Skip links

Free access. Full capability.

 

APE Privacy Policy (GDPR‑Aligned)

1. Introduction

This Privacy Policy explains how APE (“the Service”) collects, processes, and protects personal data when users build and run custom workflows, including integrations with Google APIs and vector databases. APE is designed to give users full control over their data and complies with the General Data Protection Regulation (GDPR).

2. Data Controller

The Data Controller is the organization or individual operating APE. If you use APE as a self‑hosted or private deployment, you are the Data Controller responsible for GDPR compliance.

3. Data We Process

APE processes only the data required to execute workflows created by the user. This may include:

  • Documents uploaded by the user
  • Metadata extracted from documents
  • Workflow configuration data
  • API credentials provided by the user (e.g., Google API keys)
  • Embeddings generated for vector database operations

APE does not collect data unrelated to workflow execution.

4. Use of Google APIs

If the user connects their own Google API credentials, APE accesses Google Drive files only for the purpose of executing the workflow. APE does not store, share, or reuse Google Drive data outside the workflow. API keys remain under the user’s control and can be revoked at any time.

5. Use of Vector Databases (OpenAI Embeddings)

When users enable vector database features, APE may send text fragments to the selected embedding provider (e.g., OpenAI) to generate vector representations. These fragments are used solely for semantic search and workflow logic. APE does not store raw text in the vector database unless explicitly configured by the user. Embeddings may be stored in the user’s chosen vector DB instance.

6. How We Process Data

APE processes data through modular workflow nodes such as UploadParseExtractValidateSummarizeOutput, and optional integrations like MCP modelsvector DBs, and Google APIs. All processing is performed according to the user’s workflow configuration.

7. Legal Basis for Processing

APE processes data based on:

  • User consent (when connecting external APIs)
  • Contractual necessity (executing workflows)
  • Legitimate interest (improving system reliability and security)

8. Data Storage & Retention

APE stores data only as long as required to execute the workflow or as configured by the user. Users may delete workflow data, embeddings, logs, and API credentials at any time.

9. Data Sharing

APE does not sell or share personal data with third parties. Data may be transmitted to external services only when the user explicitly enables an integration, such as:

  • Google Drive API
  • OpenAI embeddings
  • MCP‑connected AI models These services act as independent processors under their own privacy policies.

10. Security Measures

APE uses industry‑standard security practices, including encryption in transit, access control, and isolation of user workflows. Users are responsible for securing their own API keys and external database credentials.

11. User Rights (GDPR)

Users have the right to:

  • Access their data
  • Correct inaccurate data
  • Request deletion
  • Restrict processing
  • Export their data
  • Withdraw consent for external integrations

Requests can be submitted to the Data Controller.

12. Children’s Data

APE is not intended for use by children under 16 and does not knowingly process children’s data.

13. Changes to This Policy

We may update this Privacy Policy to reflect changes in functionality or legal requirements. Updates will be posted within the Service.

14. Contact

For questions or GDPR requests, contact the Data Controller at the address or email associated with your APE deployment.