Privacy Policy
Last updated: July 6, 2026
Data controller
Flow Investment AG Aeschenvorstadt 4 4051 Basel Switzerland Email: contact@agenteye.io
AgentEye is a product operated by Flow Investment AG. This policy describes how we process personal data when you use AgentEye.io.
Overview
AgentEye offers (1) a free public website readability scan and (2) paid Agent Usability Audits in which autonomous or semi-autonomous browser agents attempt real user tasks on products you submit. This policy covers both.
We do not sell personal data. We do not use advertising, retargeting, or cross-site behavioural profiling on the current website implementation.
Free website scan
When you submit a URL for a free scan, we process the URL you enter and fetch a limited set of publicly accessible pages from that site (typically the homepage, llms.txt, robots.txt, sitemap.xml, and a small number of common paths, up to roughly 15–16 URLs). We analyse the fetched HTML and text to produce an Agent Readiness Score and report.
- Submitted URL: stored with the scan result so the report can be retrieved and displayed.
- Derived public content: page HTML, text extracts, and check outcomes used to generate the score and diagnosis.
- Technical metadata: HTTP status codes, response headers relevant to the scan, and timing information from our scan process.
- IP address and server logs: our hosting provider (Vercel) processes IP addresses, request timestamps, user agent strings, and related server logs when you use the website and API. We do not use these logs for advertising.
- Email (optional): only if you choose to receive the report by email via the report page form.
Scan reports are stored and reachable at a shareable URL based on the scanned domain (e.g. /report/yourdomain.com). Anyone who knows or discovers that URL can view the report. Reports are not indexed for marketing purposes, but they are not password-protected. Do not run a scan if you do not want a report for that domain to be stored and potentially shared.
Agent Usability Audits (paid)
When you order or request an Agent Usability Audit, you may provide additional information so we can test your product. Depending on your order, this may include:
- Product access: website or application URLs, staging or production environments, and environment details.
- Test instructions: task descriptions, success criteria, personas, flows to test, and product context.
- Credentials: test account logins, API keys, temporary access tokens, or other access credentials you choose to provide.
- Materials: screenshots, recordings, failure traces, logs, and notes you send us or that we generate during testing.
- Contact and billing details: name, email, company, messages, and information needed to deliver the audit and handle payment.
To perform the audit, autonomous or semi-autonomous AI-powered browser agents may interact with your submitted product: navigating pages, reading visible content, filling forms where instructed, clicking interface elements, and attempting to complete the tasks you define. AI systems may receive your task instructions, visible page content, screenshots or page state, and failure signals to plan steps, execute tests, and produce analysis. Recordings, screenshots, and failure traces may be generated as part of the deliverable. This processing is necessary to provide the service and may involve our infrastructure providers and technical subprocessors used for hosting, storage, browser automation, and AI-assisted analysis. We do not send your data to advertising networks.
Your responsibility for submitted data
- Submit only websites, applications, or environments you own or are explicitly authorised to test.
- Provide only credentials you are authorised to share; prefer dedicated test accounts with limited permissions.
- Avoid submitting unnecessary personal data. Do not submit highly sensitive personal data (e.g. health, biometric, or government ID data) unless explicitly agreed in writing.
- Do not provide production credentials unless absolutely necessary and explicitly agreed.
- Use temporary or time-limited credentials where possible.
- You remain responsible for the lawfulness of data you submit and for securing your own systems.
Purposes and legal bases
- Free scan: analyse publicly accessible content you submit and display or email results (contract performance / legitimate interest in operating the service).
- Email reports and optional tips: deliver requested reports; marketing tips and score alerts only with your explicit opt-in (consent, withdrawable via unsubscribe).
- Agent Test orders and contact requests: respond, scope, deliver audits, and handle billing (contract / pre-contractual steps).
- Waitlist signups: notify you about availability of paid tiers (consent / legitimate interest, depending on context).
- Security and operations: protect the service, prevent abuse, debug issues, and maintain infrastructure (legitimate interest).
Cookies and browser storage
Based on the current implementation, AgentEye does not use advertising pixels or cross-site profiling tools (for example Meta Pixel, LinkedIn Insight Tag, Hotjar, or Microsoft Clarity).
We use Google Analytics 4 (via Google Tag / gtag.js) to understand aggregated website usage (for example page views). Google may set cookies or use similar identifiers for this purpose. Details: https://policies.google.com/privacy
The following additional technically necessary or functional storage is used:
- Cookie agenteye_locale: remembers your language choice (EN/DE) for up to one year. SameSite=Lax. Not used for advertising.
- localStorage key theme: stores your light/dark mode preference on your device. Not used for tracking.
- Cookie ar_admin_session: HTTP-only admin authentication cookie, set only after admin login. Not set for regular visitors.
If we add further non-essential advertising or session-replay technologies, we will update this policy and the website implementation accordingly.
Third-party providers
We use the following categories of providers to operate AgentEye:
UI fonts (Inter, JetBrains Mono) are self-hosted via Next.js next/font. No Google Fonts requests from your browser during normal page loads.
When fulfilling Agent Usability Audits, additional infrastructure for browser automation and AI-assisted test execution may process submitted URLs, credentials, screenshots, recordings, and failure traces as required to perform the audit. Specific tools vary by engagement; we select providers needed to deliver the ordered service.
- Vercel : website hosting, serverless functions, and edge delivery. Processes IP addresses, request metadata, and application traffic.
- Google Analytics / Google LLC : website usage analytics (page views and related metrics) via Google Analytics 4 when enabled on this deployment.
- Upstash Redis : database/storage for scan reports, email leads, contact and waitlist submissions, and related application data on our production deployment.
- Resend : transactional email delivery (e.g. scan reports you request by email, internal notifications about new requests). Receives recipient addresses and email content.
Data retention
- Scan report snapshots: stored for up to 90 days by default, then expire from our primary storage.
- Shareable report URLs: available while the report is stored; after expiry the report page may no longer be available.
- Email leads (report delivery, optional tips): retained until no longer needed for the stated purpose; you may request deletion.
- Contact, waitlist, and Agent Test request records: retained to handle your inquiry or order and for reasonable business records; deleted or anonymised when no longer needed.
- Test credentials and access details: kept only for the duration needed to perform the audit and any included re-test, then deleted when no longer required. Deletion is handled as part of our operational process; we do not currently guarantee automated deletion across every backup or log copy.
- Audit deliverables (reports, recordings, traces): retained for the engagement and reasonable follow-up unless you request earlier deletion or we agree otherwise.
- Billing records: retained as required by applicable accounting and tax law.
- Server logs: retained by Vercel according to their operational defaults.
International data transfers
Some providers (including Vercel, Upstash, and Resend) may process data in the United States or other countries outside Switzerland and the European Economic Area. Where required by applicable law, we rely on appropriate safeguards offered by our providers (such as standard contractual clauses or equivalent mechanisms).
Your rights
Depending on applicable law (including the Swiss Federal Act on Data Protection and, where applicable, the GDPR), you may have rights to access, rectify, erase, restrict, object to processing, and data portability. You may withdraw consent at any time where processing is based on consent. Contact contact@agenteye.io. You may lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority.
Children
The service is not directed at children under 16. We do not knowingly collect their personal data.
Changes
We update this policy when our processing changes. The date at the top shows the current version.