Last updated: July 25, 2026
Culpur Defense Inc. (“Culpur Defense,” “we,” “us,” or “our”) operates the culpur.net website, the AnvilHub marketplace (anvilhub.culpur.net), and our products, including the Anvil command-line application, BEMA, Aegis, CStrike, and EMS. This Privacy Policy explains what information we collect across these services, how we use it, and the choices you have. We designed our products to minimize the data we collect — in particular, the Anvil application is built to keep your credentials and source code on your own machine.
Who we are
The data controller is Culpur Defense Inc. For any privacy question or request, contact us at [email protected].
Information we collect
Account information. When you create an AnvilHub account or sign in, we collect the information you provide or that your identity provider shares with us — typically your name, email address, and an account identifier. Authentication is handled through our single sign-on provider; we do not store your password in plaintext.
Usage and diagnostic data. When you use culpur.net or AnvilHub, our servers and content-delivery network (Cloudflare) automatically record standard request data such as your IP address, browser type, referring page, and timestamps, for security, abuse-prevention, and reliability purposes.
Marketplace activity. If you publish, install, or interact with skills, plugins, agents, or themes on AnvilHub, we record the activity necessary to provide those features (for example, which package was installed, and install success or failure). When Anvil reports a completed install so we can count downloads, it sends the package name and version, the Anvil version, and your operating-system platform; your IP address is irreversibly hashed before storage and is not linked to your account.
The Anvil application. Anvil runs locally on your own computer. Your API keys, OAuth tokens, vault contents, source code, and conversation history are stored on your machine and are not transmitted to Culpur Defense. Anvil sends your prompts and code only to the AI provider you configure (for example Anthropic, OpenAI, Google, or a local model), using your credentials. Anvil may contact culpur.net / anvilhub.culpur.net for update checks, version information, and marketplace operations; these requests carry only what is needed for those functions. The routine update check runs at most once per day and carries no account information or identifying payload. If you enable Anvil’s optional connected features, the section below describes exactly what is transmitted.
Anvil connected features (optional)
Anvil works without any Culpur Defense account or connection: the application and its background daemon run entirely on your machine. Anvil also offers optional connected features — linking (“claiming”) a running Anvil into your AnvilHub profile and operating it from a browser through AnvilWeb, Anvil’s browser interface. These features are off by default and activate only if you turn them on. This section describes exactly what is and is not transmitted when you do.
Local mode — no cloud involved
If you enable the browser interface in local mode, your browser connects directly to the Anvil daemon on your own computer or local network. Nothing about this connection or its contents is sent to Culpur Defense — no registration, no metadata, no traffic. Device pairing in local mode is recorded only on your machine, and only a cryptographic hash of each device token is stored, never the token itself.
Claiming a device into your AnvilHub profile — hosted mode
If you choose hosted mode, you claim your running Anvil into your AnvilHub account so that your signed-in browser can reach it. When you claim a device and while it is connected, we store the following in your profile:
- a device record: the name you give it, its self-reported hostname, and its link to your account;
- a cryptographic hash of the device credential — never the credential itself;
- the source IP address and time of the device’s most recent connection (the latest value only, not a history), kept so you and we can see where your devices connect from;
- an opaque session identifier used to route your browser to the right device — it identifies a connection and contains no conversation content; and
- the names and versions of the agents, skills, plugins, and themes installed on that device, and its persona and primary-agent selection — names and versions only, never their contents. This inventory is private to your account and exists so you can manage the device from AnvilHub.
That is the complete list. Claiming and device registration never transmit your conversations, prompts, source code, API keys, vault contents, or configuration files. Your Anvil’s configuration stays on your machine; AnvilHub stores only the connection and device-management records described above.
Remote control through the relay
In hosted mode, the live session you view in your browser travels between your Anvil and your browser through our relay service. The relay exists solely to route: it forwards session traffic in memory, encrypted in transit, to your authenticated browser, and then discards it. We do not record, store, or log the contents of your sessions. The relay keeps no conversation data; its operational logs contain only connection metadata — connection events, message types, truncated session identifiers, IP addresses, and timestamps — used for security and abuse prevention. Access to a hosted session requires a short-lived signed identity token proving the browser is signed in to your account, which your own Anvil verifies before granting access.
Session sharing
Anvil includes an explicit session-sharing feature. If — and only if — you invoke it, a snapshot of that conversation is uploaded (with detected secrets scrubbed before upload), stored temporarily so your recipient can view it, and automatically deleted after its expiry period (24 hours by default). Sharing never happens automatically.
Revoking a connected device
You can revoke or remove a claimed device from your AnvilHub profile at any time, with immediate effect: the device credential stops working and remote access ends. You can equally disconnect from the device side by disabling the connection on your machine. After revocation we retain the device record itself (its name, hostname, and last connection details) for security and audit purposes; if you would like that historical record erased as well, email [email protected] and we will treat it as a deletion request.
Other Culpur Defense products
Beyond Anvil and AnvilHub, our other products collect only what they need to work. This section describes each.
BEMA
BEMA is our social media management application (web and mobile). When you connect a social account, we store the authorization tokens the platform issues so BEMA can post, schedule, and manage content on your behalf, within the permissions you grant; disconnecting an account revokes that access. We also store the content you create and schedule, the results of publishing (such as post identifiers, status, and basic engagement data the platform returns), and standard account and usage data. We access connected platforms only to carry out the actions you request. We do not sell your social data or use it for advertising.
Aegis
Aegis is our secure communication platform, built on a Matrix backend with end-to-end encryption. Messages and media in end-to-end encrypted conversations are encrypted on your device, and we cannot read them. To operate the service we process your account identifier, your devices’ public encryption keys, and the routing metadata needed to deliver messages — such as which accounts and rooms a message is addressed to, and timestamps. If you communicate with users on federated servers, the data necessary to deliver those messages is shared with those servers, which are operated by third parties under their own policies.
Anvil-verse chat (AnvilHub)
AnvilHub includes a chat service for Anvil-verse users and organisations, built on a Matrix backend. Messages are end-to-end encrypted between user devices. To operate the service we process your chat account identifier, your devices’ public encryption keys, the identifier of the device each session uses, and the routing metadata needed to deliver messages — such as which accounts and rooms a message is addressed to, and timestamps.
Chat message recovery. Culpur retains an escrowed key capable of decrypting message history, so that data can be recovered following device loss and to meet our legal and compliance obligations. This means message recovery is possible for the operator: Anvil-verse chat is not a system in which only you can ever read your messages.
Use of that key always requires two distinct authorised parties; a single Culpur administrator cannot access message content alone. Access is permitted only where (a) an organisation owner authorises recovery of that organisation’s shared rooms, (b) the affected user themselves requests recovery, or (c) we are compelled by a valid legal order, whose reference we record. Organisation owners cannot access members’ direct messages.
Every access is logged immutably with both authorising parties, the scope, and the stated reason. We notify the affected user unless a legal order prohibits us from doing so. You can see your chat identity and the devices holding your message keys in your AnvilHub profile, under Security.
CStrike
CStrike is our offensive-security engagement platform, available only for authorized security testing. Engagement data — the scopes, targets, configurations, and findings involved in an engagement — is provided by and belongs to you or your organization, and we process it only to provide the service. We treat engagement data as confidential, restrict access to it, and retain it only as long as the engagement and our agreement with you require. Account, authentication, and security-log data are handled as described elsewhere in this policy.
EMS
EMS is our enterprise management platform, provided to organizations. When your organization uses EMS, the data processed — for example, information about the organization’s systems, devices, and user accounts — is controlled by that organization; we process it on the organization’s behalf and under its instructions. If you use EMS through your employer or another organization, please direct privacy questions and requests about that data to them; we support them in responding.
How we use your information
- To provide, maintain, and improve culpur.net, AnvilHub, and Anvil;
- To authenticate you and secure your account;
- To operate the marketplace (publishing, installs, listings);
- To operate the optional connected-device and remote-control features you enable;
- To detect, prevent, and respond to fraud, abuse, and security incidents;
- To communicate with you about your account, security, or service changes; and
- To comply with legal obligations.
We do not sell your personal information.
Cookies
culpur.net and AnvilHub use cookies and similar technologies that are necessary for the site to function — for example, to keep you signed in and to remember session and display preferences. We do not use cookies to build advertising profiles, and AnvilHub contains no third-party analytics or tracking scripts. You can control cookies through your browser settings; disabling necessary cookies may prevent parts of the site from working.
Third parties we share data with
We share information only with service providers that help us run our services, and only as needed:
- Cloudflare — content delivery, DNS, and security/DDoS protection.
- Our authentication provider — single sign-on and account security.
- AI providers you choose — when you use Anvil, your prompts and code are sent directly to the provider you configure, under that provider’s own privacy policy and your own account. Culpur Defense is not a party to that exchange.
- Social platforms you connect — when you use BEMA, we exchange data with the platforms you connect, only as needed to perform the actions you request.
- Federated communication servers — when you use Aegis to communicate with users on other Matrix servers, message-delivery data is shared with those servers.
We may also disclose information when required by law, to enforce our agreements, or to protect the rights, safety, and security of our users and our services.
Data retention
We retain account and marketplace data for as long as your account is active or as needed to provide our services, and afterward only as required for legal, security, or legitimate-business purposes. Server and security logs are retained for a limited period and then deleted or anonymized. Records of claimed Anvil devices are retained after revocation for security and audit purposes, as described above, and can be erased on request.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. To exercise any of these rights, email [email protected]. We will respond within the time required by applicable law. We will not discriminate against you for exercising your rights.
Security
We use technical and organizational measures to protect your information, including encryption in transit, access controls, and the design choice of keeping Anvil credentials and code on your own device. Device credentials and pairing secrets are stored only as cryptographic hashes on our servers. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children’s privacy
Our services are not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above, and significant changes will be communicated through the site or by email where appropriate.
Contact us
Questions about this Privacy Policy or our data practices? Email [email protected].
