Legal document

Privacy Policy

What we collect, on what basis, who we send it to, how long we keep it, and what rights you have over it.

Last updated

The Indonesian text is the operative and binding version. The English text is provided as a courtesy translation only and does not govern. Where the two differ in meaning, the Indonesian text prevails. This follows Law No. 24 of 2009.

1. Who is responsible#

The Personal Data Controller for Apex is PT BEHIRE INTERNATIONAL INDONESIA, of Ruko Jalur Sutera Timur 6B No. 03, Kelurahan Kunciran, Kecamatan Pinang, Kota Tangerang, Provinsi Banten 15144, Indonesia. This policy is written to follow Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations.

Questions, requests and objections about personal data can be sent to [email protected].

[TO BE COMPLETED]Name and contact of the Personal Data Protection Officer

[TO BE COMPLETED]Official email address on the company domain

2. The data we collect#

Account data — supplied by you when you register and use the service:

  • Email address, name, and password (stored only as a bcrypt hash, never in its original form).
  • Phone number and profile photo, if you provide them. Both are optional.
  • Your Google or Facebook account identifier, if you sign in with one of them.
  • Your Telegram chat ID, if you opt in to Telegram notifications.
  • Preferences: language, theme, default market, chosen investment horizon, and notification settings.
  • Your own referral code and the referral code you signed up with.

Data you create inside the product:

  • Watchlists, portfolios and their allocations, trade journals, ideas, notes and saved picks.
  • Comments and replies you write. Comments are public within the platform.
  • The questions you type into AI features, and their answers. See "Data sent to AI providers" below — this is the part most worth understanding.

Data collected automatically as you use the service:

  • AI usage records: the feature called, the model and model tier used, token counts, cost, latency, success or failure status, and credits debited.
  • Previews of AI prompts and responses (up to roughly the first 800 characters) for incident handling, billing dispute resolution and abuse control.
  • Engagement records: content you read, save or comment on, with timestamps. These are used to compute creator payouts.
  • IP address and browser identity (user agent) on certain actions recorded in the audit log, and in server access logs.
  • Transaction records: credit purchases, subscriptions, invoices, and credit balance movements.

If you become a creator or apply as a mentor, we also collect:

  • Bank name, account number and account holder name, to pay you. This is financially sensitive personal data and is treated as access-restricted.
  • Public creator profile: biography, photo, portfolio and social links, certifications, experience, and any consultation contact you choose to display.

3. Lawful basis for processing#

Article 20 of the PDP Law requires every processing activity to have a lawful basis. These are the bases we rely on for each group of processing.

ProcessingLawful basis
Creating and running your account, giving access to the servicePerformance of a contract
Processing credit purchases, subscriptions and creator payoutsPerformance of a contract; legal obligation for financial records
Running the AI request you submit, including sending it to a model providerPerformance of a contract at your request
Sending verification, password reset and service notification emailPerformance of a contract
Security: abuse prevention, rate limiting, audit logs, fraud detectionLegitimate interests of the controller
Computing creator payouts from reader engagement recordsLegitimate interests; performance of the contract with the creator
Complying with law enforcement or competent authority requestsLegal obligation
Telegram notifications, marketing email, and product analytics if enabledConsent, which you may withdraw at any time

Where we rely on consent, withdrawing it takes effect going forward and does not undo processing already lawfully carried out.

4. Data sent to AI providers#

The model providers connected to Apex, and which may therefore receive the content of your question depending on the feature and model tier used:

  • Google (Gemini)
  • Anthropic (Claude)
  • DeepSeek
  • Groq
  • Alibaba Cloud (Qwen / DashScope)
  • OpenRouter (an aggregator that forwards to further model providers)
  • Cloudflare (Workers AI)
  • Models we run ourselves on our own infrastructure, whose data does not leave our systems.

We do not send your name, email address or account identifier to model providers with your question. However, the content you write yourself may contain personal data, and that is outside our control.

If you use your own AI provider API key (BYOK), the key is stored encrypted and your requests are forwarded to the provider using that key. That provider’s relationship and privacy policy then apply between you and them.

5. Processors and other third parties#

We use the following service providers to run Apex. Each receives only the data needed for its role.

PartyRoleData received
XenditPayment processing and disbursementPayer email address, amount, currency, invoice description, reference; for disbursement: bank name, account number, account holder name
BrevoTransactional email deliveryRecipient email address and message content (verification, password reset, notifications)
CloudflareContent delivery and edge protection; file storage; one of the AI model providersIP address, HTTP requests, and files you upload
Google, Meta (Facebook)Third-party sign-in, only if you choose itYour sign-in interaction on their service; we receive an account identifier, email and name from them
TelegramNotifications, only if you opt inChat ID and notification content
AI model providersRunning your AI requests — see the section aboveThe content of your question and its context
PostHogProduct analytics. NOT ACTIVE: the software is present in the application but not configured in the production environment, so no data is currently sent.If activated: user id, email, name, role and usage events. This page will be updated before activation.

The market data providers we use — exchanges and providers of price, economic and issuer data — are read-only sources. They receive no personal data about you.

We do not sell personal data, do not rent it, and do not trade it. We do not share personal data with advertisers.

We may disclose personal data where required by law, court order, or a lawful request from a competent authority; and in a merger, acquisition or business transfer, to the successor, subject to this policy continuing to apply.

6. Transfers outside Indonesia#

Most of the processors above run infrastructure outside Indonesia, so your personal data is processed across borders. Article 56 of the PDP Law governs transfers of personal data outside Indonesia. We address this by selecting processors that apply an equivalent level of protection, and by binding them through data processing agreements.

7. How long we keep data#

DataRetention
Account data and content you createdWhile the account is active, and afterwards for as long as needed for legal obligations or dispute resolution
Transaction, invoice and credit ledger recordsKept to satisfy financial and tax record-keeping obligations
AI prompt and response previews30 days, then removed from the usage record
AI usage metrics without prompt content (tokens, cost, latency, status)Kept for billing, cost control and audit
Email verification and password reset tokensStored only as a hash; the record of their use is kept for security audit purposes
Audit logs and server access logsKept for security and incident investigation
Creator bank details on payout recordsAttached to the relevant payout record and kept as proof of payment

8. Your rights over your personal data#

Articles 5 to 15 of the PDP Law give you the following rights as a Personal Data Subject. We extend these rights to every Apex user:

Right to information
To be told our identity, the lawful basis, the purpose of processing, and the accountability of the party requesting data. This page is how we discharge that.
Right of access
To request a copy of the personal data we process about you.
Right to rectification
To complete, update or correct inaccurate data. Some of this you can do yourself in account settings.
Right to end processing, delete and destroy
To request that processing stop and that your personal data be deleted or destroyed, so far as this does not conflict with our legal obligations to retain it.
Right to withdraw consent
To withdraw consent for processing that relies on consent, at any time.
Right to object to automated decisions
To object to solely automated decision-making producing legal effects or a significant impact on you. We do not make such decisions about users; AI output is information, not a decision about you.
Right to delay and restrict processing
To request that processing of your personal data be delayed or restricted as provided by law.
Right to data portability
To obtain and transfer your personal data in a commonly used, machine-readable format.
Right to sue and receive compensation
To bring a claim and receive compensation for a breach in the processing of your personal data as provided by law.

How to exercise these rights: send a request to [email protected] from the email address registered on your account. We may ask for further information to confirm the request genuinely comes from you — that verification protects your own account. We will respond within the period set by applicable law.

If you are not satisfied with our response, you have the right to complain to the competent personal data protection authority.

10. Security#

  • Passwords are stored as bcrypt hashes, never in their original form.
  • Traffic to the service is encrypted in transit (HTTPS).
  • Your own AI provider API keys are stored encrypted.
  • Session tokens are time-limited and are invalidated after a password change.
  • Secrets and tokens are redacted from log records before the log is written.
  • Requests are rate-limited to blunt abuse attempts.

No system is completely secure. If a personal data protection failure occurs, we will notify affected data subjects and the competent authority in writing within 3 x 24 hours of becoming aware of it, as required by Article 46 of the PDP Law.

11. Children#

Apex is not intended for children. You must be at least 18 years old to create an account. We do not knowingly collect children’s personal data. If we learn that an account was created by a child without the parental or guardian consent required by Article 25 of the PDP Law, the account will be closed and its data deleted.

12. Changes to this policy#

We may change this policy. The last updated date is shown at the top of the page. For material changes — for example a new data category, a new processing purpose, or a new processor that receives the content of your questions — we will notify you by email or an in-product notice before the change takes effect.

Baca naskah berbahasa Indonesia (naskah yang berlaku)