Legal / Privacy policy
Privacy policy
1. Who we are
BehalfID ("we", "us", "our") operates behalfid.com and provides permission-verification infrastructure for AI agents. Questions about this policy may be directed to legal@behalfid.com.
2. Data we collect
Account data
When you create a developer account we collect your email address, your date of birth, and a hashed password. We do not store your plaintext password at any point. Your date of birth is used only to confirm you meet our minimum age requirement and is not displayed in account setup or account settings.
Account setup and profile data
When you complete account setup we collect profile and workspace information, including:
- your first and last name;
- job title;
- an optional phone number — if you choose to provide one, we may use it only for account recovery, urgent security alerts, or support. We do not use it for SMS verification, phone-based two-factor authentication, or marketing outreach unless we tell you otherwise in the product;
- whether you are setting up for yourself or a business/team;
- company or organization name and workspace name;
- website and team size; and
- onboarding preferences: the AI agent tools you use, the areas you want the platform to control, your primary goal with the platform, and your first setup goal.
This information is stored on your user profile and workspace and is used to operate your account, configure your workspace, and tailor onboarding guidance.
Agent and permission data
Agent names, permission configurations, scope definitions, and expiry dates you create inside the dashboard are stored and associated with your account. API keys are stored only as SHA-256 hashes and are shown to you once at creation.
Verification request data
When your integration calls POST /api/verify, we log the agent ID, action, vendor or resource, optional amount, decision outcome, risk level, and a stable request ID. We do not log your API key; only its hash is ever stored. Raw metadata fields are logged only when BEHALFID_LOG_METADATA is enabled. Verification logs are accessible only to the account that owns the agent.
Technical and usage data
We collect IP addresses for rate-limiting and abuse prevention. These are not linked to user accounts for analytics or profiling purposes. Cookie-consent choices are also logged server-side (state only, no personal data) for product-integrity purposes.
Billing data
When you subscribe to a paid plan, billing is processed by Stripe. BehalfID stores your Stripe customer ID and subscription status but does not store your payment card details — those are held exclusively by Stripe. Billing data is used only to enforce plan limits and process your subscription.
3. Cookies and local storage
Authentication cookie
A session cookie (bhf_dev_session) is set when you log in to the developer dashboard. It is HTTP-only, SameSite=Lax, scoped to this domain, and uses a 1-hour inactivity window with a 14-day absolute lifetime. This cookie is strictly necessary — the dashboard cannot function without it.
Preferences
Theme preference (light / dark) is stored in localStorage and never transmitted to our servers.
Cookie consent
Your cookie-consent choice is stored in localStorage under the key behalf_cookie_consent. A minimal log entry (consent state only — no personal data) is also written server-side for product-integrity purposes.
No advertising cookies and no cross-site tracking are used. If you choose “Accept all”, our analytics provider (HeyCatch) sets a first-party analytics cookie and stores a random device identifier in localStorage and sessionStorage to measure product usage. Choosing “Essential only” means the analytics SDK is never initialised and none of that storage is written. No advertising networks, tracking pixels, or fingerprinting scripts are loaded.
4. How we use your data
- To authenticate and operate your developer account.
- To configure your workspace and tailor onboarding based on the preferences you provide during account setup.
- To execute, log, and deliver webhook events for verification requests.
- To enforce rate limits and detect abuse.
- To process billing and enforce plan limits via Stripe.
- To respond to support or security enquiries.
We do not sell your personal data. We do not use your verification request data to train machine-learning models.
5. Analytics
BehalfID uses HeyCatch for product analytics, and only after you accept analytics storage. It records pageviews, clicks, and in-app navigation, plus business events such as subscription changes sent from our servers. Session recording, surveys, and feature-flag requests are disabled in our configuration. We do not use advertising networks or cross-site tracking. Analytics never starts before consent, and choosing “Essential only” keeps it off entirely.
6. Data retention
- Verification logs — retained by plan (Free 7 / Team 30 / Pro 90 / Business 180 / Enterprise up to 365 days), then physically purged after a grace period.
- Webhook delivery records — retained for 30 days.
- Account data — retained for the lifetime of the account. Deleted within 30 days of a verified deletion request.
- Billing data — retained for as long as required by applicable tax and accounting law (typically 7 years), even after account deletion.
- IP addresses used for rate limiting — stored in memory only; not persisted to disk.
7. Third-party processors
| Processor | Purpose | Data shared |
|---|---|---|
| Supabase (Postgres) | Database hosting | All stored account, agent, and log data |
| Vercel | Hosting and edge delivery | Request metadata (IP, path) for routing and abuse prevention |
| Stripe | Payment processing and subscription management | Email address, billing name, payment card details (held by Stripe only), subscription events |
| HeyCatch | Product analytics (only after analytics consent) | Pageviews, clicks, in-app navigation, a random device identifier, and — once signed in — your user id, email, name, and plan; plus subscription events sent from our servers |
8. Your rights
Depending on your jurisdiction you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing.
To exercise any of these rights, email legal@behalfid.com. We will respond within 30 days. Verification logs can also be deleted immediately from the dashboard logs page.
9. Security
All data is transmitted over TLS. API keys are stored as SHA-256 hashes. Developer passwords are hashed with scrypt. Sessions use HTTP-only cookies. See our security page for a detailed breakdown of the enforcement model, secrets handling, and known limitations.
10. Changes to this policy
We may update this policy to reflect product changes or legal requirements. The effective date at the top of this page is updated whenever a material change is made. Continued use of BehalfID after a change constitutes acceptance of the revised policy.
11. Contact
Data controller: BehalfID
Email: legal@behalfid.com
See also: Terms of Service · Security and Trust