Privacy Policy
Last updated: September 18, 2026
This Privacy Policy describes how AuditAgent (“we”, “us”) handles information in connection with the AuditAgent Service. AuditAgent is currently operated by an individual rather than a registered legal entity; contact details are in §8.
1. What we collect
- Account information: your email address (used for sign-in via Supabase Auth) and the workspace(s) you create or join.
- Logged agent events (Customer Data): action names, timestamps, and input/output previews your SDK integration sends us. This is redacted in two passes before storage: a pattern/NER-based filter (Presidio) for structured PII (names, emails, phone numbers, SSNs, card numbers), then a second automated pass (an Anthropic Claude model) for anything the first pass misses, such as API keys or internal identifiers mentioned in free text. Neither pass guarantees all sensitive data is caught, see §5.
- Uploaded questionnaires: files you upload are stored in a private Supabase Storage bucket and processed to draft answers; you control export.
- Billing information: handled entirely by Whop, we store your Whop membership ID, not your card details.
- Usage/log data: standard web server logs (IP, user agent, request path) for security and debugging.
2. How we use it
To operate, maintain, and improve the Service; to communicate with you about your account, approvals awaiting a decision, or service changes; to process payment (via Whop); and to comply with legal obligations.
We do not sell Customer Data, and we do not use it to train models beyond what’s needed to generate your own questionnaire answers and redaction passes at the time you use those features.
3. Sub-processors (who else touches your data)
- Supabase: database, authentication, file storage. All account and Customer Data.
- Anthropic: second-pass redaction and questionnaire answer drafting. Event content sent for redaction/drafting only.
- Resend: transactional email (approval requests, timeout notices). Recipient email, agent/action names.
- Slack: approval notifications, only if you connect it. Agent/action names, your workspace’s chosen channel.
- Whop: payment processing. Billing contact info, subscription status.
- Vercel: dashboard hosting. Application traffic in transit.
- Hugging Face: backend/API hosting. All of the above, in transit/at rest.
4. Data retention and deletion
Customer Data is retained for as long as your account is active. On account closure, we retain data for 30 days to allow export, then delete it. Deleted data may persist in infrastructure backups for a limited window afterward before those backups themselves expire.
5. Security
Data is encrypted in transit (TLS) and at rest (via our infrastructure providers). The events table is append-only at the database level (a trigger rejects UPDATE/DELETE), so even a compromised application credential cannot alter or erase logged history. Automated redaction (§1) reduces but does not eliminate the chance that sensitive data appears in what you log; you’re responsible for not intentionally logging data your own policies prohibit collecting.
6. Your rights
Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal data. Contact us at the address in §8 to exercise these.
7. Changes to this policy
We’ll post updates here and, for material changes, notify you via email or an in-product notice.
8. Contact
AuditAgent, mawais9171@gmail.com