# Privacy notice

> Exactly what AgentGate collects on a protected page, why, how long it is kept, and your choices.

AgentGate protects forms and APIs from unwanted automation. This notice explains exactly what it collects when you use a page protected by AgentGate. It applies to the AgentGate service; the site you are visiting has its own privacy notice for the rest of its data.

## What we collect

When a protected page loads and when you submit, the AgentGate script records:

- **How you interact, not what you type.** Timings of key presses and releases (not which keys), the length of text inserted (not the text), pointer movement samples (position, pressure, pointer type), click timing and position relative to the button, scroll amounts, focus changes and IME composition events.
- **Browser environment facts.** Language, time zone, screen and window size, device pixel ratio, touch support, browser brand and platform as reported by the browser, whether automation interfaces are present, and whether built-in browser functions appear modified.
- **Request metadata.** The page and action you used, request headers the browser sends (such as user agent and language), your IP address, and TLS connection properties.
- **Proof results.** Whether your browser solved the proof of work and the per-request check, and whether you completed a visible check.

We never collect the contents of form fields through the script. The message or data you submit goes to the site you are using, which may pass it through AgentGate's gateway without AgentGate storing it.

## Why

To decide whether a request comes from a person, a declared agent, or undeclared automation, and to show a check only when something looks unusual. We do not use this data for advertising, profiling across unrelated sites, or identifying who you are.

## How it is stored

- Decisions are stored with a pseudonymous source identifier (a keyed hash scoped to one site), not your name or account.
- Full IP addresses are not written to application audit logs or traces. The decision store keeps what is needed to enforce rate limits and investigate abuse for the retention period.
- Detailed decision records are kept for **7 days** by default, and daily aggregate counts for **90 days**. Site operators may set shorter periods.
- Interaction feature vectors (numeric timing, pointer, environment and message-shape measurements) are stored for model improvement only when the site has opted in. They never include message text, which keys were pressed, raw event traces or addresses, are kept for the site's retention period (30 days by default), and are deleted when the site opts out.

## Your choices

- If a check appears and you cannot press and hold, use **"Verify another way"**, which needs no pointer or puzzle.
- Browsers that support Private Access Tokens can prove they are a real device without sharing more data, which lets the site skip the check.
- For access or deletion requests, contact the site you used; its operator can locate AgentGate records by time and site. Because records are pseudonymous, we may need details from you to find them.

## Contact

Security issues: see `/.well-known/security.txt`.
