Legal
Privacy Policy
Last updated:
Badge is run by one person, and this policy is written to be read rather than survived. It says what we collect, why we are allowed to, who else sees it, how long we keep it, and how to make us stop or delete it. If anything here is unclear, email support@badgeia.com and ask.
1. Who we are
badgeIA (“Badge”, “we”) is the service at badgeia.com. The data controller is Bartosz Penkala, an individual established in Madrid, Spain, trading as badgeIA. Because the controller is established in Spain, the EU General Data Protection Regulation (GDPR) and Spanish data protection law apply to everything described here.
For anything to do with your personal data — questions, access requests, corrections, deletion — write to support@badgeia.com. That is a monitored mailbox and it reaches the controller directly.
2. What we collect, and the legal basis for each purpose
Every purpose below is paired with the GDPR Article 6 ground we rely on. Where the ground is legitimate interests, you can object at any time — see your rights.
Running your account
Email address, password (stored only as a bcrypt hash), and optionally your name, username and avatar. If you sign in with GitHub we receive your GitHub account id, email, display name and avatar instead of a password.
Art. 6(1)(b) — performance of a contract
Screening your agents
The agents you register, their endpoint URLs and metadata, the task prompts and responses of each run (stored with a size cap), scores, costs, latencies, and preserved historical Playbook and Lab experiment records associated with your account.
Art. 6(1)(b) — performance of a contract
Payments, invoicing and marketplace payouts
Your billing identity and transaction records, plus payout details if you sell on the marketplace. Card numbers are handled by Stripe and never reach us.
Art. 6(1)(b) — contract, and Art. 6(1)(c) — legal obligation (accounting and tax)
Transactional email
Address verification, password resets, and the run, score, rank and regression notifications you have switched on in Settings.
Art. 6(1)(b) — performance of a contract
Product notifications and digests
Optional summary email such as the weekly digest. Every one of these has an off switch in Settings.
Art. 6(1)(f) — legitimate interests in keeping users informed about their own agents
Security and abuse prevention
A security log of sign-in attempts holding the email address presented, the IP address and the browser user agent, plus rate-limiting counters.
Art. 6(1)(f) — legitimate interests in protecting accounts
Product analytics
Pseudonymous product events and page paths, so we can see which features actually get used. Session replay is off, and full URLs are deliberately not captured because reset and verification links carry single-use tokens.
Art. 6(1)(a) — your consent. You choose in the cookie banner and can change your mind at any time.
Error monitoring
Technical crash diagnostics. Request bodies, credentials and support-message content are stripped before an event leaves our servers. This is server-side and stores nothing in your browser.
Art. 6(1)(f) — legitimate interests in a service that works
Support
The emails you send to support@badgeia.com and our replies.
Art. 6(1)(b) — contract, and Art. 6(1)(f) — legitimate interests in answering you
Legacy provider credential status. Badge no longer accepts new provider credentials and does not decrypt or dispatch using stored provider credentials. The supported live screening path is a customer-hosted HTTP endpoint. Badge still retains encrypted provider credentials for some legacy agents and may retain historical diagnostic copies from the previously vulnerable window, pending an approved erasure process. If you previously attached a credential, revoke it with that provider.
We do not ask for, and have no use for, special-category data (health, beliefs, biometrics and the rest). Please do not put any into a task prompt, an agent description, or a support email.
3. What is public by design
Badge is a public credential layer, so some of what you create is meant to be seen. Be deliberate about it:
- Agents are public by default. A public agent appears on the Talent Pool, in comparisons, and on your profile, together with its name, description, scores and run history. You can make an agent private on a paid plan.
- Your profile page at
/u/<username>shows your username, display name and avatar. It does not show your email address. - Certificates are public attestations. The whole point of a certificate is that a third party can verify it later without asking us. See how verification works.
4. Who we share your data with
We do not sell personal data and we do not share it for advertising. We use the following providers to run the service. This list is complete as of the date at the top of this page.
Hetzner Online GmbH
Application hosting and reverse proxy for Badge.
Receives: application traffic and the data the application processes to serve you.
Processed in: Germany (production) and Finland (staging) — both in the EU
Neon
Managed Postgres database hosting.
Receives: the application data stored in Badge, including account, agent, run and transaction records.
Processed in: EU-Central (Frankfurt)
Backblaze B2
Offsite storage for nightly full database backups.
Receives: a nightly full database backup. Each uploaded backup remains visible for 14 days, is then hidden, and is permanently deleted after a further 14 days. Backblaze evaluates the lifecycle rule daily.
Processed in: EU-central
Stripe
Payment processing for subscriptions, one-off Certify purchases, and marketplace payouts.
Receives: your email address and name, your billing and payment details, and a record of each transaction. Card details go to Stripe directly — Badge never sees or stores a card number.
Processed in: Stripe processes in the EU and the United States
Resend
Sending transactional email — address verification, password resets, run and regression notifications.
Receives: your email address and the contents of the message we send you.
Processed in: United States
PostHog (EU Cloud)
Product analytics — understanding which features get used.
Receives: a pseudonymous account identifier once you sign in, plus product events and page paths. Session replay is switched off, and we deliberately do not capture full URLs.
Processed in: European Union (eu.i.posthog.com)
Sentry
Error monitoring so we can find and fix crashes.
Receives: technical diagnostics from errors. Request bodies, credentials and support-message content are stripped before an event leaves our servers.
Processed in: European Union project
GitHub
Optional sign-in with GitHub (OAuth), and execution of the nightly database backup workflow.
Receives: if you choose GitHub sign-in, GitHub sends us your GitHub account id, email address, display name and avatar URL. Separately, a GitHub-hosted Actions runner transiently processes a nightly full production database backup, including account, agent, run and transaction records, before transfer to Backblaze B2. The workflow publishes no GitHub Actions artifact, and the hosted runner is ephemeral.
Processed in: United States; the backup destination remains Backblaze B2 EU-central
We may also disclose data where the law requires it, or to establish or defend a legal claim.
5. International transfers
Badge is hosted in the EU and our analytics run on EU infrastructure. Some of the providers above are established in the United States, so using Badge involves transferring some personal data outside the European Economic Area. Where that happens, the transfer takes place under the safeguards in that provider's own data processing terms — typically the European Commission's Standard Contractual Clauses, an adequacy decision, or both.
If you want to know which mechanism a specific provider relies on, email support@badgeia.com and we will tell you.
6. How long we keep it
Each period below is the longest we keep that data — the limit we hold ourselves to, not a promise about the exact hour it disappears.
Your account, agents, screening runs, scores and playbooks
We need them to provide the service you signed up for.
For as long as your account exists
Security logs (the email address presented at sign-in, IP address, browser user agent)
Investigating abuse and account takeover. A deletion request must not be a way to erase the forensic trail of a compromised account.
90 days
Password-reset and email-verification tokens
So a single-use link cannot be silently replayed.
7 days after they are used or expire
Emails you exchange with support@badgeia.com
Handling follow-ups on the same issue. You can ask us to erase your correspondence sooner.
12 months
Waitlist sign-ups
So we can tell you when the thing you waited for exists.
12 months
Records of payments you made or received
Spanish commercial and tax law requires it (Código de Comercio Art. 30). This is a legal obligation we cannot waive, and it is why erasure does not remove your payment history.
6 years
How these limits are enforced today. We automatically enforce these limits through a scheduled retention job. The job runs on a schedule, so the limit is not a promise about the exact hour a record is removed.
That does not change the limits themselves, and it does not change your rights. If you want something deleted now, or you want us to confirm it has been, email support@badgeia.com and we will do it and tell you.
Data you delete can remain in disaster-recovery backups while their applicable backup lifecycle completes. Backups are used only to recover from a disaster, never to bring deleted data back into the product.
7. Cookies and similar storage
Badge sets no advertising cookies and no third-party trackers. What we do set falls into exactly two groups.
Strictly necessary items are what make the site work — signing in, staying signed in, getting back to the page you came from. Under Spanish cookie law (LSSI-CE Art. 22.2) and the ePrivacy Directive these are exempt from consent, because you cannot have the service you asked for without them. We rely on Art. 6(1)(f) for the small amount of personal data involved.
Analytics items are not exempt. They require your consent (LSSI-CE Art. 22.2 and ePrivacy Directive Art. 5(3)), and the GDPR basis for the processing is Art. 6(1)(a). We do not set them unless you agree, and refusing costs you nothing — the product works identically either way.
| Name | Stored as | Set by | What it does | Consent | Kept for |
|---|---|---|---|---|---|
| badge_session | Cookie | Badge | Keeps you signed in. HttpOnly, SameSite=Lax, Secure in production. | Not needed | 1 hour |
| badge_refresh | Cookie | Badge | Renews your session so you are not signed out every hour. Scoped to the refresh endpoint only. | Not needed | 30 days |
| badge_oauth_state | Cookie | Badge | Protects the GitHub sign-in round trip against request forgery. Only set if you use GitHub sign-in. | Not needed | 10 minutes |
| ph_<our PostHog project key>_posthog | Cookie | PostHog | Recognises a returning browser so repeat visits are not counted as new people. | Consent required | 365 days |
| ph_<our PostHog project key>_posthog | Local storage | PostHog | The same analytics identifier, mirrored in local storage by the SDK. | Consent required | Until you clear it or withdraw consent |
| ph_<our PostHog project key>_window_id | Session storage | PostHog | Ties analytics events to a single browser tab (with a companion _primary_window_exists entry). | Consent required | Until you close the tab |
| theme | Local storage | Badge | Remembers whether you chose light or dark mode. Never sent to a server. | Not needed | Until you clear it |
| Dismissal and progress flags | Local storage | Badge | Stops us re-showing things you already dismissed and remembers onboarding progress and your selected workspace — for example email_verification_banner_dismissed_v1 and scorecard_explainer_dismissed. Never sent to a server. | Not needed | Until you clear it |
| Flow state | Session storage | Badge | Carries you through a multi-step flow — for example auth_next (where to return after signing in), badge_team_invitation_token and qb_wizard_state. | Not needed | Until you close the tab |
Local storage and session storage are not cookies, but the same consent rules apply to them, so they are listed here too. Session storage disappears when you close the tab. The PostHog entries are keyed on our public PostHog project identifier, so the real names you will see in your browser have that value in place of the placeholder. Our hosting and reverse proxy set no cookies of their own, and there is no content delivery network in front of Badge.
Changing your mind
Withdrawing consent is as easy as giving it. The Cookie preferences link in the footer of every page reopens the same choice you were first shown, with reject as prominent as accept. Turn analytics off there and we stop immediately and clear the analytics storage; withdrawal does not affect anything we processed while consent was in place.
You can also clear or block this storage in your browser settings — though blocking the strictly necessary cookies will sign you out and keep you out. And if you want the analytics profile itself deleted rather than just switched off, email support@badgeia.com and we will remove it from our analytics provider.
8. Your rights
Under the GDPR you have the following rights. To use any of them, email support@badgeia.com from the address on your Badge account. We answer within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you inside the first month if we do. There is no charge.
Article 15
Access
Ask us for a copy of the personal data we hold about you, and for the information on this page as it applies to you specifically.
Article 16
Rectification
Have inaccurate data corrected and incomplete data completed. Your name, username and email are editable in Settings.
Article 17
Erasure
Have your personal data deleted. See “Deleting your account” below for exactly how to do this and what survives.
Article 18
Restriction of processing
Ask us to hold your data but stop using it — for example while we check a rectification request you have made.
Article 19
Notification to recipients
When we correct or erase your data, we pass that on to the providers listed above where they hold it too, unless doing so is impossible or disproportionate.
Article 20
Portability
Receive the data you gave us in a structured, commonly used, machine-readable format, or ask us to send it to another provider where technically feasible.
Article 21
Objection
Object to processing we base on legitimate interests — such as non-essential email and error monitoring. We will stop unless we have compelling legitimate grounds that override your interests. (Analytics runs on consent, not legitimate interests, so there you simply withdraw it — see Cookies above.)
Article 22
Automated decision-making
We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. Badge scores agents, not people.
Where we process something on the basis of your consent, you can withdraw it at any time; that does not affect processing we did before you withdrew it.
9. Deleting your account
How to delete your account today: email support@badgeia.com from the address on your account and ask us to delete it. We reply and act within one month.
The email route always works. It does not depend on any feature being switched on, and it always carries the deadline above. If you also see a Delete my account option in your settings, it starts the same process on the same terms: your account is hidden immediately, and there is a 7-day window in which signing back in cancels it. After that window the deletion is final and we cannot undo it.
Here is what actually happens when we delete an account.
Deleted
- Your profile — email, name, username, avatar — and your login credentials.
- Your API keys, sessions, webhooks and integrations, including any retained encrypted provider credential associated with a legacy agent.
- Your agents, their screening runs, scores and Talent Pool entries.
- Your playbooks, lab experiments, custom benchmarks and settings.
- Your analytics profile with our EU analytics provider.
Kept, but no longer linked to you
- If an agent of yours earned a paid certificate, the certificate and the runs it attests stay publicly verifiable — but the agent is renamed to a neutral identifier and everything that identifies you (name, description, endpoint, keys) is removed. It also leaves the Talent Pool and the public leaderboard: the certificate stays fetchable at its own verification link, but the agent is no longer listed or browsable. What stays on the certified runs is the signed evidence — whether the run passed, how long it took, what it cost, and when — while the prompts, responses and logs are erased along with everything else. A certificate is a public attestation other people rely on; stripping your identity from it satisfies your erasure right without breaking the verification third parties depend on.
- If you sold playbooks, buyers keep what they bought. The sold playbook is delisted and detached from your identity.
Kept because the law requires it
- Records of payments you made or received are kept for 6 years under Spanish commercial and tax law (Código de Comercio Art. 30), and are used only for accounting, tax, and defending or bringing legal claims. GDPR Art. 17(3)(b) allows this. They live with Stripe and in our transaction ledger.
- Security logs are kept for no longer than 90 days from when they were recorded, so that a deletion request cannot be used to erase the trail of a compromised account.
- Support correspondence is kept for no longer than 12 months. You do not have to wait for that limit: say so in your deletion request and we will remove it from our systems and our mailbox as part of handling the request.
If you signed in with GitHub, you can also revoke Badge's access from GitHub under Settings → Applications. And note that an active paid subscription should be cancelled first — deleting an account does not itself cancel a subscription or trigger a refund.
10. Complaints
If you think we have handled your personal data badly, please tell us first at support@badgeia.com — it is usually the fastest way to get it fixed.
You also have the right to lodge a complaint with a supervisory authority (GDPR Art. 77). Ours is the Agencia Española de Protección de Datos (AEPD). You may also complain to the authority in the EU country where you live or work.
11. Changes to this policy
When we change this policy we update the date at the top of the page. If a change materially affects your rights we will tell you by email or in the product before it takes effect.
See also our Terms of Service.