How Anthouse handles personal data
Last updated 15 August 2026
Anthouse is operated from Sofia, Bulgaria. Company registration details are on the company details page. For anything on this page, write to privacy@anthouse.io.
Account data: your name, work email and the workspace you belong to. Usage data: which apps you opened, deployed, shared or changed, recorded as an audit event with your name against it. Content: the source of the apps you deploy and any secrets you store, which are encrypted. Billing data is held by Stripe; we never see your card.
To run the service under our contract with your organisation, and to produce the audit record that is the point of the product. The audit log exists so your employer can answer who did what. It is not used for anything else.
The full list of processors, what each one does and where it runs is published on the subprocessors page and kept current.
Apps, their databases and the workspace record are in the European Union. Sign-in is currently processed in the United States under the EU-US Data Privacy Framework and Standard Contractual Clauses. This is stated plainly on our security page and is on our roadmap to change.
Account data for as long as the workspace exists. Audit events for 90 days on Team, and for a period you choose on Enterprise. When a workspace is deleted, data is removed within 30 days except where we must keep it by law.
Access, correction, deletion, restriction, portability and objection under the GDPR. Write to privacy@anthouse.io and we will answer within 30 days. If you are an employee using Anthouse through your employer, we act on your employer's instructions and will point you to them where that is the right route. You may also complain to the Bulgarian Commission for Personal Data Protection.