Legal
Privacy policy
LAST UPDATED · 2026-09-05
Agent Evidence Recorder is operated by ktlsr. It records what AI agents did during a run so the record can later be audited. This page describes every category of data the service holds.
Account data
When you create an account we store your email address, an optional name, and — if you sign up with a password — a bcrypt hash of that password. The password itself is never stored. If you sign in with Google we store the Google account identifier and the profile email and name Google returns; we do not receive or store your Google password.
Agent run data
The data your own agents send through the API: run metadata, event timestamps, event types and durations, and the redaction findings produced during a run.
Sensitive values are redacted before storage. Where an agent handled a value we classify as sensitive, we store a SHA-256 hash of it and the location it was found in — never the original value. The same applies to API keys: only a hash is stored, and the key itself is shown once, at creation.
Who can see it
Every record is scoped to an organization and a project, resolved from your credentials on each request. You can only read data belonging to your own organization. We do not sell data, do not share it with third parties, and do not use it to train models.
Cookies
A single session cookie keeps you signed in. There is no advertising, analytics or third-party tracking on this site.
Retention and deletion
Run data is retained until you delete it or your retention window elapses. To delete your account and everything under it, email contact@ktlsr.com from your account address.
Contact
Questions about this policy, or about data we hold: contact@ktlsr.com.