Trust & data handling

A plain statement of what Ablehand processes, where it goes, and for how long. Companion to the security & trust model. Not a legal contract; the DPA is a separate document.

What the widget sends, and to whom

Data Sent to Purpose Notes
The user's goal text and clarifications Ablehand edge โ†’ TypeSafe (Jev) Choose the next control Redacted for card/SSN/token patterns before leaving the browser
An indexed table of visible controls (role + label + coarse context) Ablehand edge โ†’ TypeSafe (Jev) Choose the next control Never selectors, HTML, or hidden/password/payment fields
A bounded slice of visible page text Ablehand edge โ†’ TypeSafe (Jev) Disambiguate Redacted in-browser; per-site policy can add email/phone/IP/custom masking
The goal text, only when a form field must be composed Ablehand edge โ†’ OpenAI Generate a short typed value Only if the site enables generative_text
Page titles/headings/action labels of visited pages Ablehand edge (catalog) Suggest and jump to pages Page-level only; opt out with passive_index: false
Goal outcome (status, steps, rating) Ablehand edge (analytics) Operator dashboard, metering Goal text is PII-scrubbed at ingest; no_log disables persistence

Never sent anywhere: cookies, local storage, auth tokens, request/response bodies, password / file / hidden inputs, payment-provider iframes, or any element the site's deny lists exclude.

Subprocessors

Subprocessor Role Data Region
Vercel Hosting for the edge API, widget bundle, and site All request data in transit; runtime logs US (iad1 / sfo1)
Neon (via Vercel Marketplace) Postgres for tenant config, catalog, traces, outcomes, usage Persisted analytics and configuration US
TypeSafe (Jev) Structured decision model Goal, control table, visible-text slice US
OpenAI Generative text for typed fields (optional per site) Goal text and field label US

Retention

Per site, retention_days (default 90) bounds how long decision traces and goal outcomes are kept; a daily job deletes older rows. Usage counters (daily totals per key, no content) are kept for billing. Sites can set no_log to persist nothing beyond usage counters.

Access and controls

Open items on the compliance path

External penetration test, SOC 2 Type II, a signed DPA template, and a data-subject-request procedure are not yet in place. See the build checklist.