Privacy Policy
Applies to the Siphrix engine, the browser extension, the VS Code extension and the console at siphrix.com. Last updated 25 September 2026.
The short version
Siphrix exists to record what AI agents do on your behalf. It records metadata about actions — never the content those actions carry. Nothing is sent anywhere until you explicitly connect a machine to a console you chose. There is no telemetry, and we do not sell or share your data with anyone.
What is recorded
- The kind of action (read a file, run a command, upload a file, open an AI site, send a message).
- Its target: a file path, a command line, a web address, or the AI site involved.
- Which AI agent acted, and in which application (VS Code, a terminal, the browser).
- The machine it happened on, the time, the verdict, and the reason it was flagged.
- The name of the operating-system account Siphrix runs under on that
machine (for example
ana.pop), reported at each check-in, so your organisation can tell whose machine it is. It is not a record of who was at the keyboard at any moment. - The browser extension records that its what-is-recorded screen was shown, and when.
What is never recorded
- File contents. Siphrix records that a file was touched, never what is inside it.
- Message or conversation text. The browser extension notices that a paste looked secret-shaped; it does not store what you typed or what the AI replied.
- Browsing history. By default the extension runs only on the AI sites named in its manifest, plus any your organisation adds, and reports nothing about any other site. Your organisation can widen that to “everywhere except listed sites”. If it does, the browser itself asks you to grant the extra permission, which you can decline or later revoke; and on a page that is not an AI site the extension then notices only secret- or PII-shaped pastes — it does not record that the page was visited, its address, or anything else on it. A plain browse produces nothing. Which mode applies to you, and which sites are watched, is stated in the extension’s own popup.
- Credentials. Values shaped like tokens, API keys or passwords are masked (
token=***) before anything is written or synced.
Where it goes
By default, nowhere. The record is written to your own machine
(~/.siphrix) or, for the browser extension, to that browser's local
storage.
If you connect a machine to a console — one you run yourself, or your account at siphrix.com — the record syncs to that console and nowhere else. Connecting is always deliberate: you enter a one-time connection code. Sync is outbound only; nothing on your machine listens for incoming connections. What the console itself can pass on, and only when your organisation sets it up, is listed under Optional outbound integrations.
The connection token
When you link a machine to a console you enter a one-time connection code. The machine keeps the resulting token locally and sends it with each sync, so the console knows which of your computers is reporting. It authenticates the link and nothing else: it is not a password, it carries no personal detail, and revoking the connection in Surfaces kills it immediately.
One code connects a computer, not each piece of software on it. The browser extension asks the Siphrix already running on that machine which computer it is on, over a local bridge that never leaves the device — so on a machine you have already set up, the extension needs no code and stores no credential at all. An extension is the easiest thing on a computer to read, and a token that is not there cannot be taken. Only a browser on a machine with no Siphrix installed holds one of its own.
Your account
Accounts are provisioned by your organization's administrator, or created when you accept an invitation they send you — there is no self-serve signup. For each account we store your email address, a hash of your password (never the password), your organization and role, and the records your machines send. Passwords are hashed; session tokens expire. We do not use your data for advertising, we do not sell it, and we do not share it with third parties.
How long it is kept
A new account keeps its record for 90 days. An owner or admin can change that: any window from 30 days to ten years, or “forever” for a record held under a legal duty that outlasts any window. Older entries are pruned automatically, on the server, once an hour, and the change of window is itself written on the record. Pruning preserves tamper-evidence: an anchor is sealed before deletion so the remaining chain still verifies. A legal hold placed by an admin pauses all pruning until it is released.
The window is the employer’s decision, not ours, and theirs to justify.
Romanian employers should know that Law 190/2018, art. 5(e), caps personal data
from workplace monitoring at 30 days unless a longer period is expressly
justified or required by law. The console lists 30 days in Settings →
Keeping & deleting the record; the API accepts it too (POST /v1/retention
with {"days": 30}). Accounts opened before this default existed keep
the window they had, including “forever”, until someone changes it.
Deleting your data
Local records: delete ~/.siphrix, or the extension's storage by
removing the extension. Account data: remove a device in Surfaces to stop
its sync, or write to us to delete the account and everything in it.
Optional outbound integrations
Three features send data outside siphrix.com, and only when an owner or admin of your organisation sets them up:
- By email: a weekly report to an email address you enter. It carries counts only: how many entries were recorded, how many were flagged and how many warnings were raised, the number of actions and of flagged ones for each AI agent, and the three most frequent kinds of action. No machine, no file path, no command, no person.
- Alerts to a webhook you provide (Slack, Teams, or any https:// inbox), sent as each warning reaches the console — which is when the machine next reports, within minutes, not the instant it happens. What an alert can carry: the warning's name, severity and verdict, the kind of action (or of data a paste looked like), how many times it has happened so far, the machine's name, the web site's host name or the app it happened in, when, and a link back to the console — never a file path, a command, file contents or message text.
- A stream to your security tooling (a SIEM), set up through the API; the console has no screen for it. Each destination is a JSON webhook, a Splunk HTTP Event Collector or a syslog collector over TLS, and receives one of two things: the alerts above, with the same facts, or every entry flagged for review (a warning, or a high or critical risk). A flagged entry is sent with the fields the console shows for it: the action and its target — a file path, a command line or a web address, the AI agent, the application and tool, the verdict, the risk and why it was decided, the reason it was flagged, the machine's name and identifier, the time, and the entry's place in the record. A destination shaped for Slack or Teams is given only the alert facts, on either stream. Never file contents or message text, because the record holds neither, and a target leaves with the credential-shaped values in it already masked.
Separately, your organisation can take its own record out: a CSV or JSON export, the evidence bundle, or the OData feed that Power BI or Microsoft Sentinel reads with a key your organisation issues. That is your organisation fetching its record, not Siphrix sending it, and it carries everything the console shows, targets included.
Children
Siphrix is a developer and business tool and is not directed at children under 13.
Changes
When this policy changes, the date at the top changes and the change is listed here, newest first. The list starts after the version of 7 September 2026.
- 25 September 2026. Optional outbound integrations names all three features and what each can carry. It had named two: the stream to a SIEM was missing, and a flagged entry on that stream carries its file path or command line, which an alert never does. It had also said alerts were instant and listed less than an alert carries. This section stopped promising an announcement in the console, which nothing in the console makes.
- 16 September 2026. What is recorded gained the operating-system account each machine reports, and the entry the browser extension writes when its what-is-recorded screen is shown.
- 8 September 2026. Teams replaced PagerDuty among the alert inboxes, and the 30-day window became a choice in the console.
Contact
Questions, or a data request: privacy@siphrix.com.