Trust & data handling
A plain statement of what Ablehand processes, where it goes, and for how long. Companion to the security & trust model. Not a legal contract; the DPA is a separate document.
What the widget sends, and to whom
| Data | Sent to | Purpose | Notes |
|---|---|---|---|
| The user's goal text and clarifications | Ablehand edge โ TypeSafe (Jev) | Choose the next control | Redacted for card/SSN/token patterns before leaving the browser |
| An indexed table of visible controls (role + label + coarse context) | Ablehand edge โ TypeSafe (Jev) | Choose the next control | Never selectors, HTML, or hidden/password/payment fields |
| A bounded slice of visible page text | Ablehand edge โ TypeSafe (Jev) | Disambiguate | Redacted in-browser; per-site policy can add email/phone/IP/custom masking |
| The goal text, only when a form field must be composed | Ablehand edge โ OpenAI | Generate a short typed value | Only if the site enables generative_text |
| Page titles/headings/action labels of visited pages | Ablehand edge (catalog) | Suggest and jump to pages | Page-level only; opt out with passive_index: false |
| Goal outcome (status, steps, rating) | Ablehand edge (analytics) | Operator dashboard, metering | Goal text is PII-scrubbed at ingest; no_log disables persistence |
Never sent anywhere: cookies, local storage, auth tokens, request/response bodies, password / file / hidden inputs, payment-provider iframes, or any element the site's deny lists exclude.
Subprocessors
| Subprocessor | Role | Data | Region |
|---|---|---|---|
| Vercel | Hosting for the edge API, widget bundle, and site | All request data in transit; runtime logs | US (iad1 / sfo1) |
| Neon (via Vercel Marketplace) | Postgres for tenant config, catalog, traces, outcomes, usage | Persisted analytics and configuration | US |
| TypeSafe (Jev) | Structured decision model | Goal, control table, visible-text slice | US |
| OpenAI | Generative text for typed fields (optional per site) | Goal text and field label | US |
Retention
Per site, retention_days (default 90) bounds how long decision traces and
goal outcomes are kept; a daily job deletes older rows. Usage counters (daily
totals per key, no content) are kept for billing. Sites can set no_log to
persist nothing beyond usage counters.
Access and controls
- Site keys are public identifiers scoped to registered origins; they grant no data access. Rotate or revoke via the admin API/console.
- Admin access is token-gated; every guardrail/hint/key change is appended to an audit table with who/when/what.
- Redaction floor (cards, SSNs, tokens, keys) cannot be disabled by any config.
Open items on the compliance path
External penetration test, SOC 2 Type II, a signed DPA template, and a data-subject-request procedure are not yet in place. See the build checklist.