancellation, and approved exports. ApolloBot uses scoped identity, durable leases, hashed credentials, tenant-specific object paths, signed billing webhooks, and verified artifact hashes. No system is perfectly secure; suspected unauthorized access should be reported promptly.

Customer rights and changes

Depending on applicable law, individuals may request access, correction, deletion, or restriction. We verify authority before acting on an organization’s workspace. Material policy changes will receive a new version and effective date; an earlier version continues to govern earlier processing where required.