The short version. We collect the data we need to run our products (emails, agent endpoints, conversation transcripts, and scoring results) and use it to deliver those products to you. We don't sell your data. We don't share it with advertisers. We don't train AI models on it. If you want it deleted, email travis@clientcoded.com and we'll do it.

1. Who we are

This privacy policy applies to ClientCoded (the "Service"), operated by ClientCoded ("we," "us," "our"). The Service includes:

  • Adversarial Testing: synthetic personas that test your conversational agent, at clientcoded.com/agentproof
  • Production Monitoring: real-time scoring and alerting for your agent's live conversations, at clientcoded.com/monitoring
  • Test Environments: synthetic data environments for testing data agents, at clientcoded.com/environments
  • ClientCoded Chrome Extension: our browser extension for testing live chat widgets
  • clientcoded.com: our marketing website

You can reach us at travis@clientcoded.com.

2. What we collect and why

Marketing website (clientcoded.com)

We collect standard server logs (IP address, browser, referrer, pages visited) for security and aggregate analytics. We do not use third-party advertising trackers. If you book a meeting through Calendly, your scheduling data is handled by Calendly under their privacy policy.

When you request an audit or contact us

When you submit the audit form or otherwise contact us, we collect the details you provide so we can respond:

  • Your name, work email, company, and role
  • What you tell us about your agent and what you want tested

We use this to reach out, prepare your audit, and follow up. We do not sell it or share it with advertisers.

Test Environments (data agent testing)

When you test a data agent, your agent queries our synthetic test environments through our API. The data in those environments is generated by us; we never receive or store your production data. We store the queries your agent runs against an environment and the scores produced by comparing its answers to our computed ground truth.

Adversarial Testing and Production Monitoring

When you connect an agent for testing or monitoring, we collect:

  • Your email address (to attach results to your account and send notifications)
  • The agent endpoint URL or widget ID you submit for testing
  • The description of your agent and the success criteria you provide
  • The full synthetic conversation transcripts our test generates against your agent
  • The scorecard and individual dimension scores produced by our scoring engine
  • For production monitoring, the live conversations you route to us by webhook, scored in real time

When you subscribe, Stripe handles your payment information directly. We receive a customer ID and subscription status from Stripe; we never see your card number.

ClientCoded — AI Agent Stress Test (Chrome extension)

The extension is a thin client. It only collects what's needed to run a test and return a scorecard:

  • Your email address, which you enter in the popup, stored locally in your browser via chrome.storage.local so you don't have to re-enter it
  • The chat conversation the extension runs on the page you choose to test — every message the synthetic prospect sends and every response the chat widget returns
  • The URL, page title, and meta description of the page being tested, used to generate a realistic synthetic prospect
  • Whether the agent displayed a calendar booking link during the test (a boolean — we don't read the rest of the page)

This data is sent to our servers at clientcoded.app.n8n.cloud for persona generation, mid-conversation prospect message generation, and scoring. The resulting scorecard is stored under your email so you can revisit it later.

The extension does not:

  • Read other content on the page beyond the chat widget
  • Capture screenshots, keystrokes, or form input outside the chat widget it's actively testing
  • Track your browsing history
  • Inject ads, redirects, or third-party code into any page
  • Run when you're not actively triggering a test

3. How we use your data

We use the data described above to:

  • Deliver the product you're using (generate test conversations, monitor and score production conversations, produce scorecards)
  • Enforce free-tier limits and account access
  • Send transactional emails (test completion notifications, account confirmations, password resets, billing receipts)
  • Investigate bugs, errors, and abuse
  • Improve our scoring rubrics and detection heuristics (using aggregated, de-identified patterns — never your transcripts shared with anyone)
  • Generate anonymized, aggregated benchmarks and industry reports (e.g., average AI agent scores by dimension, failure rates by persona type). These reports never include your company name, agent endpoint, email, or any data that could identify you or your agent.
  • Comply with legal requests when required

What we don't do with your data

  • Sell or rent your personally identifiable data to third parties
  • Share it with advertisers or data brokers
  • Share your raw transcripts, scorecards, or agent configurations with other customers or third parties
  • Identify you or your company in any published benchmark, report, or dataset without your explicit written consent

4. Third-party services we use

The Service depends on the following processors. Each has its own privacy practices:

Anthropic (Claude API)
Powers adversarial testing personas, conversation and answer scoring, and extension testing. Conversation content is sent to Anthropic's API. Anthropic does not retain or train on data submitted via API.
Supabase
Database hosting for customer, conversation, test, and scorecard data.
SendGrid
Sends our transactional and notification emails (test results, alerts, and audit responses).
Stripe
Processes payments for Starter, Team, and Enterprise subscriptions. Stripe handles all card data directly.
n8n Cloud
Hosts the workflow automation that runs our backend logic.
Netlify
Hosts our website and supporting pages.
Calendly
Handles meeting scheduling when you book a call with us.
Slack
Delivers quality and regression alerts to your team's Slack workspace (per-tenant webhooks).

5. Data retention

How long we keep your data depends on which product you're using:

  • Marketing site logs: 90 days, then deleted.
  • Customer account data: Retained for the life of the account plus 90 days after cancellation, then deleted. You can request immediate deletion before that window.
  • Testing and monitoring data: Retained indefinitely so you can revisit scorecards by URL. You can request deletion at any time.
  • Extension test sessions: Temporary session state (the synthetic prospect's persona during an in-flight test) is deleted within 24 hours. Final scorecards follow the testing and monitoring retention policy above.
  • Stripe billing records: Retained as required by financial regulations (typically 7 years).

6. Your rights

Regardless of where you live, you can:

  • Request a copy of the data we hold about you
  • Request correction of any inaccurate data
  • Request deletion of your data ("right to be forgotten")
  • Withdraw consent for processing (which may mean we can't continue providing the Service)
  • Opt out of marketing emails (every marketing email has an unsubscribe link; transactional emails are not promotional)

If you're in the EU, UK, or California, you have additional rights under GDPR, UK GDPR, and CCPA respectively. To exercise any of these rights, email travis@clientcoded.com with the subject line "Privacy request." We respond within 30 days.

7. Security

All data is transmitted over HTTPS. Database access is restricted to our backend services via Supabase's service role keys. API keys for third-party services are stored as environment variables, not in code. We do not store payment card data — Stripe handles that exclusively.

No system is perfectly secure. If we discover a breach affecting your data, we will notify you within 72 hours of confirming it, as required by GDPR for EU residents and as a matter of policy for everyone else.

8. Children

ClientCoded is a B2B product. It is not intended for and is not marketed to anyone under 18. We don't knowingly collect data from children. If you believe we have, email us and we'll delete it.

9. International data transfers

Our servers and the servers of our processors are primarily located in the United States. If you access the Service from outside the US, your data will be transferred to and processed in the US. By using the Service, you consent to this transfer.

10. Changes to this policy

We may update this policy as our products and the laws governing them change. When we make material changes, we'll update the "Last updated" date at the top and, for significant changes, notify active customers by email. Continued use of the Service after changes constitutes acceptance.

11. Contact

For privacy questions, data requests, or anything else covered by this policy:

Travis at ClientCoded
Email: travis@clientcoded.com
Web: clientcoded.com