Privacy policy
AgentMeter is built so your code never leaves your machine. This page explains what data does reach our server, what we use it for and how to ask us to delete it.
Who is responsible
AgentMeter is a service operated from Bolivia ("AgentMeter", "we"). For any privacy matter, email hola@agentmeter.si.
What we never receive
The AgentMeter CLI builds reports on your machine. We never receive your source code, your files, the content of your conversations with AI agents or your private keys. Reading agent sessions, commits and tests happens only on your computer.
What data we receive and when
| When | What data |
|---|---|
| When you create your account | Your name or your agency's, email, your public key and its fingerprint, referral code and, if you were invited, who invited you. We store your API key only as a hash. |
| When you timestamp a report | The report's SHA-256 fingerprint, your signature over it and the date. We don't receive the report. |
| When you publish a portal | The full report you choose to publish, with whatever it contains: client name, period, commits, figures and invoice details. We keep it until you delete it. |
| When your client uses the portal | The name, email, decision and comment of whoever approves; and in payment notices, the name, email, method, reference and amount they enter. |
| In teams (Agency and Enterprise) | A numeric summary of each timestamped report: project, period, commits, lines, tests, minutes, sessions, AI cost, agents and models. The team owner can see it. |
| Profile and domain | The public name, headline and domains you decide to publish. |
| When you request a demo | Email, name or company and your answers to the form. |
| When you pay for a plan | Polar processes the payment. We never see your card: we receive the customer ID, the product and the subscription status. |
| When you use the website or the API | Your IP address, temporarily, to limit abuse; and the technical logs produced by our infrastructure provider. |
The public timestamp log
Each timestamp is written to a chained public log so anyone can check when a report existed. It contains the report fingerprint, your issuer fingerprint, your signature, the date and the server signature; never the report content. By design, entries in this log cannot be deleted: deleting one would break verification of every later report. If you delete your account, your name and email are erased, but fingerprints already timestamped remain.
What we use data for
- Providing the service: timestamping, publishing portals, showing your profile and your team dashboard.
- Charging for your plan and applying referral rewards.
- Protecting the service against abuse and fraud.
- Answering your questions and letting you know about important changes to the service or to these documents.
We don't sell your data, we don't use it for advertising and we don't use it to train artificial intelligence models.
Who we share it with
Only with the providers we need to operate, who process data on our behalf:
- Cloudflare: hosts the website, the API and the database, and protects the traffic.
- Polar: processes payments as merchant of record and issues receipts.
- Google Fonts: serves the website fonts, so your browser connects to Google when you open it.
- Our email provider, to answer the messages you send us.
These providers may process data outside Bolivia. We may also disclose data if a competent authority requires it by law.
Cookies and storage in your browser
We don't use advertising or third-party analytics cookies. The website stores in your browser the invite code you arrived with, to apply it when you sign up, and the team dashboard uses a secure session cookie that expires after 8 hours.
How long we keep it
- Account data, while your account is active.
- Portals, until you delete them or delete your account.
- IP addresses used to limit abuse, only for the control window, which lasts minutes or hours.
- Public log entries, permanently, as explained above.
Your rights
You can ask us to access your data, correct it, receive a copy or delete it, and object to a specific use. Email hola@agentmeter.si from your account email and include your issuer fingerprint; we reply within 15 business days. If your client approved one of your portals, they can also ask us to delete their name and email.
How we protect it
All traffic is encrypted over https. Your private key never leaves your machine. We store API keys only as hashes, sign every timestamp with the server key, rate-limit requests per IP and show published reports sandboxed, without running scripts. No system is invulnerable; if we detect an incident affecting your data, we will notify you without delay.
Minors
AgentMeter is a professional tool for people 18 and older. We don't knowingly collect data from minors.
Changes to this policy
If we change this policy, we will update the date above. If the change is significant, we will email you before it takes effect.