Privacy Policy
Last updated: September 2026
Lupus runs security tools on your device or on an agent you choose. AI requests also use your selected AI provider. This policy covers the website alpistesec.com and the Android app com.alpistesec.lupus, both published by AlpisteSec. We collect the minimum needed to run accounts, billing and the artifact delivery that installs the toolset.
What we collect
- Account data: your email address and a hashed password. If you sign in with Google, we receive your verified email address and Google account identifier to link your sign-in — no Google password is received or stored.
- Billing data: handled by the payment provider you choose — Whop or PayPal for cards and subscriptions, Google Play Billing for purchases made inside the app from a Play install, and NOWPayments / BTCPay for crypto. We never receive or store your card details. We keep a record of each transaction: amount, currency, plan, status and the provider's own reference.
- Licence and activations: which devices your account has activated, by a random install identifier generated on the device. It is not an advertising ID and is not tied to hardware serials.
- Diagnostics: app version, platform, Android version, device model, the install identifier, and — once you are signed in — your account id, plus error type, message and a hash of the stack for crashes. Your country is derived from the connection at our edge; we do not store IP addresses with these events.
- Your arsenal, if you use it: custom modules and binaries you upload are encrypted on your device before upload. We store the encrypted bytes and their file name, type and size. Access to the stored encryption key and encrypted artifacts is restricted to your account.
- Contact messages: the name, email and message you send through the contact form.
- AI response reports: when you choose “Report response” in the chat, we receive only the excerpt you review and submit, your reason, account id and submission time. No full conversation, tool output or API key is attached automatically. AlpisteSec reviews these reports to investigate problematic responses and improve the product.
What we do NOT collect
- We do not routinely upload scan results, targets, credentials, sessions or tool output to the Lupus account API. They live on your selected agent. AI use, artifact uploads and excerpts you explicitly report are the exceptions described here.
- We do not automatically upload your contacts, personal files, precise location, microphone or camera data. Files or personal information that you choose to upload or include in AI context or a report follow the transfers described in this policy.
- Any advertising identifier. There are no ads and no third-party analytics or trackers.
AI, your own keys and remote agents
When you send an AI message, the agent processes your message, relevant conversation history, system instructions and tool results. That context can include target addresses, scan findings, file contents, credentials or personal information present in the material you use. Relevant context is sent to the AI provider and model you select; replies and tool activity are retained in the agent’s conversation history. The Lupus licensing API supplies session authorization and instructions; it does not receive your normal chat transcript.
With bring-your-own-key (BYOK), your provider key or OAuth credential is stored in Android Keystore-backed storage and passed to the selected agent to authenticate provider requests. A remote agent therefore receives the credentials needed for the selected provider as well as your messages and tool results. Its operator controls that server, its logs and stored data. Review who operates an agent before connecting to it.
Providers may include OpenRouter, OpenAI, Anthropic, Google or another provider selected in the app. Routing services may send requests to the model’s upstream operator. Their own retention, training and account settings apply, including for free models; using your own key does not guarantee confidentiality or zero retention. The app shows a provider-specific notice before sending. Consult the selected provider’s policy and settings for its retention and deletion controls. Lupus does not train models on your chat or submit reports to AI providers automatically.
Who we share it with
We do not sell your data and we do not share it for advertising. We share only what each service needs in order to work: your payment provider (to take payment and tell us whether it succeeded), Google Play (to verify a purchase made through Play Billing), our hosting and object-storage providers, and our transactional email provider (to send verification and password-reset messages). When you use AI or a remote agent, data is also sent to the provider and agent operator you select, as described above. Services may process data outside your country. We also disclose data where the law requires it.
How long we keep it
Account, licence and arsenal data are kept for as long as your account exists. Diagnostic events are kept for up to 12 months and then discarded. Payment records are kept for as long as tax and accounting law requires. Your email and Lupus account link are removed from payment records on deletion; provider references remain and the provider may still associate them with you.
- AI reports are removed after 90 days of submission by an hourly retention task, or with your account, whichever comes first.
- Trial-abuse prevention retains a keyed digest of an address that used a trial after deletion, without the readable address, for as long as the one-trial rule operates.
- Play purchase/account digests remain after deletion to prevent a purchase being claimed by another account. Raw purchase tokens are removed on deletion except where required to complete cancellation.
- Pending cancellation records retain only the provider reference needed to stop billing, retry timing and a failure code until cancellation is confirmed. The reference is then erased; completion metadata is removed after 30 days.
- Local and remote-agent conversations follow the storage and deletion controls of that agent. AI-provider retention is controlled by the provider, not the Lupus account deletion endpoint.
- Private disaster-recovery database backups can retain previously stored data for up to a further 90 days after it is removed from the active service. They are access-restricted and expire on the backup retention schedule.
Deleting your account
You can delete your account and its data at any time, from the app (Settings → Delete account) or from your account page on the website. Deletion is permanent. For the full list of what is removed and what is kept, and how to request deletion if you cannot sign in, see Delete your account.
Your rights
You can request access to, correction of, or a copy of your account data at any time by emailing us. You can also object to our processing or ask us to restrict it. We respond within 30 days.
Children
Lupus is not intended for anyone under 18, and we do not knowingly collect personal information from children.
Changes
If this policy changes we update this page and the date above. Material changes are announced by email to registered users.
Contact
For privacy questions, email support@alpistesec.com.