Aktuals

Privacy Policy

What Aktuals collects, why, and the choices you have. Built around processing data on the device and uploading only what your privacy tier allows.

Last updated: June 10, 2026

Who we are

Aktuals provides AI usage and productivity intelligence for organizations: a cloud platform at aktuals.ai together with a downloadable desktop agent. This Privacy Policy explains what we collect, why, and the choices you have. Questions or requests: help@aktuals.ai.

Aktuals is in closed early access. This policy applies to aktuals.ai, app.aktuals.ai, the Aktuals desktop agent, and related services (the "Service").

Two kinds of people this covers

We handle data about two groups, with different relationships to us:

  • Account holders — people who sign in to Aktuals.
  • Members of a customer organization whose AI coding/agent sessions the desktop agent processes after that organization installs it. For this group, the organization is the controller of the data and decides what is collected; Aktuals processes it on the organization's behalf.

What we collect

Account & access data. Your email address, your organization and role, and authentication data. We store passwords only as salted hashes and multi-factor secrets only in encrypted form — never in plain text. If you join the waitlist, we store the email you give us and nothing else.

Data from the desktop agent. Only after an organization installs the agent and selects a privacy tier, the agent reads local AI-tool session files and local git metadata on enrolled machines, processes them on the device, and uploads derived records shaped by the chosen tier:

  • Tier 1 — Metrics (default). Token counts, model identifiers, timestamps, session durations, category and tool histograms, capability-class splits, confidence-banded links between sessions and shipped git commits, project labels, and counts of credentials redacted. No prompt or response text.
  • Tier 2 — Summaries. Tier 1, plus short session summaries and capped first-prompt excerpts.
  • Tier 3 — Transcripts. Tier 1 and 2, plus tiered transcript turns, stored encrypted per organization.

Identity hints. Git author email addresses observed locally, used to reconcile which work belongs to which contributor.

What stays on the device, and what we never receive

Parsing, de-duplication, and credential redaction happen on the device before anything is uploaded. The agent scans every text field it collects and removes secrets — API keys, tokens, private keys, connection strings, and similar — at the source, on every tier. We receive the redaction counts, never the secrets themselves. Each enrolled person can run a single command to see exactly what is collected at the active tier.

Our anti-surveillance commitments

These are built into the product, not just stated here:

  • Leadership views show patterns and cohorts, never ranked individuals.
  • Every person can see exactly what is collected about them.
  • There is no mode that hides collection from the people it covers.
  • Confidence is shown as bands (high / medium / low), never as a precise score implying false certainty, and dollar-shaped figures are clearly labeled as estimates, never as authoritative billing.

How we use data

To operate and secure the Service; to produce usage, productivity, and output intelligence — including categorizations, summaries, and narratives synthesized with the help of large-language-model services acting on our behalf; and to communicate with you about your account and early access. Our AI-analysis providers process data on our instructions and do not use it to train their models.

Sharing and subprocessors

We do not sell personal data and we do not use it for third-party advertising. We rely on a small set of vetted subprocessors to run the Service: cloud infrastructure and storage, AI analysis, transactional email, and identity/email. A current list is available on request at help@aktuals.ai. We may disclose data if required by law, or to protect the rights and safety of users and the public.

Storage, location, and retention

Data is stored on cloud infrastructure with per-organization isolation, and may be processed in the United States and other regions where our providers operate, with appropriate safeguards. Transcript-tier content is retained for a limited period (90 days by default) and aggregate metrics longer; an organization can configure retention and request deletion.

Security

Encryption in transit (TLS); tokens and session identifiers stored only as hashes; passwords hashed; multi-factor secrets encrypted at rest; Tier-3 transcripts encrypted per organization; and credential redaction performed at the agent before upload. No system is perfectly secure, but we design to minimize what leaves a device and what we hold.

Your rights and choices

Depending on your location, you may have rights to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise them, email help@aktuals.ai. If you are a member of a customer organization, some requests are directed through that organization as the controller; we will assist them in responding.

Cookies

We use a single first-party cookie to keep you signed in across aktuals.ai subdomains. We do not use third-party advertising or cross-site tracking cookies.

Children

Aktuals is a workplace product and is not directed to anyone under 18. We do not knowingly collect data from children.

Changes to this policy

We will post any updates on this page with a new "last updated" date, and notify account holders of material changes.

Contact

Aktuals — help@aktuals.ai.