Apex
Back to home

Privacy Policy

Apex — Privacy Policy

Effective from 1 October 2026

This Privacy Policy explains how Callstack processes personal data in connection with Apex: the website at apex.callstack.com, the developer console at platform.callstack.ai, and the API at api.callstack.ai.


1. Who we are

The controller of your personal data is Callstack.io spółka z ograniczoną odpowiedzialnością, ul. Prosta 36, 53-508 Wrocław, Poland, KRS 0000606530, NIP 8992785616 ("Callstack", "we", "us").

For anything concerning your personal data, contact us at apex@callstack.com, with "Privacy" in the subject line, or by post at the address above.


2. When we are the controller, and when we are not

We are the controller of personal data we process to run Apex as a business: website visits, accounts, billing, support, security, and compliance. If you hold an individual account, we are also the controller of the content you send to the API and receive back.

We are a processor for business customers. When a company uses Apex and its API requests contain personal data — for example, names in a document it asks Apex to summarise — that company is the controller and decides what data is sent and why. We process that data only on its instructions, under the Data Processing Agreement in Annex 2 of our Commercial Terms, and — like all API content — we do not store it. If your data reached us that way, the company's own privacy notice applies, and you should contact the company to exercise your rights. We will help it respond.

Authorised distribution partners. If you use Apex through a third-party platform or gateway, that platform is the controller of the data it collects about you. We receive only the content of your requests and the technical metadata needed to serve them.


3. What we process, why, and on what basis

Website visitors

Data Purpose Legal basis Retention
IP address, browser and device information, pages requested, timestamps Delivering the website, protecting it against attacks and abuse Our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR) 30 days
Strictly necessary cookies Keeping you signed in, remembering your consent choices, security Our legitimate interest, and the exemption for strictly necessary cookies under the Polish Electronic Communications Law Session, or up to 12 months for consent preferences
Analytics cookies Understanding how the website is used, to improve it Your consent (Art. 6(1)(a) GDPR), which you give or refuse in the cookie banner and can withdraw at any time Up to 13 months

We set analytics cookies only after you consent. Refusing them does not affect your ability to use the website or the service.

Account holders

Data Purpose Legal basis Retention
Name, email address, password (stored only as a hash), account type; for business accounts, company name and VAT number Creating and running your account Performance of the contract (Art. 6(1)(b)); for contact persons at business customers, our legitimate interest in managing the business relationship (Art. 6(1)(f)) For the life of the account, then until the limitation periods for claims expire
VAT number validation result from the EU VIES system Confirming business status and applying the correct VAT treatment Legal obligation under VAT law (Art. 6(1)(c)) As for billing records
Sanctions-list screening result Ensuring we do not provide services to sanctioned persons Legal obligation under EU and Polish sanctions law (Art. 6(1)(c)) For the life of the account plus five years
API key identifiers, spend limits, settings and consents you give in the console Operating the service according to your configuration, and demonstrating consents obtained at checkout Performance of the contract; for evidence of consents, legal obligation under consumer law (Art. 6(1)(c)) For the life of the account, then until the limitation periods for claims expire

Billing

Card payments are processed by Stripe Payments Europe, Limited. We never receive your full card number. Stripe also processes some data as an independent controller, for example to prevent fraud; its privacy policy applies to that processing.

Data Purpose Legal basis Retention
Billing name and address, VAT number, card brand, last four digits and expiry date, transaction and invoice history, credit balance Taking payment, issuing invoices, managing credits and refunds Performance of the contract; legal obligation under tax and accounting law For the period required by Polish tax and accounting law — currently five years from the end of the calendar year in which the tax payment deadline fell

Using the API

Data Purpose Legal basis Retention
Request metadata: timestamps, token counts, model identifiers, API key identifier, source IP address, response status and latency Billing, rate limiting, security, abuse prevention, troubleshooting Performance of the contract; our legitimate interest in keeping the service secure and reliable Billing records as above; other metadata up to 12 months
Individual accounts: the content of your requests (Input) and of the responses (Output) Generating responses; automated safety checks against misuse, carried out while the request is being processed Performance of the contract; our legitimate interest in preventing misuse of the service Not stored. Processed in memory only for the duration of the request, then discarded
Feedback you choose to send us, such as a response you flag in the console, together with the content you attach to it Improving Apex and investigating the issue you report Your consent (Art. 6(1)(a)), given when you submit the feedback Up to 24 months

Zero data retention. Every API request is processed under zero data retention, for every account and every route of access. Inputs and Outputs exist only in memory while the response is being generated. They are never written to disk, logs or backups, and they are never used to train our models. Once a request completes, we cannot retrieve its content — not for you, not for ourselves, and not for anyone who asks us for it. Only the request metadata described above is kept.

The only way content can reach us beyond a single request is if you deliberately send it to us as feedback. You can withdraw consent to our use of your feedback at any time by contacting us; withdrawal stops further use, but cannot undo improvements to Apex already made using it.

Support, complaints and communications

Data Purpose Legal basis Retention
Your messages to us and our replies Answering questions, handling complaints and withdrawal requests Performance of the contract; legal obligation to handle consumer complaints and withdrawals (Art. 6(1)(c)) Until the limitation periods for claims expire
Email address Service messages: security alerts, changes to terms or prices, model deprecations, billing notices Performance of the contract; legal obligation to notify changes For the life of the account
Email address Newsletters and product announcements Your consent (Art. 6(1)(a)), as required by Polish law for electronic marketing communications Until you withdraw consent or unsubscribe

Legal claims

We may retain the data described above for longer where it is needed to establish, exercise or defend legal claims, on the basis of our legitimate interest (Art. 6(1)(f)), until the relevant limitation period expires.


4. Personal data in Apex's training content

Apex is built by post-training a base model released by Qwen. Callstack's post-training used source code and technical documentation from publicly available open-source repositories, and internal Callstack technical documents. Details are in our Training Data Summary at https://apex.callstack.com/legal/training-data-summary.

Open-source repositories can incidentally contain personal data — typically the names, usernames or email addresses of contributors that appear in copyright notices, licence files and author fields. We did not seek out personal data, and our training content consisted of source code and documentation files, not commit histories, issue trackers or discussion threads. Apex is not designed to provide information about individuals.

We rely on our legitimate interest in developing a specialised software-engineering model (Art. 6(1)(f)). Because we cannot identify or contact the individuals concerned, individual notification is impossible or would involve disproportionate effort, and we provide this information publicly instead (Art. 14(5)(b) GDPR).

You may object to this processing, or exercise your other rights, by contacting us at apex@callstack.com. Removing specific data from a trained model is not always technically possible, but we will assess every request and, where appropriate, apply filtering to prevent that data appearing in Outputs.

For the training of the base model, see the documentation published by Qwen.


5. Who receives your data

We share personal data only as needed for the purposes above, with:

  • Stripe, for payment processing
  • infrastructure and hosting providers, which run our servers within the European Economic Area and store account and billing data on our behalf; API content passes through their systems only transiently and is not stored
  • email delivery and customer support providers, for sending service messages and handling your requests
  • professional advisers, such as lawyers, accountants and auditors, under duties of confidentiality
  • public authorities, where we are legally required to disclose data

Service providers acting on our behalf are bound by data processing agreements and may use the data only on our instructions. The service providers that process API content for business customers are listed in Appendix 2 to Annex 2 of our Commercial Terms.

We do not sell personal data, and we do not share it for advertising.


6. Transfers outside the European Economic Area

We process and store personal data within the European Economic Area. Where a recipient — for example our payment processor — processes data outside the EEA, the transfer is based on an adequacy decision of the European Commission or on the Commission's Standard Contractual Clauses. You can request a copy of the relevant safeguards at apex@callstack.com.


7. Automated decisions

We do not make decisions based solely on automated processing that produce legal or similarly significant effects for you within the meaning of Article 22 GDPR.

Automated systems monitor traffic for abuse and may temporarily throttle or block requests to protect the service. Any decision to suspend or close an account is taken or reviewed by a person, and you can challenge it through our complaints procedure.


8. Your rights

You have the right to:

  • access your personal data and receive a copy of it
  • rectify inaccurate data
  • erase your data, where there is no longer a basis for keeping it
  • restrict processing in certain circumstances
  • data portability for data you provided to us, processed on the basis of contract or consent
  • object to processing based on our legitimate interests, including the training processing described in Section 4
  • withdraw consent at any time, without affecting processing that took place before withdrawal

Because we do not store API content, we cannot provide copies of, correct or erase past prompts or responses — there is nothing retained to act on. Your rights apply in full to everything else we hold, including account, billing and usage metadata.

To exercise any of these rights, email apex@callstack.com. We will respond within one month, which may be extended by two further months for complex requests, in which case we will tell you why. We may need to verify your identity before acting.

You also have the right to lodge a complaint with a supervisory authority. In Poland this is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl. You may also complain to the authority in the EU country where you live or work.


9. Do you have to give us your data?

Account and billing data are needed to conclude and perform the contract; without them we cannot provide the service. VAT numbers are required for business accounts. Everything else — marketing consent, analytics cookies, feedback — is optional.


10. Security

We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls with multi-factor authentication, logical separation of customer accounts, and logging of administrative access. The measures applied to API content are described in Annex 4 of our Commercial Terms.


11. Age

Apex is not intended for anyone under 18, and we do not knowingly collect personal data from children. If you believe a child has created an account, contact us and we will delete it.


12. Changes to this Policy

We will update this Policy when our processing changes. If a change is significant, we will tell account holders by email before it takes effect. The effective date at the top shows when it was last updated.