Privacy Policy
Last updated: June 8, 2026
This Privacy Policy explains how OctopusLab (“OctopusLab”, “we”) collects, uses, shares, and protects personal data related to your use of the OctopusLab platform and websites (the “Service”). It applies to all users globally and addresses the specific rights granted by the European Union General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act / California Privacy Rights Act (“CCPA/CPRA”), and the Russian Federal Law No. 152-FZ (“152-FZ”).
1. Data Controller
The data controller for the personal data processed in connection with your use of the Service is OctopusLab. For privacy questions, contact privacy@octopus-lab.app.
2. Information We Collect
2.1 Information you provide
- Account data: email address, password (stored as a hash by our auth provider), display name, organization name.
- Project content: prompts you submit, AI-generated outputs, source code, project metadata, custom domain configurations, files you upload.
- Billing data: cryptocurrency wallet addresses, on-chain transaction hashes, plan selection, invoice records. We do not collect or store payment-card data.
- Communications: messages you send us via email or contact forms.
2.2 Information collected automatically
- Technical data: IP address, browser type and version, operating system, device identifiers, language, time-zone.
- Usage data: pages visited, features used, requests made to the API, performance metrics (Core Web Vitals), error reports.
- Cookies and similar technologies: see our Cookie Policy.
3. How We Use Your Information
- Provide, maintain, and improve the Service.
- Authenticate you and secure your account.
- Process payments and issue receipts.
- Send transactional emails (receipts, invitations, system notifications).
- Provide customer support.
- Detect, prevent, and respond to abuse, fraud, and security incidents.
- Comply with legal obligations and respond to lawful requests.
- Generate aggregated or anonymized analytics to improve the Service.
4. Lawful Basis (GDPR)
For users protected by the GDPR, we process personal data on the following bases:
- Performance of a contract — to provide the Service you have requested (Art. 6(1)(b)).
- Legitimate interests — securing the Service, preventing fraud, improving the product, transactional communications (Art. 6(1)(f)).
- Consent — for non-essential cookies and marketing communications, where required (Art. 6(1)(a)). You can withdraw consent at any time.
- Legal obligation — tax records, accounting, responding to lawful requests (Art. 6(1)(c)).
5. Sub-processors and Third Parties
We share personal data with the following processors strictly to operate the Service. Each is bound by a data-processing agreement requiring appropriate confidentiality and security measures.
| Provider | Purpose | Location |
|---|---|---|
| Vercel | Web frontend hosting, edge functions, log drain | US / EU |
| Railway | Backend API hosting | US / EU |
| Neon | Postgres database hosting (per-project branches) | EU / US |
| Cloudflare | CDN, DDoS protection, R2 object storage | Global |
| Supabase | Authentication, primary application database | EU |
| OpenRouter | AI model gateway | US |
| Anthropic, OpenAI, et al. | Large-language-model inference (accessed via OpenRouter) | US |
| Resend | Transactional email delivery | EU |
| Axiom | Request / application logs (30-day retention) | US |
| NOWPayments, xRocket | Cryptocurrency payment processing | Global |
| GitHub | Optional OAuth sign-in / repository integration | US |
We do not sell personal data and we do not share it with advertisers.
6. International Data Transfers
Some of our sub-processors are located outside the European Economic Area, the United Kingdom, or the Russian Federation. Where personal data is transferred internationally, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and equivalent UK and EEA mechanisms.
7. Data Retention
- Account data: while your account is active, plus up to 30 days after deletion to support recovery and resolve disputes.
- Project content: while the project exists; deleted within 30 days after you delete the project or close your account.
- Request and application logs: up to 30 days (Axiom dataset retention).
- Billing records: as required by applicable tax and accounting law, typically up to 7 years.
- Backups: encrypted backups may persist for an additional 30 days after deletion in primary storage.
8. Your Rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you (GDPR Art. 15; CCPA right to know).
- Rectify inaccurate personal data (GDPR Art. 16).
- Erase personal data (GDPR Art. 17; CCPA right to delete; 152-FZ право на удаление).
- Restrict or object to certain processing (GDPR Art. 18, 21).
- Data portability: receive your data in a machine-readable format (GDPR Art. 20).
- Withdraw consent at any time, without affecting prior lawful processing.
- Non-discrimination for exercising CCPA rights.
- Lodge a complaint with your local Data Protection Authority.
To exercise these rights, email privacy@octopus-lab.app. We will respond within 30 days. We may need to verify your identity before fulfilling certain requests.
9. Cookies
We use a small number of cookies. See our Cookie Policy for details and to manage preferences.
10. Children
The Service is not directed to children under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact privacy@octopus-lab.app.
11. Security
We protect your data with:
- HTTPS in transit; AES-256 at rest in Neon and Supabase.
- Row-level security (RLS) deny-all on application data.
- Encrypted application secrets (BYOK) using AES-256-GCM.
- Hardware-key authentication and least-privilege access for our staff.
- Continuous logging and anomaly review via Axiom.
No system can guarantee absolute security. If a data breach affects you, we will notify you in accordance with applicable law.
12. California Notice (CCPA/CPRA)
In the past twelve months we may have collected the categories of personal information described in § 2 above. Categories of recipients are listed in § 5. We do not“sell” or “share” personal information for cross-context behavioral advertising. California residents may exercise the rights listed in § 8 by emailing privacy@octopus-lab.app.
13. Russia Notice (152-FZ)
Для пользователей-граждан Российской Федерации: персональные данные обрабатываются с вашего согласия и для исполнения договора оказания услуг. Вы имеете право требовать уточнения, удаления или прекращения обработки ваших данных, направив запрос на privacy@octopus-lab.app.
14. Changes to This Policy
We may update this Policy from time to time. Material changes will be notified by email or in-app notice at least 14 days before they take effect. The “Last updated” date at the top reflects the current version.
15. Contact
Privacy questions: privacy@octopus-lab.app
Data Protection inquiries: dpo@octopus-lab.app