Legal
Privacy Policy
The short version: we collect personal data to run your account and to understand how Apollon is used. Code, repositories and questions you send are processed by AI to build maps and answers, and are not stored on our servers. We do not sell your data. You can delete your account at any time.
Who we are
Apollon, operated by Niko Tsiolas, a sole proprietor based in the United States ("Apollon", "we", "us"), runs the service at https://apolloncode.com. Niko Tsiolas decides how your personal data is used and is responsible for it (the "controller"). You can reach us at nikotsiolasmisc@gmail.com.
This policy explains what we collect, why, who we share it with, and the choices you have. It applies to the Apollon app and to the pre-launch page at the same address.
Personal data we collect
We collect personal data. Here is all of it.
- Account data. When you create an account: your name, email address, whether the email is verified, and your profile picture address from GitHub or Google, with the dates the account was created and updated.
- Session data. Each time you sign in we keep a session record: a session token, when it expires, your IP address and your browser's user agent (the browser and device it reports).
- Sign-in connections. If you sign in with GitHub or Google: your account id with that provider, the access, refresh and id tokens it issues, and the permissions granted. OAuth access and refresh tokens are stored encrypted. Google's sign-in id token, which contains your name, email and picture, is stored as Google issued it. We use these tokens only to sign you in.
- Email sign-in links. If you sign in by email: a one-time link sent to your address. It works once and expires after 10 minutes.
- Usage analytics. A small set of first-party events about how Apollon is used, described in Analytics and how to opt out. They include your account id when you are signed in.
- Messages you send us. If you email us, your address and what you write.
You do not need an account to use Apollon. Without one, we keep no account or session data about you, but analytics events (without an account id) and the request data in Third-party processors still apply.
Content we process but do not store
To build a map or answer a question, Apollon processes content you give it: code you paste, the contents of repositories you import, and your questions and chat messages in tours and Architecture Lab, plus topics you explore. This content is handled in memory to produce the result and is sent to OpenAI (see below). We do not store it on our servers.
If you give us a GitHub access token to read a private repository, we use it for that scan only and do not store it.
Today, your maps, questions, the code of files you scanned and code you edit stay in your browser's local storage on your device (see Cookies, storage and camera). Nothing is uploaded to your account or stored on our servers, even when you are signed in. Please do not paste passwords, keys or other people's personal data into code you send.
Hand controls, if you turn them on, use your camera. Video is processed on your device and is never sent to us or anyone else.
How we use AI
Apollon uses AI models from OpenAI. When you map code or a repository, start a tour, ask Architecture Lab a question or explore a topic, the relevant code, repository content and your question are sent to OpenAI to generate the map, explanation or answer.
Before answering, Apollon also sends your message and recent conversation turns to OpenAI's moderation service to check for signs that someone may be at risk of self-harm, so we can show crisis resources instead of a technical answer. We do not store these messages.
OpenAI processes this data under OpenAI's API terms. You can read them at openai.com/policies.
AI output can be wrong, incomplete or out of date. Check maps and answers before you rely on them. The Terms of Service say more about this.
We do not use AI to make decisions about you that have legal or similarly significant effects.
How we use personal data and why
- To provide Apollon, including your account and sign-in, because you asked for the service (performance of a contract).
- To keep Apollon secure, prevent abuse and fix problems, using session and request data (our legitimate interest in a safe, working service).
- To understand and improve Apollon with first-party analytics that hold no content and can be turned off (our legitimate interest).
- To send emails you asked for: sign-in links and, if you signed up before launch, one email when Apollon opens.
- To meet legal obligations and answer requests about your rights.
We do not sell your personal data, we do not show ads, and we do not use your data for advertising.
Third-party processors
These companies process personal data for us. We share only what each needs for the purpose listed.
| Provider | What it receives | Why |
|---|---|---|
| OpenAIAI processingPrivacy policy | Code you paste, files from repositories you import, your questions in tours and Architecture Lab, and topics you explore, including recent conversation turns for a safety check of messages. | To generate maps, explanations and answers, and for a safety check of messages so we can show crisis resources when someone may be at risk. |
| CloudflareHosting and databasePrivacy policy | Every request to Apollon, including your IP address and browser details, and the account data in our database. | To run Apollon, store accounts, keep request logs and protect the service from abuse. |
| GitHubSign-in and repository importPrivacy policy | If you sign in with GitHub, the request to sign in to Apollon. When you import a repository, the repository name and, for a private repository, the access token you give us for that scan. | To sign you in and to read the repository you asked us to map. |
| GoogleSign-in and fontsPrivacy policy | If you sign in with Google, the request to sign in to Apollon. On every page, your browser downloads fonts from Google Fonts, which gives Google your IP address and browser details. | To sign you in and to display the Geist typeface. |
| jsDelivrCode runnerPrivacy policy | When you run Python in the code panel, your browser downloads the Pyodide runtime from jsDelivr, which receives your IP address and browser details. | To run Python in your browser. |
| ResendEmail deliveryPrivacy policy | Your email address and the email itself. | Used to send sign-in links and the one launch email. |
We may also disclose personal data if the law requires it, to protect the rights and safety of users or others, or as part of a transfer of the service, in which case this policy continues to apply.
Analytics and how to opt out
We run our own analytics. There is no third-party analytics service, no cookie, no fingerprinting and no identifier that follows your browser. We do not store your IP address or full user agent with analytics events.
We record only these events:
page_viewa page was openedanalysis_starteda map was requested from a repository, pasted code or a lessonmap_openeda map was openedtour_starteda codebase tour was startedstudio_message_senta message was sent to Architecture Labsign_in_completeda sign-in finished
Each event holds the event name, the page path (without query or fragment), the kind of source where it applies (GitHub, paste or lesson), your account id if you are signed in, your country, your device type (desktop, mobile or tablet), the host name of the site that linked you, and the time. Events never contain code, repository addresses, chat text, file names or email addresses. They are kept for 12 months and then deleted automatically.
Analytics are off when your browser sends Global Privacy Control (GPC) or Do Not Track (DNT); we honour both. You can also turn analytics off for this browser with the switch below. Your choice is saved on your device.
How long we keep data
- Account data and sign-in connections: until you delete your account.
- Sessions: until you sign out, or up to 30 days after your last visit; expired sessions are deleted automatically.
- Email sign-in links: they work once and expire after 10 minutes, and are deleted automatically after they expire.
- Analytics events: 12 months, then deleted automatically.
- Server logs: kept by Cloudflare for the periods set in Cloudflare's own policies.
- Content you send for mapping or questions: not stored on our servers.
- Emails you send us: as long as needed to answer you and keep a record of requests about your rights.
Deleting your account
You can delete your account yourself, at any time, in two steps: open the account menu at the top of the page, choose Delete account, and confirm. This works in the app and on the pre-launch page.
Deletion is immediate and permanent. It removes your account data, your sessions, your GitHub and Google sign-in connections, and the analytics events tied to your account, and it signs you out. Data in your browser's local storage stays on your device until you clear it. If you cannot sign in, email nikotsiolasmisc@gmail.com from the address on the account and we will delete it for you.
Your rights
Everyone. You can ask us for a copy of your personal data, to correct it, or to delete it, wherever you live.
EEA, UK and Switzerland (GDPR). You have the right to access your personal data, correct it, delete it, receive it in a portable format, restrict or object to how we use it (including our legitimate interests), and withdraw consent where we rely on it. You can also complain to your local data protection supervisory authority.
California (CCPA/CPRA). You have the right to know what personal data we collect and how we use and disclose it, to access, correct and delete it, and not to be treated differently for using these rights. We do not sell personal data and we do not share it for cross-context behavioral advertising. We do not use sensitive personal data to infer characteristics about you.
New Jersey (New Jersey Data Privacy Act). You have the right to confirm whether we process your personal data, to access it, correct it, delete it, and get a copy in a portable format, and to opt out of targeted advertising, the sale of personal data, and profiling that produces legal or similarly significant effects. We do not do any of those three things: we show no targeted ads, we do not sell personal data, and we do not profile you.
How to make a request. Email nikotsiolasmisc@gmail.com from the address on your account, or tell us how to reach you, and say what you would like. We may ask you to confirm your identity first. An authorized agent may make a request for you with your written permission. We answer within one month under GDPR and within 45 days under US state laws, and tell you if we need more time. If we turn down a request, you can appeal by replying to our answer; if you are still not satisfied, you can contact your state attorney general or your data protection authority.
Children
Apollon is not directed to children under 13, and we do not knowingly collect personal data from them. In the EEA and the UK, people under 16 may only use Apollon with a parent's or guardian's consent. If you believe a child has given us personal data, email nikotsiolasmisc@gmail.com and we will delete it.
Security
Apollon is served over HTTPS. OAuth access and refresh tokens are stored encrypted. Google's sign-in id token, which contains your name, email and picture, is stored as Google issued it. Email sign-in links work once and expire after 10 minutes. No system is perfectly secure, so we cannot promise that data will never be accessed without permission. If we learn of a breach that affects your personal data, we will tell you and the authorities as the law requires.
International transfers
Apollon is run from the United States, and our providers process data in the United States and other countries. If you use Apollon from outside the United States, your personal data is transferred there. Where GDPR applies, these transfers rely on the safeguards our providers offer, such as the European Commission's Standard Contractual Clauses or an adequacy decision.
Changes to this policy
If we change this policy, we will update the effective date at the top. If a change is significant, we will tell signed-in users in the app or by email before it takes effect.
Contact
Questions or requests about privacy go to Niko Tsiolas at nikotsiolasmisc@gmail.com.