Apostl privacy notice

Privacy on apostl.dev

This notice describes the public Apostl website, its audit and Arena submission forms, Apostl Pulse measurement on this domain, and links to external scheduling or platform services. Last updated: 25 August 2026.

Apostl designs these flows to collect the information needed to operate and improve a developer journey without asking for passwords, private keys, wallet seed phrases, session cookies, or private customer data.

Information the site receives

When a browser or automated client requests a public page, the server can receive the IP address, User-Agent, requested path, HTTP method, response status, referral information, and timing data normally included in web requests. Apostl Pulse may classify eligible public GET and HEAD traffic heuristically and aggregate activity by canonical origin and pathname. Query strings, URL fragments, request bodies, cookies, and authorization headers are not included in Pulse events.

The free-audit form receives the email address and public quickstart URL you submit. It also sends operational metadata such as IP address, User-Agent, page URL, referrer, locale, platform, client time, and time zone. An Arena proof-pack request receives a work email plus the selected public benchmark entry and finding context. These fields are used to run the requested workflow, prevent abuse, deliver or follow up on the result, and diagnose failures.

Analytics and service providers

The site loads Google Analytics for aggregate site and conversion measurement. Cloudflare Turnstile may process a challenge when form abuse protection is enabled. Cal.com processes scheduling information when you open or use the booking experience. Accepted audit requests are forwarded to Apostl Platform for execution. The server may send the founders a Telegram notification containing the submitted email, public URL or benchmark context, and run status so the team can operate the request.

These providers process information under their own terms and privacy practices. Following an external link, opening an embedded calendar, or completing a third-party authentication flow may allow that provider to set cookies or collect additional information outside apostl.dev.

How Apostl uses information

Apostl uses submitted and request data to provide the requested audit or proof pack, secure and rate-limit public endpoints, communicate about the request, maintain service reliability, measure public product usage, and improve developer and agent onboarding. Apostl does not ask users to place secret credentials in public forms and does not publish submitter emails in public evidence reports.

Access to operational systems is limited to the team and service providers needed to run the workflow. No internet service can promise absolute security; report a suspected exposure to founders@apostl.dev and avoid sending the affected secret in the report.

Your choices and requests

You can browse the public text and machine-readable files without submitting a form. You can avoid the embedded calendar by emailing Apostl directly. Browser controls and extensions may limit third-party analytics or cookies, although some abuse-protection or scheduling features may then be unavailable.

To ask what information Apostl holds about a submission, request correction or deletion, or raise another privacy question, email founders@apostl.dev. Include enough context to locate the request, but do not send secrets or identity documents unless Apostl gives you a secure and necessary method.

Scope and changes

This notice covers apostl.dev. Authenticated Apostl Platform features or customer contracts may include additional terms and controls. Apostl will update this page when the public data flow or its material service providers change, and the updated date at the top will identify the current version.