Privacy Policy

Applies to the Siphrix engine, the browser extension, the VS Code extension and the console at siphrix.com. Last updated 28 July 2026.

The short version

Siphrix exists to record what AI agents do on your behalf. It records metadata about actions — never the content those actions carry. Nothing is sent anywhere until you explicitly connect a machine to a console you chose. There is no telemetry, and we do not sell or share your data with anyone.

What is recorded

What is never recorded

Where it goes

By default, nowhere. The record is written to your own machine (~/.siphrix) or, for the browser extension, to that browser's local storage.

If you connect a machine to a console — one you run yourself, or your account at siphrix.com — the record syncs to that console and nowhere else. Connecting is always deliberate: you enter a one-time connection code. Sync is outbound only; nothing on your machine listens for incoming connections.

The connection token

When you link a browser or a machine to a console you enter a one-time connection code. The device keeps the resulting token locally and sends it with each sync, so the console knows which of your devices is reporting. It authenticates the link and nothing else: it is not a password, it carries no personal detail, and revoking the device in Surfaces kills it immediately.

Your account

If you create an account at siphrix.com we store your email address, a hash of your password (never the password), your organization and role, and the records your machines send. Passwords are hashed; session tokens expire. We do not use your data for advertising, we do not sell it, and we do not share it with third parties.

How long it is kept

Forever by default, because an audit record with holes is not an audit record. You can set a retention window (90, 180, 400 or 730 days) in the console; older entries are then pruned automatically. Pruning preserves tamper-evidence: an anchor is sealed before deletion so the remaining chain still verifies.

Deleting your data

Local records: delete ~/.siphrix, or the extension's storage by removing the extension. Account data: remove a device in Surfaces to stop its sync, or write to us to delete the account and everything in it.

Optional outbound integrations

Two features send data outside siphrix.com, and only when you set them up yourself: a weekly report to an email address you enter, and instant alerts to a webhook you provide (Slack, PagerDuty, a SIEM). Alerts carry the rule name, action type and severity — never file contents or message text.

Children

Siphrix is a developer and business tool and is not directed at children under 13.

Changes

If this policy changes materially, the date above changes and the change is announced in the console.

Contact

Questions, or a data request: privacy@siphrix.com.