Privacy Policy

CostLayers is a source candidate for cost-optimization workflows. Repository review shows a local-first CLI path and hosted gateway code, but it does not establish the production deployment, retention jobs, backup behavior, cross-tenant isolation, or raw-data non-persistence. Hosted API mode should be treated as sensitive processing.

Effective date: July 10, 2026. Contact: rishabh@costlayers.com.

Assurance boundary: privacy statements below are labeled as source-observed behavior or explicit beta targets. They are not independent assurance or contractual service levels. The policy target is not to sell personal data or model access. Production evidence is still required for retention, deletion, isolation, logging, backups, TLS, and non-persistence.

Information We Process

CategoryExamplesSource-observed pathUnverified beta target
Account and accessEmail, repo-key status, plan labels, timestamps, keyed dashboard path, rate-limit counters.Hosted schemas exist. Dashboard URLs act as bearer credentials.Finite retention after key inactivity; complete age-based enforcement is required.
Login sessionsMagic-token hashes, session hashes, email, created and last-seen times.Logical 15-minute magic-link and 30-day session checks are source_observed.Physical purge, logout, and deployment tests remain partial.
Usage metadataToken/cost counters, cache and quality labels, request/response hashes, model and proof labels.Hosted meter and audit schemas exist.No more than 180 days after last activity is a target, not evidenced production enforcement.
Local repository scanSummaries, token counts, local receipts, semantic slices, reports under .agentspend/.The inspected CLI writes these locally and has explicit hosted-sync paths.No raw source or file-path upload in default reporting is a source intent pending deployment canary evidence.
API invoice modePrompts, request/response bodies, provider authorization, and provider-account traffic.These transit the hosted gateway when explicitly routed. Metering metadata and hashes may persist.Raw traffic should remain request-transient unless cache opt-in is enabled; deployed non-persistence is unverified.
Response-cache opt-inProvider response bodies for exact repeated requests under a repo key.Source includes explicit opt-in, a 30-day default, and keyed purge paths.Production isolation, purge races, backups, operator access, and expiry evidence remain required.
Security, abuse, supportIP/user-agent derivatives, logs, email, reports, screenshots, attachments.Multiple external and hosted stores may process these.90-day security-log and 24-month correspondence windows are targets; vendor and deployed retention evidence is missing.

Data Flow Summary

Intended Uses

Response Cache Target

Source review shows response caching disabled by default, explicit confirmation commands, a 30-day source default, and keyed purge paths. The production target is that disabling cache prevents new body persistence and purges controlled primary rows. Race, restart, backup, logging, and operator-access tests are still required; do not treat purge or expiry as deployment-verified.

Provider Keys and Model Providers

In API mode, you bring your provider key and remain responsible for the provider account, terms, prompts, outputs, and invoices. Authorization and traffic pass through the gateway. Use dedicated keys in environment variables or headers, never committed files. Source intends no provider-authorization persistence and attempts to keep CostLayers keys outside the repository, but production secret-canary, redirect, logging, and platform-permission evidence is still required.

Local Artifacts

Source review shows local artifacts under .agentspend/ and a CLI attempt to append an ignore block to the repo root .gitignore. This is partial, not a guarantee: keep the directory private, verify the ignore rule, and review every artifact before sharing.

Retention and Deletion Targets

Sharing and Subprocessors

The policy target is not to sell personal data. The categories below are non-authoritative planning categories, not a verified list of appointed legal entities. Named vendors, regions, contracts, transfer terms, retention, and effective dates are still required before production enterprise use.

Unverified categoryExpected purposePossible data
Hosting, database, storage, logs, DNS, and TLSPublic site, dashboard, gateway, account rows, deletion path, operations.Account/access data, usage metadata, security logs, and transient API traffic.
Package distributionDistribute the CLI candidate and later releases.Registry and download metadata under provider terms.
Support email and calendarSupport, security reports, scheduling, deletion requests.Messages, attachments, screenshots, logs, and scheduling metadata supplied by you.
Customer-selected model providerProcess requests under the customer's provider account.Prompts, responses, authorization, account traffic, and provider logs.

Security Targets

Source-observed mechanisms include keyed paths, rate-limit code, local-first commands, hash-based receipts, and cache opt-in controls. HTTPS/HSTS, security headers, cross-tenant isolation, encryption, backups, operator access, and production retention are not deployment-verified in this repository. See /security.html, public artifacts, and the unsigned DPA draft.

Children and Sensitive Workloads

CostLayers is intended for professional developer workflows and is not directed to children. Do not use the beta for regulated, secret-heavy, export-controlled, medical, financial, or production-critical workloads unless your organization has reviewed and approved the risk.

Changes

We may update this policy as the product matures. Material changes will be reflected by updating the effective date and, where appropriate, by notifying active users through the product or email.