actuity

Privacy Policy

How Actuity handles information across public scans, approved agent tests, scheduled monitoring, and billing.

Updated September 28, 2026Version 2.2~6 min readEnglish

01Information you provide

We collect account details such as your name and email; product names and URLs; site authorization attestations and verification records; support messages; and report feedback. When you define a customer job, we also collect the persona, business need, desired outcome, approved public scope, expected result, and optional safe test inputs. Do not provide passwords, payment-card data, secrets, or sensitive personal data as test inputs.

Dodo Payments hosts checkout and payment details. We receive the customer, subscription, plan, billing-period, payment-status, tax, cancellation, and refund information needed to provide the Service; we do not receive or store full card numbers.

02Information collected during scans and agent tests

For a scan, we fetch public pages and may record submitted and resolved URLs, public HTML and rendered content, robots and sitemap responses, public integration descriptions, HTTP status and timing data, and derived findings. For an approved agent test, structured and visual profiles perform the bounded public job you approved. We collect request metadata, allowlisted action events, redacted page observations, screenshots and browser traces that pass our evidence policy, evaluator results, and the resulting Product/QA report.

We minimize evidence before storage. We do not intentionally persist passwords, cookies, authorization headers, full private request or response bodies, or hidden model reasoning. Automated redaction can make mistakes, so each report shows its evidence deadline and you can request early deletion by emailing actuitytech@gmail.com.

03Usage, analytics, and reliability data

Standard service logs may include IP address, browser or device details, timestamps, request identifiers, route, status, and security signals. Sentry may receive technical error context when configured. PostHog product analytics is optional and runs only after your consent. Its bounded events exclude customer-job text, report content, evidence, and URL query strings. You may decline analytics without losing scanning or report access.

04How we use information

We use information to authenticate users; verify authority; run, evaluate, and explain scans and agent tests; deliver reports and confirmed monitoring changes; enforce plan limits; process billing; provide support; measure reliability and costs; prevent abuse; secure the Service; and comply with legal obligations. We do not sell personal information or use customer report content for advertising.

05Service providers and integrations

We disclose only the information needed to providers supporting hosting, databases, private evidence storage, model and isolated-browser execution, email, security, and support. Product-specific recipients can include Dodo Payments for payment processing, OpenAI and TypeSafe for the models that plan and check agent runs (they receive the task and text read from the public pages being tested), PostHog for optional consent-based analytics, Sentry for error monitoring, and our email provider. Provider processing may occur in other countries.

Issue-tracker and chat integrations such as Linear, Jira, and Slack are coming soon and are not included in current plans, so no report data is sent to them today. We will update this policy before any such integration becomes available.

06Retention and deletion

Raw agent test evidence, including retained screenshots and traces, is kept for no more than 30 days; each report shows its deadline. To have that evidence deleted early, email actuitytech@gmail.com from the workspace account email with the run you want removed. Deletion removes raw objects while preserving a minimal deletion audit record and the outcome report. Short-lived raw Dodo webhook payloads are normally deleted after 30 days.

Derived reports, findings, account records, usage ledgers, billing decisions, and security audit records are retained while the account is active and as reasonably needed for service, fraud prevention, disputes, accounting, and legal obligations. Cancelling does not delete the workspace.

You can delete your account yourself in Settings. That deletes the workspace and everything in it, including reports, findings, usage records, and retained evidence, and then your sign-in. Deletion is refused while a paid plan is still active, so cancel it in Billing first. We keep only a minimal record that an account was deleted and when, without your name or email. Dodo Payments keeps its own payment records as the payment processor.

07Your choices and rights

You can decline optional analytics, request deletion of retained run evidence, cancel billing without deleting existing reports, and delete your whole account yourself in Settings. Depending on your location, you may also request access, correction, export, restriction, objection, or deletion by emailing actuitytech@gmail.com.

08Security

We use tenant-scoped access controls, encryption in transit, private evidence storage, short-lived evidence access, redaction, action and network boundaries, audit records, and operational safeguards. No transmission or storage method is completely secure.

09Changes and contact

Actuity is run by its founders, Aman Jha (@WhyParabola) and Priyanshu Tiwari (@priyanshudotsol), based in New Delhi, India. It is not yet an incorporated company, so Aman Jha and Priyanshu Tiwari are responsible for your data under this policy. We may update this policy and will post material changes here with a new effective date. Questions or privacy requests can be sent to actuitytech@gmail.com.

A question about your data?

We’ll explain what we collect and why in plain English.