Privacy Policy

Last updated: September 2026

This is a plain-language draft written for WebOps Agent as it launches, not a substitute for review by a lawyer in your jurisdiction — in particular, review it against GDPR/CCPA or any other regime that applies to your actual users before relying on it.

1. What we collect

DataWhere it comes from
Account info (email, hashed password, company name)Signup / team invites
Issue reports (page URL, description)The embeddable widget
Screenshots of the reported pageCaptured client-side by the widget at submission time
Page content the agent reads while investigatingThe agent's own page fetch/Playwright reproduction, at the time it processes a report
Integration credentials (WordPress, Jira, Trello, Asana, Slack)Settings — encrypted at rest, never sent to Claude
Usage/cost data (tokens, estimated spend)Generated internally per request, for the budget feature

2. How it's used, and who sees it

Issue reports, screenshots, and page content are sent to Anthropic's Claude API so the agent can classify the report and draft a response — Claude acts as a subprocessor for this purpose only, under Anthropic's own API data handling terms. Drafted content/price changes and their originating screenshot are shown to whichever of your teammates has Manager or Admin access, so they can review and approve or reject them. We don't sell your data or share it with any other third party.

3. Cookies

WebOps Agent sets exactly one cookie: a signed session cookie that keeps you logged in after you sign in. It's strictly functional — there is no third-party analytics or advertising cookie on this site.

4. Retention and deletion

Your tenant's data is kept for as long as your account exists. From Settings → Danger Zone, an Admin can export everything under your tenant as JSON at any time, or permanently delete the tenant and everything under it (requests, drafts, approvals, integrations, audit log) — this is irreversible.

5. Security

Passwords are hashed (bcrypt), integration credentials are encrypted at rest (Fernet), and every database row is scoped to your tenant — other tenants cannot see your data. Sessions are protected by a signed cookie; we support two-factor authentication (TOTP) for logging in.

6. Your rights

You can access, export, or delete your tenant's data at any time (Settings → Danger Zone) without contacting us. If you have a question we haven't answered here, reach out — see below.

7. Contact

Questions about this policy: echos.solutions@gmail.com