AntaraX Frame

Privacy

Last updated 2026-07-31

Draft — not yet reviewed by a lawyer. The factual parts of this document — what is collected, where it goes, who processes it — were written from the running code and are accurate as of 2026-07-31. The legal framing around them has not been reviewed and should not be relied on until it has been.

The short version

AXF is a ledger of your own infrastructure. Almost everything it holds is data you typed in about services you already pay for. We use it to show you your estate and to run your account — not to build a profile of you, and not to sell to anyone.

There is no advertising tracker, no third-party analytics and no session recording in this product. The only cookie set is the one that keeps you signed in, which is why you have never seen a cookie banner here: a strictly-necessary session cookie does not require consent.

What is collected

Account

Name, email address and profile picture, from your Google account. Nothing else is requested from Google.

Why: To sign you in, to show teammates who did what, and to email you.

What you enter

Asset names, vendors, costs, renewal dates, notes, monitoring URLs, project briefs, and the way you group things into stacks, systems, teams and projects.

Why: This is the product. It is your record of your own estate.

Billing

Subscription status, plan and invoice history. Card details are held by Stripe, never by AXF.

Why: To run your subscription.

Product usage

A first-party log of significant actions — an asset created, a plan generated — with your user id and a timestamp. There is no third-party analytics, no advertising tracker and no session recording.

Why: To understand which parts of the product are used, and to investigate faults.

We do not ask for, and have no use for, your date of birth, government identifiers, location, or contacts. If a field in the product does not exist, the data behind it is not being collected somewhere else.

Who else touches it

Running the product means other companies process some of this data on our behalf. Here is all of them, and precisely what reaches each one.

SupabaseDatabase, authentication and file storage — the system of record

Everything you enter, plus your name, email address and Google profile picture.

Their privacy policy →

VercelRuns and serves the application

Request metadata (IP address, user agent, requested path) in server logs.

Their privacy policy →

GoogleSign-in

Your sign-in request. Google returns your name, email address and profile picture to us.

Their privacy policy →

StripeSubscription paymentsConditional

Your email address and payment details. Card numbers go to Stripe directly and are never stored by AXF.

When: Only if you subscribe to a paid plan.

Their privacy policy →

ResendSends the emails the product needs to send

Recipient email addresses and message contents — renewal reminders, workspace invitations and product announcements.

Their privacy policy →

Anthropic (Claude) or Google (Gemini)Generates infrastructure plans and cost-optimisation suggestionsConditional

The project brief you write, and the names, vendors, categories and monthly costs of the assets in scope. Your name, email address and account identifiers are never included in a prompt.

When: Only when an API key has been configured. Without one, plans are built from a local catalogue and no data leaves AXF.

Their privacy policy →

ScreenshotOneCaptures a thumbnail of a monitored site so you can see it is upConditional

The monitoring URL you entered for an asset.

When: Only for assets where you set a monitoring URL, and only if a key has been configured.

Their privacy policy →

About the AI features specifically

Two features can send data to a language model: generating an infrastructure plan, and generating cost-optimisation suggestions. What goes into those prompts is the project brief you wrote and the names, vendors, categories and monthly costs of the assets in scope. Your name, email address and account identifiers are never put in a prompt.

If no API key is configured, neither feature calls out at all — plans are assembled from a local pricing catalogue and nothing leaves AXF.

Where it is stored

The database region is [confirm the Supabase project region before publishing]. It has not been asserted here because it is a hosting setting rather than something visible in the code, and stating the wrong region would be worse than stating none.

Some of the companies above operate outside your country, so processing them means data crossing a border. That is inherent to using a hosted product and is listed above so you can judge it.

Your rights

Under Malaysia's PDPA — and under the GDPR if you are in the EU or UK — you can ask for a copy of your data, ask for it to be corrected, and ask for it to be deleted.

For any of these: haziqfaris@reka.re. We will not ask you to justify the request, and there is no charge.

How long it is kept

Your estate data is kept for as long as your account exists, because it is a ledger and a ledger that forgets is useless. When you delete your account it is removed. Billing records are kept for as long as tax rules require, which is [confirm the retention period with an accountant].

Who we are

[registered company name and number], at [registered address]. Contact: haziqfaris@reka.re.

Changes

If this changes in a way that affects you, we will say so in the product rather than quietly editing this page. The date at the top is the last substantive change.

Questions about any of this: haziqfaris@reka.re.