Skip to content
AI Hub Sign in Hire an agent
Trust

Trust: what happens to your data

Only what is true today: where the data lives and for how long, who takes part in processing it, how it is protected and what we do if something goes wrong. We hold no certifications yet — so we show what can be checked.

How long it is kept

Retention is a property of the kind of data, not a decision made at the moment of writing.

WhatHow long
Full text of conversations with the agent30 days after the last message
Web chat history in the cabinet90 days
A conversation with the consultant on the siteup to 90 days
The agent's notes about the workwhile you use the agent
Backups of the agent's environment35 days; encrypted and verified by restore every day
Logs of the functions and the agent's environment30 days
Site CDN logs (address, browser, page)90 days; only numbers go into analytics
A file from the request form before scanningup to 14 days; a file with a threat is deleted at once

Who takes part in processing

Three kinds of participants — and you choose the model and the channel.

Amazon Web Services

Compute, storage, mail (Amazon SES), file scanning. The site and the cabinet run in the EU (Frankfurt); the agent's environment runs in the region you choose or in your own AWS account.

The model provider

The one whose subscription or key you connected — Anthropic, OpenAI and others — or Amazon Bedrock in your AWS. A request is processed on that provider's terms.

The channel

Telegram, if you connected a bot. The cabinet's web chat works without intermediaries.

The site does not track you

Check it yourself: developer tools → Network.

No cookies on the pages

Only the cabinet sets one (the session after sign-in) and the consultant chat (to continue the conversation).

Not a single third-party request

No counters, no external fonts, no widgets. A network audit checks this on every release.

Statistics without scripts

Counted from the CDN logs as daily numbers — nothing runs in your browser for it.

Protection

A separate environment per customer

Its own machine, secrets, logs and backups. Data of different customers does not mix.

No inbound ports

The agent's environment accepts no incoming connections: management goes through AWS Systems Manager, questions through a queue.

Keys and tokens are write-only

Kept in AWS Secrets Manager. After saving nobody sees them, and they never reach the agent's memory.

Sign-in without passwords

A one-time code by email. Roles: owner and observer.

HTTPS and strict policies

HTTPS only, a strict content security policy, and the page cannot be framed by another site.

Files are scanned

Every file from the form is checked by Amazon GuardDuty; only a clean one goes to work.

The agent keeps its boundaries

Says it is an AI, does not follow instructions found in documents, does not remember special categories of data. Built-in tools are off — only the ones you grant.

Monitoring

CloudWatch alarms and a morning digest on the agents and the site.

If something goes wrong

  1. We record it and assess the level — from a leak to a single failed turn.
  2. First we stop the damage: the agent, a line or the chat — with one button.
  3. We tell you about a breach of your data's security without undue delay; the deadline is set in the data processing agreement.
  4. We review it within five working days: the cause, a new rule and the check that proves it.

When you leave

  1. We hand over an export of the agent's data.
  2. We delete the environment: the machine, secrets, logs and cabinet records.
  3. Backups expire on their own — within 35 days; the encryption key is destroyed after 30 days.

Honestly, about what we do not have yet

We hold no SOC 2 or ISO 27001 certification. The privacy policy, terms and data processing agreement are with our lawyer; we do not publish text that has not been agreed. Questions left? Ask in a request — we will answer to the point.