# Privacy at Agent Bridle

Bridle is a product about trust, so how we handle data is part of the product. This is a summary, not a contract; a full data processing agreement is available to customers.

## Your provider API keys

When your agents call a model provider through Bridle, your provider API key travels in the request headers to that provider. It is never written to disk, never written to our logs, and never stored.

## Your Bridle keys

Keys your agents use to authenticate to Bridle are stored only as a SHA-256 hash. We show a key once, at creation, and cannot recover it afterwards. Lost a key, revoke it and mint a new one.

## What we log

By default we log metadata: agent identity, model, token counts, cost, latency, and outcome. We do not store prompt or response content unless you switch on payload logging for a specific agent, and then only truncated previews.

## The website

This site uses Google Analytics. Analytics stay off until you accept the cookie banner; in the EEA nothing is set before you choose. Decline and the site works the same.

## Retention and access

Audit logs are retained for the period appropriate to their purpose, at least six months for compliance use, and are exportable to you at any time.

## Contact

Privacy questions or data requests: contact@agentbridle.com
