Privacy Policy
Last Updated: April 15, 2026
1. Controller
The controller within the meaning of the GDPR is Agents as a Service, reachable at privacy@aaas.builders.
2. Information We Collect
When you use aaas.builders, we collect information you voluntarily provide — including your email address when you run a Skill Slam or submit a brief. We also collect anonymised usage data (page views, session identifiers, hashed IP addresses) to improve our services.
3. How We Use Your Information
We use collected information to:
- Deliver Skill Slam outputs to your email address
- Send follow-up proposals within 48 hours of a slam completion
- Improve our AI models and service quality
- Prevent abuse and enforce rate limits
We do not sell, rent, or share your personal information with third parties for marketing purposes.
4. Legal Basis
Processing is based on Art. 6(1)(b) GDPR (contract performance) for delivering slam results, and Art. 6(1)(f) GDPR (legitimate interests) for service improvement and security measures.
5. Data Storage & Security
Your data is stored and processed by Google Cloud Firestore in the United States (us-east1 region). International transfer of personal data is governed by Google's Standard Contractual Clauses (SCCs) and, where applicable, the EU-U.S. Data Privacy Framework. We are in the process of migrating to EU-based storage; this page will be updated when that migration completes.
We implement industry-standard security measures including encrypted transit (TLS), hashed IP identifiers, and role-based access controls. Email addresses are stored with one-click unsubscribe capability.
Personal data is deleted once no longer required for its original purpose, and no later than 24 months after last activity.
6. Third-Party Services
We use the following third-party services to operate aaas.builders:
- Firebase / Google Cloud — database, hosting, and AI inference
- Resend — transactional email delivery
- Firebase Hosting — static site delivery
Each provider operates under its own privacy policy and data processing agreements.
7. Your Rights
Under the GDPR you have the right to:
- Access your personal data (Art. 15 GDPR)
- Rectification of inaccurate data (Art. 16 GDPR)
- Erasure of your data (Art. 17 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR)
- Object to processing (Art. 21 GDPR)
To unsubscribe from emails, use the unsubscribe link in any email we send or visit aaas.builders/unsubscribe. For data deletion requests, contact privacy@aaas.builders.
8. Cookies & Local Storage
We use browser localStorage to store your theme preference (dark/light mode). We do not use tracking cookies or third-party advertising cookies.
9. Supervisory Authority
You have the right to lodge a complaint with a supervisory authority. The competent authority is the one in your place of residence or the location of the alleged infringement. In Germany, this is the relevant state data protection authority (Landesbeauftragte für Datenschutz).
10. Contact
For privacy inquiries or data deletion requests: privacy@aaas.builders