Legal
Privacy Policy
Last updated: 24 July 2026. This policy describes how Asteria (“we”) handles information when you use asteria.run and the Windows agent.
1. Who we are
Asteria operates the Deception Cloud service at asteria.run (and legacy alias hosts that serve the same product). Contact: [email protected].
2. What we collect
Account & dashboard
- Email, optional display name, password hashes (we do not store plaintext passwords)
- Billing-related identifiers when you subscribe (processed via our payment provider)
- Support messages you send us
Agent & security telemetry
- Server hostname/IP labels you configure, agent version, online/offline heartbeats
- Honeypot events: source IPs, attempted credentials on decoy services, trap hits, threat alerts, block actions you initiate
- Optional remote-control outcomes you trigger from the dashboard (e.g. process terminate, session logoff)
Technical logs
- Request metadata (IP, user-agent, timestamps) for abuse prevention and reliability
3. Why we process data
- Provide the product: register agents, show dashboards, deliver alerts
- Security of the service (fraud, abuse, account recovery)
- Billing and subscription management
- Improve reliability (anonymous aggregate stats may appear on the public site)
4. Legal bases (where GDPR/KVKK-style rules apply)
We process data to perform the contract (provide the service you signed up for), for legitimate interests (secure and improve the platform), and where required by law. For Turkish KVKK: you may request access, correction, deletion, or restriction via [email protected], subject to security and legal retention needs.
5. Sharing
We do not sell personal data. We may share limited data with:
- Infrastructure and email delivery providers under contract
- Payment processors for paid plans
- Authorities when legally required
6. Retention
Account data is kept while your account is active. Security event history retention depends on plan and operational needs; you may request deletion of linked server data subject to verification. Backups may persist for a limited recovery window.
7. Security
We use HTTPS, hashed credentials, tokenized agent auth, and access controls on the cloud. No method is perfectly secure — see also our Security overview.
8. Cookies
We use session cookies necessary for sign-in and dashboard access. We do not run third-party advertising trackers on the marketing site.
9. Children
The service is intended for business and adult IT professionals, not for children.
10. Changes
We may update this policy; the “Last updated” date will change. Material changes may be noted on the site or by email for account holders.