AgentGuards

Privacy Policy

Last updated: July 12, 2026

1. Overview

AgentGuards ("we", "us") operates the guardrail API at agentguards.co. This Privacy Policy explains what data we collect, how we use it, and your rights over it.

2. Data We Collect

We collect the following categories of data:

  • Account data — email address, name, and authentication credentials managed via Clerk.
  • API usage data — request timestamps, check results (pass/block), token counts, and tenant identifiers. We do not store the content of prompts beyond what is needed for real-time processing, unless you turn on the optional setting described in section 4.
  • Billing data — plan tier and subscription status. Payment card details are processed and stored by our payment provider; we do not store card numbers.
  • Technical data — IP addresses, browser type, and logs, collected automatically when you access our website or API.

3. How We Use Your Data

We use the data we collect to:

  • Provide and operate the Service.
  • Enforce usage quotas and plan limits.
  • Send transactional emails (account creation, key alerts).
  • Detect abuse and ensure security.
  • Comply with legal obligations.

We do not sell your personal data to third parties.

4. Sharing Blocked Prompts (Optional, Off by Default)

By default, we never store the content of your prompts. You can optionally turn on "Share blocked prompts to improve detection" (Dashboard → Checks). This is the only setting that causes prompt content to be retained, and it is off unless you switch it on.

What is stored when it is on. Only the text of prompts that our machine-learning checks (PromptGuard and the LLM injection check) blocked. Prompts that were allowed are never stored. We store the blocked text alongside the check that flagged it, its confidence score, and your tenant identifier.

What is never stored, even when it is on. Prompts that triggered our secret-detection or PII-detection checks are excluded from collection entirely — precisely because their content contains the credential or personal data that triggered the check. Prompts blocked only by pattern-based (non-ML) checks are also not collected.

Why we do it. Solely to reduce false positives and improve the accuracy of the detection models that run in the Service. Collected prompts are reviewed — with the assistance of an automated classifier and by our staff — and may be used as training data for those models. We do not use them for any other purpose, and we do not sell them.

Retention. Collected prompts that have not been reviewed are deleted after 90 days. You can turn the setting off at any time, which stops all further collection.

Because the content of a blocked prompt may itself contain information you consider sensitive, you should only enable this setting if you are comfortable with the handling described above.

5. Data Retention

Account data is retained for the lifetime of your account and for 30 days after deletion. Usage event data is retained for 12 months for billing and audit purposes. API request payloads processed in real time are not persisted to long-term storage, except where you have enabled the optional setting described in section 4.

6. Third-Party Services

We share data with the following sub-processors:

  • Clerk — identity and authentication.
  • AWS (eu-north-1) — cloud infrastructure hosting all data.
  • OpenAI — used only if you enable the optional setting in section 4, to help classify collected blocked prompts during review. Blocked prompt content is sent to OpenAI for this purpose. If the setting is off, no prompt content is sent.
  • Payment processor — billing and subscription management.
  • Google Analytics — website usage analytics.
  • X (Twitter) Ads — advertising measurement and retargeting.

7. Cookies

Our website uses session cookies required for authentication. We also use analytics and advertising cookies and similar technologies — including Google Analytics and the X (Twitter) advertising pixel — to understand site usage and to measure and retarget advertising. These third parties may set their own cookies and process limited browsing data in accordance with their respective privacy policies. You can block non-essential cookies through your browser settings.

8. Your Rights

Depending on your location, you may have the right to access, correct, or delete your personal data, or to object to or restrict certain processing. To exercise any of these rights, contact us at support@agentguards.co. We will respond within 30 days.

9. Data Security

All data is transmitted over HTTPS. API keys are stored encrypted at rest. We follow industry-standard practices to protect your information, though no system is completely secure.

10. International Transfers

All infrastructure runs in AWS eu-north-1 (Stockholm). If you access the Service from outside the EU, your data may be transferred internationally subject to appropriate safeguards.

11. Changes to This Policy

We may update this policy from time to time. We will notify you of significant changes via email. Continued use of the Service after changes constitutes acceptance.

12. Contact

Privacy questions or requests: support@agentguards.co