Privacy and your data#
This page explains what Astralyx keeps about people (accounts), for how long, and how each person exercises their rights over it — under Brazil's data protection law (LGPD) and any other. What your work uses and produces stays on your machines; see What leaves your machines.
The legal texts are the Privacy Policy and the Terms of Use, also at astralyx.cloud/privacy with the list of sub-processors. Questions and requests: [email protected] (Astralyx's data protection officer).
Drafts under legal review
The current Terms of Use and Privacy Policy (version 2026-10-draft)
are drafts still being reviewed by a lawyer, and are marked as such
wherever they are shown. A draft can be read and accepted, but nobody
is required to accept it: the rules below apply from the first reviewed
version.
Before you begin#
- Everything on this page is about your own account: anyone signed in can do it, in Account → Privacy (the account menu, Privacy & your data).
- In the API examples,
ASTRALYX_APIishttps://api.astralyx.cloud/v1andASTRALYX_TOKENa CLI session or an API token for all your workspaces (API tokens and automation).
What Astralyx keeps, and for how long#
| What | Why | Kept |
|---|---|---|
| Your name, e-mail address, and your password as a one-way hash (or your Google or GitHub identity) | Your account and signing you in | Until you delete the account |
| Your sessions: when they started, IP address, browser or client | Keeping you signed in; security | Until they expire: 12 hours in the browser, 30 days for astra |
Every sign-in and every change made through the console, astra or the API, with time and IP address (the audit log) |
Access records Brazilian law requires (Marco Civil da Internet); security; your organisation's record of who changed what | 12 months by default, never less than 6 |
| Organisation and workspace memberships, invitations | Your access | Memberships: until removed; invitations: 30 days after accepted or expired |
| Personal API tokens: name, prefix, dates (the token only as a hash) | Scripts acting as you | Until revoked, or 30 days after they expire |
| Which version of the Terms and the Privacy Policy you accepted, when and from which address | Proof of acceptance | With the account |
| Your choice about product news by e-mail | Consent | With the account |
| Your privacy requests: what you asked and when it was answered, never the content | Showing they were answered | 5 years |
Events of runs and machines are kept 90 days by default (an organisation can choose per workspace: Events). They describe the organisation's work, not you.
Astralyx keeps no password, token or secret in a form that can be used: they are stored as one-way hashes, or encrypted. It does not sell personal data, use it for advertising, or set tracking cookies — only the session cookie and the theme preference.
The Terms of Use and the Privacy Policy#
Each version of the Terms of Use and the Privacy Policy has a name and an effective date. Each acceptance is recorded with the version, the time, your IP address and your browser.
Drafts (marked "Draft — under legal review") can be read and accepted, but are never required: signing up does not ask for them, and nothing is blocked while the documents in effect are drafts. You can accept one by choice in Account → Privacy → Terms and consents.
Reviewed versions are required. Creating an account means accepting them: the sign-up form asks for it, and signing up with Google, GitHub or single sign-on shows the same request before anything else. When Astralyx publishes a new reviewed version, everyone accepts it at their next use of the console: a dialog shows what changed (each document opens in a new tab), with Accept and continue and Sign out. Until you accept, the console shows nothing else. Reading your account, accepting, signing out and the privacy actions below always work: someone who does not accept can still download their data or delete their account.
Accept in the dialog. Account → Privacy → Terms and consents lists every version you accepted, with when; each links to its text.
$ curl -sS "$ASTRALYX_API/legal"
{"items":[{"kind":"terms","version":"2026-10-draft","effective_at":"2026-10-02T00:00:00Z","title":"Terms of Use","draft":true},
{"kind":"privacy","version":"2026-10-draft","effective_at":"2026-10-02T00:00:00Z","title":"Privacy Policy","draft":true}]}
$ curl -sS -X POST "$ASTRALYX_API/me/legal/accept" -H "Authorization: Bearer $ASTRALYX_TOKEN" \
-H "Content-Type: application/json" -d '{"versions": {"terms": "2026-10-draft", "privacy": "2026-10-draft"}}'
GET /me lists what you still have to accept in legal_pending.
GET /legal/{kind} returns the text in effect (English and Portuguese,
Markdown) and GET /legal/{kind}/{version} any earlier version. If a
version you send is no longer the one in effect, the answer is
409 TERMS_OUTDATED: read the new one first.
Scripts and pipelines that use your personal API token or a CLI
session keep working for 30 days after a new reviewed version takes
effect: their answers carry the header Astralyx-Terms: pending, so they
can warn you. After 30 days they are refused with 403 TERMS_NOT_ACCEPTED
until you accept in the console. Watch for the header in automation:
$ curl -sSI "$ASTRALYX_API/organizations" -H "Authorization: Bearer $ASTRALYX_TOKEN" | grep -i astralyx-terms
astralyx-terms: pending
Product news by e-mail#
Optional and off unless you turn it on (a box on the sign-up form, or later). E-mails the service needs — verification, invitations, approvals, alerts you set up, receipts — are sent either way.
Account → Privacy → Terms and consents: tick or untick Product news by e-mail. It applies at once and shows since when it is on.
Every change is recorded in the audit log with its time and address.
Correct your name and e-mail address#
Account → Privacy → Profile: change Name and select Save name. To change the address, enter the new one (and your current password, if you have one) and select Change e-mail. Astralyx sends a link to the new address, valid 24 hours, and tells your current address; your account moves to the new address when the link is opened.
$ curl -sS -X PATCH "$ASTRALYX_API/me" -H "Authorization: Bearer $ASTRALYX_TOKEN" \
-H "Content-Type: application/json" -d '{"name": "Ana Souza"}'
$ curl -sS -X POST "$ASTRALYX_API/me/email" -H "Authorization: Bearer $ASTRALYX_TOKEN" \
-H "Content-Type: application/json" -d '{"email": "<new address>", "password": "<password>"}'
{"status":"check the new address to confirm it"}
| Error | Cause |
|---|---|
400 INVALID_NAME |
The name is longer than 200 characters. |
400 INVALID_EMAIL, 400 SAME_EMAIL |
Not an address, or already yours. |
403 INVALID_CREDENTIALS |
The password is wrong. |
409 EMAIL_TAKEN |
When the link is opened, another account uses that address. |
429 TOO_MANY_ATTEMPTS |
More than 5 changes requested in an hour. |
If you sign in with Google, GitHub or single sign-on, the address there is the provider's; change it there too.
Download your data#
A copy of everything Astralyx keeps about you: your profile, sign-in identities (the provider and your account's identifier there), sessions (IP address, browser, dates), command-line sign-ins, your API tokens' names and prefixes, your organisation and workspace memberships, invitations you received and sent, the versions you accepted and your consents, your privacy requests, and the audit entries about you (up to 50 000). It never contains a password, a password hash or a token.
It comes as JSON (to take to another service) and as a readable page (HTML). Each can be downloaded once, within one hour; then the copy is deleted. Both the request and each download are recorded in the audit log.
- Open Account → Privacy and, under Download my data, select Prepare a copy.
- Select Download JSON and Download readable page.
$ curl -sS -X POST "$ASTRALYX_API/me/privacy/exports" -H "Authorization: Bearer $ASTRALYX_TOKEN"
{"id":"0192f3a4-7000-…","expires_at":"2026-10-02T13:00:00Z",
"download":{"json":"/api/v1/me/privacy/exports/0192f3a4-7000-…/download?format=json","html":"…?format=html"}}
$ curl -sS -o my-data.json "$ASTRALYX_API/me/privacy/exports/<id>/download?format=json" \
-H "Authorization: Bearer $ASTRALYX_TOKEN"
A second download of the same format, or one after the hour, answers
404 EXPORT_NOT_FOUND: prepare a new copy. At most 5 copies an hour.
Delete your account#
Deleting your account removes, at once, your profile (name and e-mail), sign-in identities, sessions, API tokens, consents and memberships. Your sessions end and your tokens stop working. A receipt is e-mailed to you.
What is kept, because the law requires it: the time and IP address of
your sign-ins and of the changes made in your name (the access records of
the Marco Civil da Internet), no longer linked to your name or e-mail but to
a code, deleted user <code>, which the receipt quotes. They are deleted
when the audit log's period ends (12 months from each record by default).
What is not yours to delete: runs, machines, models, drives and data belong to the organisations they are in, and stay on their machines. Deleting your account does not delete them; ask the organisation's owner.
What must happen first#
An organisation always keeps an owner. Deleting is refused, with the list, while you are:
- the last owner of an organisation others belong to — transfer ownership to another member (Members), or delete the organisation;
- the only member of an organisation that still has clusters — remove them, or delete the organisation.
An organisation only you belong to, with no clusters — your personal one, typically — is deleted with your account.
Delete#
- Open Account → Privacy. Under Delete my account, anything that must happen first is listed, each with a link to where to do it.
- Select Delete my account…, type your e-mail address and your password, and confirm.
If you sign in with Google, GitHub or single sign-on (no password), sign out and in again first: the deletion must happen within 10 minutes of signing in.
$ curl -sS "$ASTRALYX_API/me/privacy" -H "Authorization: Bearer $ASTRALYX_TOKEN" # deletion.blockers
$ curl -sS -X POST "$ASTRALYX_API/me/privacy/deletion" -H "Authorization: Bearer $ASTRALYX_TOKEN" \
-H "Content-Type: application/json" -d '{"confirm_email": "<your address>", "password": "<password>"}'
{"deleted":true,"reference":"deleted user 3f9a0c51d2e47b86","at":"2026-10-02T12:30:00Z","orgs_deleted":["ana-lima"]}
Only with a CLI session (astra login) or the console, never with a
personal API token.
| Error | Cause |
|---|---|
400 CONFIRMATION_MISMATCH |
The address typed is not the account's. |
403 INVALID_CREDENTIALS |
The password is wrong. |
403 REAUTH_REQUIRED |
Called with a personal API token; or, without a password, you signed in more than 10 minutes ago. |
409 ACCOUNT_HAS_ORGANISATIONS |
Organisations to transfer or delete first (detail.blockers). |
After deletion the address is free: signing up with it again makes a new, empty account.
Other requests#
For anything the console does not do — you cannot sign in, you want to know more about how your data is used, or you object to something — write to [email protected]. Astralyx may ask you to confirm it is you, confirms at once and answers in full within 15 days. You may also petition Brazil's data protection authority (ANPD).
For organisation admins#
- A member who deletes their account leaves the organisation at once.
Your audit log keeps their entries, with time
and address, under
deleted user <code>instead of their e-mail. Pending invitations to them are withdrawn, and their address is removed from your e-mail alert channels. - Owners who leave: transfer ownership before they go (Members) — an owner cannot delete their account while the organisation would be left without one.
- Your organisation's work is yours. For the metadata of your work that Astralyx keeps (the names, specifications, states and events of machines, runs, deployments, agents and flows, and usage counts) your organisation is the controller and Astralyx processes it on your behalf. Requests from people about personal data in your work go to you; Astralyx helps you answer them.