← Back to home

Privacy Policy

Effective date: 2026-03-07

Controller: Bittoku KK, Japan

Contact: [email protected]

1. What We Collect

When you use Ex-Machina, we collect:

2. How We Use It

We do not sell your data, use it for advertising, or share it with third parties beyond what is described in this policy.

3. Third-Party Processors

We share data with the following sub-processors to operate the service:

ProcessorPurposeLocationNotes
AnthropicAI conversation processingUS30-day retention; no model training on API data; DPA available
StripeSubscription billingUSPCI DSS Level 1 compliant
Plausible AnalyticsWebsite analyticsEU (Germany)Cookieless; no personal data collected; GDPR compliant
CloudflareCDN, DDoS protection, tunnelUSDoes not store user content; transit only
HetznerServer hostingUS (Ashburn VA)GDPR compliant; data encrypted at rest (LUKS full-disk)

4. Data Retention

Data TypeActive AccountAfter CancellationAfter Deletion Request
Account dataKept30 days → archived7-day grace → purged
Agent memory & workspaceKept30 days → archived7-day grace → purged
Conversation logsPer-tier retention30 days → deletedImmediate delete
Stripe billing recordsKeptStripe policy appliesAnonymised by Stripe
Encrypted backups30-day rotationNaturally expiresCannot selectively purge; expires ≤ 30 days

5. Your Rights

Depending on your jurisdiction, you may have the following rights:

6. Security Measures

Your conversations and agent memories are encrypted at rest. Nobody — not even Ex-Machina staff — can read your private data.

7. International Data Transfers

Our servers are located in the US (Hetzner, Ashburn VA). AI processing is performed by Anthropic (US). If you are in the EU, these transfers are covered by Standard Contractual Clauses (SCCs) entered into with Anthropic, Stripe, and Hetzner.

Bittoku KK is a Japanese entity subject to APPI. For users in Japan, we notify you that your data is transferred to the US for processing (APPI Article 24).

8. Breach Notification

In the event of a data breach affecting your personal information, we will notify affected users by email within 72 hours of discovery, and notify applicable regulatory authorities as required by law (GDPR Art. 33, APPI).

9. Cookies

We use one functional cookie: your authentication session token (httpOnly, secure). This cookie is strictly necessary for the service to function and does not require consent under ePrivacy rules.

We use Plausible Analytics for website traffic measurement. Plausible is cookieless — it sets no cookies and collects no personal data. No cookie consent banner is required.

10. Contact

For privacy questions, data access requests, or to exercise your rights, contact us at: [email protected]

Controller: Bittoku KK, Japan