Privacy Policy
CostLayers is a source candidate for cost-optimization workflows. Repository review shows a local-first CLI path and hosted gateway code, but it does not establish the production deployment, retention jobs, backup behavior, cross-tenant isolation, or raw-data non-persistence. Hosted API mode should be treated as sensitive processing.
Effective date: July 10, 2026. Contact: rishabh@costlayers.com.
Assurance boundary: privacy statements below are labeled as source-observed behavior or explicit beta targets. They are not independent assurance or contractual service levels. The policy target is not to sell personal data or model access. Production evidence is still required for retention, deletion, isolation, logging, backups, TLS, and non-persistence.
Information We Process
| Category | Examples | Source-observed path | Unverified beta target |
|---|---|---|---|
| Account and access | Email, repo-key status, plan labels, timestamps, keyed dashboard path, rate-limit counters. | Hosted schemas exist. Dashboard URLs act as bearer credentials. | Finite retention after key inactivity; complete age-based enforcement is required. |
| Login sessions | Magic-token hashes, session hashes, email, created and last-seen times. | Logical 15-minute magic-link and 30-day session checks are source_observed. | Physical purge, logout, and deployment tests remain partial. |
| Usage metadata | Token/cost counters, cache and quality labels, request/response hashes, model and proof labels. | Hosted meter and audit schemas exist. | No more than 180 days after last activity is a target, not evidenced production enforcement. |
| Local repository scan | Summaries, token counts, local receipts, semantic slices, reports under .agentspend/. | The inspected CLI writes these locally and has explicit hosted-sync paths. | No raw source or file-path upload in default reporting is a source intent pending deployment canary evidence. |
| API invoice mode | Prompts, request/response bodies, provider authorization, and provider-account traffic. | These transit the hosted gateway when explicitly routed. Metering metadata and hashes may persist. | Raw traffic should remain request-transient unless cache opt-in is enabled; deployed non-persistence is unverified. |
| Response-cache opt-in | Provider response bodies for exact repeated requests under a repo key. | Source includes explicit opt-in, a 30-day default, and keyed purge paths. | Production isolation, purge races, backups, operator access, and expiry evidence remain required. |
| Security, abuse, support | IP/user-agent derivatives, logs, email, reports, screenshots, attachments. | Multiple external and hosted stores may process these. | 90-day security-log and 24-month correspondence windows are targets; vendor and deployed retention evidence is missing. |
Data Flow Summary
- Local audit,
source_observed: audit and proof commands write local artifacts; verify behavior before sensitive use. - Hosted dashboard, target: default reporting should receive keyed metrics, hashes, counters, account labels, and dashboard state rather than raw source or prompts.
- Hosted API mode: provider-bound prompts, responses, and authorization pass through the gateway. This is sensitive hosted processing, regardless of persistence targets.
- Response cache,
source_observed: source requires explicit opt-in and includes keyed disable/purge logic; deployed enforcement is not verified.
Intended Uses
- Operate dashboards, signup, rate limits, abuse controls, and tenant-scoped account paths.
- Measure cost counters, provider calls avoided, quality labels, and proof hashes.
- Route API mode only when a customer explicitly enables it for a controlled workflow.
- Debug failures, prevent abuse, improve onboarding, and respond to support requests.
- Publish aggregate benchmarks only after redaction and claim-boundary review.
Response Cache Target
Source review shows response caching disabled by default, explicit confirmation commands, a 30-day source default, and keyed purge paths. The production target is that disabling cache prevents new body persistence and purges controlled primary rows. Race, restart, backup, logging, and operator-access tests are still required; do not treat purge or expiry as deployment-verified.
Provider Keys and Model Providers
In API mode, you bring your provider key and remain responsible for the provider account, terms, prompts, outputs, and invoices. Authorization and traffic pass through the gateway. Use dedicated keys in environment variables or headers, never committed files. Source intends no provider-authorization persistence and attempts to keep CostLayers keys outside the repository, but production secret-canary, redirect, logging, and platform-permission evidence is still required.
Local Artifacts
Source review shows local artifacts under .agentspend/ and a CLI attempt to append an ignore block to the repo root .gitignore. This is partial, not a guarantee: keep the directory private, verify the ignore rule, and review every artifact before sharing.
Retention and Deletion Targets
- Local cleanup,
partial:costlayers privacy delete-localtargets identified CostLayers files and reports manual cleanup. Verify its output; customized files and external stores are outside that command. - Hosted primary rows, target:
costlayers privacy delete-hosted --yesand/engine/v1/deleteare intended to revoke a key and remove controlled primary rows. End-to-end receipts, retries, races, and operating history are not evidenced. - Manual requests, target: acknowledge within 2 business days and complete validated primary-store deletion within 30 days.
- Backups, target: deleted primary rows should age out within 30 days where controlled by CostLayers. Backup inventory, encryption, expiry, tombstone replay, and restore tests remain
unknown. - Separate boundaries: hosted deletion cannot remove local files, provider records, npm/package logs, infrastructure logs, or support records held under another valid requirement.
Sharing and Subprocessors
The policy target is not to sell personal data. The categories below are non-authoritative planning categories, not a verified list of appointed legal entities. Named vendors, regions, contracts, transfer terms, retention, and effective dates are still required before production enterprise use.
| Unverified category | Expected purpose | Possible data |
|---|---|---|
| Hosting, database, storage, logs, DNS, and TLS | Public site, dashboard, gateway, account rows, deletion path, operations. | Account/access data, usage metadata, security logs, and transient API traffic. |
| Package distribution | Distribute the CLI candidate and later releases. | Registry and download metadata under provider terms. |
| Support email and calendar | Support, security reports, scheduling, deletion requests. | Messages, attachments, screenshots, logs, and scheduling metadata supplied by you. |
| Customer-selected model provider | Process requests under the customer's provider account. | Prompts, responses, authorization, account traffic, and provider logs. |
Security Targets
Source-observed mechanisms include keyed paths, rate-limit code, local-first commands, hash-based receipts, and cache opt-in controls. HTTPS/HSTS, security headers, cross-tenant isolation, encryption, backups, operator access, and production retention are not deployment-verified in this repository. See /security.html, public artifacts, and the unsigned DPA draft.
Children and Sensitive Workloads
CostLayers is intended for professional developer workflows and is not directed to children. Do not use the beta for regulated, secret-heavy, export-controlled, medical, financial, or production-critical workloads unless your organization has reviewed and approved the risk.
Changes
We may update this policy as the product matures. Material changes will be reflected by updating the effective date and, where appropriate, by notifying active users through the product or email.