Privacy Policy
Troxy is an AI governance and policy enforcement platform. We handle your account data, policy configurations, and agent activity logs to evaluate and govern your AI agents' actions. We do not sell your data, share it with advertisers, or use it for any purpose beyond operating the service.
1. Who We Are
Troxy ("we", "us", "our") operates the Troxy platform available at troxy.io, including the dashboard at dash.troxy.io and the Troxy CLI. We provide AI governance, policy enforcement, and agent activity monitoring for our users.
For questions about this policy, contact us at [email protected].
2. Data We Collect
Account data
- Email address (used to authenticate and communicate with you)
- Account creation date and last login
Policy and agent configuration
- Governance policies you define (action types, thresholds, rules, target domains)
- Agent names and connected MCP server configurations
- Notification preferences (email, Telegram) and associated contact details
Agent activity and audit data
- Actions evaluated by Troxy, including the action type, agent identity, decision (allow, block, escalate, notify), policy matched, and timestamp
- Payload metadata for evaluated actions (action target, domain, category — not full payload content)
- Secrets detection results, including the type of sensitive data detected and the action taken, with redacted previews of the detected pattern
- This data populates your dashboard activity feed and audit trail
Escalation and approval data
- When an action is escalated, the action context is stored so you can review and approve or deny it from the dashboard
- Approval decisions (approved, denied) and the timestamp of each decision
Usage data
- Pages visited within the dashboard, actions taken (anonymized event tracking)
- API request logs (IP address, timestamp, endpoint) retained for security and debugging
AI provider keys
- If you use the Troxy chat feature, your AI provider API key (Anthropic, OpenAI, etc.) is stored in your browser's localStorage only. It is sent with each chat request to our API, used to call the provider on your behalf, and is never stored on our servers
Notification channel credentials
- If you enable Telegram notifications, your Telegram bot token and chat ID are stored encrypted at rest
- If you enable email notifications, your email address is used for delivery
- These credentials are used solely to deliver governance alerts and notifications
3. How We Use Your Data
- To evaluate agent actions against your configured policies in real time
- To display agent activity, audit trails, and policy outcomes in your dashboard
- To deliver governance alerts and escalation notifications via your configured channels
- To detect and flag sensitive data (API keys, credentials) in agent payloads
- To maintain security logs for debugging and abuse prevention
- To improve our secrets detection patterns and policy templates (using aggregated, anonymized data only)
- To communicate with you about your account, policy updates, and service changes
We do not use your data to train AI models. We do not share agent payload content with third parties.
5. Data Sharing
We do not sell, rent, or share your data with third parties for advertising or marketing purposes. We share data only in the following circumstances:
- Notification delivery: When you enable email or Telegram notifications, we send alert content to your configured delivery channels. This includes action summaries and policy decision details
- Legal compliance: If required by law, court order, or government regulation, we may disclose data subject to legal review
- Service providers: We use infrastructure providers (cloud hosting, email delivery) that process data on our behalf under data processing agreements. These providers do not have access to use your data independently
- Business transfers: In the event of a merger, acquisition, or asset sale, data may be transferred as part of the transaction, subject to the same privacy protections
6. Data Retention
- Account data is retained for as long as your account is active
- Agent activity logs and audit trails are retained for 90 days by default. You can export logs before they expire
- Escalation records (including action context) are retained for 90 days after resolution
- Secrets detection results are retained for 90 days with redacted previews only — full secret content is never stored
- API request logs are retained for 30 days for security and debugging purposes
- When you close your account, your data is deleted within 30 days, except where retention is required by law
7. Security
- Your API keys are hashed (bcrypt) and never stored in plaintext
- Troxy uses TLS 1.2+ for all data in transit and AES-256 encryption at rest
- Notification channel credentials (Telegram tokens) are encrypted at rest
- Secrets detection does not persistently store detected secret content. Only redacted metadata is logged
- We conduct regular security reviews and do not use third-party analytics or data partners
- No third-party tracking scripts are loaded in the dashboard
- If you believe your account has been compromised, contact [email protected] immediately
8. Your Rights
Depending on your jurisdiction (EU GDPR, California CCPA, Israel PPL), you may have the following rights regarding your data:
- Access: Request a copy of your personal data
- Rectification: Request correction of inaccurate data
- Erasure: Request deletion of your personal data (subject to legal retention requirements)
- Portability: Request an export of your data in a machine-readable format
- Objection: Object to certain processing of your data
- Withdrawal: Withdraw consent for data processing at any time
To exercise these rights, contact [email protected]. We will respond within 30 days.
9. Children's Privacy
Troxy is not intended for use by individuals under 18. We do not knowingly collect data from children. If you believe a minor has provided us with personal data, contact [email protected] and we will delete it.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or dashboard notification at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.
11. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
- Email: [email protected]
- Security: [email protected]
- Website: troxy.io