1. Controller
The controller for data processing on this website within the meaning of the GDPR is HBW Softwares UG (haftungsbeschränkt), Sigbertstraße 5, 51427 Bergisch Gladbach, Germany, email [email protected].
2. Visiting the website
The marketing site and the product application are served from a virtual server operated by Hostinger, located in Boston, United States. When you open a page, your browser transmits data that the hosting provider processes to deliver it: IP address, the page requested, the time of the request, referrer, browser and operating system. This is necessary to serve the site and to keep it secure.
Cloudflare, Inc. sits in front of both domains as a content delivery network, terminates the TLS connection and filters abusive traffic. It processes the same connection data for that purpose.
Legal basis: Art. 6 (1) (f) GDPR, our legitimate interest in operating a working, secure website.
3. Analytics, and what the cookie banner actually decides
We use PostHog to count page views and understand which pages help. PostHog is configured to store and process data on servers in the European Union.
Consent does not switch analytics on and off. It switches whether we may store an identifier on your device. If you decline, or before you answer, PostHog runs in memory-only mode and the handbook pages use an identifier that exists for one page view and is never stored. Your visit is counted; you are not recognizable on your next visit. If you accept, an identifier is stored in a first-party cookie so repeat visits and the step from this site into the product can be recognized as one person.
Recorded either way: page URL, path, host, referrer, and coarse browser information. We do not record form contents, and we do not sell or share this data with advertisers.
Legal basis: Art. 6 (1) (a) GDPR (your consent) for storing the cookie; Art. 6 (1) (f) GDPR for the aggregate, non-identifying page count. You can withdraw consent at any time by deleting the cookies for this site in your browser, which restores the unanswered state and shows the banner again.
4. Asking for access
If you ask for access we process the email address you enter, the page you asked from, and, only if you choose to add it, the free-text note about the agent stack you use. We use it to invite you when access opens and to decide what to support first. We do not send unrelated marketing.
These entries are stored in our own database, a Postgres database operated by Neon Inc. and hosted in the Amazon Web Services Europe (London) region, alongside the rest of the service. They are not exported to a third-party marketing tool.
Legal basis: Art. 6 (1) (b) GDPR, steps taken at your request prior to entering into a contract. We keep an entry until it has been invited and used, or for twelve months after you ask for access, whichever comes first, and we delete it sooner on request.
5. Your account and your API keys
If you create an account at app.lagias.com, we process your email address for authentication, either by one-time code or through Google sign-in. The application, its API and the research engine run on a virtual server operated by Hostinger, located in Boston, United States. Your account and the records described below are stored in a Postgres database operated by Neon Inc., hosted in the Amazon Web Services Europe (London) region.
While you hold an API key we record what that key did: the tool called, the time, whether it succeeded, an error code when it did not, the engine time consumed, and the credits charged. We also record when a key is created and when it is revoked. This is what a usage bill, a quota and a security notice are made of, and it is the record we would need if a key were ever misused.
For founder accounts using the research workspace, the briefs submitted and the results produced for them are also stored. The chat in that workspace is answered by a large language model: the messages sent in a thread, and the research brief the copilot derives from them, are transmitted to OpenRouter, Inc. (United States), an AI model gateway, which routes them to the selected model provider in order to produce a reply. We never pass monetary amounts into a brief. So that we can diagnose failed conversations, traces of these turns are exported to Mastra Platform, operated by Mastra AI, Inc. An automatic filter removes credentials and values that look like personal data before a trace leaves our server.
Legal basis: Art. 6 (1) (b) GDPR, performance of the contract for the service you are using; Art. 6 (1) (f) GDPR for the key and usage records, our legitimate interest in metering the service and keeping it secure.
6. Email we send you
We send transactional email only: your sign-in code, a notice when an API key is created on your account, a warning when your monthly quota is nearly used up, and a message when access is granted. Delivery is handled by Resend (Plus Five Five, Inc.), which processes the recipient address and the message for that purpose.
Legal basis: Art. 6 (1) (b) GDPR for messages the service cannot work without; Art. 6 (1) (f) GDPR for the security notice, our legitimate interest and yours in you learning promptly that a key was created.
7. Recipients and processors
- Hostinger, server located in Boston, United States: hosting of the marketing site, the application, the API and the research engine
- Neon Inc., United States: the production database, with data stored in the Europe (London) region
- Cloudflare, Inc., United States: content delivery, TLS termination and abuse filtering for lagias.com and app.lagias.com
- Stripe Payments Europe, Limited and Stripe, Inc., with Link as merchant of record: payment and billing data for paid plans, including the billing details and payment method you enter at checkout, the subscription and its invoices
- OpenRouter, Inc. (United States): the chat copilot, as a gateway to the underlying model provider
- Mastra AI, Inc., United States: traces and logs of copilot turns, for diagnostics
- Resend (Plus Five Five, Inc.), United States: delivery of transactional email
- PostHog (EU region): product analytics, data stored in the European Union
- Better Auth, United States: sign-in and account events for our operations dashboard
- Google Ireland Limited: sign-in with Google, for accounts that use it
Each acts as a processor under a data processing agreement, except for the payment chain: as merchant of record it is a controller in its own right for the payment and for the anti-fraud and accounting duties that come with taking money, and we never see your full card number.
The application, its API and the research engine run on a server in the United States, and several of the processors listed above are established there. Those transfers rest on the EU standard contractual clauses and, where the recipient is certified under it, the EU-US Data Privacy Framework. The production database is held in the United Kingdom, which the European Commission has recognized as offering an adequate level of protection.
8. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Where processing rests on consent, you may withdraw it at any time with effect for the future. To exercise any of these, write to [email protected].
Signed in, two of these are buttons rather than emails. The settings screen in the dashboard exports everything held about your account as a JSON file, and deletes the account together with its keys, usage records and research.
You also have the right to lodge a complaint with a supervisory authority. The competent authority for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen.
9. Changes
We update this policy when the processing it describes changes. The date below is the version you are reading.
Last updated: August 2026