Effective Date:
July 2026
Last Updated:
July 2026
Legal Entity:
Effortless Labs PTE. Ltd. (Singapore)
Product/Service:
LocusGraph (the "Service")
Account and Identity Information
This is the data LocusGraph stores on your behalf—the "memories" that your agents use:
Full name
Account identification and billing
Email address
Authentication, account recovery, service notifications
Organization/team name
Account management, multi-tenant isolation
Billing address (if applicable)
Payment processing and legal compliance
Phone number (optional)
Enterprise support and account verification
Critical principle: All memory data belongs to you. We store it, index it, and help your agent retrieve it—but you retain full ownership and can export or delete it at any time.
Memory and Event Data (Your Core Data)
How we collect it: You provide this directly during signup, account setup, or billing configuration.
Your Control
Events
Structured admissions containing typed kind, source, payload, context, and metadata
You emit; you control what gets stored
Patterns
Authentication, account recovery, service notifications
Contact
Skills
Account management, multi-tenant isolation
Organization
Context metadata
Payment processing and legal compliance
Billing
Confidence scores
Enterprise support and account verification
Contact
Critical principle: All memory data belongs to you. We store it, index it, and help your agent retrieve it—but you retain full ownership and can export or delete it at any time.
API and Integration Data
When you connect LocusGraph to external tools and APIs:
Your Consent
LLM providers (OpenAI, Anthropic, etc.)
Prompts, context, memory retrieval results when your agent requests them
Required per-integration; you control which LLMs connec
Agent frameworks (LangChain, etc.)
Events and skills necessary for your agent to function
Required at setup; revocable anytime
Webhooks and custom APIs
Payloads you send to us; responses we return to you
Configured by you; you control the data flow
Third-party monitoring tools (optional)
Usage metrics, error logs (if you opt in)
Explicit opt-in only
No data leakage: Integrations are scoped—your memory data doesn't automatically flow to third parties. Data is shared only when your agent explicitly retrieves it.
Technical and Operational Data
To operate and secure the Service, we automatically collect:
Purpose
Authentication logs
Login timestamps, IP addresses, authentication success/failure
Security, account recovery, fraud detection
API usage logs
Endpoint called, timestamp, request/response size, latency, HTTP status
Rate limiting, performance optimization, debugging
Error logs
Stack traces, error messages, context where failures occur
Bug fixes, reliability improvements
Infrastructure metrics
CPU usage, memory, storage, network I/O (aggregated, not traced to individuals)
Capacity planning, performance monitoring
Device information
Browser/OS type, device type, screen resolution (when using web UI)
Compatibility testing, user experience optimization
General geolocation
City/region level only (derived from IP, no precise geolocation)
Compliance with data residency laws (e.g., keeping EU data in EU)
We do NOT collect: Precise geolocation, advertising IDs, behavioral tracking pixels, or interest-based profiling.
Communications and Support Data
When you contact us:
Support tickets: Messages, attachments, any data you include to help us debug your issue
Email communications: Contents of emails between you and our team
Feedback and surveys: Responses to product feedback requests (optional)
We use this data to help you, improve the Service, and maintain records of support interactions.
Primary Purposes
What We Do Not Do
We do NOT train AI models on your memory data. Your events, patterns, and skills are never used to train or improve our AI models, even in aggregated form.
We do NOT train AI models on your memory data. Your events, patterns, and skills are never used to train or improve our AI models, even in aggregated form.
We do NOT use your memory data for interest-based advertising or behavioral profiling.
We do NOT use your data for purposes beyond what you explicitly authorize in this policy.
How Memory Data Is Stored
Encrypted at rest: All memory data is encrypted.
Encrypted in transit: All data traveling between your client and our servers uses TLS 1.3 or higher.
Immutable event log: Events are write-once; they cannot be modified after admission, preserving an audit trail.
Indexed for retrieval: Memory data is indexed to enable fast retrieval by your agent; indexing does not modify the original data.
How We Access Your Memory
Effortless Labs staff do not routinely access your memory data. Access is limited to:
Debugging: If you report a bug, we may review relevant memory data with your explicit permission to diagnose the issue.
Security investigations: If we detect suspicious activity, we may review logs and relevant memory to prevent harm.
Legal compliance: If compelled by lawful legal process (court order, subpoena, etc.), we will notify you unless prohibited by law.
All such access is logged and auditable—you can request an audit trail of who accessed what data and when.
How Your Agent Uses Memory
When your agent retrieves memory (e.g., "what pagination strategy works for this API?"):
The agent sends a query to LocusGraph
LocusGraph performs semantic and typed retrieval over your skill graph
The retrieved skills are returned to your agent
The agent uses those skills in its reasoning and execution
Agent may emit a new event recording the outcome
Your agent owns the retrieval loop. We provide the mechanism; you control what gets retrieved and how it's used
Data Retention Schedule
Notes
Memory data (events, patterns, skills)
Until you delete it or your account is terminated
You can delete any memory manually anytime
Account metadata
Duration of account + 30 days (grace period for recovery)
Deleted after 30 days unless account is reactivated
API access logs
90 days
Older logs are aggregated and then deleted
Authentication logs
30 days
Kept for security incident investigation
Support ticket data
2 years
Retained for dispute resolution and continuous improvement
Error and infrastructure logs
30 days
Aggregated and then deleted
Billing and payment records
7 years
Required by accounting and tax law
Account Deletion
If you request account deletion:
All memory data is securely deleted within 7 days
Your account metadata is anonymized and removed within 30 days
Backups are deleted on the next scheduled backup cycle (typically within 90 days)
Billing records are retained for 7 years as required by law, but are no longer linked to your identity
Note: If you have data in Enterprise isolated compute, deletion timelines may vary; contact us for specifics.
Data Minimization
We collect only the data necessary for each purpose. We do not:
Collect behavioral data beyond what's needed to operate the Service
Retain data longer than necessary
Build profiles based on memory data
Cross-reference your data with external sources (e.g., data brokers, social media)
Encryption
At rest: AES-256 encryption for all memory data, account data, and logs
In transit: TLS 1.3 (or higher) for all client-server communication
API keys: Stored hashed (salted bcrypt); we never store plain-text secrets
Database encryption: Transparent encryption at the database layer
Access Controls
Role-based access control (RBAC): Team members have minimally-scoped permissions
Multi-factor authentication (MFA): Required for all administrative accounts
Session management: Sessions expire after inactivity; forced re-authentication for sensitive operations
Audit logging: All administrative actions are logged with timestamp, actor, and change details
Infrastructure Security
Hosted on secure cloud infrastructure: Amazon Web Services (AWS) with dedicated VPC isolation
DDoS protection: Cloudflare WAF for application-layer attack mitigation
Regular penetration testing: Conducted by independent third parties annually
Intrusion detection: Real-time monitoring for suspicious access patterns
Backup and recovery: Daily encrypted backups; tested quarterly for integrity
Incident Response
If a security incident occurs:
We investigate immediately
We assess the scope and impact
For data breaches affecting personal information, we notify affected users within 72 hours (or as required by applicable law)
We notify relevant authorities as required by law (e.g., GDPR, CCPA)
We provide guidance on protective measures
We Never Sell Your Data
Effortless Labs does not sell, rent, or otherwise commercially distribute your personal information or memory data to third parties.
Third Parties We Work With
We share data only with third parties who:
Are contractually bound to maintain at least the same level of protection as this policy
Have a legitimate business need to access the data
Process data only as instructed by us or you
Data Shared
Data Shared
Cloud infrastructure
Amazon Web Services (AWS)
Your data is stored on AWS servers in your chosen region
Hosting and storage
Security & monitoring
Cloudflare
Authentication logs, access patterns (anonymized)
DDoS protection, firewall, analytics
Payment processing
Stripe, Razorpay
Billing address, email, payment method (processed directly by Stripe/Razorpay, not stored by us)
Billing and subscription management
LLM providers
OpenAI, Anthropic, or others you authorize
Prompts, memory retrieval results, only when your agent requests them
Agent execution (optional; you control this)
Customer analytics
(Optional) PostHog or similar
Aggregated usage metrics only (no memory data)
Product improvement (opt-in)
Subprocessor Addendum
For enterprise customers requiring a full subprocessor list with jurisdictions and data processing terms, we provide a Data Processing Addendum (DPA) that includes:
Named list of all sub-processors
Jurisdictions where data is processed
Data processing terms and limitations
Liability and indemnification
Request this via support@locusgraph.com.
Your Agent's External LLM
When your agent calls an external LLM (OpenAI, Anthropic, etc.):
Prompts and context are sent to that LLM provider per their terms
You control which LLM is used—you can disable integrations anytime
Each LLM provider has their own privacy policy—review theirs for their specific data handling
LocusGraph does not train on data passed to external LLMs—but the LLM provider may (check their terms)
Legal Requests
If we receive a lawful request from law enforcement or a government authority to disclose your data:
We will notify you unless legally prohibited
We will disclose only what is legally required
We will challenge overbroad requests where legally permissible
We will provide copies of the legal process when we comply
Depending on your jurisdiction, you may have the following rights. We honor these rights regardless of jurisdiction (we go beyond legal minimums):
Universal Rights (All Users)
We share data only with third parties who:
Are contractually bound to maintain at least the same level of protection as this policy
Have a legitimate business need to access the data
Process data only as instructed by us or you
How to Request
Access
Get a copy of your personal information and memory data
Use account settings or email privacy@locusgraph.com
Correct
Fix inaccurate information
Update directly in account settings or contact us
Delete
Request deletion of your account and data
Go to Settings > Account Deletion or email privacy@locusgraph.com
Export
Download your memory data in a portable format (JSON, CSV, etc.)
Use Settings > Data Export or contact us
Revoke integrations
Disconnect any third-party integrations anytime
Settings > Connected Services
Opt-out of analytics
Disable optional analytics tracking
Settings > Privacy Preferences
GDPR Rights (EU Residents)
If you're in the European Union, you additionally have:
Right to portability: Get your data in a machine-readable format for transfer to another service
Right to restrict processing: Ask us to limit how we use your data while you consider other options
Right to object: Object to processing for certain purposes (though this may limit Service functionality)
Right to not be subject to automated decision-making: LocusGraph's skill retrieval is transparent and explainable; you can always override agent decisions
Data Protection Officer: To exercise GDPR rights or lodge a complaint, contact:
Email: privacy@locusgraph.com
Postal address: Effortless Labs PTE. Ltd., Singapore (will provide full address on request)
Regulatory authority: If we don't resolve your complaint, you can lodge a complaint with your local data protection authority (e.g., Ireland's DPC, Germany's BfDI)
CCPA Rights (California Residents)
If you're in California, you additionally have:
Right to know: Get details about what personal information we collect, use, and share
Right to delete: Request deletion of personal information (except where exceptions apply)
Right to opt-out: Opt out of any "sale or sharing" of personal information (we don't do this, but the right exists)
Right to limit use: For sensitive personal information, limit its use to necessary purposes
For CCPA requests: Email privacy@locusgraph.com with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days.
PDPA Rights (Singapore Residents)
If you're in Singapore, the Personal Data Protection Act (PDPA) grants rights to:
Access, correct, or withdraw consent for collection/use
Make requests via privacy@locusgraph.com
Other Jurisdictions
If you're in other jurisdictions with privacy laws (LGPD in Brazil, PIPL in China, PDPL in UAE, etc.), we honor the rights granted under your local law. Contact us if you're unsure of your rights.
How to Exercise Rights
Email: privacy@locusgraph.com with your request and proof of identity
Account settings: Many requests can be self-served (export, delete, update)
Enterprise: If you're an enterprise customer, contact your account manager
Response time: We aim to respond to all requests within 30 days. Complex requests may take up to 90 days.
LocusGraph is operated by Effortless Labs (Singapore), and your data may be processed in multiple countries:
Data Residency
Default: Your data is stored in AWS regions closest to your location (e.g., EU data in eu-west-1 Ireland, UAE data in middle east region)
Enterprise: You can request a specific region or multi-region setup; this is configurable per plan
Cross-Border Transfers
If data must be transferred across borders (e.g., EU to US for processing):
Lawful basis: We rely on Standard Contractual Clauses (SCCs) between Effortless Labs and processors
Safeguards: We ensure a level of protection equivalent to the origin jurisdiction
Your rights: For EU residents, GDPR Chapter 5 rights apply to transfers
If you have concerns about cross-border transfers, you can:
Request EU-only data storage
Use our self-hosted option (Enterprise plan)
Contact privacy@locusgraph.com to discuss alternatives
LocusGraph is not directed at children under 18. We do not knowingly collect personal information from minors.
If we become aware that a minor has provided information, we will delete it promptly. If you're a parent or guardian concerned about a minor's use of LocusGraph, contact privacy@locusgraph.com.
We may update this Privacy Policy periodically to reflect:
Changes in our practices
New legal requirements
Feedback from users
How we notify you:
Material changes: We'll email you before the change takes effect
Minor clarifications: We'll update the policy and note the change date at the top
Your choice: If a material change significantly restricts your rights, you can delete your account before the change takes effect
Continued use = acceptance: If you continue using LocusGraph after a change takes effect, you accept the new policy.
For questions, requests, or concerns about privacy:
Inquiry Type
Contact
General privacy questions
privacy@locusgraph.com
Data requests (access, export, delete)
privacy@locusgraph.com
Security incidents or breaches
support@locusgraph.com
Enterprise/DPA requests
support@locusgraph.com
Complaints or GDPR inquiries
privacy@locusgraph.com
Mailing address (for formal notices):
Effortless Labs PTE. Ltd.
Singapore
(Full address provided upon request)
Response time: We aim to respond to all inquiries within 7 business days.
LocusGraph is designed with privacy at its core:
✅ You own your memory data — we store and retrieve it, but it's yours
✅ We don't train on your data — your events, patterns, and skills are never used to improve our AI
✅ We don't sell your data — we have no business model built on data monetization
✅ Explicit controls — you can export, delete, or revoke integrations anytime
✅ Transparent security — we publish our encryption standards, infrastructure, and audit practices
✅ Compliant with GDPR, CCPA, PDPA — and respect rights under other privacy laws
If you have questions about this policy or how we handle your data, please reach out. We're here to help.