Artificial UsersJoin the waitlist

Privacy policy

Last updated 17 September 2026.

Artificial Users is a product of Astral. This page says what we collect, what we do with it, and what will happen to your data when the product runs. It is written to match what the software actually does. If the software changes, this page changes in the same release.

1. What this covers today

The waitlist form and this website. Nothing runs against your product yet. Section 4 describes what will happen when it does, so you can read it before you join rather than after.

This site sets no cookies and runs no analytics. Every page is a static file. Only the waitlist page loads anything from a third party: Cloudflare Turnstile, which is the check that you are a person and not a script. Turnstile sees your IP address and your browser, and Cloudflare states that it does not use it to track you across sites. No other page loads it, and no page on this site runs any other script.

2. What the waitlist collects

When you join the waitlist you give us your email address, the URL of your product, its stage, whether you use Claude Code or Codex or neither, whether you use a terminal, your operating system, and whether Chrome is installed.

The form is ours. It posts straight to our own database, which is hosted by Supabase in the United States. If you are somewhere else, joining the waitlist means your answers are stored there. Nobody else receives it. We use it for two things: to decide who gets an invite, and to email you when yours is ready. We do not sell it, we do not share it, and we do not send anything else to it.

Two things are recorded that you did not type. Cloudflare Turnstile checks that the submission came from a person, and we keep only its yes or no answer. We also keep a one way hash of your IP address, so that one network cannot flood the list. It is kept apart from your answers, in a table of attempts that is swept daily and holds nothing older than two days. The hash is keyed with a secret, so it cannot be turned back into an address by trying every address, and it is never used to identify you.

The question about Claude Code and Codex is there only to size an option we have not built. It is not a requirement and it does not affect your invite.

3. How to have it deleted

Email david@astral.now and ask. We delete your row and confirm. You do not have to give a reason and it does not affect anything else.

4. What will happen when you run it

This section describes the product, not the waitlist. It becomes true for you on the day you install the runner and start a session.

What leaves your machine. Two things. When you pair a machine with your account, its name as your operating system reports it, so you can tell your machines apart in your device list and revoke the right one. Pairing also records the IP address the request came from, and the network that address belongs to, and shows both to you on the approval page, so that you can see whether the machine asking is yours before you approve it. That address is held only on the pending pairing, which lives at most ten minutes. The pairing is deleted the moment the machine collects its token. One that is never collected, because you did not approve it or the machine had already gone, is deleted within an hour of expiring. And for each run, an evidence pack: screenshots of your live product, the page text the stranger read, the values it typed into your forms, and the log of what it did. That is the whole list.

What is removed before it leaves. Text is redacted on your own machine before upload and again when it arrives. Anything typed into a field your product marks as a password is replaced before it is written down at all, and pattern matching removes things shaped like keys, tokens, card numbers and email addresses. Redaction does not touch screenshots. Anything visible on your screen at the moment of a screenshot is in that screenshot, including your own customers' data if it was on the page.

How long we keep it. The raw pack is deleted the moment intake finishes, whether we accepted it or rejected it. A rejected run leaves only a diagnostic summary of file names, sizes, hashes and validation errors, with no content, kept 7 days so we can tell you why your run failed. A pack uploaded but never handed in to be checked is deleted within a day. An accepted pack's screenshots, the page text the stranger read, the values it typed and the log of what it did, along with the report written from them, are kept 90 days. So is the pack's description of itself: which machine made it, when the run started and ended, and which files it held. The report keeps, beside its text, the recorded details of each finding: what the stranger noted and quoted, what it filled in for whoever fixes it, the page address, the name of its screenshot, and what our checks said about it. It also keeps the run's cleanup list: what the run created inside your product, such as the account the stranger signed up with (its email address included) and anything it added, so you can remove them. Nothing new leaves your machine for this; these are the same details, kept with the report. Mail sent to a session's synthetic address is kept 90 days.

Deleting a report. You can delete any report and its evidence from your account at any time. That removes every screenshot and everything else stored from that run's evidence pack, and clears the report's text, the details of its findings and its cleanup list from the report itself. One copy is not yet removed: while a report is being written, our checking service keeps a working record of its text and those details, and that record currently stays after the report is deleted or expires. We are changing this so the working record is cleared with the report, and this page will say so when it is. The record that a session was used stays, because it is an accounting entry.

What we do not attest. The evidence comes from your machine. We bind each pack to a run and to the brief it was produced from, and we check it against our own limits, but we do not certify that it was produced by unmodified software.

Who processes the model calls. Anthropic, on AWS Bedrock, under terms that do not permit training on the content. We pay for those calls. You need no account with either of them.

What runs inside your product. A session creates a real account and real data inside the product you point it at. Staging is the default target. Before any run against production you confirm, once per project, that you own the product or have authority to test it.

Your own keys. If you have an Anthropic or OpenAI key in your shell, we note that it is present and never read it, never transmit it, and never meter it. The model calls go to our gateway with our key.

5. Who to contact

David Babunashvili, Astral. david@astral.now.