Scope
This policy applies to Agent Experience Monitor's website, readiness audits, authenticated workspace, monitoring service, and related transactional emails. The service inspects public website content only; it does not sign in to a monitored site, submit forms, or complete purchases.
Information we process
- Account information, including your first name, last name, email address, authentication metadata, workspace role and invitation status.
- Website URLs, public page metadata, bounded visible-text evidence, audit results, findings, scores, and monitoring configuration.
- Subscription identifiers, status, and billing-period dates received from Paddle. We do not receive or store full payment-card details.
- Bounded operational events used to diagnose failures and protect the service.
- With your permission on the production website, Google Ads click attribution, browser or device measurement data, and a completed readiness-audit conversion event. We do not send your account email to Google Ads, and enhanced conversions are disabled.
- With the same permission, bounded first-touch campaign fields such as source, medium, campaign, landing path, and external referrer host may be attached to a newly created workspace. We do not store Google or LinkedIn click identifiers in the workspace record.
- A one-way network identifier used for free-audit abuse prevention when that protection is enabled. Raw visitor IP addresses are not stored in the application database for this purpose.
How information is used
We use this information to deliver audits, verify site ownership, schedule monitoring, manage workspace membership and invitations, measure regressions, send requested reports and alerts, administer subscriptions, secure the service, prevent abuse, and investigate operational failures. We do not sell personal information. Consent-based advertising measurement is used only to understand whether an advertisement leads to workspace activation or a completed readiness audit and to improve campaign spend.
Service providers
We use the following providers to operate the service. They process information for the stated purpose under their own contractual and security commitments.
- Cloudflare: Application hosting, network delivery, DNS, and security controls.
- Supabase: Authentication and PostgreSQL application data storage.
- Trigger.dev: Queued and scheduled audit processing.
- OpenAI: Optional bounded analysis of sanitized evidence; raw HTML is not sent and response storage is disabled.
- Resend: Transactional report, regression, and operational email delivery.
- Paddle: Merchant-of-record billing, payment processing, taxes, and subscription management.
- Google Ads: Consent-based advertising attribution and completed readiness-audit conversion measurement on the production website.
Retention and deletion
Product evidence is kept for defined periods and then removed from normal application access. Full details, including the treatment of readiness audits, monitoring history, site deletion, and billing records, are in the Data Retention Policy.
Your choices and rights
You can remove a monitored site from your workspace, manage renewal through Paddle, or ask to access, correct, export, or delete personal information associated with your account. Some subscription, transaction, security, or aggregate usage records may be retained where required for legal, accounting, fraud-prevention, or operational purposes.
Google Ads measurement is off until you accept it. You can change or withdraw that choice below at any time. Your choice is stored in this browser.
Security and international processing
We use environment isolation, access controls, encrypted transport, bounded evidence, and server-only secrets to reduce risk. No internet service can guarantee absolute security. Our providers may process information in countries other than yours, subject to their applicable safeguards.
Contact
Send privacy or data-rights requests to privacy@agentwebtest.com. We may need to verify account or domain ownership before completing a request.