Agent Watch contact@agent-watch.ai

Privacy

Last updated 4 September 2026

Agent Watch measures what AI coding agents cost an engineering team and applies the budgets that team sets. That needs token counts, not code.

What never leaves your machine

  • Your prompts, and the agent's responses.
  • Tool inputs and outputs, including shell commands and their output.
  • The contents of any file the agent reads or writes.
  • Your source code.
  • Credentials, tokens and environment variables.

One exception, named rather than buried: for each prompt and response we send a character count and a SHA-256 fingerprint of the text, to recognise duplicate turns. A fingerprint cannot be turned back into a prompt, but someone holding both it and a guess at the exact text could confirm the guess. We will disable it for your organisation on request.

What we collect

From the endpoint agent, once per completed turn:

  • Token counts, model name and the cost of the turn.
  • Your email address, from git config user.email unless your administrator configures a different one. Per-developer attribution is the product, so this is not optional.
  • The repository's remote URL with credentials stripped, the branch, the commit SHA, and the paths of files the agent touched. Paths only, never contents.
  • Tool names, timings and durations. Which coding agent and version, and the operating system.

From the web application: your name, email address and profile picture as your identity provider returns them, plus your organisation and your role in it. We set one session cookie to keep you signed in. There are no passwords, no advertising and no third-party trackers.

Every value is scrubbed for credential shapes before it is sent, whatever your settings say.

Signing in with Google

Google shares your name, email address, profile picture and, for Workspace accounts, your organisation's domain. We request nothing else — not Drive, not Gmail, not your calendar. Agent Watch's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. GitHub sign-in shares the equivalent profile information and nothing more.

Where it goes, and for how long

Agent Watch runs on Google Cloud in the United States. Three processors handle data on our behalf: Google Cloud (hosting and databases), Descope (sign-in) and Resend (transactional email). Your administrator may separately connect GitHub, Jira, Linear or Slack, and can revoke those at any time. We do not sell your data or share it with anyone else.

Usage records are kept for 12 months, so that spend can be analysed over time. Account records are deleted when your organisation's account closes. Data is encrypted in transit and at rest, and each organisation's data is isolated at the database level.

Your rights

Write to contact@agent-watch.ai to get a copy of your data, correct it, or have it deleted, and we will answer within 30 days. If Agent Watch holds your data on behalf of your employer we will refer the request to them, because it is theirs to release. A data processing agreement is available on request. Under the GDPR you may also complain to your national supervisory authority; we rely on the Standard Contractual Clauses for transfers out of the EU and UK.

Changes

If we change what we collect we will say so here and tell account administrators first. Agent Watch, Tel Aviv, Israel, is responsible for the data described on this page.