Privacy Policy
Version 1.0 · Effective August 1, 2026
This policy describes what Agent War Table stores, who processes it, and how to delete it. It describes actual system behavior, not intentions.
1. What we store
- Account data — email, name, brokerage, market area, phone, website, and brand tone, as you provide them.
- Mission data — the briefs you submit, every stage output the experts generate, and the compiled deliverables.
- Usage data — per-stage token counts, durations, and mission counts. This drives your usage meter and our cost accounting.
- Security data — an audit log of logins, deploys, exports, tier changes, rate-limit hits, and access-control violations, with IP address and user agent.
- Frontend telemetry — page performance metrics and client-side error reports, tied to a hashed session identifier rather than to your account.
- Billing data — subscription tier, status, and period dates. We never see or store your card number; Stripe holds it.
2. What we do not store
We do not store consumer personal information, and our Terms prohibit you from pasting it into briefs. Briefs should describe audiences at neighborhood or segment level, never named individuals.
3. Processors
- Anthropic — receives your brief and prior stage output to generate each stage. Model generation only.
- Supabase — database and authentication. All account, mission, and usage data is stored here.
- Vercel — application hosting and request logs.
- Stripe — payment processing. Card data goes directly to Stripe and never touches our servers.
- Sentry — error monitoring. Exception reports are scrubbed so that mission content is not included in error events.
4. Who can see your missions
Access control is enforced at the database level by row-level security, not by application code alone — a user cannot read another user's missions even if an application bug tried to let them.
Support and operations staff cannot read your mission content. Our internal admin tools and operations interface are deliberately built to expose metadata — counts, durations, token spend, status — and never the body of a strategy document. This is a structural limit, not a policy promise.
5. Deleting your data
Delete any mission from your vault and its stages and deliverables are removed with it by database cascade. Ask us to delete your account and we remove your profile, missions, stages, deliverables, and usage records.
Two things survive deletion, deliberately: security audit-log entries, which exist to detect abuse and would be worthless if deletable; and billing records that tax law requires us to retain. Backups age out on their retention schedule rather than being edited in place.
6. Cookies
We use authentication cookies to keep you signed in. They are httpOnly, secure, and same-site. We do not use advertising or cross-site tracking cookies.
7. Security
Encryption in transit and at rest; row-level security on every table; secrets in environment variables only; audit logging of security-relevant events; automated anomaly detection on failed logins, ownership violations, and abnormal usage. No system is perfectly secure, and we will not claim otherwise.
8. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export your data, and to object to processing. Email support@agentwartable.com and we will respond within 30 days.
9. Changes
Material changes will be announced in-product before taking effect. The version and effective date at the top of this page always reflect what is currently live.
Pre-launch draft. This document has not yet been reviewed by an attorney. It states the platform's actual practices accurately, but it must be reviewed by counsel licensed in the operating jurisdiction before paid launch — doc 05 §4 lists these pages as launch blockers.