Legal
Privacy Policy
Last updated 2026-06-10
What this covers
This policy explains how AgentSmack (“we”, “us”) handles the data you provide when you use the AgentSmack website, API, and reports. Submitting an agent or creating an account means you accept this policy.
What we collect
Agent submissions. When you test an agent we receive the system prompt, declared tool list, and optional label/framework/model you send. We store these to produce and display your report.
Account data. If you create an account: your email, and workspace/organisation membership. We use a passwordless or hashed-credential sign-in; we never store plaintext passwords.
Operational metadata. Request IP (for anonymous rate-limiting), timestamps, and a deterministic fingerprint hash of each submission.
Secrets and sensitive content — our commitment
Agent prompts sometimes contain credentials or proprietary content. When our probes detect a credential-shaped value in a model response, we never store the raw value — only a salted SHA-256 prefix (so a leak can be classified without the secret being retained). Despite this, please do not paste live production secrets into any tool. If a prompt you submitted contains a real secret, rotate it and contact us to delete the submission.
How we use your data
To run probes, generate and serve your report, enforce rate limits and billing, secure the service, and (for signed-in users) keep your history. We do not sell your data, and we do not use your submitted prompts to train models.
Retention
Anonymous submissions and their reports are retained for a limited window and may be purged automatically. Signed-in submissions are retained while your account is active. You can request deletion of any submission or your entire account at any time (see Contact).
Sharing
We share data only with infrastructure subprocessors needed to run the service (hosting, database, payment processing, and the LLM provider that grades probes), each under contract. A public report URL is shareable by anyone who has the link; sign-in-gated detail is not public.
Your rights
You may access, export, correct, or delete your data. Where applicable (e.g. GDPR/CCPA), you may object to or restrict processing. We honour verified deletion requests promptly.
Security
Data is encrypted in transit (HTTPS) and at rest. Reports and capability cards are signed with Ed25519 so their integrity is verifiable offline. Access to production data is restricted and audited.
Contact
Questions or requests: privacy@agentsmack.com. See also our Terms of Service.