Privacy Policy
Effective August 12, 2026 · rev 2026-08-12.draft-1
This policy covers the AgentLens website, free scans, journey demos, and paid audits. The short version: we collect the minimum needed to run your audit, credentials are sealed so we cannot read them, and everything has a deletion story.
What we collect
- Email addresses — for audit delivery, plan-generation tokens, journey demos, and the waitlist. Payment details go directly to Stripe; we never see or store card numbers.
- Audit targets and run evidence — the target you specify, generated test plans, and recordings of agent runs (the product itself).
- Sealed credentials — encrypted in your browser to the audit worker's key. The web application stores only ciphertext it cannot decrypt, plus the variable names for display.
- Operational logs — standard request logs and error traces.
Retention
- Sealed credentials: deleted the moment your audit completes, fails, is refunded, or needs your action — enforced in code and by a daily sweep.
- Audit evidence and reports: retained 180 days after completion, then purged. [FOUNDER: confirm window]
- Journey demo recordings: retained 90 days.
- Waitlist and marketing data: kept until you unsubscribe; every marketing email carries a one-click unsubscribe.
Processors we rely on
Stripe (payments), Vercel (hosting), Supabase (database and evidence storage), Resend (email), E2B (sandboxes), Anthropic and agent vendors (the models the audits exercise). Each receives only what its role requires; credentials reach only the audit worker.
What we don't do
- No selling or renting personal data.
- No advertising trackers.
- No training models on your credentials or private run evidence.
Your rights
Email audits@agentlens.dev to access or delete your data (waitlist entries, audit emails and links, journey records). Deletion requests are honored within 30 days. EU/UK residents: the legal bases we rely on are contract performance (audits) and consent (marketing). [FOUNDER: confirm DSAR window + controller entity.]