Legal · Privacy
Privacy Policy
AufsichtAI is local-first software. It runs on your own machine, keeps your data in your own directories, and by default sends nothing to us - the only network calls it makes are the ones you trigger. This policy explains what that means in practice, what little data touches our systems at all, and the rights you hold under the law.
Version 2.0 · Last updated 21 September 2026 · Effective on publication.
Who is responsible
This website and the AufsichtAI software are published by XYF TECH SOLUTION, an individual enterprise (perusahaan perseorangan) domiciled in Indonesia, acting as the data controller for the limited processing described below. Although an individual enterprise is not a separate legal entity, the operator accepts responsibility for the commitments in this policy. For any privacy request or question, contact us at privacy@xyftech.com and we will respond within a reasonable period, and in any case within the timeframes required by applicable law.
The short version
We designed AufsichtAI so that we never see your work. The software has no telemetry, no analytics, and no cloud backend: your source code, your prompts, your workspaces, your ledger, and your evidence all stay on the device where you run it. The single exception is an update check you run yourself, described below. This marketing and documentation site is a set of static pages that set no cookies and run no trackers. The only personal data we handle is what you deliberately send us, such as an email when you contact support or a payment reference when you subscribe, and we handle that only for the purpose you sent it.
Legal basis and the laws we follow
We process personal data in accordance with Indonesia's Law No. 27 of 2022 on Personal Data Protection (Undang-Undang Pelindungan Data Pribadi, "UU PDP") and, where it applies to visitors in the European Economic Area, Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"). Our lawful bases are consent for optional communications, contractual necessity for delivering a subscription you purchased, and legitimate interest for keeping the site secure and functioning. Where we rely on consent you may withdraw it at any time, and where we rely on legitimate interest you may object as described below.
What the software does with your data
When you run AufsichtAI, everything lives where you put it. The workspace seal, the hash-chained ledger, single-use permits, and the evidence files are written to directories on your machine and are never transmitted to us. Reports and logs carry only statuses and proof codes, for example "PASS" or "WRITE_ASSERTION_FAILED" together with a hash, and never the contents of your files, your secrets, or your API keys. Because there is no server on our side receiving any of this, there is nothing for us to lose, sell, or hand over.
Data that never leaves your machine
The following categories are processed entirely on your own device and are structurally inaccessible to us: source code and file contents; sealed workspaces and their encryption material; single-use permits and tickets; passwords, tokens, and API keys; and the results of any work, of which only pass or fail statuses are recorded locally. Deleting these is entirely in your hands, as described under your rights.
This website
The pages you are reading are static files hosted on Vercel. They set no cookies, load no analytics scripts, and embed no cross-site trackers. Your language and theme preference are stored only in your browser's local storage and never reach us. Vercel keeps standard technical logs such as IP address, timestamp, and requested URL for a limited period to protect the service against abuse and to diagnose faults; this is processed on the basis of legitimate interest and is not used to build any profile of you. The separate account site, which does use a session, is described in the next section.
The account and download site
The account site at aufsicht-license.aufsicht.dev is a separate service from the pages you are reading, and unlike them it does use a session. You sign in with Google or GitHub; we receive your email address and the identifier your provider gives us, and nothing else from that provider. We store that account record, your chosen plan, and the personal download token that authenticates your install and update commands. A session cookie keeps you signed in until you sign out; it is our own short-lived token, not an advertising identifier. You can regenerate the download token at any time, which immediately revokes the old one and breaks any script still using it. The account site also runs on Vercel and inherits the same technical logging described above.
When you redeem a paid order you paste the output of aufsicht fingerprint - a 32-character hash describing your machine - so that the licence key can be bound to it. That fingerprint is stored with your order and used to check that a key belongs to the machine it was issued for. It is not hardware serial numbers, a device advertising ID, or any identifier you did not already have locally.
Updates and other network calls
The software makes no outbound calls while you work: no telemetry, no crash reporting, no usage counts, no phone-home. The two exceptions are both things you start yourself. First, aufsicht update contacts our release registry using your personal download token, downloads a build, and verifies its checksum before replacing the binary - that request reveals your token to us and nothing else about your work. Second, the initial install script you run downloads the binary from the same registry. Neither call sends file contents, prompts, ledger entries, or evidence anywhere.
AI model providers are separate
AufsichtAI does not choose or supply an AI model. If the agent you connect uses a cloud model, your prompts and code travel to that provider under that provider's own privacy terms, over which we have no control and for which we are not responsible. If you use a local model, the entire setup can run offline with no third party involved. Review the policy of whichever model provider you select.
Payments
If you subscribe to a paid tier, payments are processed by Xendit (PT Xendit Teknologi / Xendit Pte. Ltd.), our payment processor, primarily via QRIS. We receive only the information needed to match your payment to your licence, such as a payment reference, invoice ID, and the email you use for your key; your card or bank credentials are handled by Xendit and your own bank or payment app, and are never seen or stored by us. Xendit processes your payment data under its own privacy policy. Licence keys are bound to your machine and validated locally; we retain the minimum billing records required by Indonesian tax and accounting rules. Xendit notifies us by webhook when a payment settles so your order can be matched to your account, and a redeemed order keeps your email, plan, and the machine fingerprint described above.
Retention
We keep support correspondence for as long as needed to resolve your matter and a reasonable period afterwards, and we keep billing records for the period required by law. Everything the software generates is kept for exactly as long as you keep it on your own device, because we never hold a copy.
Your rights
Under the UU PDP and, where applicable, the GDPR, you have the right to access the personal data we hold about you, to correct it, to erase it, to restrict or object to its processing, to withdraw consent, and to data portability. Because your operational data lives only on your machine, you can exercise the strongest of these rights yourself at any moment: delete the workspace, ledger, and evidence directories and it is gone. For the limited data we hold, such as support emails or billing references, contact privacy@xyftech.com and we will act on your request within the timeframes the law requires. If you believe we have mishandled your data, you may lodge a complaint with the competent supervisory authority in your jurisdiction.
Children
AufsichtAI is a developer tool intended for professional use and is not directed at children. We do not knowingly collect personal data from anyone we know to be under the age of majority in their jurisdiction.
Subprocessors and where data goes
We rely on a short list of processors, each of which only ever sees the data needed to do its job. Vercel hosts this site, the account site, and the account API. GitHub and Google act as identity providers when you choose to sign in with them, under their own privacy policies. Xendit processes payments as described above. If we add a processor that handles personal data, we will update this list. Some of these providers process data outside Indonesia; where the GDPR applies to you, we rely on appropriate safeguards such as standard contractual clauses, and we do not transfer your operational data at all because it never leaves your machine.
Changes
This policy is versioned together with the site. When we make a material change we will update the version number and date above, and where the law requires it we will seek your renewed consent. Continued use after an update means you have read the current version.