01Overview
Armature, Inc. ("Armature", "we", "us") helps software products get discovered and used by AI coding agents. This policy explains what personal data we collect, how we use it and what choices you have.
This policy covers four separate things. Each one handles data in a different way, so each one has its own section. A section applies only to the thing it names. It never applies to the other three.
Section 06 covers the contact details of the people we do business with. Sections 07 to 16 apply to all four, but only to the data that sections 02 to 06 describe.
If you use a product that one of our customers built, that customer's privacy policy applies to you. Please contact that customer first.
02Website
Scope: this section applies only to your visits to armature.tech and leaderboards.armature.tech, including the leaderboards, the library, the blog and our forms. It does not apply to the scanner, the Agent Discoverability service or the Armature platform.
Traffic data: we measure traffic with Vercel Analytics, which stores no identifier on your device. We also record page views and clicks with PostHog, without a person profile. Section 14 explains both.
Forms: when you send us the contact form or a leaderboard form, we receive what you type in it, such as your email address, your company and your message. The form sends it to our team's Slack workspace, and we use it to reply to you.
Calls: when you book a call, the Cal.com scheduler collects the details you enter, such as your name and your email address.
Advertising measurement: we load the X advertising pixel and the LinkedIn Insight Tag so we can measure campaigns we run on X and LinkedIn. These tags may set cookies or similar identifiers and send visit data to X or LinkedIn. When you send us a contact form or a lead form, or book a call, we also report that a contact was completed. We report it without the content of your message or your email address.
03Agent Discoverability Readiness scanner
Scope: this section applies only to the free Agent Discoverability Readiness scanner at armature.tech/agent-readiness. The scanner needs no account. It is separate from the Agent Discoverability service and from the Armature platform, and their sections do not apply to it.
When you submit a domain, Armature makes bounded read-only requests to that public website, linked public documentation, and fixed public registries. We follow robots rules. We also honor the ArmatureDiscoverabilityScanner: disallow and legacy AgentReadinessScanner: disallow opt-out directives. We do not sign in or submit credentials.
Exa is a web search provider. For Exa checks, we send the canonical public domain, a derived brand name, and fixed search text. We run two general searches and nine fixed directory searches. We do not send raw page bodies to Exa.
The latest complete result can appear on a public domain result page and in the public Agent Discoverability leaderboard. The page shows the public domain, test outcomes, public evidence, corrective actions, and scan time. It does not publish visitor identity, network data, raw artifacts, or scanner secrets.
A result page may request the public domain icon from Google's favicon service. The request uses a no-referrer policy.
We use a signed essential cookie to limit abuse. It contains a random identifier and issue time. It is not an account and is not used for advertising. We also keep one-way network and requester keys, and may use a server-validated bot challenge. Browser code never receives the raw network address, signing secrets, or scanner backend address.
Completed scan data and HTTP metadata are kept for at most 90 days. Raw scan artifacts expire after 7 days. Scan events expire after 24 hours. The public result cache expires after 24 hours. Access and security logs expire after 30 days. Encrypted backups expire within 90 days. To stop future scans or ask for deletion, email privacy@armature.tech. We verify control of the domain without asking for credentials.
04Agent Discoverability service
Scope: this section applies only to the Agent Discoverability service, the growth service that we run for a company for a monthly fee. It does not apply to the website, the scanner or the Armature platform.
The service needs no data from you. We do not ask for access to your systems, your code, your accounts, your analytics or your users' data, and we do not receive any of them. You install nothing, and you connect nothing to Armature.
We test from the outside. Our coding agents run in our own isolated sandboxes, on test repositories that we own. They read only public information, such as your public website, your public documentation, package registries and the public web. No test runs in your codebase or on your production systems.
We test coding agents from providers such as Anthropic, OpenAI, Cursor, Meta and xAI. Other AI models act as the user and score the results. All these models receive only our test tasks, our test repositories and public information. They receive nothing from you.
The results show which products coding agents choose, yours and others. They contain no personal data. We also write drafts for you, such as guides or documentation pages. Your team reviews every draft, and you decide what to publish.
The only personal data that the service uses is the contact details of the people we work with, such as their names and work email addresses. Section 06 covers that data.
If you later decide to share data with us, for example a traffic report, we first agree in writing on what you share and how we use it. That agreement then applies to that data. If your company also uses the Armature platform, section 05 applies to that use, and only to that use.
05Armature platform
Scope: this section applies only if you or your company use the Armature app at app.armature.tech or eu.armature.tech. The app runs MCP Analytics and MCP & CLI Evals, our Agent Usability products, and AI Traffic, which is in private beta. This section does not apply to the website, the scanner or the Agent Discoverability service.
The platform is the only part of Armature that receives data from your systems. It receives this data only after you install our software development kit (SDK) or our package.
Account data: when you create an account, we collect your name, your email address and your workspace details.
Billing data: Stripe processes payments. We receive the billing status and invoices, and we never store card numbers.
Session data: customers install our SDK in their MCP (Model Context Protocol) servers, Claude Connectors or ChatGPT Apps. The SDK sends us agent session data, such as tool calls, user intents and agent output. Detection models scan this data and redact personal information and secrets by default, before anything reaches storage.
Eval data: we store the eval suites that you define and the runs they produce. In a run, real agents replay workflows against your MCP server or command-line interface (CLI), and we store the resulting transcripts and scores.
AI Traffic data: our package on your server sends us data about requests from AI crawlers and other bots. For each request, it sends the time, host, path, method, status, user agent and source IP address. It removes query strings, and it does not collect cookies, request bodies or authorization headers. We use the IP address to check the crawler, and then we discard it. We may keep a keyed hash of it to detect abuse.
Usage data: we record how you use the Armature app with privacy-preserving product analytics. The app also loads the X pixel when you visit it or create an account.
For session data, eval data and AI Traffic data, we act as a processor. We process that data on behalf of our customer, who decides what to send. If you are an end user of a customer's product, that customer's privacy policy applies to you, and you should contact them first.
06People we do business with
Scope: this section applies to the people we deal with at customers, prospects, partners and suppliers, for all our products, including the Agent Discoverability service.
We keep their contact details, such as their name, work email address, company and job title. We also keep our emails and messages, our notes from calls, and the contracts and invoices.
We get these details from you, from your colleagues, or from public professional sources such as company websites and LinkedIn.
We use them to talk with you, to do the work we agreed on, to send invoices and to keep business records. We keep them in our email, calendar, customer relationship management (CRM), note and accounting tools.
07How we use data
We use personal data only for these purposes:
- To provide and run our products. In the Armature platform, this includes running AI models that rebuild, classify and score sessions.
- To bill customers and manage accounts.
- To answer your messages and support requests.
- To secure our products and prevent abuse.
- To improve our products.
- To measure advertising campaigns we run on X and LinkedIn. We do this on the website and in the Armature app only.
We do not sell personal data.
08Legal bases (EEA and UK)
The General Data Protection Regulation (GDPR) applies in the European Economic Area (EEA), and its UK version applies in the United Kingdom (UK). Where either one applies, we rely on these legal bases:
- Performance of a contract, to provide the product that you or your company signed up for.
- Legitimate interests, to secure and improve our products, to run the scanner, to deal with business contacts and to measure the advertising we run.
- Consent where the law requires it, for example for advertising tags in the EU, the EEA, the UK and Switzerland.
- Legal obligations, for example for tax and accounting records.
For session data, eval data and AI Traffic data in the Armature platform, we act as a processor, and our customer's legal basis applies.
10Hosting and transfers
The Armature platform runs in two regions: an EU-based hosting region and a US-based hosting region. Customers choose where their workspace lives when they sign up. Data in an EU workspace is stored and processed in the EU.
The website, the scanner and the Agent Discoverability service run on our providers' infrastructure in the US and the EU.
Where personal data is transferred outside the EEA or the UK, we rely on Standard Contractual Clauses or equivalent safeguards.
11Retention
- Scanner: section 03 lists the retention periods.
- Agent Discoverability service: the service holds no data from you. We keep the contact details of the people we work with as described below.
- Business contacts: we keep contact details while we work together, and after that as long as we need them for our records or as the law requires.
- Armature platform: account data is kept while your account is active. Session data is kept for the retention period of your plan: 7 days on the free plan and a custom period on custom plans. AI Traffic keeps raw events for 30 days by default. When you delete your account or ask us to delete data, we remove it from production promptly and from backups within 90 days.
12Security
- We encrypt data in transit and at rest.
- In the Armature platform, we redact personal data and secrets by default, before storage.
- We control access with multi-factor authentication and audit logs.
- We keep secrets in a managed secret store.
- We keep development and production in separate environments.
No system is perfectly secure. If you find a vulnerability, report it to security@armature.tech and we will work with you in good faith.
13Your rights
Depending on where you live, you can ask to access, correct, export or delete your personal data, and object to or restrict some processing. Email privacy@armature.tech and we will respond within 30 days. You can also complain to your local supervisory authority.
If you are an end user of a customer's product, contact that customer first and we will support their response.
15Children
Our products are business tools. They are not directed at children under 16, and we do not knowingly collect their data.
16Changes and contact
We will update this policy when our practices change, and we will change the date at the top. For material changes, we will notify customers by email or in the product.