On this page
- 1. Who we are
- 2. Our role and your organisation
- 3. Information we process
- 4. Local capture and outbound workflows
- 5. Use of information and legal grounds
- 6. Customer content and model improvement
- 7. AI services and integrations
- 8. Recipients and sharing
- 9. Browser storage and product analytics
- 10. Retention and deletion
- 11. Security and international processing
- 12. Rights and choices
- 13. Children and changes
1. Who we are
Ansight, Inc., a Delaware corporation (“Ansight,” “we,” “us”), provides tools that help people and agents build, test, investigate, and verify applications. This policy covers our website, accounts and customer portal, CLI and local player, SDK-related service interactions, agent skills and plugins, cloud evidence services, integrations, remote companion connections, and support.
Contact support@ansight.ai with Privacy request in the subject line, or write to Ansight, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States. Our support page explains how to contact us without sending unnecessary sensitive information.
2. Our role and your organisation
We act as a controller or equivalent business for information used for our own account administration, billing, security, support and business operations. For customer content processed solely to provide a customer’s requested service, we act as a processor or service provider to the extent required by applicable law and our agreement. Roles depend on the activity, not only where software runs.
Customers normally decide which apps to instrument, what evidence to collect, who can access it and which workflows to run. A customer may itself be a processor for another organisation. A data processing agreement (DPA), where required, supplements the service agreement; this public policy does not replace one or override a restriction in one.
If an app operator uses Ansight to process information about you, contact that operator about its collection and use. We do not control its notices or legal basis. An organisation administrator’s acceptance cannot waive another person’s statutory privacy rights or grant intellectual-property rights the organisation does not possess.
3. Information we process
We receive information directly from you, from your organisation’s administrators and authorised users, from devices and software you connect, from integrations and service providers, and through service activity.
“Customer Content” means the material you or your authorised users provide or make available through the service, including app evidence, source, files, prompts, tests and results.
| Category | Examples | Purposes |
|---|---|---|
| Account and organisation | Name, email, authentication identifiers, organisation membership and roles, invitations, preferences, entitlements | Sign-in, access management, collaboration and administration |
| Billing | Plan, metered usage, credits, invoices, payment status, billing contact and processor references | Payments, accounting, billing support and fraud prevention |
| Runtime evidence | App, device and build metadata; screenshots and video where enabled; UI trees and visible text; touches and navigation; logs, requests and responses; crashes; memory/FPS and other metrics; annotations and analyses | Capture, inspection, replay, debugging, testing, performance analysis and sharing |
| Workspace and app content | Test prompts, assertions, tasks, triggers, source made available to an execution environment, binaries, dependencies, files, artifacts, database and preference results, tool inputs and outputs | Run authorised workflows and return evidence and results |
| Credentials and secret references | Account tokens, pairing or connection credentials, secret aliases and scoped execution credentials | Authorise connections and requested actions; storage depends on the relevant credential mechanism |
| Support and feedback | Messages, contact details, issue descriptions, attachments and diagnostics you send | Respond to requests and investigate faults or security concerns |
| Website and product activity | Pseudonymous identifiers, page and campaign attribution, browser or device information, IP information available to service infrastructure, usage and command outcomes, download and install/update events | Operate, secure and improve services and understand adoption |
| Remote companion connections | Connection and device identifiers, connection metadata, screen/control streams and selected files | Provide remote access you enable, troubleshoot connections and protect the service |
A payment provider collects payment details through its payment flow. We receive transaction information needed to manage your account. Never send full card details to support.
Evidence can contain personal or confidential information even in development builds: credentials, location, communications, health or financial records can appear in screens, logs, requests and tool results. Use synthetic data and test accounts, minimise capture, and review evidence before sending it to us or another service. Ansight does not currently use Customer Content to train models, as explained in Section 6.
4. Local capture and outbound workflows
Ordinary SDK capture sends evidence to the host on your chosen development machine. The host stores captures and Trends history locally. Opening a local player or inspecting a local capture does not, by itself, upload that capture to Ansight cloud storage.
Local evidence consists of ordinary files and databases, not an encrypted Ansight vault. Your OS account, filesystem permissions, machine encryption and backups determine local protection. Credential storage is separate. The technical security documentation describes current limitations, including clear-text development-network transport and workspace code running with the host user’s permissions.
Separate activities can send information elsewhere:
- Export or agent handoff: a ZIP, screenshot or tool result creates another copy at the selected destination. An external agent can send that evidence to its own model provider.
- Cloud sharing: uploads a capture to the chosen organisation and audience. The CLI shares raw captures by default; sanitization must be selected explicitly.
- Cloud Trends: uploads selected metrics and comparison history.
- Cloud test tracking: uploads run summaries and counts; this is distinct from a hosted AI runner receiving prompts and tool results.
- AI tests or analysis: send relevant prompts, screenshots, logs and tool interactions to the selected model service or runner.
- Remote access: enabled remote companion connections can transmit connection metadata, screen/control traffic and authorised files through the configured connection or relay.
- Account services, analytics and support: can communicate online independently of capture storage.
Local storage does not mean every activity is offline. Disabling one feature does not disable unrelated account, update, billing, security or externally configured agent traffic. Installing a skills plugin does not itself upload all local files or authorise model-training collection.
5. Use of information and legal grounds
We use information to provide functionality; administer access and subscriptions; execute and track jobs; deliver results and service messages; support customers; diagnose faults; prevent abuse; comply with law; and establish or defend legal claims. Appropriate service measurements and feedback help improve reliability and usability. Using an AI model to fulfil your request is described in Sections 6 and 7.
Where a law requires a legal basis, the applicable basis may be performance of a contract with the individual, legitimate interests in operating a secure and useful business service subject to affected individuals’ rights, legal obligations, or consent where required. Business-contact administration may rely on legitimate interests rather than a contract with that individual. Consent may be withdrawn for future processing without affecting processing already lawfully performed. A contractual permission is not automatically a sufficient privacy-law basis.
Customer-directed processing follows the applicable instructions and agreement. We do not use a processor relationship as blanket permission for independent training. Ansight is not intended for making employment, credit, insurance or other legally significant decisions about individuals.
6. Customer content and model improvement
Ansight does not currently use Customer Content to train or fine-tune models. We do not operate a customer-content training programme or collect contributions for a future programme. No training opt-out is needed under our current practices. Using a model to perform a test or analysis you request is different from using your content to train that model.
If we introduce a training programme, we will explain its scope, eligible information, retention and participation choices before it starts, update this policy, and obtain any permissions or consent required by law, customer agreements and source-platform terms. This policy does not authorise future training or the retrospective use of existing content for that purpose.
OpenAI integration: Data received or accessed through Ansight’s ChatGPT or Codex integration—including requests, prompts, tool outputs, app evidence and derived examples—is excluded from independent model training, fine-tuning and cross-customer evaluation. This restriction follows copies and derivatives and cannot be removed through a future organisation training setting. We process App Requests only as necessary to fulfil their instructions or comply with law, and do not use them to develop models competing with OpenAI. OpenAI’s own processing is governed by its agreement with the user or workspace.
7. AI services and integrations
Processing paths include hosted service calls and customer-configured agents or provider accounts. The implementation supports OpenAI, Anthropic and Google Gemini for relevant analysis paths; availability depends on feature and configuration. A requested workflow may send relevant text, images and, where supported, video. Results, diagnostics and usage records may be retained with the workflow.
A local runner may still make remote model requests. Provider retention, abuse monitoring, training settings and human access depend on the applicable service agreement and account configuration. We do not describe all AI processing as zero-retention. A provider’s consumer chatbot terms can differ from API or enterprise terms. Ask us to confirm the arrangement before using sensitive content.
The OpenAI integration must not collect, solicit or process protected health information, payment-card/PCI-regulated data, government identifiers, or access credentials and authentication secrets. Do not provide personal information of children under 13 or the applicable age of digital consent. Use synthetic or already-sanitized fixtures prepared outside the integration when a source contains restricted information. Other sensitive personal information may only be processed where strictly necessary, expected, lawfully consented to, and prominently disclosed before collection. These platform restrictions apply independently of any agreement with Ansight for another service.
Customer-enabled integrations can exchange app identifiers, issue details, artifacts, outcomes and other selected data. Revocation stops future access within its scope but does not erase information already delivered. A plugin or skill is an instruction package, not a separate OS security boundary.
8. Recipients and sharing
Information may be disclosed to authorised organisation users and administrators; recipients you select; providers of infrastructure, authentication, payments, email, analytics, AI and connectivity; professional advisers; authorities where legally required; and parties involved in a corporate transaction subject to appropriate protections.
The following providers support the listed functions. Each receives information relevant to the feature being used, rather than all Customer Content.
| Provider | Function and information involved |
|---|---|
| Supabase | Authentication, account and organisation records, database services and cloud evidence storage |
| Microsoft Azure | Website and portal delivery and software distribution, including request metadata |
| Stripe | Payments and subscriptions, including billing details and transaction records |
| Resend | Service email and feedback delivery, including recipient details and message content |
| Google Analytics | Website visits and interactions, including browser identifiers and page information |
| PostHog | Website, portal and product usage measurements, including pseudonymous identifiers and event metadata |
| OpenAI, Anthropic and Google Gemini | AI workflows supported by the selected feature, including the prompts and evidence needed for that workflow |
| Cloudflare | Optional TURN relay connectivity for remote companion connections |
Customer-configured model accounts, agents and other integrations may have their own provider relationships. Contact us for the subprocessor information and processing locations applicable to your service.
Organisation administrators manage access within their permissions. Public sharing permits viewing without sign-in; authenticated sharing is not necessarily team-restricted. Recipients can retain downloaded copies. Select an audience deliberately and avoid public links for confidential evidence.
We do not sell raw Customer Content or use it to build advertising profiles. Statutory definitions of sale, sharing and targeted advertising can be broader than ordinary commercial meanings; applicable privacy choices remain available. If information is represented as de-identified, we maintain it in that form and do not attempt re-identification except lawful testing of de-identification safeguards.
9. Browser storage and product analytics
We use basic analytics to understand whether people use Ansight and which features are useful, including activity and session counts, downloads, installation and update events, and command outcomes. These measurements can include pseudonymous installation or browser identifiers, software version and event metadata. They are not a collection of your capture contents for model training. Identifiers can distinguish repeat use and are not necessarily anonymous; portal events may be associated with an account identifier.
The website uses Google Analytics and PostHog. Website and portal measurements can include page paths, referral sources, campaign labels and actions such as copying an installation command or opening the portal. Cookies and local browser storage support analytics, attribution, preferences and authentication. Service infrastructure can also receive IP addresses and browser information when handling requests.
Our PostHog event collection on the website and portal checks browser Do Not Track and Global Privacy Control signals. These checks do not disable Google Analytics, necessary service logging or every use of browser storage. You can block or clear cookies and site storage through your browser and use its tracking protections; doing so may reset preferences or sign you out. Contact support@ansight.ai for help with privacy choices or requests concerning information already collected.
The CLI queues pseudonymous daily activity outside CI and installation/update events. Detailed usage tracking is enabled by default. Run ansight analytics status to inspect its status or ansight analytics detailed disable to disable detailed tracking. Local-player activity is also queued. The running host sends queued events to PostHog. Disabling detailed tracking does not disable daily activity or installation/update events. It also does not disable account, billing or customer-configured agent traffic.
10. Retention and deletion
Retention means how long information is kept before it is deleted or made anonymous. We retain records for as long as lawfully necessary for the purposes described in this policy, including applicable recordkeeping requirements, using the following periods or criteria. We delete or anonymise personal information when there is no longer a lawful need to retain it. There is no single legal maximum that applies to every type of record. The duration depends on the service, your settings, whether an account or support issue remains active, and legal or security requirements.
| Information | How long it is kept and how deletion works |
|---|---|
| Local captures, Trends history and exports | Remain on your machine until you delete them or applicable local cache rules remove them. Ansight does not remotely delete these files through an account deletion request. Trends databases, exports and your backups are separate copies. |
| Cloud captures, analyses and shared evidence | You and your authorised organisation users control which captures are uploaded and can delete them through the service within your permissions. Uploaded captures remain available until you delete them, an organisation retention rule removes them, or the service or organisation closes, subject to the backup and legal exceptions below. There is no automatic expiry where no retention rule is configured. Deleting the local capture does not delete its cloud copy. |
| Account and organisation records | Kept while needed to provide and administer the account or organisation. After closure, information still needed for billing, security, disputes or legal obligations is retained for those purposes. Leaving an organisation or deleting an individual account does not delete that organisation’s evidence or other users’ records. |
| Support and feedback | Kept while handling the request and afterward to the extent needed to resolve related issues, maintain relevant support history, or address disputes and legal obligations. The nature and sensitivity of the issue determine what is needed. |
| Billing and security records | Kept for applicable accounting and tax duties, fraud and incident investigations, and the establishment or defence of legal claims. Relevant statutory periods and the duration of an investigation or dispute determine retention. |
| Usage analytics | The local CLI queue holds at most 250 events for up to 30 days. Transmitted analytics are separate and are kept while needed to measure adoption, compare usage over time and investigate product issues. The queue limit is not a 30-day deletion promise for PostHog or Google Analytics records. |
| Browser storage | Remains until its expiry, replacement or removal through browser or account controls. Clearing it does not delete events already transmitted to an analytics provider. |
Deleted information may remain in backups until those backups expire or are replaced. Legal obligations or an active dispute can require us to preserve relevant records beyond an ordinary deletion request. We limit continued retention to the applicable purpose and explain relevant exceptions when responding to a request. We do not promise immediate erasure from every backup or provider system.
Use available capture and organisation deletion controls or contact support@ansight.ai for a deletion request. We may need to resolve account ownership or organisation dependencies first. Deleting a sharing link prevents future access through that link but cannot recall copies already downloaded by recipients. Customer-configured providers and agents handle their copies under their own arrangements.
11. Security and international processing
We use safeguards appropriate to the service and risks, and expect customers to secure devices and accounts they manage. No service is completely secure. Consult the technical security documentation for present boundaries. Local capture and workspace execution have different security boundaries from our cloud services.
Information may be processed in the United States and other countries where relevant providers or authorised personnel operate. Delaware incorporation does not establish where all data is stored or accessed. A storage region does not necessarily restrict AI processing, support access, relays, logs or backups to that region.
Where international-transfer restrictions apply, we use the safeguards required for the relevant transfer, such as an applicable adequacy decision or contractual safeguards. Contact us for information about the arrangements applicable to your data or to request a copy of relevant safeguards. We do not claim data-transfer framework certification or a residency guarantee unless expressly documented for the service.
12. Rights and choices
Depending on applicable law, you may have rights to know whether we process your information; access, correct, delete or obtain a copy; restrict or object to processing; portability; withdraw consent; or opt out of sale, sharing, targeted advertising or qualifying profiling. Conditions and exceptions apply. We will not unlawfully discriminate against you for exercising your rights.
Email support@ansight.ai with Privacy request, identifying the request and relevant account or interaction. We verify identity and authority proportionately and respond within applicable legal deadlines. Authorised agents may submit requests with appropriate authority. If we cannot fulfil a request, we explain the reason to the extent permitted. Where an appeal right applies, reply with Privacy appeal. You may also complain to the relevant data-protection regulator or attorney general. The postal address in Section 1 is also available.
For customer-controlled content, we normally refer the request to the customer and assist as required by agreement and law. Your account request does not authorise erasure of another organisation’s records. Unsubscribe from optional marketing through its mechanism or contact us; necessary service messages may continue.
European, UK, Swiss, California and other US state laws can differ. Applicability depends on actual activities, individuals and legal thresholds, not solely incorporation. Ask us for the relevant purpose, basis, recipients or transfer safeguards. Acceptance of these terms does not waive mandatory rights.
13. Children and changes
Ansight is a professional service for adults and organisations, not directed to children. Do not register if under 18. Developers are responsible for data in their test apps. Do not submit children’s personal information. Use synthetic data for tests involving children or sensitive records; the OpenAI integration restrictions in Section 7 also apply. Contact us if you believe such information has been provided inappropriately.
The effective date appears at the top of this policy. Material changes receive appropriate notice and additional consent where required. A new policy does not retroactively authorise an incompatible use of information. Contact Ansight, Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, United States, or support@ansight.ai.