Effective Date:

July 2026

Last Updated:

July 2026

Legal Entity:

Effortless Labs PTE. Ltd. (Singapore)

Product/Service:

LocusGraph (the "Service")

LocusGraph Privacy Policy

LocusGraph Privacy Policy

Overview

Overview

LocusGraph is a typed knowledge graph platform that enables AI agents to accumulate, store, and reuse structured memory across sessions. It is operated by Effortless Labs PTE. Ltd. (a Singapore-incorporated private limited company, "we," "us," or "our").

This Privacy Policy describes how we collect, use, protect, and manage your information when you access and use LocusGraph, whether through our web application, API, SDKs, or other channels (collectively, the "Service").

Your privacy is central to how LocusGraph works. Unlike traditional AI platforms that may use your interactions to train models or sell data, LocusGraph is designed with data ownership and control at its core. This policy explains exactly how we handle that responsibility.

LocusGraph is a typed knowledge graph platform that enables AI agents to accumulate, store, and reuse structured memory across sessions. It is operated by Effortless Labs PTE. Ltd. (a Singapore-incorporated private limited company, "we," "us," or "our").

This Privacy Policy describes how we collect, use, protect, and manage your information when you access and use LocusGraph, whether through our web application, API, SDKs, or other channels (collectively, the "Service").

Your privacy is central to how LocusGraph works. Unlike traditional AI platforms that may use your interactions to train models or sell data, LocusGraph is designed with data ownership and control at its core. This policy explains exactly how we handle that responsibility.

Information We Collect

Information We Collect

Account and Identity Information

This is the data LocusGraph stores on your behalf—the "memories" that your agents use:

Category
Purpose

Full name

Account identification and billing

Email address

Authentication, account recovery, service notifications

Organization/team name

Account management, multi-tenant isolation

Billing address (if applicable)

Payment processing and legal compliance

Phone number (optional)

Enterprise support and account verification

Critical principle: All memory data belongs to you. We store it, index it, and help your agent retrieve it—but you retain full ownership and can export or delete it at any time.

Memory and Event Data (Your Core Data)

How we collect it: You provide this directly during signup, account setup, or billing configuration.

Data Type
Data Type
What It Is
What It Is
Your Control

Events

Structured admissions containing typed kind, source, payload, context, and metadata

You emit; you control what gets stored

Patterns

Authentication, account recovery, service notifications

Contact

Skills

Account management, multi-tenant isolation

Organization

Context metadata

Payment processing and legal compliance

Billing

Confidence scores

Enterprise support and account verification

Contact

Critical principle: All memory data belongs to you. We store it, index it, and help your agent retrieve it—but you retain full ownership and can export or delete it at any time.

API and Integration Data

When you connect LocusGraph to external tools and APIs:

Integration Type
Integration Type
Data Shared
Data Shared
Your Consent

LLM providers (OpenAI, Anthropic, etc.)

Prompts, context, memory retrieval results when your agent requests them

Required per-integration; you control which LLMs connec

Agent frameworks (LangChain, etc.)

Events and skills necessary for your agent to function

Required at setup; revocable anytime

Webhooks and custom APIs

Payloads you send to us; responses we return to you

Configured by you; you control the data flow

Third-party monitoring tools (optional)

Usage metrics, error logs (if you opt in)

Explicit opt-in only

No data leakage: Integrations are scoped—your memory data doesn't automatically flow to third parties. Data is shared only when your agent explicitly retrieves it.

Technical and Operational Data

To operate and secure the Service, we automatically collect:

Category
Category
What We Collect
What We Collect
Purpose

Authentication logs

Login timestamps, IP addresses, authentication success/failure

Security, account recovery, fraud detection

API usage logs

Endpoint called, timestamp, request/response size, latency, HTTP status

Rate limiting, performance optimization, debugging

Error logs

Stack traces, error messages, context where failures occur

Bug fixes, reliability improvements

Infrastructure metrics

CPU usage, memory, storage, network I/O (aggregated, not traced to individuals)

Capacity planning, performance monitoring

Device information

Browser/OS type, device type, screen resolution (when using web UI)

Compatibility testing, user experience optimization

General geolocation

City/region level only (derived from IP, no precise geolocation)

Compliance with data residency laws (e.g., keeping EU data in EU)

We do NOT collect: Precise geolocation, advertising IDs, behavioral tracking pixels, or interest-based profiling.

Communications and Support Data

When you contact us:

  • Support tickets: Messages, attachments, any data you include to help us debug your issue

  • Email communications: Contents of emails between you and our team

  • Feedback and surveys: Responses to product feedback requests (optional)

We use this data to help you, improve the Service, and maintain records of support interactions.

How We Use Your Information

How We Use Your Information

We use information only for purposes necessary to deliver LocusGraph and comply with law. Here's the full breakdown:

We use information only for purposes necessary to deliver LocusGraph and comply with law. Here's the full breakdown:

Primary Purposes

  1. Deliver the Service

    • Store and manage your account

    • Process, retrieve, and organize your memory data

    • Run your agents and execute skill retrieval

    • Manage integrations and API connections

  2. Security and Fraud Prevention

    • Detect and prevent unauthorized access

    • Monitor for anomalous activity (e.g., bulk data exports)

    • Protect against DDoS, injection attacks, and other threats

    • Respond to security incident

  3. Support and Troubleshooting

    • Respond to your support requests

    • Debug errors in your agent's execution

    • Help you configure and optimize your setup

  4. Service Improvement

    • Analyze usage patterns (aggregated, not individual-level)

    • Identify performance bottlenecks

    • Design new features based on demand

  5. Legal and Compliance

    • Respond to lawful requests from authorities

    • Enforce our Terms of Service

    • Protect the rights, property, and safety of Effortless Labs, our users, and the public

    • Comply with applicable privacy laws (GDPR, CCPA, PDPA, etc.)

  1. Deliver the Service

    • Store and manage your account

    • Process, retrieve, and organize your memory data

    • Run your agents and execute skill retrieval

    • Manage integrations and API connections

  2. Security and Fraud Prevention

    • Detect and prevent unauthorized access

    • Monitor for anomalous activity (e.g., bulk data exports)

    • Protect against DDoS, injection attacks, and other threats

    • Respond to security incident

  3. Support and Troubleshooting

    • Respond to your support requests

    • Debug errors in your agent's execution

    • Help you configure and optimize your setup

  4. Service Improvement

    • Analyze usage patterns (aggregated, not individual-level)

    • Identify performance bottlenecks

    • Design new features based on demand

  5. Legal and Compliance

    • Respond to lawful requests from authorities

    • Enforce our Terms of Service

    • Protect the rights, property, and safety of Effortless Labs, our users, and the public

    • Comply with applicable privacy laws (GDPR, CCPA, PDPA, etc.)

What We Do Not Do

We do NOT train AI models on your memory data. Your events, patterns, and skills are never used to train or improve our AI models, even in aggregated form.

  • We do NOT train AI models on your memory data. Your events, patterns, and skills are never used to train or improve our AI models, even in aggregated form.

  • We do NOT use your memory data for interest-based advertising or behavioral profiling.

  • We do NOT use your data for purposes beyond what you explicitly authorize in this policy.

Memory and Knowledge Graph Data

Memory and Knowledge Graph Data

LocusGraph's core function is to remember things on behalf of your agents. This section explains exactly how we handle that responsibility.

LocusGraph's core function is to remember things on behalf of your agents. This section explains exactly how we handle that responsibility.

How Memory Data Is Stored

  • Encrypted at rest: All memory data is encrypted.

  • Encrypted in transit: All data traveling between your client and our servers uses TLS 1.3 or higher.

  • Immutable event log: Events are write-once; they cannot be modified after admission, preserving an audit trail.

  • Indexed for retrieval: Memory data is indexed to enable fast retrieval by your agent; indexing does not modify the original data.

How We Access Your Memory

Effortless Labs staff do not routinely access your memory data. Access is limited to:

  • Debugging: If you report a bug, we may review relevant memory data with your explicit permission to diagnose the issue.

  • Security investigations: If we detect suspicious activity, we may review logs and relevant memory to prevent harm.

  • Legal compliance: If compelled by lawful legal process (court order, subpoena, etc.), we will notify you unless prohibited by law.

All such access is logged and auditable—you can request an audit trail of who accessed what data and when.

How Your Agent Uses Memory

When your agent retrieves memory (e.g., "what pagination strategy works for this API?"):

  1. The agent sends a query to LocusGraph

  2. LocusGraph performs semantic and typed retrieval over your skill graph

  3. The retrieved skills are returned to your agent

  4. The agent uses those skills in its reasoning and execution

  5. Agent may emit a new event recording the outcome

Your agent owns the retrieval loop. We provide the mechanism; you control what gets retrieved and how it's used

Data Processing and Retention

Data Processing and Retention

Data Retention Schedule

Category
Category
Retention Period
Retention Period
Notes

Memory data (events, patterns, skills)

Until you delete it or your account is terminated

You can delete any memory manually anytime

Account metadata

Duration of account + 30 days (grace period for recovery)

Deleted after 30 days unless account is reactivated

API access logs

90 days

Older logs are aggregated and then deleted

Authentication logs

30 days

Kept for security incident investigation

Support ticket data

2 years

Retained for dispute resolution and continuous improvement

Error and infrastructure logs

30 days

Aggregated and then deleted

Billing and payment records

7 years

Required by accounting and tax law

Account Deletion

If you request account deletion:

  1. All memory data is securely deleted within 7 days

  2. Your account metadata is anonymized and removed within 30 days

  3. Backups are deleted on the next scheduled backup cycle (typically within 90 days)

  4. Billing records are retained for 7 years as required by law, but are no longer linked to your identity

Note: If you have data in Enterprise isolated compute, deletion timelines may vary; contact us for specifics.

Data Minimization

We collect only the data necessary for each purpose. We do not:

  • Collect behavioral data beyond what's needed to operate the Service

  • Retain data longer than necessary

  • Build profiles based on memory data

  • Cross-reference your data with external sources (e.g., data brokers, social media)

Data Security

Data Security

Encryption

  • At rest: AES-256 encryption for all memory data, account data, and logs

  • In transit: TLS 1.3 (or higher) for all client-server communication

  • API keys: Stored hashed (salted bcrypt); we never store plain-text secrets

  • Database encryption: Transparent encryption at the database layer

Access Controls

  • Role-based access control (RBAC): Team members have minimally-scoped permissions

  • Multi-factor authentication (MFA): Required for all administrative accounts

  • Session management: Sessions expire after inactivity; forced re-authentication for sensitive operations

  • Audit logging: All administrative actions are logged with timestamp, actor, and change details

Infrastructure Security

  • Hosted on secure cloud infrastructure: Amazon Web Services (AWS) with dedicated VPC isolation

  • DDoS protection: Cloudflare WAF for application-layer attack mitigation

  • Regular penetration testing: Conducted by independent third parties annually

  • Intrusion detection: Real-time monitoring for suspicious access patterns

  • Backup and recovery: Daily encrypted backups; tested quarterly for integrity

Incident Response

If a security incident occurs:

  1. We investigate immediately

  2. We assess the scope and impact

  3. For data breaches affecting personal information, we notify affected users within 72 hours (or as required by applicable law)

  4. We notify relevant authorities as required by law (e.g., GDPR, CCPA)

  5. We provide guidance on protective measures

Data Sharing and Third Parties

Data Sharing and Third Parties

We Never Sell Your Data

Effortless Labs does not sell, rent, or otherwise commercially distribute your personal information or memory data to third parties.

Third Parties We Work With

We share data only with third parties who:

  • Are contractually bound to maintain at least the same level of protection as this policy

  • Have a legitimate business need to access the data

  • Process data only as instructed by us or you

Category
Category
Third Parties
Third Parties
Data Shared
Data Shared

Cloud infrastructure

Amazon Web Services (AWS)

Your data is stored on AWS servers in your chosen region

Hosting and storage

Security & monitoring

Cloudflare

Authentication logs, access patterns (anonymized)

DDoS protection, firewall, analytics

Payment processing

Stripe, Razorpay

Billing address, email, payment method (processed directly by Stripe/Razorpay, not stored by us)

Billing and subscription management

LLM providers

OpenAI, Anthropic, or others you authorize

Prompts, memory retrieval results, only when your agent requests them

Agent execution (optional; you control this)

Customer analytics

(Optional) PostHog or similar

Aggregated usage metrics only (no memory data)

Product improvement (opt-in)

Subprocessor Addendum

For enterprise customers requiring a full subprocessor list with jurisdictions and data processing terms, we provide a Data Processing Addendum (DPA) that includes:

  • Named list of all sub-processors

  • Jurisdictions where data is processed

  • Data processing terms and limitations

  • Liability and indemnification

Request this via support@locusgraph.com.

Your Agent's External LLM

When your agent calls an external LLM (OpenAI, Anthropic, etc.):

  • Prompts and context are sent to that LLM provider per their terms

  • You control which LLM is used—you can disable integrations anytime

  • Each LLM provider has their own privacy policy—review theirs for their specific data handling

  • LocusGraph does not train on data passed to external LLMs—but the LLM provider may (check their terms)

Legal Requests

If we receive a lawful request from law enforcement or a government authority to disclose your data:

  1. We will notify you unless legally prohibited

  2. We will disclose only what is legally required

  3. We will challenge overbroad requests where legally permissible

  4. We will provide copies of the legal process when we comply

Your Data Rights

Your Data Rights

Depending on your jurisdiction, you may have the following rights. We honor these rights regardless of jurisdiction (we go beyond legal minimums):

Universal Rights (All Users)

We share data only with third parties who:

  • Are contractually bound to maintain at least the same level of protection as this policy

  • Have a legitimate business need to access the data

  • Process data only as instructed by us or you

Right
Right
What It Means
What It Means
How to Request

Access

Get a copy of your personal information and memory data

Use account settings or email privacy@locusgraph.com

Correct

Fix inaccurate information

Update directly in account settings or contact us

Delete

Request deletion of your account and data

Go to Settings > Account Deletion or email privacy@locusgraph.com

Export

Download your memory data in a portable format (JSON, CSV, etc.)

Use Settings > Data Export or contact us

Revoke integrations

Disconnect any third-party integrations anytime

Settings > Connected Services

Opt-out of analytics

Disable optional analytics tracking

Settings > Privacy Preferences

GDPR Rights (EU Residents)

If you're in the European Union, you additionally have:

  • Right to portability: Get your data in a machine-readable format for transfer to another service

  • Right to restrict processing: Ask us to limit how we use your data while you consider other options

  • Right to object: Object to processing for certain purposes (though this may limit Service functionality)

  • Right to not be subject to automated decision-making: LocusGraph's skill retrieval is transparent and explainable; you can always override agent decisions

Data Protection Officer: To exercise GDPR rights or lodge a complaint, contact:

  • Email: privacy@locusgraph.com

  • Postal address: Effortless Labs PTE. Ltd., Singapore (will provide full address on request)

  • Regulatory authority: If we don't resolve your complaint, you can lodge a complaint with your local data protection authority (e.g., Ireland's DPC, Germany's BfDI)

CCPA Rights (California Residents)

If you're in California, you additionally have:

  • Right to know: Get details about what personal information we collect, use, and share

  • Right to delete: Request deletion of personal information (except where exceptions apply)

  • Right to opt-out: Opt out of any "sale or sharing" of personal information (we don't do this, but the right exists)

  • Right to limit use: For sensitive personal information, limit its use to necessary purposes

For CCPA requests: Email privacy@locusgraph.com with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.

PDPA Rights (Singapore Residents)

If you're in Singapore, the Personal Data Protection Act (PDPA) grants rights to:

  • Access, correct, or withdraw consent for collection/use

  • Make requests via privacy@locusgraph.com

Other Jurisdictions

If you're in other jurisdictions with privacy laws (LGPD in Brazil, PIPL in China, PDPL in UAE, etc.), we honor the rights granted under your local law. Contact us if you're unsure of your rights.

How to Exercise Rights

  1. Email: privacy@locusgraph.com with your request and proof of identity

  2. Account settings: Many requests can be self-served (export, delete, update)

  3. Enterprise: If you're an enterprise customer, contact your account manager

Response time: We aim to respond to all requests within 30 days. Complex requests may take up to 90 days.

International Data Transfers

International Data Transfers

LocusGraph is operated by Effortless Labs (Singapore), and your data may be processed in multiple countries:

Data Residency

  • Default: Your data is stored in AWS regions closest to your location (e.g., EU data in eu-west-1 Ireland, UAE data in middle east region)

  • Enterprise: You can request a specific region or multi-region setup; this is configurable per plan

Cross-Border Transfers

If data must be transferred across borders (e.g., EU to US for processing):

  • Lawful basis: We rely on Standard Contractual Clauses (SCCs) between Effortless Labs and processors

  • Safeguards: We ensure a level of protection equivalent to the origin jurisdiction

  • Your rights: For EU residents, GDPR Chapter 5 rights apply to transfers

If you have concerns about cross-border transfers, you can:

  • Request EU-only data storage

  • Use our self-hosted option (Enterprise plan)

  • Contact privacy@locusgraph.com to discuss alternatives

Children and Minors

Children and Minors

LocusGraph is not directed at children under 18. We do not knowingly collect personal information from minors.

If we become aware that a minor has provided information, we will delete it promptly. If you're a parent or guardian concerned about a minor's use of LocusGraph, contact privacy@locusgraph.com.

Policy Changes

Policy Changes

We may update this Privacy Policy periodically to reflect:

  • Changes in our practices

  • New legal requirements

  • Feedback from users

How we notify you:

  • Material changes: We'll email you before the change takes effect

  • Minor clarifications: We'll update the policy and note the change date at the top

  • Your choice: If a material change significantly restricts your rights, you can delete your account before the change takes effect

Continued use = acceptance: If you continue using LocusGraph after a change takes effect, you accept the new policy.

Contact Us

Contact Us

For questions, requests, or concerns about privacy:

Inquiry Type
Contact

General privacy questions

privacy@locusgraph.com

Data requests (access, export, delete)

privacy@locusgraph.com

Security incidents or breaches

support@locusgraph.com

Enterprise/DPA requests

support@locusgraph.com

Complaints or GDPR inquiries

privacy@locusgraph.com

Mailing address (for formal notices):
Effortless Labs PTE. Ltd.
Singapore
(Full address provided upon request)

Response time: We aim to respond to all inquiries within 7 business days.

Summary

Summary

LocusGraph is designed with privacy at its core:

  • ✅ You own your memory data — we store and retrieve it, but it's yours

  • ✅ We don't train on your data — your events, patterns, and skills are never used to improve our AI

  • ✅ We don't sell your data — we have no business model built on data monetization

  • ✅ Explicit controls — you can export, delete, or revoke integrations anytime

  • ✅ Transparent security — we publish our encryption standards, infrastructure, and audit practices

  • ✅ Compliant with GDPR, CCPA, PDPA — and respect rights under other privacy laws

If you have questions about this policy or how we handle your data, please reach out. We're here to help.