Privacy
What we collect and hold. Your email address, for sign-in and receipts. If you save a run on a paid plan: the answer you pasted, the scorer's result, the identity of the run as you entered it (agent name, model or version, configuration label, run date, who ran it), your notes and severity per step, your acceptance criteria, and the transcript only if you ticked that it contains no client data. We never ask for credentials, API keys, a connection to your agent or real records; the scenario inputs are invented. Page visits and button presses are counted with an anonymous browser cookie, never with what you pasted.
How we collect it and why. From you, when you sign in, save or download. What you paste is scored in your browser and is not sent to us unless you save the run. We use saved data only to show it back to you, to sign you in and to bill a plan. We do not sell data, run advertising, or share your runs with anyone.
Where it is kept and who can see it. Saved runs and your account are stored in a Supabase database in Sydney, Australia (AWS ap-southeast-2), encrypted at rest and reached only over encrypted connections. Some processors are outside Australia, so personal information is likely to be disclosed overseas: Stripe (payments; processed in the United States and other countries where Stripe operates), SendGrid (sign-in links and receipts; the United States) and Cloudflare (serves the pages; data centres in many countries including Australia and the United States). Those four are the only services that handle your data for us. People you invite to your account see what their role allows; on Underwriter, a person invited to one workspace sees only that workspace. We open a saved record only to answer a request from you.
Keeping and deleting saved runs. A saved run is kept until you delete it or close your account. Deleting a run removes its answer, result, notes and transcript at once, and the API answers 404 for it after. Before deleting a workspace or closing the account, export it as JSON from your saved runs page. Closing your account deletes everything saved under it.
Seeing and correcting what we hold. Everything saved under your account is on your saved runs and account page; correct or delete it there. For anything else, write to support@theartofservice.com.
Complaints. Write to support@theartofservice.com with what happened. We acknowledge a complaint within 5 business days and answer within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
This policy is free to read here; for a copy in another form, write to support@theartofservice.com.
AI Agent Compliance Workflow Tester is operated by The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001, Australia.
Sign-in security, the audit log and deleting your data. Two-step sign-in is optional unless the owner of a Team or Underwriter account requires it for everyone on it; the authenticator key is stored encrypted and recovery codes only as one-way hashes. The account keeps an audit log of sign-ins and sign-outs, two-step sign-in changes and refused codes, opening, saving, deleting and exporting saved work, teammate invitations and role changes, security settings and plan changes. Each entry holds who, when, the kind of action and which saved record, with a one-way hash of the network address and the browser family; it never holds what you pasted or saved. On Team and Underwriter the owner and editors of the account can read and export it; on Solo you can read your own. Entries are deleted automatically after two years. You can delete a saved record, or your whole account and everything saved under it, yourself from the account page; deleting an account cancels an active subscription, and Stripe keeps its own record of past payments.