How Anthouse handles personal data

Privacy

Last updated 15 August 2026

Who we are

Anthouse is operated from Sofia, Bulgaria. Company registration details are on the company details page. For anything on this page, write to privacy@anthouse.io.

What we collect

Account data: your name, work email and the workspace you belong to. Usage data: which apps you opened, deployed, shared or changed, recorded as an audit event with your name against it. Content: the source of the apps you deploy and any secrets you store, which are encrypted. Billing data is held by Stripe; we never see your card.

Why we hold it

To run the service under our contract with your organisation, and to produce the audit record that is the point of the product. The audit log exists so your employer can answer who did what. It is not used for anything else.

Who else processes it

The full list of processors, what each one does and where it runs is published on the subprocessors page and kept current.

Where it is held

Apps, their databases and the workspace record are in the European Union. Sign-in is currently processed in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses. This is stated plainly on our security page and is on our roadmap to change.

How long we keep it

Account data for as long as the workspace exists. Audit events for 90 days on Team, and for a period you choose on Enterprise. When a workspace is deleted, data is removed within 30 days except where we must keep it by law.

Your rights

Access, correction, deletion, restriction, portability and objection under the GDPR. Write to privacy@anthouse.io and we will answer within 30 days. If you are an employee using Anthouse through your employer, we act on your employer's instructions and will point you to them where that is the right route. You may also complain to the Bulgarian Commission for Personal Data Protection.