Skip to main content
FC File Contractsby Agentsor
How it works Data boundary Pricing Start free

Early-access privacy notice · version 2026-07-27-v3

File contents stay local. Account and run metadata do not.

This notice covers the Agentsor File Contracts website, account-verification flow, hosted receipt collector, backend receipt retention, and operational alerts. There is no customer dashboard or customer-visible run history in free early access. Hampus Johansson is the data controller. Contact hello@agentsor.ai or use the postal address in the footer.

What the service receives

When you request a monitor, the service receives your business email, a non-sensitive monitor label, selected cadence, consent record, request time, privacy-preserving abuse-prevention data, and a bounded user-controlled link-source hint. That hint helps compare owned pages but is not proof of where a visitor came from. When a client submits a run, the bearer token selects the server-side monitor. The fixed JSON body contains the envelope version, run identifier, start and finish time, overall result, file format, bounded observed row/byte counts, six fixed check statuses, fixed reason codes, and project-keyed contract/schema/output HMAC-SHA256 fingerprints. The raw ingest token is not stored after activation; the service stores its one-way digest.

What the service is designed not to receive

Do not submit file contents, rows, cell values, samples, filenames, filesystem paths, storage locations, hostnames, query text or results, credentials, personal data from the file, customer records, or free-form notes. The local verifier is designed to reject those fields from its hosted envelope. A fingerprint is not encryption of the underlying file and must not be treated as a substitute for keeping sensitive inputs local.

Purposes and legal bases

Monitor verification, ingest authentication, backend receipt retention, deadlines, incident detection, requested alerts, manual support, and verified data-rights requests are processed to provide the free early-access service you request and to take steps before a contract. Security logs, abuse controls, service integrity, and legal claims are processed for legitimate interests and applicable legal obligations.

File Contracts Pro is planned at $29 USD per month for up to 10 monitored feeds. The planned bundle includes 30-day redacted run history, two alert recipients, and self-serve ingest-token rotation, monitor pause, and monitor deletion. It would be month to month and cancellable before the next renewal. It does not currently include a customer dashboard or paid support SLA. No checkout, paid entitlement, or charge is available today.

If the email-verified activation client requests planned Pro paid early access with its separate short-lived one-time capability, we store the fixed plan, exact offer-copy hash and version, current privacy and terms versions, request time, existing monitor relationship, and exact one-response permission hash and version. The record proves possession of that capability after email verification; it does not prove a human clicked a particular control. We use that record only to measure requested paid access and, if the requested checkout becomes available, send the one response authorized. It is not marketing consent. The capability is separate from the long-lived machine ingest token. No card, bank, invoice, or other billing data is processed because no checkout or paid plan is currently offered.

Processors and transfers

The service uses infrastructure and email providers to host the application, database, backups, and requested transactional messages. Their processing locations and safeguards may change as vendors change. The current operator will maintain appropriate processor terms and transfer safeguards where required. The service does not sell account or run metadata.

Retention

Submitted redacted run receipts are configured for automatic deletion after the free service's seven-day receipt-retention period. This is backend retention, not a customer-visible history feature. The cleartext verification link and token in the transactional outbox are scrubbed when the message is sent or discarded, or when activation completes. The raw Pro-request capability is returned only in the email-verified activation response and is never stored; it becomes unusable after 30 minutes and is consumed by a request. Its one-way digest and bounded issuance, expiry, offer, notice, permission, and consumption metadata are retained with the other paid-interest evidence unless erased through the verified procedure below. Sent and discarded delivery rows are deleted after 30 days. If the email provider reports a bounce, suppression, or complaint, the service retains a domain-separated SHA-256 pseudonymous digest of the normalized address, a fixed reason, and timestamps so it does not send later transactional mail to that address after the ordinary delivery row is deleted. This suppression record is not treated as anonymous data and remains until a verified request or legal requirement justifies changing it. Verification, consent, monitor, incident, audit, paid-early-access request, and other operational metadata does not currently have a promised self-serve or fixed automated deletion interval. A verified closure or data-rights request is reviewed manually, subject to technical dependencies and any legal retention duty. The owner-only erasure procedure can remove the paid-interest request and its capability after verification while retaining a pseudonymous erasure-event digest, timestamp, fixed reason, and deletion counts for integrity and legal evidence. Encrypted backup copies age out under the documented 35-day backup rotation.

Your choices and rights

There are no self-serve token-rotation, alert, monitor-deletion, or account-deletion controls in free early access. You can stop local submissions at any time. To request manual token revocation, stop operational email, close a monitor, or exercise applicable access, correction, deletion, restriction, portability, or objection rights, email the contact above. The operator will verify authority and confirm the action and any data that must be retained. In-place token rotation is not available; a new verified activation creates a new monitor. You may complain to the Swedish Authority for Privacy Protection (IMY).

Security and limits

Ingest tokens are bearer credentials and must be protected like passwords. Stored tokens are one-way hashed; transport uses HTTPS; access is bounded; and backups are encrypted. No service can promise absolute security. Do not use early access for safety-critical, regulated, or high-risk decisions without independent controls.

Return to File Contracts

File Contracts by Agentsor

Local CSV and Parquet checks with hosted deadlines and transition alerts.

Privacy Terms Cron guide Python feed Source code Contact

© 2026 Agentsor

Operated by Hampus Johansson

Boelundsvägen 2A, 23252 Åkarp, Sweden

hello@agentsor.ai