What data we collect
Account and authentication data
When you create an account, we collect:- User information - Names, email addresses, user IDs
- Authentication credentials - API keys (encrypted), session tokens
- Organization details - Organization name, team membership
Code and repository data
When you connect a code repository:- Repository metadata - Repository URLs, branch names, file paths
- Code snippets - Small excerpts (typically 100-500 characters) showing where agents are used
- Commit information - Author names/emails, timestamps, commit messages (from git history)
Agent session data
When you monitor runtime agent sessions:- Agent prompts - Input prompts sent to LLM models
- LLM responses - Model outputs and completions
- Model metadata - Model identifiers (for example, “claude-3-5-sonnet”), timestamps
- Policy violations - Guardrail policy IDs and enforcement actions
System metadata
To operate the service, we collect:- IP addresses - For security monitoring and access control
- Session IDs - To track user sessions and API requests
- Trace IDs - For debugging and performance monitoring
How we protect your data
Encryption
- In transit: All data transmitted to Flint AI uses TLS 1.2 or higher (HTTPS)
- At rest: All stored data is encrypted using AES-256 or equivalent industry-standard encryption
- API keys: Your authentication credentials are encrypted before storage
Access controls
- Principle of least privilege: Only authorized SandboxAQ personnel can access customer data, and only when necessary for support or operations
- Role-based access control (RBAC): Internal access is restricted by job function
- Multi-factor authentication (MFA): Required for all personnel accessing production systems
Network security
- Firewall protection: Production infrastructure is protected by firewalls and network segmentation
- Intrusion detection: Automated monitoring for unauthorized access attempts
- DDoS protection: Distributed denial-of-service mitigation
Monitoring and incident response
- Security monitoring: 24/7 automated monitoring for security events
- Incident response plan: Defined procedures to detect, contain, and remediate security incidents
- Breach notification: We’ll notify you within 72 hours if a data breach affects your data (see our DPA for details)
Compliance and audits
- Vulnerability management: Regular vulnerability assessments and penetration testing
- Security training: All employees receive data security and privacy training
- Third-party audits: We undergo regular security audits and assessments
Data retention
We retain data only as long as necessary to provide the service or as required by law.Retention periods by data type
Retention tiers:
- Very short: Up to 14 days
- Short: Up to 2 months
- Medium: Up to 6 months
- Long: Up to 1 year
- Very long: Up to 5 years
After you cancel
When you terminate your subscription:- Within 30 days: We delete all Personal Data (as defined in our DPA)
- Exception: Data required by law to retain (for example, audit logs for regulatory compliance)
- Usage Data: Anonymized/aggregated analytics may be retained per Agreement Section 7(b)
Sub-processors
We engage the following third-party sub-processors to help provide Flint AI Platform:
Changes to sub-processors: We’ll notify you at least 30 days in advance before adding or replacing any sub-processor. If you object on reasonable data protection grounds, contact us within 15 days at privacy@sandboxaq.com.
Stay informed: Contact us to receive email notifications when we update this list.
International data transfers
Where we process data
Personal data may be processed in:- United States (primary infrastructure location)
- European Union (if you select EU region, when available)
EU and UK transfers
For customers in the European Economic Area (EEA) or United Kingdom, transfers to countries without an adequacy decision are protected by Standard Contractual Clauses (SCCs). Legal framework:- EU transfers: EU Standard Contractual Clauses (2021) - Module 2 (Controller to Processor)
- UK transfers: UK International Data Transfer Addendum (IDTA)
Managing your data
Access your data
You can view and export your data through the Flint AI Platform dashboard:- Account settings: View and update user information
- Repository connections: See which repositories are connected
- Session history: View agent session logs and policy violations
Delete your data
You have the right to request deletion of your Personal Data:- Account deletion: Delete your account from Settings, then Account
- Specific data deletion: Contact privacy@sandboxaq.com with your request
Data subject rights (EU/UK)
If you’re in the EEA or UK, you have additional rights under GDPR:- Right to access - Request a copy of your Personal Data
- Right to rectification - Correct inaccurate data
- Right to erasure - Request deletion (“right to be forgotten”)
- Right to restriction - Limit how we process your data
- Right to portability - Receive your data in a machine-readable format
- Right to object - Object to processing based on legitimate interests
Third-party integrations
Flint AI Platform integrates with:- GitHub - To discover agents in your code repositories
- LLM providers - When you use runtime monitoring, we observe interactions with your configured LLM providers (but don’t control their data handling)
- Your agreement with the third-party provider (for example, GitHub Terms)
- Our End User License Agreement
- Our internal security protocols
Data compaction and storage tiers
Automatic data optimization
To manage data efficiently while maintaining security: Data compaction: For certain ID-based data, such as inventory records, we retain only the most current version once older versions have been processed. This reduces redundancy and ensures data integrity. Tiered storage: Older data is automatically moved to long-term storage tiers with appropriate security controls. This balances performance (fast access to recent data) with cost-effectiveness (cheaper storage for historical data). Example: A 6-month-old agent session might be moved to archival storage, but remains accessible if you need it for compliance reporting.Privacy and legal
Privacy policy
This page describes how we handle data when acting as a Processor on your behalf (that is, processing data you control). For information about data we collect when acting as a Controller (for example, website analytics, product usage), see our Privacy Policy.Data Protection Addendum (DPA)
If you’re subject to GDPR or other data protection laws, see our Data Protection Addendum for:- Legal roles (Controller vs. Processor)
- GDPR Article 28 compliance details
- Standard Contractual Clauses (SCCs)
- Audit rights and breach notification procedures
End User License Agreement
For general terms about Customer Data, see our End User License Agreement Section 7(c):- What constitutes Customer Data
- Prohibited Data (what not to submit)
- Usage Data (anonymized analytics)
Contact us
For data handling questions:Email: privacy@sandboxaq.com For technical support:
Email: support@sandboxaq.com For security issues:
Email: security@sandboxaq.com