Legal
Privacy Policy
What Anthros accesses through Meta, Google and Microsoft connections, how tokens are stored, and how to have data deleted.
This Privacy Policy explains what information Anthros handles, why, where it is stored and how you can have it deleted. It applies to the website anthros.ai.vn, to Anthros instances, and to the Anthros connection service at connect.anthros.ai.vn.
1. Who we are
Anthros is software developed and licensed by Benocode Company Limited (Công ty TNHH Benocode), tax code 0319354596, 124 Nguyen Van Kinh Street, Cat Lai Ward, Ho Chi Minh City, Vietnam ("Benocode", "we", "us").
Anthros is an agent operations runtime: AI agents work on tasks for an organization, and people approve the steps that need a human decision.
2. How Anthros is deployed, and who controls your data
Every customer organization receives its own Anthros instance on a server dedicated to that organization. Instances are not shared between customers, and one customer's data is never stored in another customer's instance.
- The customer organization decides what Anthros is used for and which accounts are connected. For data inside its instance, the customer organization is the data controller.
- Benocode installs, updates and maintains instances on the customer's behalf. When we do so we act as a service provider (data processor) and only access an instance to operate, support or secure it.
- For this website and for messages you send us directly, Benocode is the data controller.
3. Information we handle
On this website. We do not use advertising or analytics cookies. The site stores only your theme and language preference in your browser. Our servers keep standard technical logs (IP address, browser type, page requested, time) to keep the service secure. If you email us, we keep your message and contact details to reply.
In an Anthros instance.
- Account data: name, email address, role, and a password hash or sign-in identifier for each user the organization invites.
- Work data: tasks, messages, files, approvals, agent output and activity history that users and agents create.
- Connection data: access tokens and the basic profile of the account that authorized a connection (for example, the account ID and display name), described in section 4.
4. Data accessed through Meta, Google and Microsoft connections
An organization administrator can connect third-party accounts in Settings › Connections. Anthros only connects an account when someone with permission in that account signs in and approves the request. Anthros uses the data from a connection only to perform the tasks users ask for, inside that organization's own instance.
Meta (Facebook and Instagram). Permissions requested: ads_read, ads_management, pages_show_list, pages_read_engagement, pages_manage_posts, business_management, and openid to identify the connecting account.
- We use them to list the ad accounts and Facebook Pages you grant, read ad performance (spend, reach, results), create and edit campaigns, ad sets and ads, and read, publish or schedule Page posts.
- New ads that Anthros creates always start paused. Write actions run only when a user of your organization requests or approves them.
Google Workspace. Scopes requested, all read-only: drive.readonly, documents.readonly, spreadsheets.readonly.
- We use them to read the Drive files, Google Docs and Google Sheets that you choose, so agents can use them as source material for a task.
- Anthros does not modify, delete or share your Google files.
Microsoft 365. Permissions requested: Files.Read.All, Sites.Read.All, offline_access, openid, profile.
- We use them to list and read the OneDrive and SharePoint files and sites you grant, so agents can use them as source material.
- Anthros does not modify, delete or share your Microsoft files.
MCP servers. An administrator may connect Model Context Protocol servers. Anthros sends a server only the requests that a task needs, and the data that server returns is handled under that server's own terms.
5. How tokens are stored
- Access and refresh tokens are stored only in the customer's own Anthros instance, encrypted at rest with AES-256-GCM. The encryption keys stay on that instance.
- The connection service at connect.anthros.ai.vn holds the OAuth client secrets for the Anthros apps. It completes the sign-in exchange with Meta, Google or Microsoft and hands the resulting tokens to your instance; it is not where your tokens are kept.
- Tokens are never shown in the Anthros interface, never written to logs on purpose, and never sent to AI model providers.
6. How we use information
We use information only to provide, secure, support and improve the service you asked for: running tasks, showing results, sending notifications you enabled, and keeping instances working.
When an agent works on a task, the instance sends the content needed for that task to the AI model provider that your organization configures. That provider processes the content under its own terms. Benocode does not use your data, or data obtained through Meta, Google or Microsoft, to train AI models.
7. We do not sell your data
We do not sell, rent or trade personal data or data obtained through any connection. We do not use it for advertising, and we do not transfer it to data brokers.
Google API Services. Anthros's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
8. Who else processes data
- The hosting provider of the server that runs your instance.
- The AI model provider your organization configures, for the content of the tasks it processes.
- Meta, Google, Microsoft and any MCP server you connect, when Anthros calls them on your behalf.
- Authorities, only when Vietnamese law requires it.
9. Retention and deletion
- Connection tokens are kept until the connection is removed. Disconnecting in Settings › Connections deletes the stored tokens from the instance immediately. Revoking Anthros from your Meta, Google or Microsoft account also stops all further access.
- Work data is kept for as long as the organization uses its instance, or until users or administrators delete it.
- When a customer ends its agreement, we delete the instance and its backups within 30 days, unless the customer asks us in writing to export the data first.
- Website messages are kept for up to 24 months, then deleted.
Step-by-step instructions are on our Data Deletion page.
10. Security
Each instance runs on its own server, traffic is encrypted with TLS, secrets are encrypted at rest, and access by Benocode staff is limited to the people who maintain the instance. No system is perfectly secure; if we learn of a breach that affects your data, we will notify the customer organization without undue delay.
11. Your rights
Depending on where you live — including under Vietnam's Decree 13/2023/ND-CP on personal data protection and, where it applies, the EU GDPR — you may ask to access, correct or delete your personal data, restrict or object to its processing, withdraw consent, or receive a copy of it.
If your data is in an organization's instance, please contact that organization first; we will help them respond. You can also write to us directly using the contact details below.
12. International transfers
Your instance is hosted in the region agreed with your organization. Connected services and AI model providers may process data in other countries under their own safeguards.
13. Children
Anthros is a business tool and is not directed to children under 16.
14. Changes to this policy
We will update the version number and the "Last updated" date at the top of this page when this policy changes, and notify customer organizations of material changes.
15. Contact
Benocode Company Limited — 124 Nguyen Van Kinh Street, Cat Lai Ward, Ho Chi Minh City, Vietnam. Email: hi@anthros.ai.vn · Phone: +84 942 27 97 27