Destaris

Privacy Policy

Last updated 29 June 2026

Introduction

This Privacy Policy describes how Atypical (ABN 24 716 351 826), operating as Destaris ("we", "us", or "our"), collects, uses, discloses, and protects personal information through the Destaris desktop application, the destaris.ai website, and any related cloud features (the "Service").

We are committed to complying with the Australian Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the EU General Data Protection Regulation (GDPR), and other applicable privacy laws.

1. What stays on your machine

Destaris runs on your machine. The following are not collected by us:

  • The content your Workflows fetch, transform, or produce;
  • Your connected credentials and API keys (they live in your OS keychain and environment); and
  • The prompts and outputs of your AI steps, which run as your own AI CLI.

Keeping execution and credentials local by design removes whole categories of privacy risk.

2. Information we collect

  • Website analytics. Device and browser information, IP address and approximate location, and usage data and interactions with the website.
  • Error diagnostics. Crash and error reports, which may include technical details about the event.
  • Cloud features (if you use them). If you sign in, the account information needed to authenticate you (such as name and email), payment information for any paid subscription, and the run metadata needed to provide history and coordinate across your machines.

3. How we use information

We use personal information to provide, maintain, and improve the Service; process subscriptions and payments; send transactional communications and provide support; and understand usage to improve our services. With your consent, we may send marketing communications, which you can opt out of at any time.

4. How we share information

We share information with third-party service providers who assist us in operating the Service, including:

  • Cloudflare (hosting, security, and content delivery);
  • Sentry (error monitoring);
  • PostHog (analytics); and
  • Convex and Clerk (database/backend and authentication for the cloud features).

These providers are contractually obligated to protect your information and use it only for the purposes we specify. We may also disclose information if required by law, legal process, or government request, or to protect our rights, property, or safety, or that of our users or others. We do not sell your personal information.

5. International data transfers

Your information may be transferred to and processed in countries other than your own, including the United States and other jurisdictions where our service providers operate. We ensure appropriate safeguards are in place for such transfers, including standard contractual clauses, reliance on our providers' compliance frameworks, and other legally recognised transfer mechanisms.

6. Data retention

We retain personal information for as long as necessary to provide the Service and fulfil the purposes described in this Policy. Cloud run metadata is retained according to your plan's retention period; if you cancel, we retain associated cloud data for 6 months following termination. You can ask us to delete information we hold about you.

7. Cookies and tracking

The website uses cookies and similar technologies for essential functions (security, preferences), analytics (understanding usage patterns), and performance. You can manage cookie preferences through your browser settings; disabling certain cookies may affect functionality.

8. Your rights

8.1 All users. Depending on your location, you may have rights to access the personal information we hold about you, correct inaccurate information, request deletion, object to or restrict certain processing, receive your information in a portable format, and withdraw consent where processing is based on consent.

8.2 Australian users. Under the Privacy Act, you have the right to access and correct your personal information. You may also complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.

8.3 EU/UK users (GDPR). If you are in the European Economic Area or United Kingdom, you have additional rights under GDPR, including erasure, data portability, and the right to lodge a complaint with your local supervisory authority. Our lawful bases for processing include contract performance, legitimate interests, and consent.

8.4 Exercising your rights. To exercise any of these rights, contact us at privacy@destaris.ai. We will respond within the timeframes required by applicable law.

9. Security

We implement appropriate technical and organisational measures to protect personal information, including encryption in transit and at rest, access controls and authentication, regular security assessments, and incident response procedures. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect their personal information. If we learn we have collected information from a child without appropriate consent, we will delete it.

11. Changes to this policy

We may update this Policy from time to time. We will notify you of material changes by posting the updated Policy and updating the date above. Your continued use of the Service after changes constitutes acceptance of the updated Policy.

12. Contact us

Questions about your privacy? Contact us at:

Atypical · ABN 24 716 351 826 · privacy@destaris.ai