What happens to your data
A factual description of what this Suhail deployment sends, to whom, and what it keeps. Generated from this server's live configuration, so it cannot drift from what the software actually does.
This is not a privacy policy or a contract.
It makes no promises and grants no rights. It is the engineering account of the
system, published so that you — and the lawyer who writes the policy — can see
what is actually true today.
Where this runs
This server's traffic reaches websites from KW. Sites you visit through Suhail see that location, not yours. Everything Suhail stores is stored on this one server.
What leaves this server
| What | Who receives it | Why |
|---|---|---|
| The task you typed, a screenshot of every page the run opens, that page's text and its accessibility tree, and any file you attach | openrouter (minimax/minimax-m3) | This is how the agent sees. There is no mode in which it works without sending them. |
| The same, onward to whichever vendor OpenRouter routes to | the provider OpenRouter routes to | Suhail sends data_collection=deny, so OpenRouter routes only to providers that do not retain or train on the request. |
| Voice notes you record | OpenAI (Whisper) | Speech-to-text only. |
| Search terms the agent composes from your task | The configured search API | Only when the agent searches; the page contents it then opens go to the model provider above, not back to the search vendor. |
| Your email and what you bought (never card details — those are typed on Stripe's own page, not ours) | Stripe | Payment for prepaid task packs. |
What never leaves
- Your stored passwords and other vault secrets. The model is given the name of a secret, never its value; the browser fills the real value in at the field, and a secret is bound to its registered domain so it cannot be typed on any other site.
- Anything to a recipient a web page asked for. Instructions found inside a page are treated as data, never as commands.
What is kept here, and for how long
| What | Where | Why |
|---|---|---|
| Your account and sign-in sessions | This server's database | So you can sign in. |
| Every run: its steps, a screenshot per step, the full model transcript, and what it cost | This server's database and disk | This is the audit trail — it is what lets you replay exactly what was done on your behalf. |
| Files you upload and files a run produces | This server's disk | So a run can attach them and you can download them. |
| The browser profile a run uses, including cookies for sites you signed into | This server's disk | So you do not sign in again on every run. |
| If you arrived from an advertisement: the campaign parameters on the link you followed, the site that referred you, and the fact that you signed up and that a first task was delivered | This server's database | So we can tell which advertising is worth paying for. It is not sent anywhere by Suhail, and no advertising or analytics cookie is set on you. |
Retention: there is no automatic deletion yet.
Runs, screenshots, transcripts and uploaded files are kept until somebody removes
them by hand. If you need something deleted, ask and it will be deleted. A stated
retention period is one of the things the privacy policy still has to decide.
What we have not done yet
- The terms of service and privacy policy are drafts awaiting counsel's review. There is no data-processing agreement yet. This page exists so that nothing is misrepresented in the meantime.
- There is no automated export or deletion. Both are done by hand on request.