Privacy policy

Last updated 27 July 2026.

Octulus provides an AI agent that answers questions about a customer's website. This policy explains what we collect, why, and what we do not do with it.

What we collect

What we do not do

Subprocessors

We use Anthropic PBC to generate answers. Retrieved passages and the visitor's question are sent to the Claude API for the duration of the request. We do not permit that content to be used for model training.

Hosting is provided by our infrastructure vendor in the EU. A current subprocessor list is available on request from [email protected].

Retention

Conversations and captured leads are retained for the life of the workspace and deleted within 30 days of a workspace being deleted. Demo workspaces created without an account are deleted automatically after 72 hours. Rate-limiting metadata is held in memory only and is not persisted.

Your rights

If you are in the EEA or UK, you have the right to access, correct, export or delete personal data we hold about you, and to object to processing. Website visitors should contact the site operator whose agent they used; we will assist that operator as data processor. Direct requests to [email protected] and we will respond within 30 days.

Controller and processor roles

For our own website and customer accounts, Octulus is the data controller. For conversations happening on a customer's site, the customer is the controller and Octulus is the processor acting on their instructions.

Security

Data is encrypted in transit with TLS. Access to production systems is limited to named operators. The crawler rejects hosts resolving to private address ranges so it cannot be used to reach internal infrastructure.

Changes

We will post any change to this policy on this page and update the date above. Material changes will be emailed to account holders.

Contact

Questions about this policy: [email protected].