Privacy Policy
How Agnostics collects, uses, stores, and deletes personal data.
Overview
Agnostics provides adversarial testing for AI applications. This policy describes what personal data we collect, why we collect it, and the choices you have.
This policy applies to the Agnostics website, product, and related support channels.
Data we collect
Account information such as name, email address, organization name, and role when you sign up or are invited to a workspace.
Target configuration you provide for scans, including endpoints, prompts, test parameters, and encrypted credentials.
Scan results, findings, Release Gate decisions, reports, and audit events generated during your use of the product.
Billing information processed by our payment provider. We do not store full payment card numbers on our servers.
Support messages and contact form submissions you send to us.
Product usage events such as pages visited, features used, and conversion actions when you accept optional analytics cookies.
Device and browser metadata such as user agent, approximate location derived from IP address, and web vitals for security and product improvement when analytics is enabled.
Chatbot messages you send through our public sales chat when you choose to interact with it.
Lifecycle communication preferences when you configure them in the product.
How we use data
To authenticate users, manage organizations, and provide the service you request.
To run scans, generate findings, compute Release Gate decisions, and produce reports.
To process subscriptions, invoices, and billing support.
To respond to support requests and communicate about your account.
To detect abuse, protect the platform, and maintain service reliability.
To improve product performance and security.
We do not sell personal data.
Legal bases
Where required by law, we process personal data based on contract performance, legal obligation, consent, or legitimate interests depending on the activity and jurisdiction.
How we share data
We use subprocessors to host the application, authenticate users, process payments, and deliver email when enabled. See the Subprocessors page for the current list.
We may disclose information if required by law, to protect rights and safety, or in connection with a merger or acquisition with appropriate notice where required.
Report share links expose only the report snapshot you choose to share, subject to expiry and revocation settings.
Retention
Active account data: we retain account, project, target, scan, finding, and report data while your account is active and as needed to provide the service.
Scan history: retention follows your plan limits. Older scan data may become eligible for deletion after downgrade or account closure.
Encrypted connection details: retained while the target exists unless you delete the target or request deletion.
Billing records: retained as required for tax, accounting, and fraud prevention after cancellation.
Support requests and audit records: retained for operational and security investigation needs.
Logs and backups: deletion requests may not immediately remove data from backups or aggregated logs. Residual copies are purged on our normal backup rotation schedule.
You may request deletion of personal data. See the Data Requests page for details.
Security
We encrypt data in transit using TLS. Target credentials and other sensitive configuration values are encrypted at rest.
Access within organizations is role-based. We design for tenant isolation between customer workspaces.
No online service can guarantee absolute security. See the Security page for more detail on our controls and honest limitations.
Your rights
Depending on your location, you may have rights to access, correct, delete, or restrict processing of personal data, or to object to certain processing.
You can submit a request through the Data Requests page or Contact page. We may verify your identity before responding.
If you are in the European Economic Area or United Kingdom, you may also lodge a complaint with your local supervisory authority.
International transfers
Where personal data is transferred across borders, we use appropriate safeguards required by applicable law, including standard contractual clauses where needed.
We may process and store information in the United States and other countries where our subprocessors operate.
Children
Agnostics is a business product and is not directed to children under 16. We do not knowingly collect personal data from children.
Changes to this policy
We may update this policy from time to time. We will post the revised version on this page and update the last updated date.
Contact
Privacy questions can be submitted through the Contact page (/contact) or Data Requests page.