Pre-launch counsel-review draft
Privacy Policy
This pre-launch draft describes the data flows implemented in the application and identifies production, retention, and legal decisions that remain unresolved.
Professional legal review required before publication
This draft is not effective, has not been approved by counsel, and is not legal advice. Bracketed decisions and review markers must be resolved before publication.
- Effective date
- To be set after professional legal approval
- Last revised
- To be set after professional legal approval
- Draft record
- M27 counsel-review draft 1, prepared August 27, 2026
Draft boundary
This draft is intended to describe NoirGen Agent QA, a service of NoirGen LLC. It is not effective, has not been approved by counsel, and must not be treated as a representation that the production service or every provider is live.
The application contains implemented data-handling controls, but production infrastructure, provider activation, secret injection, deployment, and recovery verification remain gated through M28. The final policy must be checked against the configuration actually deployed at launch.
Information the service may handle
Across the service and the providers a customer enables, data handling may include the following categories. Not every category is stored in the application database, and the exact production provider set remains subject to M28 verification:
- Account, profile, authentication, session, organization, and membership information
- Agent endpoint and connector configuration, including encrypted credential-header values
- Knowledge sources, uploaded text, test prompts, cases, assertions, rubrics, and reference facts
- Customer-agent responses, execution attempts, evaluation evidence, scores, baselines, and regression comparisons
- Schedules, alerts, alert recipients, usage records, plan entitlements, and billing-state metadata
- Deletion-request, activation-event, analytics-delivery, audit, support, security, and operational records
Authentication records may include a name, email address, profile image, provider account identifier, OAuth tokens, verification-token records, and an opaque database-session token. Connector credential-header values are stored in a dedicated encrypted envelope; that field-level protection does not mean every other database field is encrypted by the application itself.
If production edge and hosting services are activated, those services may also process the network and request metadata necessary to route, secure, operate, and diagnose requests. The exact production logging fields and their retention must be confirmed from the deployed configuration before this draft becomes effective.
How information is used
The application is designed to use information to:
- authenticate users, maintain sessions, and authorize organization access;
- store agent, knowledge, test, scheduling, alert, usage, and account settings;
- send configured prompts to customer-controlled agent endpoints and retain selected responses as tenant-private test evidence;
- run deterministic and model-assisted evaluation, calculate health signals, and compare results with selected baselines;
- deliver transactional authentication and alert email;
- administer fixed-limit plans and reconcile Stripe-hosted subscription state;
- prevent abuse, investigate failures, protect the service, and operate privacy-filtered observability and product-event pipelines; and
- respond to support, security, billing, privacy, and deletion communications.
Model-assisted evaluations are probabilistic. See the separate AI evaluation limitations page before relying on a result.
Providers and other recipients
The planned provider set includes Google Cloud, Cloudflare, OpenAI, Stripe, Resend, PostHog, Sentry, and Zoho Mail. Their purposes and the categories they may receive are listed on the Subprocessors page. Live use, legal entity details, processing regions, and provider-specific retention must be verified during the M28 production handoff.
OpenAI requests for enabled draft-generation or evaluation modes can include selected knowledge material, test definitions, rubrics, reference facts, and customer-agent responses. The application sets store: false and excludes connector credentials. That request setting is not a promise of zero provider retention and does not establish a data-residency or zero-data-retention program.
Stripe-hosted surfaces handle payment and billing details. The application stores bounded customer, subscription, price, invoice-state, and webhook-receipt metadata, but does not store payment-card details or raw Stripe webhook bodies in its product tables.
Other customer-selected or user-selected recipients include:
- Google OAuth: Optional third-party sign-in. The user's relationship with Google is also governed by Google's terms and privacy notice. Profile and authentication information selected by the user and OAuth account/session tokens stored by the application.
- Customer-configured agent endpoint: A customer-directed destination used to execute tests. It is selected and controlled by the customer and is not represented as a NoirGen subprocessor. Test prompts, configured authorization headers, request templates, and the data returned by the endpoint.
A customer-configured agent endpoint is a customer-directed destination. Customers are responsible for the endpoint, its authorization, and whether the test data sent to it is appropriate.
Cookies and local browser storage
Auth.js uses an HttpOnly cookie containing an opaque session token. The corresponding user and database session remain server-side. The configured database-session maximum is 30 days, with periodic session updates. Passwordless email links are configured with a 15-minute maximum age.
The site's theme control uses local browser storage under the default key theme to remember a light, dark, or system preference.
Product analytics is implemented as a server-side PostHog delivery path; the browser is not given a PostHog project key and does not perform product-analytics capture. Sentry is configured to disable cookie collection and default personal-data collection. These application settings do not control cookies or storage used on Google, Stripe, Cloudflare, or other provider-hosted surfaces.
Retention is not yet a public promise
The repository does not define a complete automatic retention or purge schedule for customer accounts, tenant content, test history, evaluation evidence, alerts, analytics receipts, support mail, or operational logs. Those records therefore must not be described here as expiring after an invented number of days.
Stripe replay protection intentionally permits a bounded processed-event receipt to outlive a later organization deletion after its organization reference is removed. The final retention policy must address that audit and replay record, together with legal holds, billing evidence, backups, and deletion recovery.
The reviewed infrastructure design includes database backups and private object-storage versioning and soft delete. The application now includes a fail-closed private Google Cloud Storage adapter, but those settings and the adapter have not been verified as live customer-data behavior. M28 deployment evidence and an approved retention schedule are required before any duration is represented publicly.
Account and organization deletion requests
An authenticated user can open Dashboard → Settings → Data deletion requests. An account request requires the current account email. An organization request requires the exact current organization name and current owner authorization. A pending request can be cancelled from the same surface.
These controls create or cancel a reviewable request receipt only. They do not immediately delete an account, organization, membership, session, subscription, usage record, test evidence, backup, or provider record; they do not cancel Stripe billing or create a refund; and they do not establish a completion deadline.
A person who cannot use the authenticated path may contact [email protected]. Do not include passwords, API keys, endpoint credentials, or payment-card details in the message. Mailbox monitoring, identity reverification, fulfillment steps, response targets, and permitted retention exceptions must be approved and operationally verified before launch.
See Data deletion for the current step-by-step request path and its limitations.
Privacy rights and unresolved legal decisions
Applicable privacy rights depend on the user's location, the customer's role, the data, and the law that applies. This draft does not yet make claims about a particular legal basis, controller/processor allocation, sale or sharing, targeted advertising, international transfers, residency, minor users, or jurisdiction-specific request deadlines.
Contact
Privacy and deletion questions may be sent to [email protected]. This address is the designated M27 contact, but mailbox activation, monitoring, retention, escalation ownership, and response targets remain launch prerequisites rather than promises in this draft.