Legal

Privacy Policy

InspectModular is designed to collect only what is necessary to provide AI governance services. We do not sell your data, use it for advertising, or share it with third parties except as described here.

Last updated: August 2, 2026
What data InspectModular collects
Account data
Email address and organization name provided during access setup. Used solely to manage your account and contact you about the Service.
Audit events
Structured metadata about AI agent activity: tool name, action type, timestamp, token counts, model name, policy outcome, machine ID, and username. No source code or prompt text is ever collected.
API key metadata
Hashed API keys and their associated permissions and usage counts. Raw API keys are never stored.
Usage data
Aggregated statistics about Service usage (e.g., requests per day, features used). Used to improve the product and diagnose issues.
Log data
Server access logs including IP address, request timestamps, and response codes. Retained for 30 days for security and diagnostic purposes.
What InspectModular does not collect

InspectModular is explicitly designed to not collect source code, file contents, AI prompts, model responses, or any developer-written content. The Primer daemon processes agent actions locally and transmits only structured metadata to the cloud API.

We do not use cookies for tracking, do not fingerprint browsers, and do not build behavioral profiles of individual users or developers. Session authentication uses secure, server-side tokens only.

How we use your data
Service delivery
Audit event data is used to populate your organization's dashboard, generate compliance exports, and enforce policy rules. This is the core function of the product.
Security
Log data and access patterns are analyzed to detect unauthorized access, abuse, and security incidents.
Product improvement
Aggregated, anonymized usage statistics are used to understand how the product is used and to prioritize improvements. Individual audit events are not used for this purpose.
Legal compliance
We may process data to comply with applicable law, legal process, or enforceable government requests. We will notify affected customers where legally permitted to do so.
Data sharing and third parties

InspectModular does not sell your data. We do not share your data with third parties for advertising or marketing purposes.

We use the following sub-processors to operate the Service:

Supabase
Database and authentication infrastructure. Data hosted on AWS us-east-1. EU region available on request.
Cloudflare
API edge network and DDoS protection. Request metadata passes through Cloudflare infrastructure.
Resend
Transactional email delivery for magic link authentication and account notifications.

Each sub-processor is contractually bound to process data only as instructed and to maintain appropriate security measures.

Data retention

Audit events are retained for the duration specified in your service agreement. Enterprise customers have access to unlimited retention. Upon termination of your account, you may request a full export of your data. We will delete your data within 30 days of a verified deletion request, except where retention is required by law.

Your rights
Access
You may request a copy of the personal data we hold about your account at any time.
Correction
You may request correction of inaccurate personal data.
Deletion
You may request deletion of your account and associated personal data. Audit events belonging to your organization will be deleted within 30 days.
Portability
You may request an export of your audit data in CSV or JSON format from the dashboard at any time.
Objection
If you are in the EU, you have the right to object to processing of your personal data under certain circumstances.

To exercise any of these rights, contact privacy@inspectmodular.com. We will respond within 30 days.

Changes to this policy

We may update this Privacy Policy from time to time. We will provide at least 30 days notice for material changes via the email address associated with your account. The current version will always be available at inspectmodular.com/privacy.

Questions or concerns? Contact us at privacy@inspectmodular.com.