Skip to main content
Behalf/ID
ProductAdaptive engineDevelopersPricingSecurityStatus
Sign inStart building

Legal / Privacy policy

Privacy policy

Effective 2 July 2026

On this page

  1. 1. Who we are
  2. 2. Data we collect
  3. 3. Cookies and local storage
  4. 4. How we use your data
  5. 5. Analytics
  6. 6. Data retention
  7. 7. Third-party processors
  8. 8. Your rights
  9. 9. Security
  10. 10. Changes to this policy
  11. 11. Contact

1. Who we are

BehalfID ("we", "us", "our") operates behalfid.com and provides permission-verification infrastructure for AI agents. Questions about this policy may be directed to legal@behalfid.com.

2. Data we collect

Account data

When you create a developer account we collect your email address, your date of birth, and a hashed password. We do not store your plaintext password at any point. Your date of birth is used only to confirm you meet our minimum age requirement and is not displayed in account setup or account settings.

Account setup and profile data

When you complete account setup we collect profile and workspace information, including:

  • your first and last name;
  • job title;
  • an optional phone number — if you choose to provide one, we may use it only for account recovery, urgent security alerts, or support. We do not use it for SMS verification, phone-based two-factor authentication, or marketing outreach unless we tell you otherwise in the product;
  • whether you are setting up for yourself or a business/team;
  • company or organization name and workspace name;
  • website and team size; and
  • onboarding preferences: the AI agent tools you use, the areas you want the platform to control, your primary goal with the platform, and your first setup goal.

This information is stored on your user profile and workspace and is used to operate your account, configure your workspace, and tailor onboarding guidance.

Agent and permission data

Agent names, permission configurations, scope definitions, and expiry dates you create inside the dashboard are stored and associated with your account. API keys are stored only as SHA-256 hashes and are shown to you once at creation.

Verification request data

When your integration calls POST /api/verify, we log the agent ID, action, vendor or resource, optional amount, decision outcome, risk level, and a stable request ID. We do not log your API key; only its hash is ever stored. Raw metadata fields are logged only when BEHALFID_LOG_METADATA is enabled. Verification logs are accessible only to the account that owns the agent.

Technical and usage data

We collect IP addresses for rate-limiting and abuse prevention. These are not linked to user accounts for analytics or profiling purposes. Cookie-consent choices are also logged server-side (state only, no personal data) for product-integrity purposes.

Billing data

When you subscribe to a paid plan, billing is processed by Stripe. BehalfID stores your Stripe customer ID and subscription status but does not store your payment card details — those are held exclusively by Stripe. Billing data is used only to enforce plan limits and process your subscription.

3. Cookies and local storage

Authentication cookie

A session cookie (bhf_dev_session) is set when you log in to the developer dashboard. It is HTTP-only, SameSite=Lax, scoped to this domain, and uses a 1-hour inactivity window with a 14-day absolute lifetime. This cookie is strictly necessary — the dashboard cannot function without it.

Preferences

Theme preference (light / dark) is stored in localStorage and never transmitted to our servers.

Cookie consent

Your cookie-consent choice is stored in localStorage under the key behalf_cookie_consent. A minimal log entry (consent state only — no personal data) is also written server-side for product-integrity purposes.

No advertising cookies and no cross-site tracking are used. If you choose “Accept all”, our analytics provider (HeyCatch) sets a first-party analytics cookie and stores a random device identifier in localStorage and sessionStorage to measure product usage. Choosing “Essential only” means the analytics SDK is never initialised and none of that storage is written. No advertising networks, tracking pixels, or fingerprinting scripts are loaded.

4. How we use your data

  • To authenticate and operate your developer account.
  • To configure your workspace and tailor onboarding based on the preferences you provide during account setup.
  • To execute, log, and deliver webhook events for verification requests.
  • To enforce rate limits and detect abuse.
  • To process billing and enforce plan limits via Stripe.
  • To respond to support or security enquiries.

We do not sell your personal data. We do not use your verification request data to train machine-learning models.

5. Analytics

BehalfID uses HeyCatch for product analytics, and only after you accept analytics storage. It records pageviews, clicks, and in-app navigation, plus business events such as subscription changes sent from our servers. Session recording, surveys, and feature-flag requests are disabled in our configuration. We do not use advertising networks or cross-site tracking. Analytics never starts before consent, and choosing “Essential only” keeps it off entirely.

6. Data retention

  • Verification logs — retained by plan (Free 7 / Team 30 / Pro 90 / Business 180 / Enterprise up to 365 days), then physically purged after a grace period.
  • Webhook delivery records — retained for 30 days.
  • Account data — retained for the lifetime of the account. Deleted within 30 days of a verified deletion request.
  • Billing data — retained for as long as required by applicable tax and accounting law (typically 7 years), even after account deletion.
  • IP addresses used for rate limiting — stored in memory only; not persisted to disk.

7. Third-party processors

ProcessorPurposeData shared
Supabase (Postgres)Database hostingAll stored account, agent, and log data
VercelHosting and edge deliveryRequest metadata (IP, path) for routing and abuse prevention
StripePayment processing and subscription managementEmail address, billing name, payment card details (held by Stripe only), subscription events
HeyCatchProduct analytics (only after analytics consent)Pageviews, clicks, in-app navigation, a random device identifier, and — once signed in — your user id, email, name, and plan; plus subscription events sent from our servers

8. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing.

To exercise any of these rights, email legal@behalfid.com. We will respond within 30 days. Verification logs can also be deleted immediately from the dashboard logs page.

9. Security

All data is transmitted over TLS. API keys are stored as SHA-256 hashes. Developer passwords are hashed with scrypt. Sessions use HTTP-only cookies. See our security page for a detailed breakdown of the enforcement model, secrets handling, and known limitations.

10. Changes to this policy

We may update this policy to reflect product changes or legal requirements. The effective date at the top of this page is updated whenever a material change is made. Continued use of BehalfID after a change constitutes acceptance of the revised policy.

11. Contact

Data controller: BehalfID
Email: legal@behalfid.com

See also: Terms of Service · Security and Trust

Behalf/ID

Identity, permissions and approval gates for AI agents.

Product

  • Overview
  • Adaptive engine
  • Pricing

Developers

  • Quickstart
  • API
  • SDK
  • Status

Company

  • About
  • Blog
  • Contact
  • Design partners

Compare

  • BehalfID vs PolicyLayer
  • BehalfID vs Cerbos
  • Best AI agent authorization

Trust

  • Security
  • Compliance
  • Privacy
  • Terms
  • Legal
© 2026 BehalfIDsecurity@behalfid.com