Legal

Privacy Policy

Last updated: 2026-07-27

Zero data plane architecture

Core Spend SDK policy evaluation runs in your application runtime. For supported provider bindings, prompt and completion content travels between your application and the selected model provider; AgentGuard is not an inference proxy. Customer-supplied provider credentials and locally configured signing private keys are not sent to AgentGuard by those bindings.

This boundary does not apply to data you intentionally submit to AgentGuard's hosted website, dashboard, account, support, billing, consent, workflow, or verification features.

What we DO receive or process through hosted features:

What we do NOT receive from governed Spend SDK calls:

Cookies and local storage

The dashboard may use cookies, local storage, or session tokens to keep you logged in and route you to the right workspace. The public website may use lightweight analytics to understand aggregate usage.

Third-party processors

Hosted features use processors visible in the local implementation, including Privy for authentication, Stripe for billing, Postmark for email, Vercel and Vercel KV or compatible storage for hosting and account state, PostHog for analytics, OpenRouter for help-chat responses and managed inference, and optional Supabase, Hermes, or Telegram destinations. The core Spend SDK provider bindings do not route governed prompt or completion content through AgentGuard, but a selected model provider still receives the inference request.

Data retention

Hosted account, license, billing, inquiry, support, analytics, workflow, and dashboard data is retained according to the feature and configured processor. The local source does not establish every processor's backup or deletion interval. A signed receipt that you retain remains verifiable with its public key after hosted data is removed; cryptographic signing does not itself publish or retain the receipt.

User rights

If you are covered by GDPR, CCPA, or similar privacy laws, you may request access, correction, export, or deletion of personal information we hold about your account. Email [email protected].

International transfers

Hosted account, license, billing, inquiry, support, analytics, and workflow data may be processed in the United States or in regions used by the configured infrastructure providers. The governed SDK inference path remains application to selected provider and does not pass through AgentGuard infrastructure.

Children's privacy

AgentGuard is built for businesses and developers. It is not directed to children under 13.

Contact

Privacy questions can be sent to [email protected].

Back to top

Functional-use disclaimer

All terminology and labels used in AgentGuard materials are descriptive of software functionality only, not legal definitions or guarantees of compliance. Terms such as receipt, audit log, evidence, audit trail, attestation, signed, verified, attested, compliance, compliant, outcome, settlement, capability tier, and settles refer to cryptographic software records and programmed state transitions only. They do not state that any record has binding legal effect, official certification, or equivalent status to records maintained by courts, banks, auditors, regulators, or agencies.

Terms drawn from audit, evidence, settlement, credit, debt, market, liquidity, maturity, and similar domains are used only in a functional and descriptive sense. An audit log is a sequence of recorded software events. Evidence means a record that may support a user review. Settlement means a final software state. None of these terms should be read as legal, financial, accounting, or regulatory advice.

Financial-context words such as trade, trading, liquidity, maturity, market, clearing, and exchange, if used in examples, describe token, budget, or workflow mechanics only. AgentGuard does not operate as a broker-dealer, exchange, clearinghouse, investment adviser, insurer, government agency, or regulated marketplace.

Words such as offer, obligation, credit, debt, payment, settle, maker, and taker refer only to hypothetical or user-operated agent workflows, simulated transaction states, or software configuration examples. AgentGuard does not transmit money, extend credit, custody funds, offer financial instruments, or guarantee settlement of obligations.

References to certify, verify, attest, signed, or validated are cryptographic and computational terms. They mean that software performed a signature, hash, schema, or chain check. AgentGuard does not claim that receipts are admissible legal evidence by default, that a court or regulator must accept them, or that use of AgentGuard alone fulfills any legal standard. The software is provided as-is as a technical audit tool.