Privacy
Bridle is a product about trust, so how we handle data is part of the product, not an afterthought. This page describes our approach in plain terms. It is a summary, not a contract; a full data processing agreement is available to customers.
Your provider API keys
When your agents call a model provider through Bridle, your provider API key travels in the request headers to that provider. It is never written to disk, never written to our logs, and never stored. It passes through and is gone.
Your Bridle keys
The keys your agents use to authenticate to Bridle are stored only as a SHA-256 hash. We show a key once, at creation, and cannot recover the original afterwards. If a key is lost, you revoke it and mint a new one.
What we log
By default we log metadata about each call: the agent identity, the model, token counts, cost, latency, and outcome. We do not store the content of your prompts or the model's responses unless you switch on payload logging for a specific agent, and then only truncated previews. The choice is yours, per agent.
The website
This website uses Google Analytics to understand how it is used. Analytics stay switched off until you accept the cookie banner; in the European Economic Area nothing is set before you choose. You can decline and the site works exactly the same.
Retention and access
Audit logs are retained for the period appropriate to their purpose, at least six months for compliance use, and are exportable to you at any time. Access to customer data inside Bridle is limited to what is needed to run and support the service.
Contact
Questions about privacy or a data request go to contact@agentbridle.com.