Last updated 2026-07-31
Draft — not yet reviewed by a lawyer. The factual parts of this document — what is collected, where it goes, who processes it — were written from the running code and are accurate as of 2026-07-31. The legal framing around them has not been reviewed and should not be relied on until it has been.
AXF is a ledger of your own infrastructure. Almost everything it holds is data you typed in about services you already pay for. We use it to show you your estate and to run your account — not to build a profile of you, and not to sell to anyone.
There is no advertising tracker, no third-party analytics and no session recording in this product. The only cookie set is the one that keeps you signed in, which is why you have never seen a cookie banner here: a strictly-necessary session cookie does not require consent.
Name, email address and profile picture, from your Google account. Nothing else is requested from Google.
Why: To sign you in, to show teammates who did what, and to email you.
Asset names, vendors, costs, renewal dates, notes, monitoring URLs, project briefs, and the way you group things into stacks, systems, teams and projects.
Why: This is the product. It is your record of your own estate.
Subscription status, plan and invoice history. Card details are held by Stripe, never by AXF.
Why: To run your subscription.
A first-party log of significant actions — an asset created, a plan generated — with your user id and a timestamp. There is no third-party analytics, no advertising tracker and no session recording.
Why: To understand which parts of the product are used, and to investigate faults.
We do not ask for, and have no use for, your date of birth, government identifiers, location, or contacts. If a field in the product does not exist, the data behind it is not being collected somewhere else.
Running the product means other companies process some of this data on our behalf. Here is all of them, and precisely what reaches each one.
Everything you enter, plus your name, email address and Google profile picture.
Request metadata (IP address, user agent, requested path) in server logs.
Your sign-in request. Google returns your name, email address and profile picture to us.
Your email address and payment details. Card numbers go to Stripe directly and are never stored by AXF.
When: Only if you subscribe to a paid plan.
Recipient email addresses and message contents — renewal reminders, workspace invitations and product announcements.
The project brief you write, and the names, vendors, categories and monthly costs of the assets in scope. Your name, email address and account identifiers are never included in a prompt.
When: Only when an API key has been configured. Without one, plans are built from a local catalogue and no data leaves AXF.
The monitoring URL you entered for an asset.
When: Only for assets where you set a monitoring URL, and only if a key has been configured.
Two features can send data to a language model: generating an infrastructure plan, and generating cost-optimisation suggestions. What goes into those prompts is the project brief you wrote and the names, vendors, categories and monthly costs of the assets in scope. Your name, email address and account identifiers are never put in a prompt.
If no API key is configured, neither feature calls out at all — plans are assembled from a local pricing catalogue and nothing leaves AXF.
The database region is [confirm the Supabase project region before publishing]. It has not been asserted here because it is a hosting setting rather than something visible in the code, and stating the wrong region would be worse than stating none.
Some of the companies above operate outside your country, so processing them means data crossing a border. That is inherent to using a hosted product and is listed above so you can judge it.
Under Malaysia's PDPA — and under the GDPR if you are in the EU or UK — you can ask for a copy of your data, ask for it to be corrected, and ask for it to be deleted.
For any of these: haziqfaris@reka.re. We will not ask you to justify the request, and there is no charge.
Your estate data is kept for as long as your account exists, because it is a ledger and a ledger that forgets is useless. When you delete your account it is removed. Billing records are kept for as long as tax rules require, which is [confirm the retention period with an accountant].
[registered company name and number], at [registered address]. Contact: haziqfaris@reka.re.
If this changes in a way that affects you, we will say so in the product rather than quietly editing this page. The date at the top is the last substantive change.