Privacy Policy
What we collect, on what basis, who we send it to, how long we keep it, and what rights you have over it.
1. Who is responsible#
The Personal Data Controller for Apex is PT BEHIRE INTERNATIONAL INDONESIA, of Ruko Jalur Sutera Timur 6B No. 03, Kelurahan Kunciran, Kecamatan Pinang, Kota Tangerang, Provinsi Banten 15144, Indonesia. This policy is written to follow Law No. 27 of 2022 on Personal Data Protection (the "PDP Law") and its implementing regulations.
Questions, requests and objections about personal data can be sent to [email protected].
[TO BE COMPLETED]
[TO BE COMPLETED]
2. The data we collect#
Account data — supplied by you when you register and use the service:
- Email address, name, and password (stored only as a bcrypt hash, never in its original form).
- Phone number and profile photo, if you provide them. Both are optional.
- Your Google or Facebook account identifier, if you sign in with one of them.
- Your Telegram chat ID, if you opt in to Telegram notifications.
- Preferences: language, theme, default market, chosen investment horizon, and notification settings.
- Your own referral code and the referral code you signed up with.
Data you create inside the product:
- Watchlists, portfolios and their allocations, trade journals, ideas, notes and saved picks.
- Comments and replies you write. Comments are public within the platform.
- The questions you type into AI features, and their answers. See "Data sent to AI providers" below — this is the part most worth understanding.
Data collected automatically as you use the service:
- AI usage records: the feature called, the model and model tier used, token counts, cost, latency, success or failure status, and credits debited.
- Previews of AI prompts and responses (up to roughly the first 800 characters) for incident handling, billing dispute resolution and abuse control.
- Engagement records: content you read, save or comment on, with timestamps. These are used to compute creator payouts.
- IP address and browser identity (user agent) on certain actions recorded in the audit log, and in server access logs.
- Transaction records: credit purchases, subscriptions, invoices, and credit balance movements.
If you become a creator or apply as a mentor, we also collect:
- Bank name, account number and account holder name, to pay you. This is financially sensitive personal data and is treated as access-restricted.
- Public creator profile: biography, photo, portfolio and social links, certifications, experience, and any consultation contact you choose to display.
3. Lawful basis for processing#
Article 20 of the PDP Law requires every processing activity to have a lawful basis. These are the bases we rely on for each group of processing.
| Processing | Lawful basis |
|---|---|
| Creating and running your account, giving access to the service | Performance of a contract |
| Processing credit purchases, subscriptions and creator payouts | Performance of a contract; legal obligation for financial records |
| Running the AI request you submit, including sending it to a model provider | Performance of a contract at your request |
| Sending verification, password reset and service notification email | Performance of a contract |
| Security: abuse prevention, rate limiting, audit logs, fraud detection | Legitimate interests of the controller |
| Computing creator payouts from reader engagement records | Legitimate interests; performance of the contract with the creator |
| Complying with law enforcement or competent authority requests | Legal obligation |
| Telegram notifications, marketing email, and product analytics if enabled | Consent, which you may withdraw at any time |
Where we rely on consent, withdrawing it takes effect going forward and does not undo processing already lawfully carried out.
4. Data sent to AI providers#
The model providers connected to Apex, and which may therefore receive the content of your question depending on the feature and model tier used:
- Google (Gemini)
- Anthropic (Claude)
- DeepSeek
- Groq
- Alibaba Cloud (Qwen / DashScope)
- OpenRouter (an aggregator that forwards to further model providers)
- Cloudflare (Workers AI)
- Models we run ourselves on our own infrastructure, whose data does not leave our systems.
We do not send your name, email address or account identifier to model providers with your question. However, the content you write yourself may contain personal data, and that is outside our control.
If you use your own AI provider API key (BYOK), the key is stored encrypted and your requests are forwarded to the provider using that key. That provider’s relationship and privacy policy then apply between you and them.
5. Processors and other third parties#
We use the following service providers to run Apex. Each receives only the data needed for its role.
| Party | Role | Data received |
|---|---|---|
| Xendit | Payment processing and disbursement | Payer email address, amount, currency, invoice description, reference; for disbursement: bank name, account number, account holder name |
| Brevo | Transactional email delivery | Recipient email address and message content (verification, password reset, notifications) |
| Cloudflare | Content delivery and edge protection; file storage; one of the AI model providers | IP address, HTTP requests, and files you upload |
| Google, Meta (Facebook) | Third-party sign-in, only if you choose it | Your sign-in interaction on their service; we receive an account identifier, email and name from them |
| Telegram | Notifications, only if you opt in | Chat ID and notification content |
| AI model providers | Running your AI requests — see the section above | The content of your question and its context |
| PostHog | Product analytics. NOT ACTIVE: the software is present in the application but not configured in the production environment, so no data is currently sent. | If activated: user id, email, name, role and usage events. This page will be updated before activation. |
The market data providers we use — exchanges and providers of price, economic and issuer data — are read-only sources. They receive no personal data about you.
We do not sell personal data, do not rent it, and do not trade it. We do not share personal data with advertisers.
We may disclose personal data where required by law, court order, or a lawful request from a competent authority; and in a merger, acquisition or business transfer, to the successor, subject to this policy continuing to apply.
6. Transfers outside Indonesia#
Most of the processors above run infrastructure outside Indonesia, so your personal data is processed across borders. Article 56 of the PDP Law governs transfers of personal data outside Indonesia. We address this by selecting processors that apply an equivalent level of protection, and by binding them through data processing agreements.
7. How long we keep data#
| Data | Retention |
|---|---|
| Account data and content you created | While the account is active, and afterwards for as long as needed for legal obligations or dispute resolution |
| Transaction, invoice and credit ledger records | Kept to satisfy financial and tax record-keeping obligations |
| AI prompt and response previews | 30 days, then removed from the usage record |
| AI usage metrics without prompt content (tokens, cost, latency, status) | Kept for billing, cost control and audit |
| Email verification and password reset tokens | Stored only as a hash; the record of their use is kept for security audit purposes |
| Audit logs and server access logs | Kept for security and incident investigation |
| Creator bank details on payout records | Attached to the relevant payout record and kept as proof of payment |
8. Your rights over your personal data#
Articles 5 to 15 of the PDP Law give you the following rights as a Personal Data Subject. We extend these rights to every Apex user:
- Right to information
- To be told our identity, the lawful basis, the purpose of processing, and the accountability of the party requesting data. This page is how we discharge that.
- Right of access
- To request a copy of the personal data we process about you.
- Right to rectification
- To complete, update or correct inaccurate data. Some of this you can do yourself in account settings.
- Right to end processing, delete and destroy
- To request that processing stop and that your personal data be deleted or destroyed, so far as this does not conflict with our legal obligations to retain it.
- Right to withdraw consent
- To withdraw consent for processing that relies on consent, at any time.
- Right to object to automated decisions
- To object to solely automated decision-making producing legal effects or a significant impact on you. We do not make such decisions about users; AI output is information, not a decision about you.
- Right to delay and restrict processing
- To request that processing of your personal data be delayed or restricted as provided by law.
- Right to data portability
- To obtain and transfer your personal data in a commonly used, machine-readable format.
- Right to sue and receive compensation
- To bring a claim and receive compensation for a breach in the processing of your personal data as provided by law.
How to exercise these rights: send a request to [email protected] from the email address registered on your account. We may ask for further information to confirm the request genuinely comes from you — that verification protects your own account. We will respond within the period set by applicable law.
If you are not satisfied with our response, you have the right to complain to the competent personal data protection authority.
10. Security#
- Passwords are stored as bcrypt hashes, never in their original form.
- Traffic to the service is encrypted in transit (HTTPS).
- Your own AI provider API keys are stored encrypted.
- Session tokens are time-limited and are invalidated after a password change.
- Secrets and tokens are redacted from log records before the log is written.
- Requests are rate-limited to blunt abuse attempts.
No system is completely secure. If a personal data protection failure occurs, we will notify affected data subjects and the competent authority in writing within 3 x 24 hours of becoming aware of it, as required by Article 46 of the PDP Law.
11. Children#
Apex is not intended for children. You must be at least 18 years old to create an account. We do not knowingly collect children’s personal data. If we learn that an account was created by a child without the parental or guardian consent required by Article 25 of the PDP Law, the account will be closed and its data deleted.
12. Changes to this policy#
We may change this policy. The last updated date is shown at the top of the page. For material changes — for example a new data category, a new processing purpose, or a new processor that receives the content of your questions — we will notify you by email or an in-product notice before the change takes effect.