Skip to content
dispatchr

Legal / privacy

Privacy policy.

last updated 2026-08-10

On this page
In short

This site keeps 30-day server logs and nothing else: no cookies, no analytics, and the contact form is a demo. The app collects what it takes to run your tests, encrypts your credentials, and never trains models on your data. Write to legal@godispatchr.ai and a human answers within a month.

01

Who we are

This policy is issued by Dispatchr Labs Inc., a corporation organized under the laws of the State of Delaware, USA (Delaware file number 10721314) ("dispatchr", "we", "us", "our"). Our registered address is c/o our registered agent, Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Our operations are based in Dublin, Ireland. The persons responsible for the website are Adam Bell and Ranbir Singh Jhass.

For the purposes of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the "GDPR"), we are the controller of the personal data described in this policy. We have not appointed a Data Protection Officer, and none is required for processing of this scale. Contact for all privacy matters: legal@godispatchr.ai.

02

One policy, two places

dispatchr lives at two addresses. godispatchr.ai (the "Site") is this marketing website: informational only, with no accounts and no payments. dispatchr.dev (the "Application") hosts the dispatchr application, an invite-only closed beta in which autonomous agents test our customers' software.

This one policy covers both. Sections 03 to 05 describe the Site, sections 06 to 11 describe the Application, and sections 12 to 17 apply to everything. Use of the Site is governed by our Terms of use (/legal/terms); use of the Application is governed by the Beta terms (/legal/beta).

03

The marketing site: what we collect

Server logs. Our infrastructure records a log entry for every request made to the Site. Each entry contains:

  • your IP address
  • the path requested and the HTTP method
  • your browser's user-agent string
  • the referring page (referer header), where your browser sends one
  • coarse geolocation (country and city) derived from the request
  • a timestamp

Contact form. The contact form on the Site is a user-interface demonstration. It does not transmit or store what you type, on our servers or anywhere else. The real channel is email.

Nothing else. The Site has no accounts, no payments, no newsletter, and no waitlist: beta invitations are outbound only, meaning we approach design partners ourselves, so there is no signup form collecting your details. Automated agents reading our public pages are welcome and are logged the same way as any other visitor; a machine-readable summary of the Site is available at /llms.txt.

04

The marketing site: why we log, and for how long

We process server logs for three purposes: security (detecting and investigating attacks), abuse prevention (identifying and blocking abusive traffic), and operational monitoring (diagnosing errors and keeping the Site available).

The legal basis is our legitimate interest in operating a secure and reliable website, Article 6(1)(f) GDPR. We consider this interest to outweigh the minimal intrusion of a short-lived log entry because the logs are never used to profile you or make decisions about you and are deleted within 30 days.

Server logs are retained for no longer than 30 days and are then deleted automatically. We retain no other personal data through the Site.

05

The marketing site: cookies, hosting, and transfers

The Site sets no cookies and uses no local-storage tracking, no analytics, no fingerprinting, no third-party scripts, and no advertising technology of any kind. PostHog, the analytics tool used in the Application, does not run here. There is nothing to consent to, which is why the Site shows no cookie banner. For details, see the Cookie statement at /legal/cookies.

The Site is hosted by Vercel Inc. (USA), which processes server logs on our behalf as a processor under Article 28 GDPR. Logs are therefore transferred to and stored in the USA; these transfers are safeguarded by the European Commission's Standard Contractual Clauses. We do not sell personal data and we do not share it for advertising or marketing.

06

The application: what we collect

When you use the Application, we process four categories of data:

  • Account identity: your name, email address, and workspace details
  • Test targets and configurations: the systems you point our agents at and the instructions you give us for testing them, including credentials you provide for those systems
  • Test results: findings, logs, screenshots, and recordings captured from the software under test
  • Product usage telemetry: how the Application itself is used, so we can fix and improve it

Target credentials are stored encrypted at rest and are used only to run the tests you configure, nothing else.

You own all test results and reports the Application produces for you. We take only the license we need to operate the service on your behalf; the Beta terms spell this out.

07

We never train models on your data

We never train or fine-tune AI models on customer data. Not on your targets, not on your credentials, not on your test results, not on your telemetry.

The AI models that power our agents are self-hosted on infrastructure dispatchr controls. No external AI provider processes customer data: nothing you give the Application is sent to a third-party model API.

08

Personal data inside test content

The software our agents test is yours, so test results can contain personal data from your systems: a name in a screenshot, an email address in a log line.

During the beta, we handle this content under the mutual confidentiality clause of the Beta terms. Please minimize the personal data our agents can encounter: where you can, point them at staging environments seeded with synthetic data rather than at production.

We will offer a Data Processing Agreement under Article 28 GDPR at general availability. We do not offer one yet, and this policy will be updated when we do.

09

The application: hosting, subprocessors, and cookies

Application data is hosted on Amazon Web Services (AWS) across multiple regions. Where processing occurs outside the European Economic Area, transfers are safeguarded by the European Commission's Standard Contractual Clauses.

PostHog (PostHog Cloud EU, hosted in the European Union) processes product usage telemetry on our behalf as a subprocessor.

The Application sets strictly necessary session and authentication cookies, plus PostHog analytics. There is no advertising and no cross-site tracking anywhere, on the Site or in the Application. We may disclose data where required by applicable law or legal process, or to establish, exercise, or defend legal claims; we never sell it.

10

The application: retention, export, and deletion

We keep customer data for as long as your account is open, because the Application needs it to run and re-run your tests.

Export. Ask us within 30 days of your account closing and we will export your results in a reasonable format.

Deletion. Customer data is deleted within 30 days of account closure or of your deletion request.

11

Security and breach notification

Target credentials are encrypted at rest, and we apply appropriate technical and organizational measures to protect customer data. We also keep customer data and test results confidential under the Beta terms.

If we confirm a personal-data breach that affects you, we will notify you without undue delay, and we will notify the competent supervisory authority where the GDPR requires it.

12

Emails we send

The only emails we send are service emails: security notices, changes to our terms or this policy, and operational messages about your account or your runs. We send no marketing email and there is no newsletter.

13

Legal bases at a glance

In summary, our legal bases under the GDPR are:

  • Site server logs: legitimate interests, Article 6(1)(f) (security, abuse prevention, operational monitoring)
  • Application account data, targets, configurations, and test results: performance of a contract, Article 6(1)(b) (providing the service under the Beta terms)
  • Product usage telemetry and service security: legitimate interests, Article 6(1)(f) (understanding, improving, and protecting the service)
  • Retention or disclosure the law demands: legal obligation, Article 6(1)(c)

Where we rely on legitimate interests, you can object; see section 14.

14

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Article 15)
  • have inaccurate data rectified (Article 16)
  • have your data erased (Article 17)
  • restrict our processing (Article 18)
  • receive your data in a portable format (Article 20)
  • object to processing based on legitimate interests (Article 21)

To exercise any of these rights, email legal@godispatchr.ai. We will respond within one month of receiving your request, as Article 12(3) GDPR requires, and we will tell you if we need to extend that period for a complex request. Exercising your rights is free of charge.

One honest caveat for the Site: raw log entries are not indexed by name or identity, so we may be unable to link a request to you without additional information from you (Article 11 GDPR). Where that is the case, we will say so and explain what we would need.

15

Complaints

If you believe our processing infringes the GDPR, you have the right to lodge a complaint with a supervisory authority. Our lead contact point is the Irish Data Protection Commission (DPC, dataprotection.ie). If you live in another EU or EEA country, you may instead complain to the supervisory authority of your country of residence or place of work. We would appreciate the chance to address your concern first at legal@godispatchr.ai, but you are not required to contact us before complaining.

16

Automated decisions and children

We do not carry out automated decision-making that produces legal or similarly significant effects concerning you within the meaning of Article 22 GDPR. Our agents make automated assessments of software, not of people.

No one under 16 may use the Site or the Application, and neither is directed at children. If you believe a child has provided us with personal data, contact legal@godispatchr.ai and we will delete it.

17

Changes and contact

If our data practices change, we will update this policy and its revision date before the change takes effect, and we will flag material changes prominently on the Site. Material changes that affect Application customers are also emailed to account holders. The version published here is always the current one.

Dispatchr Labs Inc., registered address c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA. Operations based in Dublin, Ireland. For questions about this policy, or anything else concerning your personal data, write to legal@godispatchr.ai. A human reads that inbox.