Apova Developer Privacy Notice
Version: developer-privacy-v1
Effective date: September 15, 2026.
1. Who we are and scope
Apova Inc., incorporated in Delaware, provides the developer portal and Agent Atlas sandbox APIs and MCP interfaces. Our mailing address is 1259 El Camino Real, Unit #1120, Menlo Park, CA 94025. Contact legal@apova.ai for privacy questions, security reports and data requests.
This notice covers developer onboarding, access administration, sandbox use and related support. It does not replace a separate notice for marketing or sales activities, or an agreement governing approved customer-data processing. Controlled real-data evaluation requires a separately agreed scope, applicable data-processing arrangements and privacy controls. Sandbox access alone does not authorize personal data in API payloads.
2. Information we process
| Information | Source | Purpose |
|---|---|---|
| Email, account identifiers and verification status | You and the authentication service | Sign-in, account security and access administration |
| Individual/organizational capacity, organization where applicable, and intended use | You | Review and administer access |
| Terms version, acceptance time, account reference and approval decisions | Your actions and authorized reviewers | Establish assent and the scope of approved access |
| Credential metadata, project and operation identifiers, timestamps, usage and error categories | Service activity | Authorization, quotas, support, security and reporting |
| Network/request metadata and security events | Your connection and service activity | Protect availability, investigate misuse and diagnose failures |
| Submitted sandbox inputs, evaluation results and categorical outcome feedback | API/MCP requests and authorized feedback submitters | Provide and verify requested evaluations and investigate issues |
| Passkey credential identifiers, public keys and verification records where enrolled | Your authenticator and verification interaction | Bind and verify supported step-up requests |
| Support correspondence | You and support personnel | Respond to requests and resolve issues |
Use synthetic API test data by default. Account emails and security metadata can still be personal information; calling the environment a sandbox does not make all its records anonymous. Avoid including secrets or unnecessary personal information in support requests or test inputs.
3. Use, feedback and training
We process information to provide, administer, secure and support the agreed service. We use minimized counts, latency measurements, error categories and quota information for operational reporting. We limit debugging and abuse investigation to necessary information and the applicable retention period.
General product suggestions and permitted operational aggregates may inform improvements. This does not grant an unrestricted license to reuse API inputs or outputs for unrelated research or offline datasets.
Ordinary API/MCP use, terms acceptance and categorical feedback do not grant permission for Atlas training. Any dataset participation requires separate explicit enrollment, identified purpose and dataset version, provenance, privacy review, retention terms and approval. A new dataset or purpose requires new authorization. Contact legal@apova.ai to revoke future authorized training use. Revocation does not promise removal of influence from a model already trained; the separate enrollment must address derived artifacts before training.
4. Service providers and disclosures
We use service providers for authentication, hosting, storage, network security, communications and configured evaluation processing. Providers involved in the developer service include:
| Provider | Role |
|---|---|
| Supabase | Account authentication and email-verification identity records |
| Cloudflare | Website delivery, network protection and restricted reviewer access where applicable |
| Google Cloud | Hosted API processing, application storage and operational logging |
| Resend | Verification and service-notification email delivery |
| Anthropic, where enabled | Configured evaluation enrichment |
Provider access depends on the function and configuration; an email provider is not thereby a recipient of ordinary API payloads. Authorized Apova personnel may access necessary records for support, security and access review. We may disclose necessary information to comply with legal requirements or protect rights and security, subject to applicable law. A separate customer-data agreement governs approved processing on a customer's instructions. Atlas training restrictions are not a representation that every provider has identical processing or retention terms.
5. Cookies and account access
The portal uses a secure, HTTP-only sign-in cookie and a short-lived verification cookie. The current portal implementation sets the sign-in cookie for no more than one hour and the verification cookie for ten minutes. Signing out removes the portal's sign-in cookie; cookies expiring or being removed does not itself erase the underlying account or audit records.
Network security and restricted reviewer access may involve additional security cookies. Browser controls can limit cookies, but blocking necessary cookies can prevent sign-in and account functions from working. This notice makes no claim that all website activity is cookie-free or anonymous.
6. Retention and deletion
We use separate retention schedules for operational data, reporting and legal/security evidence. Retention periods do not authorize an otherwise prohibited use of data.
| Record class | Ordinary retention schedule | Clock |
|---|---|---|
| Sandbox inputs and evaluations, with linked feedback | 30 days | Original source record lifecycle; linked feedback expires with its parent |
| Minimized reporting metadata | 120 days | Original reporting bucket |
| Denied or withdrawn application and associated operational profile | 90 days | Final denial or withdrawal |
| Approved operational account profile | Account life plus 90 days | Closure of the applicable account/service relationship |
| Necessary legal assent and approval evidence | 5 years | Later of account closure or last applicable acceptance/approval event |
| Security/application logs | 12 months | Log event timestamp |
| Ordinary support correspondence | 24 months | Ticket/conversation closure |
These schedules are subject to applicable rights requests and specific legal requirements. Keeping legal assent evidence does not authorize retaining the entire operational profile for the same period. Closing sandbox access does not automatically close an unrelated service account that remains in use.
Copying an input into a support, security or audit record does not restart its clock or automatically extend its retention. Any preservation hold must identify the necessary records and their lineage, purpose, approving Privacy/Legal role, approval time, review date and release condition. Security may request a hold for an incident. Active holds are reviewed at least every 90 days. When released, the original lifecycle applies; records past their original deadline become due for deletion without a new retention period.
Backups and provider copies have separate deletion/rotation processes. Deletion from active stores is not a promise of immediate removal from every backup. Restoration must preserve applicable deletion obligations. Separately approved training artifacts follow the specific enrollment and artifact policy, not a general extension of sandbox retention.
7. Security and minimized evidence
We apply access controls and safeguards appropriate to the processing mode. We limit access to credentials, account records and necessary legal evidence. Audit and reporting records must omit unnecessary personal information and use redaction or pseudonymous identifiers where appropriate. Pseudonymized information is not necessarily anonymous; necessary mappings and identifiable legal evidence require restricted access.
Controlled real-data evaluation requires appropriate privacy categorization and protection before durable payload storage. Encryption does not mean authorized processing never requires plaintext. No service can guarantee that every security incident is prevented. Report suspected compromise to legal@apova.ai.
8. Requests and choices
Contact legal@apova.ai to request access, correction, deletion, closure of developer access or withdrawal of training permission. You may also use available authenticated account controls. Submitting a request is not confirmation that it has been completed.
We verify identity and authority proportionately using information associated with the account. We do not routinely require sensitive identity documents for an ordinary request. An authorized agent must provide reasonable evidence of authority, with additional verification where required. We respond within applicable legal deadlines and provide any legally required explanation or appeal process. Rights and exceptions depend on the applicable jurisdiction; this notice does not require waiver of statutory rights.
The sandbox is not directed to individuals under 18. If we learn that an underage individual submitted personal information during onboarding, we restrict affected access and arrange appropriate deletion handling, subject to specific legal requirements. Contact legal@apova.ai if you believe this has occurred.
9. Changes
We identify material changes to this notice and provide appropriate notice. A privacy-notice update does not supply implied consent to train on previously submitted data. The version and publication/effective date will be presented with the notice when activated.
