What we keep, and why.
Short, because we keep very little. It follows the same sections as our full privacy policy, which is with a solicitor and will replace this page once reviewed. For builds, runs and evidence, see Security.
1. What we collect
The waitlist. Your email address, and whatever else you chose to tell us: your name, what you test, which agent you use, your note, the page you signed up from and any campaign tags in its link. We also record whether you ticked “Email me product updates”, and when.
Double opt-in. We send one email asking you to confirm the address. Until you click it, you’re not on the list, and we won’t email that address again.
Your account. Your email address, your sign-in method, your organisation and its API keys (we keep a hash; the secret is shown once), plus what you run: builds, run records, evidence and usage for billing. Signing in sets a session cookie on the app. This marketing site sets none.
What we send. Your invite, and anything needed to run your account. Product updates only if you ticked the box — it starts unticked. Every email has a one-click unsubscribe link.
2. This website
Static pages. No cookies, no analytics, no tracking pixels, no third-party scripts. Fonts are served from this domain. The server that hosts it keeps standard request logs for a few days.
Product analytics, when we turn them on, are recorded on our server when you do something in the product — signed up, connected, ran. Nothing runs in your browser to collect them, and they never include screenshots or build contents.
3. Who we share it with
We don’t sell or share your details. These providers run parts of the service for us, and only for the job named:
| Provider | What it does for us | Where |
|---|---|---|
| Our hosting provider | Hosts the server and the encrypted backups | EU |
| GitHub | Sign-in with GitHub, reviewer access to evidence, CI sign-in | US |
| Resend | Delivers our email: sign-in links, invites, the waitlist | US |
| Stripe | Takes payment on paid plans. Card details go to Stripe, not us | UK, IE, US |
| Cloudflare | DNS, and serves this website and the status page. API traffic doesn’t pass through it | Global |
| Sentry | Error reports from our servers. Server-side, when enabled | EU |
| PostHog | Product analytics. Server-side only, when enabled | EU |
The simulators run on Macs we own, in the UK. Your builds and evidence are there only while a run is in progress. There’s no model provider on the list because there’s no model in the hosted path.
4. How long we keep it
Evidence lasts as long as your plan says: 7 days on Free; 30, 90 or 180 days on paid plans. Uploaded builds are kept for 7 days. Your account lasts until you close it. Invoices are kept for as long as UK tax law requires. Backups roll off within 30 days.
5. Your rights, and getting it removed
You can ask for a copy of what we hold, ask us to correct it, or ask us to stop using it. Email [email protected]; we reply within a month and don’t charge.
To have everything removed — waitlist entry, account, runs, evidence, keys — email [email protected] with “Delete my data” in the subject, and we’ll confirm when it’s done. Unsubscribing from updates doesn’t remove you from the waitlist unless you ask.