Astru is the open-source autonomous-company platform. We collect the minimum we need to run the platform for you, we never sell data, and you can export + delete everything in two clicks.
What we collect
Account data. Email, name, company slug, password hash (or magic-link token), Stripe customer id.
Product data. Tasks you queue, agent outputs, audit log, credit ledger, Mission/Brand-Voice documents you author or that an agent drafts for you.
Operational data. Server logs, error traces (via Sentry), LLM-call traces (via Langfuse), aggregate page analytics (via Plausible, no cookies).
What we do NOT collect
We do not record your input fields in PostHog session replays. We do not sell your data to advertisers. We do not use your private documents to train any model.
Where your data lives
Managed astru.app: US-East (Supabase). Self-host: wherever you deploy. Either way the same code applies the same RLS policies. Your data is isolated per company.
Your rights
Signed in, you can export your full dataset from Settings → Billing → Request data export (a downloadable JSON bundle of your company’s data). To request account deletion or any GDPR / CCPA data-subject request (access, portability, deletion, rectification), email dsr@astru.dev or POST to /api/dsr. We verify the requester’s identity, then complete it within 30 days (GDPR) / 45 days (CCPA).
Third-party processors
Supabase (database, auth, storage), Stripe (billing), Resend (transactional email), Anthropic (LLM), Inngest (durable workflows), Sentry (errors), Langfuse (LLM observability), Plausible (page analytics, no cookies), Vercel (hosting). Full sub-processor list available at /legal/dpa.