Legal

Privacy Policy

Last updated July 20, 2026.

1. Overview

This Privacy Policy explains how Lukas Friedman, sole proprietor doing business as Ballast (“Ballast,” “we”) collects, uses, and shares information when you use the Ballast platform, websites, and APIs (the “Service”). For workspace and workflow content processed on behalf of a customer, we act as a processor; that customer is the controller.

2. Information we collect

  • Account data — name, email, hashed password, workspace membership and role, and (if you opt in) a phone number for SMS approvals.
  • Workflow content — the workflows, inputs, run outputs, evaluations, and logs you create or generate.
  • Usage & telemetry — run counts, cost attribution, timestamps, and an immutable audit log of actions.
  • Billing data — plan and subscription status. Card details are handled by Whop; we do not store full card numbers.
  • Technical data — IP address, request metadata, and device/browser information for security and reliability.

3. How we use information

To provide, secure, and improve the Service; to authenticate users and enforce access controls; to meter usage and process billing; to send transactional messages (including approval texts you opt into); to provide support; to detect abuse and comply with law.

4. Legal bases (EEA/UK)

Where GDPR applies, we process on the bases of contract (to deliver the Service), legitimate interests (security, product improvement), consent (e.g., SMS opt-in), and legal obligation.

5. Subprocessors & sharing

We share data with vendors that help us run the Service, under contract and only as needed:

  • Hosting / database — Vercel and Render (application hosting) and Supabase (managed Postgres).
  • Model providers — Anthropic and/or OpenAI, when you configure them to run agent steps.
  • Payments — Whop.
  • Messaging & email — Twilio (SMS) and Resend (email).
  • Analytics — Google Analytics (Google LLC), for aggregate website usage on our marketing site.

We do not sell personal information. We may disclose information to comply with law or protect rights and safety.

6. Retention

We retain account data while your account is active. Runs and audit logs are retained per your plan’s retention window and then deleted by an automated sweeper. You may request earlier deletion, subject to legal and operational limits.

7. Security

We use industry-standard measures: encryption in transit, hashed passwords (scrypt), scoped API keys, role-based access control, tenant isolation, an SSRF guard on outbound tool calls, and audit logging. No system is perfectly secure; report concerns to security@ballastos.com.

8. International transfers

We may process data in the United States. Where required, we use appropriate safeguards such as Standard Contractual Clauses for transfers out of the EEA/UK.

9. Your rights

Depending on your location, you may have rights to access, correct, delete, port, or object to processing of your personal data, and to withdraw consent. To exercise them, contact us at the address below. Customers’ end-user data requests are handled through the customer as controller.

10. Cookies

The console uses strictly necessary cookies for authentication — a session cookie and a readable CSRF token — and local storage for preferences. Our marketing website additionally offers Google Analytics to measure aggregate traffic; its analytics cookies are set only if you accept them in our cookie banner, and you can change or withdraw that choice at any time (). We do not sell your personal information or use it for cross-site advertising.

11. Children

The Service is not directed to children under 16, and we do not knowingly collect their personal data.

12. Changes & contact

We may update this Policy; material changes will be posted here with a new date. For privacy questions or a Data Processing Addendum, contact legal@ballastos.com. A postal address for legal correspondence is available on request.