Skip to main content
Behalf/ID
DocsBlogSecurityStatus
Sign inContinue with GoogleGet started
Get started

Legal / Privacy policy

Privacy policy

Effective 2 July 2026

On this page

  1. 1. Who we are
  2. 2. Data we collect
  3. 3. Cookies and local storage
  4. 4. How we use your data
  5. 5. Analytics
  6. 6. Data retention
  7. 7. Third-party processors
  8. 8. Your rights
  9. 9. Security
  10. 10. Changes to this policy
  11. 11. Contact

1. Who we are

BehalfID ("we", "us", "our") operates behalfid.com and provides permission-verification infrastructure for AI agents. Questions about this policy may be directed to legal@behalfid.com.

2. Data we collect

Account data

When you create a developer account we collect your email address, your date of birth, and a hashed password. We do not store your plaintext password at any point. Your date of birth is used only to confirm you meet our minimum age requirement and is not displayed in account setup or account settings.

Account setup and profile data

When you complete account setup we collect profile and workspace information, including:

  • your first and last name;
  • job title;
  • an optional phone number — if you choose to provide one, we may use it only for account recovery, urgent security alerts, or support. We do not use it for SMS verification, phone-based two-factor authentication, or marketing outreach unless we tell you otherwise in the product;
  • whether you are setting up for yourself or a business/team;
  • company or organization name and workspace name;
  • website and team size; and
  • onboarding preferences: the AI agent tools you use, the areas you want the platform to control, your primary goal with the platform, and your first setup goal.

This information is stored on your user profile and workspace and is used to operate your account, configure your workspace, and tailor onboarding guidance.

Agent and permission data

Agent names, permission configurations, scope definitions, and expiry dates you create inside the dashboard are stored and associated with your account. API keys are stored only as SHA-256 hashes and are shown to you once at creation.

Verification request data

When your integration calls POST /api/verify, we log the agent ID, action, vendor or resource, optional amount, decision outcome, risk level, and a stable request ID. We do not log your API key; only its hash is ever stored. Raw metadata fields are logged only when BEHALFID_LOG_METADATA is enabled. Verification logs are accessible only to the account that owns the agent.

Technical and usage data

We collect IP addresses for rate-limiting and abuse prevention. These are not linked to user accounts for analytics or profiling purposes. Cookie-consent choices are also logged server-side (state only, no personal data) for product-integrity purposes.

Billing data

When you subscribe to a paid plan, billing is processed by Stripe. BehalfID stores your Stripe customer ID and subscription status but does not store your payment card details — those are held exclusively by Stripe. Billing data is used only to enforce plan limits and process your subscription.

3. Cookies and local storage

Authentication cookie

A session cookie (bhf_dev_session) is set when you log in to the developer dashboard. It is HTTP-only, scoped to this domain, and expires when your session ends or after 30 days of inactivity. This cookie is strictly necessary — the dashboard cannot function without it.

Preferences

Theme preference (light / dark) is stored in localStorage and never transmitted to our servers.

Cookie consent

Your cookie-consent choice is stored in localStorage under the key behalf_cookie_consent. A minimal log entry (consent state only — no personal data) is also written server-side for product-integrity purposes.

No third-party or advertising cookies are used. BehalfID does not load tracking pixels, fingerprinting scripts, or analytics SDKs.

4. How we use your data

  • To authenticate and operate your developer account.
  • To configure your workspace and tailor onboarding based on the preferences you provide during account setup.
  • To execute, log, and deliver webhook events for verification requests.
  • To enforce rate limits and detect abuse.
  • To process billing and enforce plan limits via Stripe.
  • To respond to support or security enquiries.

We do not sell your personal data. We do not use your verification request data to train machine-learning models.

5. Analytics

BehalfID does not use third-party analytics, advertising networks, or cross-site tracking. No tracking cookies or fingerprinting scripts are loaded on any page of the service.

6. Data retention

  • Verification logs — retained for 90 days, then automatically purged.
  • Webhook delivery records — retained for 30 days.
  • Account data — retained for the lifetime of the account. Deleted within 30 days of a verified deletion request.
  • Billing data — retained for as long as required by applicable tax and accounting law (typically 7 years), even after account deletion.
  • IP addresses used for rate limiting — stored in memory only; not persisted to disk.

7. Third-party processors

ProcessorPurposeData shared
MongoDB AtlasDatabase hostingAll stored account, agent, and log data
VercelHosting and edge deliveryRequest metadata (IP, path) for routing and abuse prevention
StripePayment processing and subscription managementEmail address, billing name, payment card details (held by Stripe only), subscription events

8. Your rights

Depending on your jurisdiction you may have the right to access, correct, delete, or port your personal data, and to object to or restrict certain processing.

To exercise any of these rights, email legal@behalfid.com. We will respond within 30 days. Verification logs can also be deleted immediately from the dashboard logs page.

9. Security

All data is transmitted over TLS. API keys are stored as SHA-256 hashes. Developer passwords are hashed with scrypt. Sessions use HTTP-only cookies. See our security page for a detailed breakdown of the enforcement model, secrets handling, and known limitations.

10. Changes to this policy

We may update this policy to reflect product changes or legal requirements. The effective date at the top of this page is updated whenever a material change is made. Continued use of BehalfID after a change constitutes acceptance of the revised policy.

11. Contact

Data controller: BehalfID
Email: legal@behalfid.com

See also: Terms of Service · Security and Trust

Behalf/ID

Approval gates
for coding agents.

© 2026 BehalfID

All systems operational
CLISDK
Product
  • Sandbox
  • Design partners
  • Security
  • Blog
  • Start building
Docs
  • Quickstart
  • Deploy approvals
  • CLI & MCP
  • API reference
  • SDK
Company
  • Design system
  • Status
  • Design partners
Legal
  • Legal hub
  • Terms of Service
  • Privacy policy
  • Security
  • Compliance