agentspeed.

Privacy Policy

Last updated: July 26, 2026

This policy explains what personal data we handle, why, who we share it with, and the rights you have. AgentSpeed is metadata-first: the ingest contract has no prompt or output field, and known content-bearing keys are stripped before validation. Short log and error messages you choose to send are stored as sent.

1. Who we are and what this covers

This Privacy Policy explains how Vantlir LLC, a Wyoming limited liability company, which operates the AgentSpeed service (“AgentSpeed,” “we,” or “us”), handles personal data in connection with our websites, applications, and APIs (the “Service”).

It sits alongside our metadata-first privacy explainer, which describes in detail how the ingest API is built so that prompt and output content has nowhere to land, and where the limits of that are. This Policy is the formal document covering the personal data we do handle.

2. Controller and processor roles

For account, billing, and website data, we act as the data controller. For personal data that may be contained in the telemetry you send us, we act as your processor, handling it on your behalf and under your instructions; that processing is governed by our Data Processing Addendum. This Policy focuses on the data we control.

3. Information we collect

We collect the following categories of data:

  • Account data: your email address (used for one-time sign-in links) and your organization name.
  • Authentication data: a strictly necessary session cookie and short-lived, hashed sign-in tokens.
  • Usage and log data: IP address, browser/user-agent, timestamps, and pages or endpoints accessed, used for security, rate limiting, and diagnostics.
  • Telemetry metadata: the run metadata you send (status, timing, token counts, computed cost, model/agent/span/tool names, error type and a short error message). The contract is metadata-first by design, and it is worth being exact about what that does and does not mean. The public schema has no prompt or model-output field. Known content-bearing keys (for example prompt, completion,messages, content) are stripped before validation, so a client that sends them out of habit cannot get them stored. Any unknown field that remains after stripping is rejected rather than saved. The limit: the message and errorMessage fields are accepted and stored as sent, within their length limits — we cannot tell prose from a log line, so if you put prompt text there it is stored like any other string you send. Metadata-first is a design goal enforced at the boundary, not a guarantee about arbitrary text you choose to place in an accepted field. See the enforcement explainer for how this is enforced.
  • Billing data: handled by Stripe. We store your plan, subscription status, and a customer identifier; we do not store full payment-card numbers.
  • Communications: messages you send us (for example, support requests).

4. Scanning public websites

Separately from the telemetry product, AgentSpeed fetches and grades publicly available web pages to measure how readable and usable they are for AI agents. We do this for sites our users ask about, sites people submit on our public scan page, and a curated set we scan to build industry benchmarks.

We request pages the same way a search engine would, from a clearly identified user-agent (AgentSpeedBot). We read only what a page serves publicly: we do not sign in, we do not submit forms, we do not attempt to reach anything behind authentication, and we do not follow links to private or internal addresses.

A scan stores the page’s public content and the results we derive from it, and can publish a report at a public URL. Portions of visible page text are sent to Anthropic for analysis of how an agent would read the page. Values that look like credentials are redacted before storage, but public page text can still contain personal data (a named author, a team member’s work email) because the site chose to publish it.

Our legal basis is legitimate interests (GDPR Art. 6(1)(f)): assessing publicly published material to produce and improve a technical measurement service. We consider this proportionate because the material is already public, we take only what the site serves to any visitor, and we honour the site’s own instructions about automated access. Because the basis is legitimate interests, you have an absolute right to object under GDPR Art. 21, and the paragraph below is how to exercise it without contacting us at all.

How to stop us. We honour robots.txt before we fetch, not after: disallow AgentSpeedBot and we make no further requests to your site, remove your reports from public view, and stop listing you in our sitemap. You can also write to privacy@agentspeed.com and we will remove a domain by hand. See our bot page for the exact directive.

5. How and why we use data

We use personal data to:

  • provide, operate, secure, and maintain the Service;
  • authenticate you and send transactional email (sign-in links, alerts, digests, and service notices);
  • process payments and manage subscriptions;
  • provide support and respond to your requests;
  • understand usage in aggregate to improve the Service; and
  • comply with legal obligations and enforce our terms.

6. Legal bases (EEA/UK)

Where the GDPR or UK GDPR applies, we rely on: performance of our contract with you (to provide the Service); our legitimate interests (to secure, maintain, and improve the Service and prevent abuse); your consent (where we ask for it); and compliance with legal obligations.

7. Cookies and tracking

We use two strictly necessary cookies: one to keep you signed in, and a companion marker that lets our site header reflect your signed-in state without slowing every page. Neither carries tracking data or personal information beyond the fact that a session exists.

We use Vercel Web Analytics to understand aggregate traffic. It is cookieless and does not track you across other websites. We do not use advertising trackers, and we do not engage in cross-site tracking. Because we set no non-essential cookies, no cookie-consent banner is required to use AgentSpeed.

8. How we share data

We share personal data with vetted sub-processors that help us run the Service (for example, hosting, database, email, and payments). We maintain a current list, including what each one processes and where, and provide it on request: email privacy@agentspeed.com.

We may also disclose data to comply with the law or a valid legal request, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (with notice where required). We do not sell personal data, and we do not share it for cross-context behavioral advertising.

9. Data retention

We keep account data for as long as your account is active. Telemetry is retained according to your plan (currently from 7 days on the free plan up to 180 days on higher plans) and is then automatically deleted by a scheduled job. Logs are kept for a limited period for security and diagnostics.

Scan results for public websites are kept indefinitely, because score history over time is the point of the measurement. Ask us to remove a domain and we delete its scans and stop collecting new ones. See “Scanning public websites” above for both ways to do that.

When you ask us to delete your account, we remove your account data and remaining telemetry within 30 days. We keep billing and transaction records for 7 years, because tax and accounting law requires it. Those records contain your plan, amounts, and dates, and never payment-card numbers.

Aggregate website analytics are collected and retained by Vercel Web Analytics under Vercel’s own retention policy. That data is cookieless and is not linked to your account.

10. International transfers

We and our sub-processors are based primarily in the United States, so your data may be processed there. Where we transfer personal data out of the EEA or the UK, we rely on appropriate safeguards such as the Standard Contractual Clauses.

11. Security

We protect data with encryption in transit, hashing of API keys and sign-in tokens, access controls, and a metadata-first design that minimizes the sensitive data we hold in the first place. No system is perfectly secure, but data minimization is our strongest safeguard.

12. Your rights

Depending on where you live, you may have the right to access, correct, delete, port, or restrict the personal data we hold about you, and to object to certain processing. If you are in California, you have rights under the CCPA/CPRA to know, delete, and correct your data, to opt out of its “sale” or “sharing” (we do neither), and not to be discriminated against for exercising those rights.

To exercise any of these rights, email privacy@agentspeed.com. We will respond within the time required by law. If we process your data as a processor on a customer’s behalf, we will refer your request to that customer.

13. Children

The Service is not directed to children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us data, contact us and we will delete it.

14. Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

15. Contact us

Questions, requests, or complaints? Email privacy@agentspeed.com. If you are in the EEA or UK and believe we have not addressed your concern, you may also lodge a complaint with your local data-protection authority.

Privacy Policy · AgentSpeed