Who we are
Apex World Labs ("Apex", "we", "us") operates apexworldlabs.com, the Aether platform, and the products built on it. We are headquartered in San Francisco, California, USA. In the European Union our representative is reachable at the contact address below; in the United Kingdom, our UK representative is reachable at the same address.
What we collect
We collect only what we need to evaluate, deliver and improve the products you ask for. Concretely:
- Account data — name, work email, organisation, role, and the products you are evaluating.
- Authentication data — SSO claims and SCIM-provisioned attributes, when your organisation uses them.
- Usage data — API calls, model invocations, tool calls, evaluation runs and aggregate metrics required to operate, bill and secure the service.
- Audit data — immutable trace records of decisions, tool calls and memory writes for accountability and incident response.
- Customer content — the data you submit to Aether for processing (prompts, simulation cases, code, lab data, etc.).
- Website analytics — minimal first-party analytics on apexworldlabs.com. We do not use third-party advertising trackers.
What we do not collect
- We do not collect special-category data (race, religion, sexual orientation, etc.) unless you explicitly submit it as customer content for a documented purpose.
- We do not knowingly collect data from individuals under 16.
- We do not buy or rent personal data from third parties.
How we use customer data
Customer content is used to provide the service to you. We do not use customer content to train base models. Customer fine-tunes are scoped to the customer that requested them and are never re-used across tenants. Right-to-delete is enforced by the runtime, not by a post-hoc job.
Legal bases
Under GDPR and UK-GDPR our lawful bases are: performance of a contract with you or your organisation; our legitimate interest in operating, securing and improving the service; consent where required; and compliance with applicable legal obligations.
Sharing
We share data with vetted sub-processors (cloud infrastructure, observability, payments) under written data-processing agreements. A current sub-processor list is available on request. We do not sell personal data, and we do not share customer content with third parties for marketing.
Retention
- Account data — for the life of the customer relationship, plus a tail required by tax and audit obligations (typically 7 years in the US).
- Customer content — controlled by your retention policy. Default is the duration of the contract.
- Audit data — minimum 7 years for regulated deployments; configurable for non-regulated tenants.
- Website analytics — 13 months.
Your rights
Under GDPR, UK-GDPR, CCPA, CPRA and other applicable regimes you have the right to access, correct, delete or port your personal data; to restrict or object to processing; to withdraw consent; and to lodge a complaint with a supervisory authority. To exercise any of these, write to privacy@apexworldlabs.com.
Transfers
Our default infrastructure is multi-region. Where data crosses regions we use the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, and additional safeguards appropriate to the jurisdiction. Customers can pin data-residency to a single region under the Team and Enterprise tiers.
Security
Engineering controls are documented at /security and the trust policy at /legal/trust. We hold SOC 2 Type II; ISO 27001 and ISO 42001 certifications are in progress.
Children
Our products are not directed to individuals under 16 and we do not knowingly collect data from them. If you believe a minor has shared data with us, write to privacy@apexworldlabs.com.
Changes
We update this notice when material changes occur. Material changes are announced via a banner on apexworldlabs.com and via email to account contacts. The current version, the effective date and a change log are available in the document footer.