Trust
Trust and security at idapt
Where your data lives, who can reach it, and what we do when someone asks for it. Everything on this page is something we can show you.
idapt is operated by Logos Industries, a French société par actions simplifiée. Because the controller is established in France, the GDPR governs your data wherever in the world it is processed.
Where your data lives
The application, its database and your files are processed in the United States. Email and product analytics are processed in the European Union. In full: Germany, France, United States.
| What | Where | Provider | Safeguard |
|---|---|---|---|
| The application | United States (Ashburn, Virginia (ash)) | Hetzner | Standard Contractual Clauses |
| Your chats, notes, tasks and account records | United States (Ashburn, Virginia (ash), CloudNativePG PostgreSQL) | Hetzner | Standard Contractual Clauses |
| Caching and real-time delivery | United States (Ashburn, Virginia (ash), Valkey in-cluster) | Hetzner | Standard Contractual Clauses |
| Your files and generated media | United States (Western North America (WNAM)) | Cloudflare R2 | Data Privacy Framework, SCCs as fallback |
| Database backups | United States (Western North America (WNAM)) | Cloudflare R2 | Data Privacy Framework, SCCs as fallback |
| A second, write-once backup copy | United States (us-east-1, S3 with 30-day object lock) | Amazon Web Services | Data Privacy Framework, SCCs as fallback |
| Secrets and encryption keys | United States (us-east-1, Secrets Manager and KMS) | Amazon Web Services | Data Privacy Framework, SCCs as fallback |
| Code you or an agent runs | United States (us-east-1, Lambda) | Amazon Web Services | Data Privacy Framework, SCCs as fallback |
| The search index over your content | United States (aws-us-east-1) | Turbopuffer | Standard Contractual Clauses |
| GPU cloud computers | United States (Secure Cloud) | RunPod | Standard Contractual Clauses |
| Email we send you | France (European Union) | Brevo | Processed in the EEA |
| Product analytics | Germany (PostHog Cloud EU, AWS eu-central-1 (Frankfurt)) | PostHog | Standard Contractual Clauses |
For transfers outside the European Economic Area we rely on the European Commission's Standard Contractual Clauses, supported by a documented assessment of the destination country's law, or on the recipient's certification under the EU-U.S. Data Privacy Framework. You can request a copy of those safeguards from [email protected].
Sub-processors
We publish every third party that may process personal data on our behalf: 29 in total, including 7 infrastructure providers and 14 AI model providers we hold contracts with. A further 47 model providers are reachable through the OpenRouter gateway when you select a model they serve; those are listed by name too.
The list is generated from the same registry the application uses, so it cannot fall out of step with what we actually run. Business customers get 30 days' notice before we add one.
What we do, and do not do, with your data
Never used to train models
Not ours, not anyone else's. Model providers receive your prompts through their business APIs solely to generate the response you asked for, and are contractually barred from training on them. You can restrict routing to providers we have verified do not train, bring your own API keys, or run models on your own computer.
Never sold
We do not sell personal data and we do not build advertising profiles. If you accept marketing cookies, a pseudonymous identifier is shared with Google so we can measure which advert led to a sign-up. Nothing else, and you can refuse it.
Yours to take with you
Every resource exports in an open format: Markdown, JSON, CSV, ZIP, and standard git for repositories. We charge no egress or switching fees.
Deleted when you say so
Delete your account from Settings and your identifying details go immediately. To have the content you created erased too, ask us and we do it within a month. We keep invoices and payment records for the ten years French tax law requires, and nothing else.
How it is protected
Isolation enforced in the database
Every table carries PostgreSQL row-level security, so one workspace cannot read another's rows even if application code is wrong. Published apps are served on their own subdomain, which is the security boundary between them.
Encryption, and where the keys are
TLS on every connection, encryption at rest for the database, object storage and backups. To be straight about a weakness: the encryption keys are currently held in the same jurisdiction as the data they protect. Moving key custody is on our roadmap and we will say when it moves.
Who at idapt can read your content
Nobody, in the ordinary course. Access to customer content requires a deliberate elevation, is limited to the people who need it to resolve a specific issue, and is logged. Administrative access is restricted to a small explicit allowlist of verified idapt staff addresses. Two-factor authentication is available on every account, and we are working to require it for staff.
Backups and recovery
Continuous backups with a bounded recovery point, 30-day retention, and a second write-once copy held under object lock with a different provider so one compromised account cannot destroy both.
Government and law enforcement requests
We require valid legal process, we challenge requests that are broader than their stated purpose, and we tell you unless a law or court order forbids it. We produce the minimum the order actually compels, never a convenience export.
We are a French company. Under Article 48 GDPR, an order from a third-country court or authority is enforceable against us only through an international agreement such as a mutual legal assistance treaty, and we say so to any authority that asks without one.
Requests received to date
0
Updated annually. A period with no requests is reported as zero rather than omitted.
Incidents and vulnerability reports
If we have a breach
We notify the CNIL within 72 hours of becoming aware, and notify affected people directly without undue delay where the risk to them is high. Where we act as a processor for a business customer, we notify that customer so they can meet their own deadline.
If you find a vulnerability
Write to [email protected]. We acknowledge within 3 working days and assess within 10. We will not pursue legal action against researchers acting in good faith under the terms published at /.well-known/security.txt.
Controls you can configure
- Restrict which model providers a workspace may use at all.
- Route only to providers verified not to train on your data, or only to models running on your own hardware.
- Bring your own provider API keys, so calls bill to your account.
- Set how much autonomy agents have, from read-only to fully autonomous, per chat and per workspace.
- Cap spend per API key and per billing account.
- Review the audit log of who accessed which resource, and when.
Where we stand on regulation
We do not display certification badges we do not hold. There is no such thing as a GDPR certification, and we will not imply one.
GDPR
We comply as a controller established in France. Our lead supervisory authority is the CNIL. We maintain a record of processing, a data protection impact assessment, and a transfer impact assessment.
Digital Services Act
We host user content, so the notice-and-action mechanism at Report Content applies, and every restriction we impose comes with a statement of reasons and a route to contest it.
The documents
Questions this page does not answer: [email protected].