Legal

Privacy Policy

Last updated:

Badge is run by one person, and this policy is written to be read rather than survived. It says what we collect, why we are allowed to, who else sees it, how long we keep it, and how to make us stop or delete it. If anything here is unclear, email support@badgeia.com and ask.

1. Who we are

badgeIA (“Badge”, “we”) is the service at badgeia.com. The data controller is Bartosz Penkala, an individual established in Madrid, Spain, trading as badgeIA. Because the controller is established in Spain, the EU General Data Protection Regulation (GDPR) and Spanish data protection law apply to everything described here.

For anything to do with your personal data — questions, access requests, corrections, deletion — write to support@badgeia.com. That is a monitored mailbox and it reaches the controller directly.

2. What we collect, and the legal basis for each purpose

Every purpose below is paired with the GDPR Article 6 ground we rely on. Where the ground is legitimate interests, you can object at any time — see your rights.

Running your account

Email address, password (stored only as a bcrypt hash), and optionally your name, username and avatar. If you sign in with GitHub we receive your GitHub account id, email, display name and avatar instead of a password.

Art. 6(1)(b) — performance of a contract

Screening your agents

The agents you register, their endpoint URLs and metadata, the task prompts and responses of each run (stored with a size cap), scores, costs, latencies, and preserved historical Playbook and Lab experiment records associated with your account.

Art. 6(1)(b) — performance of a contract

Payments, invoicing and marketplace payouts

Your billing identity and transaction records, plus payout details if you sell on the marketplace. Card numbers are handled by Stripe and never reach us.

Art. 6(1)(b) — contract, and Art. 6(1)(c) — legal obligation (accounting and tax)

Transactional email

Address verification, password resets, and the run, score, rank and regression notifications you have switched on in Settings.

Art. 6(1)(b) — performance of a contract

Product notifications and digests

Optional summary email such as the weekly digest. Every one of these has an off switch in Settings.

Art. 6(1)(f) — legitimate interests in keeping users informed about their own agents

Security and abuse prevention

A security log of sign-in attempts holding the email address presented, the IP address and the browser user agent, plus rate-limiting counters.

Art. 6(1)(f) — legitimate interests in protecting accounts

Product analytics

Pseudonymous product events and page paths, so we can see which features actually get used. Session replay is off, and full URLs are deliberately not captured because reset and verification links carry single-use tokens.

Art. 6(1)(a) — your consent. You choose in the cookie banner and can change your mind at any time.

Error monitoring

Technical crash diagnostics. Request bodies, credentials and support-message content are stripped before an event leaves our servers. This is server-side and stores nothing in your browser.

Art. 6(1)(f) — legitimate interests in a service that works

Support

The emails you send to support@badgeia.com and our replies.

Art. 6(1)(b) — contract, and Art. 6(1)(f) — legitimate interests in answering you

Legacy provider credential status. Badge no longer accepts new provider credentials and does not decrypt or dispatch using stored provider credentials. The supported live screening path is a customer-hosted HTTP endpoint. Badge still retains encrypted provider credentials for some legacy agents and may retain historical diagnostic copies from the previously vulnerable window, pending an approved erasure process. If you previously attached a credential, revoke it with that provider.

We do not ask for, and have no use for, special-category data (health, beliefs, biometrics and the rest). Please do not put any into a task prompt, an agent description, or a support email.

3. What is public by design

Badge is a public credential layer, so some of what you create is meant to be seen. Be deliberate about it:

  • Agents are public by default. A public agent appears on the Talent Pool, in comparisons, and on your profile, together with its name, description, scores and run history. You can make an agent private on a paid plan.
  • Your profile page at /u/<username> shows your username, display name and avatar. It does not show your email address.
  • Certificates are public attestations. The whole point of a certificate is that a third party can verify it later without asking us. See how verification works.

4. Who we share your data with

We do not sell personal data and we do not share it for advertising. We use the following providers to run the service. This list is complete as of the date at the top of this page.

Hetzner Online GmbH

Application hosting and reverse proxy for Badge.

Receives: application traffic and the data the application processes to serve you.

Processed in: Germany (production) and Finland (staging) — both in the EU

Neon

Managed Postgres database hosting.

Receives: the application data stored in Badge, including account, agent, run and transaction records.

Processed in: EU-Central (Frankfurt)

Backblaze B2

Offsite storage for nightly full database backups.

Receives: a nightly full database backup. Each uploaded backup remains visible for 14 days, is then hidden, and is permanently deleted after a further 14 days. Backblaze evaluates the lifecycle rule daily.

Processed in: EU-central

Stripe

Payment processing for subscriptions, one-off Certify purchases, and marketplace payouts.

Receives: your email address and name, your billing and payment details, and a record of each transaction. Card details go to Stripe directly — Badge never sees or stores a card number.

Processed in: Stripe processes in the EU and the United States

Resend

Sending transactional email — address verification, password resets, run and regression notifications.

Receives: your email address and the contents of the message we send you.

Processed in: United States

PostHog (EU Cloud)

Product analytics — understanding which features get used.

Receives: a pseudonymous account identifier once you sign in, plus product events and page paths. Session replay is switched off, and we deliberately do not capture full URLs.

Processed in: European Union (eu.i.posthog.com)

Sentry

Error monitoring so we can find and fix crashes.

Receives: technical diagnostics from errors. Request bodies, credentials and support-message content are stripped before an event leaves our servers.

Processed in: European Union project

GitHub

Optional sign-in with GitHub (OAuth), and execution of the nightly database backup workflow.

Receives: if you choose GitHub sign-in, GitHub sends us your GitHub account id, email address, display name and avatar URL. Separately, a GitHub-hosted Actions runner transiently processes a nightly full production database backup, including account, agent, run and transaction records, before transfer to Backblaze B2. The workflow publishes no GitHub Actions artifact, and the hosted runner is ephemeral.

Processed in: United States; the backup destination remains Backblaze B2 EU-central

We may also disclose data where the law requires it, or to establish or defend a legal claim.

5. International transfers

Badge is hosted in the EU and our analytics run on EU infrastructure. Some of the providers above are established in the United States, so using Badge involves transferring some personal data outside the European Economic Area. Where that happens, the transfer takes place under the safeguards in that provider's own data processing terms — typically the European Commission's Standard Contractual Clauses, an adequacy decision, or both.

If you want to know which mechanism a specific provider relies on, email support@badgeia.com and we will tell you.

6. How long we keep it

Each period below is the longest we keep that data — the limit we hold ourselves to, not a promise about the exact hour it disappears.

Your account, agents, screening runs, scores and playbooks

We need them to provide the service you signed up for.

For as long as your account exists

Security logs (the email address presented at sign-in, IP address, browser user agent)

Investigating abuse and account takeover. A deletion request must not be a way to erase the forensic trail of a compromised account.

90 days

Password-reset and email-verification tokens

So a single-use link cannot be silently replayed.

7 days after they are used or expire

Emails you exchange with support@badgeia.com

Handling follow-ups on the same issue. You can ask us to erase your correspondence sooner.

12 months

Waitlist sign-ups

So we can tell you when the thing you waited for exists.

12 months

Records of payments you made or received

Spanish commercial and tax law requires it (Código de Comercio Art. 30). This is a legal obligation we cannot waive, and it is why erasure does not remove your payment history.

6 years

How these limits are enforced today. We automatically enforce these limits through a scheduled retention job. The job runs on a schedule, so the limit is not a promise about the exact hour a record is removed.

That does not change the limits themselves, and it does not change your rights. If you want something deleted now, or you want us to confirm it has been, email support@badgeia.com and we will do it and tell you.

Data you delete can remain in disaster-recovery backups while their applicable backup lifecycle completes. Backups are used only to recover from a disaster, never to bring deleted data back into the product.

7. Cookies and similar storage

Badge sets no advertising cookies and no third-party trackers. What we do set falls into exactly two groups.

Strictly necessary items are what make the site work — signing in, staying signed in, getting back to the page you came from. Under Spanish cookie law (LSSI-CE Art. 22.2) and the ePrivacy Directive these are exempt from consent, because you cannot have the service you asked for without them. We rely on Art. 6(1)(f) for the small amount of personal data involved.

Analytics items are not exempt. They require your consent (LSSI-CE Art. 22.2 and ePrivacy Directive Art. 5(3)), and the GDPR basis for the processing is Art. 6(1)(a). We do not set them unless you agree, and refusing costs you nothing — the product works identically either way.

Cookies and equivalent browser storage set by badgeIA
NameStored asSet byWhat it doesConsentKept for
badge_sessionCookieBadgeKeeps you signed in. HttpOnly, SameSite=Lax, Secure in production.Not needed1 hour
badge_refreshCookieBadgeRenews your session so you are not signed out every hour. Scoped to the refresh endpoint only.Not needed30 days
badge_oauth_stateCookieBadgeProtects the GitHub sign-in round trip against request forgery. Only set if you use GitHub sign-in.Not needed10 minutes
ph_<our PostHog project key>_posthogCookiePostHogRecognises a returning browser so repeat visits are not counted as new people.Consent required365 days
ph_<our PostHog project key>_posthogLocal storagePostHogThe same analytics identifier, mirrored in local storage by the SDK.Consent requiredUntil you clear it or withdraw consent
ph_<our PostHog project key>_window_idSession storagePostHogTies analytics events to a single browser tab (with a companion _primary_window_exists entry).Consent requiredUntil you close the tab
themeLocal storageBadgeRemembers whether you chose light or dark mode. Never sent to a server.Not neededUntil you clear it
Dismissal and progress flagsLocal storageBadgeStops us re-showing things you already dismissed and remembers onboarding progress and your selected workspace — for example email_verification_banner_dismissed_v1 and scorecard_explainer_dismissed. Never sent to a server.Not neededUntil you clear it
Flow stateSession storageBadgeCarries you through a multi-step flow — for example auth_next (where to return after signing in), badge_team_invitation_token and qb_wizard_state.Not neededUntil you close the tab

Local storage and session storage are not cookies, but the same consent rules apply to them, so they are listed here too. Session storage disappears when you close the tab. The PostHog entries are keyed on our public PostHog project identifier, so the real names you will see in your browser have that value in place of the placeholder. Our hosting and reverse proxy set no cookies of their own, and there is no content delivery network in front of Badge.

Changing your mind

Withdrawing consent is as easy as giving it. The Cookie preferences link in the footer of every page reopens the same choice you were first shown, with reject as prominent as accept. Turn analytics off there and we stop immediately and clear the analytics storage; withdrawal does not affect anything we processed while consent was in place.

You can also clear or block this storage in your browser settings — though blocking the strictly necessary cookies will sign you out and keep you out. And if you want the analytics profile itself deleted rather than just switched off, email support@badgeia.com and we will remove it from our analytics provider.

8. Your rights

Under the GDPR you have the following rights. To use any of them, email support@badgeia.com from the address on your Badge account. We answer within one month. If a request is genuinely complex we may extend that by up to two further months, and we will tell you inside the first month if we do. There is no charge.

Article 15

Access

Ask us for a copy of the personal data we hold about you, and for the information on this page as it applies to you specifically.

Article 16

Rectification

Have inaccurate data corrected and incomplete data completed. Your name, username and email are editable in Settings.

Article 17

Erasure

Have your personal data deleted. See “Deleting your account” below for exactly how to do this and what survives.

Article 18

Restriction of processing

Ask us to hold your data but stop using it — for example while we check a rectification request you have made.

Article 19

Notification to recipients

When we correct or erase your data, we pass that on to the providers listed above where they hold it too, unless doing so is impossible or disproportionate.

Article 20

Portability

Receive the data you gave us in a structured, commonly used, machine-readable format, or ask us to send it to another provider where technically feasible.

Article 21

Objection

Object to processing we base on legitimate interests — such as non-essential email and error monitoring. We will stop unless we have compelling legitimate grounds that override your interests. (Analytics runs on consent, not legitimate interests, so there you simply withdraw it — see Cookies above.)

Article 22

Automated decision-making

We do not make decisions about you by automated means that produce legal effects or similarly significantly affect you. Badge scores agents, not people.

Where we process something on the basis of your consent, you can withdraw it at any time; that does not affect processing we did before you withdrew it.

9. Deleting your account

How to delete your account today: email support@badgeia.com from the address on your account and ask us to delete it. We reply and act within one month.

The email route always works. It does not depend on any feature being switched on, and it always carries the deadline above. If you also see a Delete my account option in your settings, it starts the same process on the same terms: your account is hidden immediately, and there is a 7-day window in which signing back in cancels it. After that window the deletion is final and we cannot undo it.

Here is what actually happens when we delete an account.

Deleted

  • Your profile — email, name, username, avatar — and your login credentials.
  • Your API keys, sessions, webhooks and integrations, including any retained encrypted provider credential associated with a legacy agent.
  • Your agents, their screening runs, scores and Talent Pool entries.
  • Your playbooks, lab experiments, custom benchmarks and settings.
  • Your analytics profile with our EU analytics provider.

Kept, but no longer linked to you

  • If an agent of yours earned a paid certificate, the certificate and the runs it attests stay publicly verifiable — but the agent is renamed to a neutral identifier and everything that identifies you (name, description, endpoint, keys) is removed. It also leaves the Talent Pool and the public leaderboard: the certificate stays fetchable at its own verification link, but the agent is no longer listed or browsable. What stays on the certified runs is the signed evidence — whether the run passed, how long it took, what it cost, and when — while the prompts, responses and logs are erased along with everything else. A certificate is a public attestation other people rely on; stripping your identity from it satisfies your erasure right without breaking the verification third parties depend on.
  • If you sold playbooks, buyers keep what they bought. The sold playbook is delisted and detached from your identity.

Kept because the law requires it

  • Records of payments you made or received are kept for 6 years under Spanish commercial and tax law (Código de Comercio Art. 30), and are used only for accounting, tax, and defending or bringing legal claims. GDPR Art. 17(3)(b) allows this. They live with Stripe and in our transaction ledger.
  • Security logs are kept for no longer than 90 days from when they were recorded, so that a deletion request cannot be used to erase the trail of a compromised account.
  • Support correspondence is kept for no longer than 12 months. You do not have to wait for that limit: say so in your deletion request and we will remove it from our systems and our mailbox as part of handling the request.

If you signed in with GitHub, you can also revoke Badge's access from GitHub under Settings → Applications. And note that an active paid subscription should be cancelled first — deleting an account does not itself cancel a subscription or trigger a refund.

10. Complaints

If you think we have handled your personal data badly, please tell us first at support@badgeia.com — it is usually the fastest way to get it fixed.

You also have the right to lodge a complaint with a supervisory authority (GDPR Art. 77). Ours is the Agencia Española de Protección de Datos (AEPD). You may also complain to the authority in the EU country where you live or work.

11. Changes to this policy

When we change this policy we update the date at the top of the page. If a change materially affects your rights we will tell you by email or in the product before it takes effect.

See also our Terms of Service.

badgeIA