Legal
Privacy Policy
Delegus verifies whether an AI agent was authorized to act. We are an authorization service, not an identity or profiling product — we do not need or want personal data about end users to do our job. This policy explains what we do handle.
Last updated September 23, 2026.
Who we are
Delegus, Inc., a Delaware corporation ("Delegus", "we"). This policy covers the delegus.ai website and the Delegus service (the API, SDK, CLI, and console). Contact: hello@delegus.ai.
What we collect
The website
Privacy-preserving, cookieless analytics (aggregate page views, no cross-site tracking, no advertising profiles), and anything you choose to send us — for example, your email if you write to us or apply to the pilot program.
The service
- Verification inputs you send to
/verify: the signed grant, the per-request proof, and the action metadata (for example a resource identifier and amount). These are the technical facts a decision is computed from. - Decision Receipts and evidence: the signed record of each decision and the hashes of what it referenced, stored as tamper-evident evidence.
- What was checked: since September 23, 2026, with each decision (approved or refused) we also keep the action the service sent us to check: its type, the item or resource, and for a purchase the amount and currency (for an API call, the request method). We keep it so your dashboard can show what was bought and for how much, and so usage can be measured by value. It is kept with the decision record for seven years. After that, Delegus clears these details (what was asked, the amount and the currency) automatically. The signed receipt itself and its evidence stay available for verification, as the retention section describes. It is shown only to the service that sent it, its organization, and Delegus staff. It is not published, and the signed receipt itself still holds only a fingerprint of it. We do not store the company’s permission or the agent’s signed request, and this adds nothing about the buyer’s identity.
- Account information for a tenant: organization name, a contact email, and API keys (we store only a hash of each key, never the key itself), plus usage counts.
We do not require personal information about your end users to operate. If you choose to place personal data inside an action payload, you are the controller of it; keep it to what the decision needs.
How we use it
- To provide the service — evaluate verifications and return decisions.
- To create and retain the signed receipts and referenced evidence (this is the product, not a side effect).
- Security, abuse prevention, rate limiting, and support.
- Billing, for paid tiers.
We do not sell your data, and we do not use it to build advertising or cross-customer profiles.
Retention
Decision Receipts and the evidence they reference are retained for seven years, as the protocol specifies — durable, re-verifiable evidence is the point of the service. Account information is kept while your account is active and for a reasonable period afterward for legal and audit purposes. Note that receipts are signed when they are issued, so a copy that has been changed no longer verifies, and we keep historical decisions rather than altering or deleting them.
Who we share it with
We use a small number of service providers to run Delegus on our behalf. Each works under contract and only to provide its part of the service:
- AWS runs the Delegus API, the signing keys and the evidence store (United States, us-east-1).
- Vercel hosts this website and the console at app.delegus.ai.
- Neon is the console’s database: organization names, contact emails, sign-in records, usage summaries and account settings.
- Resend sends our email, such as sign-in links and replies to pilot applications.
- Upstash stores pilot applications sent through this website and counts clicks on our tracked links.
- Anthropic powers an internal assistant our staff use to run the business. It may process business contact details and account usage summaries; it is never given your verification inputs, receipts, evidence or keys.
- Google Workspace handles our own email and correspondence, for example when you write to hello@delegus.ai.
- Stripe handles billing, for paid tiers.
We disclose data if required by law, and we would tell you unless legally prohibited. We do not sell data.
Security
Signing keys are held in a hardware-backed key service; API keys are stored only as hashes; access is restricted and audited. A SOC 2 examination is underway (not yet complete). More detail on the security page.
Your choices
Write to hello@delegus.ai to access, correct, or delete account information, or to ask a question about this policy. We honor applicable privacy rights (including under GDPR and CCPA where they apply). One limit to be honest about: signed receipts are immutable evidence by design, so we cannot alter a past decision record — but we can delete account and contact information.
International
The Delegus API, its evidence store and the console’s database are hosted in the United States. Additional regions are available to enterprise customers on request.
Changes
We will post any changes here and update the date above. Material changes affecting customers will be communicated directly.
Contact
Questions, requests, or complaints about this policy:
Delegus, Inc.
Attn: Jane Hagger
400 Concar Dr, San Mateo, California 94402
Email: hello@delegus.ai
Your use of the Site is also governed by our Terms of Use, which include how disputes are resolved.