privacy policy
Last updated: July 27, 2026 · Effective date: July 27, 2026
This Privacy Policy explains how ExosphereHost, Inc., a Delaware corporation doing business as Failproof AI ("Failproof," "we," "us"), collects, uses, discloses, and protects personal information in connection with befailproof.ai and our products, including AgentEye and the Failproof CLI (collectively, the "Services").
Capitalized terms not defined here have the meaning given in our Terms of Service.
1. Two Different Roles — Please Read This First
How we handle data depends on which of two categories it falls into. The distinction matters, so we state it up front.
A. Data we control. Information about you as a visitor, prospect, account holder, or user of our website and dashboard — your name, work email, company, billing details, support messages, and product usage analytics. For this data we are the controller (or "business" under U.S. state laws). This Policy governs it.
B. Data you send us through the Services. Agent telemetry captured from your environment — prompts, tool calls and their arguments, responses, file paths, command invocations, session traces, logs, and metrics. We call this Customer Data. For this data we act as a processor (or "service provider") on behalf of our customer — the organization that deployed the Services. We process it only on that customer's instructions and under our agreement with them.
If you are an employee, contractor, or end user of a company that uses Failproof and you have questions about Customer Data, contact that company directly. They control it, and we will refer requests to them. Our processing of Customer Data is governed by our agreement with that customer, not by this Policy.
2. Information We Collect
2.1 Information you give us
| Category | Examples | Why |
|---|---|---|
| Account data | Name, work email, password hash, company name, job title | Create and secure your account |
| Billing data | Billing contact, address, tax ID, plan, transaction history | Process payments and comply with tax law |
| Communications | Support tickets, sales emails, demo requests, meeting notes, event sign-ups | Respond to you and manage the relationship |
| Content you submit | Feedback, bug reports, survey responses, community posts | Improve the product |
We do not receive or store full payment card numbers. Card data is collected and processed directly by our payment processor.
2.2 Information collected automatically
| Category | Examples |
|---|---|
| Device and connection | IP address, browser type, operating system, device identifiers, language |
| Usage analytics | Pages viewed, features used, buttons clicked, session duration, referring URL |
| API and CLI telemetry | API keys used (identifier, never the secret), request timestamps, endpoints called, response codes, error traces, SDK and CLI version |
| Cookies and similar technologies | See Section 7 |
2.3 Customer Data ingested by the Services
The Services are designed to observe and, in the case of the Failproof CLI, intercept agent activity. Depending on how a customer configures them, this can include prompts and completions, tool and function calls with their arguments, tool responses, file paths and file contents accessed by an agent, shell commands, environment metadata, timestamps, session and trace identifiers, and user or agent identifiers.
Customer Data can contain personal information, source code, credentials, and other sensitive material. The customer deploying the Services decides what is captured and is responsible for configuring redaction, filtering, and scoping controls. We provide these controls; we do not choose their settings.
2.4 Information from third parties
We receive business contact information from data enrichment and prospecting providers, publicly available sources, event organizers, referrals, and integration partners you authorize. Where required by law, we rely on your consent or our legitimate interest in B2B marketing, and we honor opt-outs.
We do not knowingly collect special categories of data (health, biometric, precise geolocation, political or religious views) and ask that you not submit it.
3. How We Use Information
We use data we control to:
- provide, operate, maintain, and secure the Services;
- authenticate users and manage accounts and permissions;
- process payments, invoices, renewals, and taxes;
- provide support and respond to your requests;
- monitor performance, debug, and improve reliability;
- develop new features and analyze product usage;
- send service and security notices (these are not marketing and you cannot opt out while you hold an account);
- send marketing communications about our products, subject to Section 8;
- detect, investigate, and prevent fraud, abuse, and security incidents;
- comply with legal obligations and enforce our agreements.
We also generate aggregated and de-identified statistics from operation of the Services — for example, aggregate agent failure-mode frequencies, latency distributions, or benchmark data — and use them to improve our products and publish industry insights. This data does not identify you, your organization, your users, or your customers, and we do not attempt to re-identify it.
Automated decision-making. We do not use personal information to make decisions producing legal or similarly significant effects about individuals without human involvement.
4. Legal Bases (EEA, UK, and Switzerland)
Where GDPR or UK GDPR applies to data we control:
| Purpose | Legal basis |
|---|---|
| Providing the Services under a contract | Performance of a contract (Art. 6(1)(b)) |
| Billing, tax, and record-keeping | Legal obligation (Art. 6(1)(c)) |
| Security, fraud prevention, product improvement, B2B marketing | Legitimate interests (Art. 6(1)(f)) |
| Cookies and marketing where consent is required | Consent (Art. 6(1)(a)) |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights. You may object at any time — see Section 9.
Where we act as a processor for Customer Data, our customer determines the legal basis.
5. How We Share Information
We do not sell personal information, and we do not share it for cross-context behavioral advertising.
We disclose information to:
Sub-processors and service providers who process data on our behalf under written contracts limiting them to our instructions. These cover cloud hosting and compute, telemetry storage and analytics databases, payment processing, transactional email and support tooling, product analytics, and error monitoring. We will provide the current list, including each provider's role and processing location, on request at privacy@befailproof.ai.
Professional advisors — lawyers, accountants, auditors, and insurers, under duties of confidentiality.
Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to confidentiality protections. We will notify you if your information becomes subject to a different privacy policy.
Legal and safety — where we believe in good faith that disclosure is required by law, legal process, or governmental request, or is necessary to protect the rights, property, or safety of Failproof, our customers, or the public. Where legally permitted, we will notify the affected customer before disclosing Customer Data.
With your direction — to integrations and third-party services you connect.
6. International Transfers
We are based in the United States, and our infrastructure and personnel are located in [the United States and India]. Using the Services involves transferring data to these locations.
For transfers from the EEA, UK, or Switzerland we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum or Swiss equivalent where applicable), together with supplementary technical and organizational measures including encryption in transit and at rest and access controls. A copy of the relevant clauses is available on request at privacy@befailproof.ai.
7. Cookies and Tracking
We use cookies and similar technologies on our website and in the dashboard:
- Strictly necessary — authentication, session management, security, load balancing. These cannot be disabled.
- Functional — remembering preferences such as theme and dashboard layout.
- Analytics — understanding how the site and product are used so we can improve them.
We do not use advertising or cross-site tracking cookies.
Where required, we ask for consent before setting non-essential cookies and you can change your choice at any time through our cookie banner. You can also block cookies in your browser, though parts of the Services may stop working.
8. Marketing Communications
We send product news, technical content, and event invitations to business contacts. You can unsubscribe using the link in any marketing email or by emailing privacy@befailproof.ai. We will still send transactional and security messages related to your account.
9. Your Rights
Depending on where you live, you may have the right to:
- access the personal information we hold about you;
- correct inaccurate information;
- delete your information;
- port your information to another provider;
- object to or restrict processing, including direct marketing;
- withdraw consent where processing is based on consent, without affecting prior processing;
- opt out of sale, sharing, or targeted advertising (we do none of these);
- appeal a refused request, where your jurisdiction provides for appeals;
- not be discriminated against for exercising your rights.
To exercise a right, email privacy@befailproof.ai. We will verify your identity — usually by confirming control of the email associated with your account — and respond within the period required by law (generally 30 days under GDPR, 45 days under U.S. state laws, extendable where permitted). An authorized agent may submit a request on your behalf with proof of authorization.
If your request concerns Customer Data, we will forward it to the relevant customer and support them in responding, but we cannot action it directly.
EEA and UK residents may lodge a complaint with their local supervisory authority. Indian residents may raise a grievance with us at privacy@befailproof.ai and, if unresolved, with the Data Protection Board of India.
10. Data Retention
| Data | Retention |
|---|---|
| Account and profile data | Duration of the account, then [90] days |
| Billing and tax records | [7] years, as required by law |
| Support communications | [3] years from last contact |
| Website and product analytics | [24] months, then aggregated |
| Security and audit logs | [12] months |
| Customer Data (telemetry, traces) | Per the customer's configured retention setting; by default [90] days, and in all cases deleted or exported within [30] days of account termination |
| Marketing contacts | Until you unsubscribe, then a suppression record only |
Backups are purged on a rolling cycle of up to [35] days. We may retain information longer where necessary to comply with law, resolve disputes, or enforce our agreements.
11. Security
We maintain administrative, technical, and physical safeguards appropriate to the sensitivity of the data, including encryption in transit (TLS 1.2+) and at rest, role-based access control, least-privilege access to production systems, multi-factor authentication for internal accounts, network isolation, audit logging, secret scanning, vulnerability management, and vendor security review.
No system is perfectly secure. We cannot guarantee absolute security, and you are responsible for safeguarding your credentials and API keys and for configuring the redaction and scoping controls we provide.
If we become aware of a breach affecting your personal information, we will notify you and applicable regulators as required by law and without undue delay.
12. Children
The Services are business tools intended for organizations and are not directed to anyone under 18. We do not knowingly collect personal information from children. If you believe a child has provided us information, contact privacy@befailproof.ai and we will delete it.
13. Changes to This Policy
We may update this Policy. We will post the revised version with a new effective date and, for material changes, provide notice by email or in-product at least [30] days before it takes effect. Your continued use after the effective date constitutes acceptance.
14. Contact Us
ExosphereHost, Inc. (d/b/a Failproof AI)
8 The Green, Suite R
Dover, DE 19901
United States
Privacy: privacy@befailproof.ai
Security: security@befailproof.ai
Legal: legal@befailproof.ai