1. Purpose of this page
This page helps organisations assess Agent Logger's data flow. It is not a countersigned data processing agreement and does not change the controller and processor roles created by law. Contact us if your organisation needs a signed DPA for a separately agreed enterprise service.
2. Data roles
| Activity | Typical role |
|---|---|
| Agent Logger account, licence, payment, fraud prevention, and support | Continual Labs normally acts as an independent controller, as described in the Privacy Policy |
| Browser context processed only inside the customer's extension and local MCP runtime | The customer controls the processing; Continual Labs does not receive the content in normal operation |
| Browser context the customer sends to its chosen AI assistant | The customer's agreement with that AI provider determines their respective roles |
| Content deliberately supplied to Continual Labs for a support case | Continual Labs processes it to provide and secure support, under the Privacy Policy or an applicable written agreement |
3. Local product data flow
Screenshots, DOM details, URLs, console errors, network diagnostics, and selected page content are not uploaded to Continual Labs during ordinary use. They move between the selected browser tab, the extension, the local Agent Logger runtime, and the AI assistant the customer configured.
- The customer decides which users, sites, tabs, and AI providers are authorised.
- The customer is responsible for notices, lawful basis, access controls, and instructions concerning data subjects in its browser content.
- Local artifacts and state remain on customer-controlled devices until removed through product, browser, runtime, or operating-system controls.
- Customers should avoid production personal data where test data or redaction will meet the development purpose.
4. Hosted service information
| Category | Examples | Hosted provider |
|---|---|---|
| Account and authentication | Email, name, user ID, session and security events | Supabase and Vercel |
| Licence and device | Entitlement, pseudonymous installation fingerprint, device label, browser, timestamps | Supabase and Vercel |
| Payment | Customer and transaction IDs, amount, status, consent, cancellation, refund and dispute state | Stripe, Supabase, and Vercel |
| Card data | Payment card number, expiry, security checks | Stripe; Continual Labs does not receive or store the full card details |
| Support and lifecycle communication | Support contact details and message, optional email preferences, consent and delivery timestamps | Supabase, Vercel, and Hostinger |
5. Service providers
- Supabase: authentication and PostgreSQL database; the current project is hosted in a Japan region.
- Stripe: hosted card setup, payment processing, fraud prevention, refunds, and disputes.
- Vercel: website and API hosting, content delivery, deployment, and infrastructure logs.
- Hostinger: Agent Logger mailbox hosting and SMTP delivery for payment, support, and optional lifecycle messages.
Providers may use affiliated infrastructure and approved sub-processors. Where Continual Labs acts as a processor under a signed agreement, we will provide the applicable provider list and change notice mechanism in that agreement. Transfers outside the UK must use an adequacy route or appropriate safeguards such as the UK IDTA or UK Addendum where required.
6. Security measures
- TLS for hosted network traffic and Stripe-hosted collection of card details
- Supabase row-level security and separation of public, authenticated, and service credentials
- Signed short-lived entitlements and revocation for official paid access
- Explicit local pairing, authenticated reconnect, scoped methods, payload limits, and fail-closed handling
- Selected-tab monitoring and user-initiated capture controls
- Secret scanning, dependency review, deterministic release packaging, and restricted publish workflows
- Logs designed to use request IDs and error codes rather than browser content, credentials, screenshots, or card data
Security is a shared responsibility. Customers must secure endpoints, browser profiles, MCP clients, AI-provider credentials, and the sites and data their users can access.
7. Assistance and incidents
For a service security issue, contact us without including live credentials or unnecessary personal data. Where a signed agreement makes Continual Labs a processor, incident notification, data-subject assistance, deletion, return, audit information, and regulator support will follow that agreement and applicable law.
8. Evaluation checklist
- Document the sites, data classes, user roles, AI provider, and lawful purpose for your deployment.
- Configure the smallest tab and feature permissions needed.
- Review the AI provider's DPA, retention, model-training, and international-transfer settings.
- Set an internal retention process for local screenshots, artifacts, logs, and support exports.
- Test revocation, account offboarding, device removal, and incident response before production use.
Contact Information
Product: Agent Logger
Company: Continual Labs Limited (company no. 17387340)
Email: hello@agentlogger.com
Registered office: 23 Oaklands Road, Northfleet, Gravesend, England, DA11 8PA
Website: agentlogger.com