01Who we are
“We”, “us”, “A'nil Cyborg” — sab ek hi cheez. A'nil Cyborg ek product hai jo banata hai Aliens Pvt. Ltd. (India) aur uska EU representative Aliens Software GmbH (Berlin). Both entities are the joint data controller for everything on this site and product.
- India: Aliens Pvt. Ltd. · Mumbai, Maharashtra · CIN U72900MH2018PTC306745
- EU rep: Aliens Software GmbH · Friedrichstraße 76, 10117 Berlin · HRB 234567 B
- Founder & CEO: A'nil Nayak (also our acting Data Protection Officer)
- Reach us: privacy@anilcyborg.com · 48-hour response SLA
02What we collect
3 buckets, total. No fourth bucket hidden in fine print.
A. Account & billing data YOU GIVE US
- Name, work email, company name, role, country
- Billing address & tax ID (GST / VAT / EIN as applicable)
- Payment method token only — full card data goes to Stripe, we never see it
- Optional: profile picture, phone, time zone
B. Cyborg work data YOU GIVE YOUR CYBORG
- Anything you connect via integrations — Slack messages, GitHub PRs, Notion docs, Linear issues, etc.
- Anything your Cyborg writes back — code, replies, designs, reports, decisions
- Skill memory — facts your Cyborg learns about your company (people, products, processes)
- Audit log — every action, with timestamp, scope, and reason
↳ All of this lives only inside your tenant. One Cyborg, one machine, one customer. Read how the isolation works.
C. Telemetry & logs WE GENERATE
- Server logs — IP, user-agent, timestamps (kept 30 days, then aggregated)
- Usage metrics — task counts, latency, error rates (no content, just shapes)
- Crash reports — stack traces, sanitized; no user data
- Security events — failed logins, anomalous API calls (kept 12 months)
⚠ What we explicitly do not collect: behavioural profiles, advertising IDs, third-party analytics, browser fingerprints, location precision beyond country, social-media graphs, training corpora from your data.
03Why we collect it (legal basis)
Under GDPR Article 6 we have to tell you the basis for each use. Here it is, no jargon:
| Data | Why | Basis |
| Email, name, company | Create your account, send critical product email | Contract |
| Billing address, tax ID | Issue legal invoices, comply with tax law | Legal obligation |
| Cyborg work data | Run the service you're paying for | Contract |
| Skill memory | Make your Cyborg better at your work | Contract |
| Audit log | Security, accountability, your own SOC2 | Legitimate interest |
| Server logs | Detect abuse, debug incidents | Legitimate interest |
| Crash reports | Fix bugs that affect you | Legitimate interest |
| Phone (optional) | 2FA, urgent incident calls | Consent |
04Who we share with
The honest list:
- Nobody — we do not sell, rent, lease, barter, or "share for marketing" your data with anyone. Full stop.
- Subprocessors we use to run the product — listed in section 05. They process under DPA, only what they need.
- Authorities, when legally compelled — valid court order in our jurisdiction. We push back on overbroad asks, fight gag orders where we can, and notify you unless legally prohibited.
- Acquirers, in a sale or restructure — you'd be notified 60 days in advance and given an export window. (We're bootstrapped & profitable, so this is hypothetical.)
05Subprocessors
We keep the list short on purpose. Each one has a signed DPA and a documented purpose.
| Provider | Purpose | Region | DPA |
| AWS | Compute, storage, network | ap-south-1 (Mumbai), eu-central-1 (Frankfurt) | ✓ |
| Stripe | Payment processing | Ireland · USA | ✓ |
| Postmark | Transactional email | USA | ✓ |
| Cloudflare | DDoS, edge cache (no data residency) | Global edge | ✓ |
| Sentry (self-hosted) | Error tracking | Our AWS, eu-central-1 | n/a (self-hosted) |
| Anthropic / OpenAI / Mistral | LLM inference (per-tenant routing) | EU + US tenants only on EU-hosted endpoints | ✓ (no-train clause) |
↳ Subprocessor list change ho to 30-day advance notice email + this page updated. Subscribe to changelog.
06AI training & models
This is the question every customer asks first. Direct answer:
- Your data does not train any global model. Period. Hamare contracts with Anthropic, OpenAI, Mistral all carry explicit "no training on customer prompts/completions" clauses.
- Your Cyborg learns inside your tenant only. Skill memory is per-customer, encrypted at rest, never accessible to us beyond support escalations you approve.
- We do not aggregate. No “anonymized telemetry to improve the model” loophole. The model you query is the same one your competitor queries — only the context differs, and your context never leaves your tenant.
- Opt-out is moot — there is nothing to opt out of, because we don't opt you in.
07Cookies & tracking
Yeh page jo tum padh rahe ho — 0 cookies, 0 trackers, 0 fingerprinting. Try DevTools → Application → Cookies. Empty.
Inside the product (app.anilcyborg.com) we use strictly necessary cookies only:
ac_session — auth session (HttpOnly, Secure, SameSite=Lax, 14 days)
ac_csrf — CSRF token (session lifetime)
ac_theme — light/dark preference (1 year, you set it)
No GA, no Hotjar, no Segment, no Meta pixel. We use Plausible (self-hosted, cookieless) for aggregate page-view counts on this marketing site only — no personal data, no cross-site profile.
08How long we keep data
| Data | Retention | What happens after |
| Account data | Lifetime of contract + 30 days | Hard delete |
| Cyborg work data | Per your settings (default: forever, you can autoexpire) | Hard delete or export |
| Skill memory | Lifetime of contract + 30 days | Hard delete |
| Audit log | 7 years (compliance) | Hard delete |
| Server logs (with IP) | 30 days | Aggregated, IP stripped |
| Invoices | 10 years (tax law) | Hard delete |
| Marketing site analytics | 12 months | Aggregated forever, no PII |
"Hard delete" matlab: encrypted shards overwritten, backups crypto-shredded within 90 days. No soft-deletes that "linger".
09Your rights
Under GDPR, India DPDP 2023, and CCPA you have:
→AccessGet a copy of everything we hold on you. JSON export, ≤ 7 days.
→CorrectionFix anything wrong. Self-serve in product, or email us.
→Deletion"Right to be forgotten." Done in ≤ 30 days, confirmed in writing.
→PortabilityExport in machine-readable format. JSON, no lock-in.
→RestrictionPause processing while a dispute is being resolved.
→ObjectionObject to legitimate-interest processing. We'll review and reply.
→Withdraw consentAnywhere consent is the basis (e.g. phone for 2FA).
To exercise any right, mail privacy@anilcyborg.com. No portals, no tickets. A human (usually A'nil) replies within 48 hours and acts within 30 days.
10International transfers
You pick your data residency at signup. Three regions, no surprises:
- EU customers → eu-central-1 (Frankfurt). Data stays in EU/EEA. SCCs in place for any incidental sub-processor touch.
- India customers → ap-south-1 (Mumbai). Data stays in India. DPDP-compliant.
- Rest of world (incl. US) → ap-south-1 default, or eu-central-1 on request.
We do not move your data between regions without your written approval. Disaster-recovery snapshots stay in the same region, encrypted with region-local KMS keys.
11Children's data
A'nil Cyborg ek B2B product hai. Hum knowingly under-16 (under-18 in India) ka data collect nahi karte. Agar tumhe lagta hai galti se kuch chala gaya hai, mail karo — 7 din me delete kar denge.
12Breach notification
If we suffer a security incident that materially affects your data:
- 72-hour SLA — we notify you and the relevant DPA within 72 hours of confirmed scope, per GDPR Art. 33.
- What you'll get — affected data classes, time window, root cause (or current hypothesis), containment status, remediation, your action items.
- Public post-mortem — for any P1/P2 incident, we publish a redacted post-mortem on the blog within 14 days.
- No NDAs — we will not gag you about an incident affecting your data.
Report a vulnerability: security@anilcyborg.com · PGP key + bounty program.
13Changes to this policy
Material changes get 30-day advance email + a banner in the product. Small clarifications get a changelog entry but no email storm. Full history below:
- v2.1 · MAY 1, 2026 Clarified subprocessor list, added Mistral, added "No NDAs" breach clause.
- v2.0 · APR 9, 2026 Public launch version. Rewritten in plain English. India DPDP added.
- v1.0 · JAN 14, 2026 Internal beta with 3 design partners. Original draft.
14Contact & DPO
One inbox, one human, fast replies. No portals, no auto-responders.