Privacy Policy
PassportForAgents is a free, open beta. This policy describes our actual data practices in plain terms; the hosted service is provided as-is (see the Terms). We will expand it before any future commercial offering.
Last updated: 2026-06-07
What we collect
- Account information you provide via our authentication provider (your email address, and any name you supply).
- API keys we issue to you (stored hashed, never in plaintext).
- Agent and domain data you submit for verification (domains, public keys, capabilities, passport documents).
- Basic operational logs (timestamps, request metadata) needed to run and secure the service.
What we do not do
We do not sell your data, run third-party advertising, or load third-party tracking or analytics. Authentication is the only embedded third-party dependency.
Processors & where data lives
We use a small set of infrastructure providers acting as processors on our behalf, each handling data only to run the service:
- Clerk — authentication (your email and session).
- Supabase — managed Postgres (accounts, hashed API keys, verification records).
- Vercel — hosting and CDN.
These providers operate in the United States, so your data may be processed there. For EU/UK users, our lawful basis is the legitimate interest in providing the service you signed up for (and consent for any optional features). We retain account data only while your account is active, plus a short window for security logs; public registry entries you publish stay public until you remove them. Request access or deletion any time via the contact below.
Cookies
We use essential cookies set by our authentication provider to keep you signed in. We do not use advertising or cross-site tracking cookies.
Your rights
You may request access to, correction of, or deletion of your account data by contacting us. Verification records you publish to the public registry are, by design, public.