This policy explains what personal data we collect across tomphillips.uk and SentinelProxy(at sentinelproxy.tomphillips.uk), why, who it's shared with, and the rights you have over it.
§01Who's responsible, and in what role
Tom Phillips, a sole trader based in the United Kingdom, operates the Service. Contact: tom@tomphillips.uk.
- Data controller — for your account and website data (registration details, support messages, technical logs). We decide how and why this is processed.
- Data processor — for the logs you send through SentinelProxy (“Customer Data”). You are the controller of that data and of any personal data within it; we process it only on your instructions, to provide the Service.
§02What we collect
- Account data — email address, password (hashed by Supabase Auth), display name, workspace name.
- Customer Data (ingested logs) — the system prompts, user inputs, model responses, latency and metadata your agents send to our ingestion endpoint. Common personal data patterns (emails, phone numbers, payment-card numbers, national insurance numbers, IP addresses) are redacted at the edge, on a best-effort basis, before the log is stored.
- Your Anthropic API key — if you enable Bring Your Own Key, your key is stored encrypted (AES-256-GCM) and used only to make model calls for your workspace. It is never shown again or sent to your browser.
- Technical data — request logs (IP, user agent), rate-limit counters, and error diagnostics, used for security and debugging and held briefly.
- Payment data — when paid plans launch: name, email, billing details and card data processed by Stripe (we never see or store card numbers).
- Support data — messages you send us, retained as long as needed to resolve them.
§03Why we use your data
- To run your account (sign-in, password reset).
- To ingest, evaluate, and self-heal the agent logs you send — the core SentinelProxy function.
- To process payments and send receipts (when paid plans launch).
- To send service-related emails (password resets, security and key-failure alerts).
- To respond to support questions.
- To detect and prevent fraud, abuse, and security incidents, and to enforce rate limits.
- To meet legal obligations (e.g. retaining transaction records for tax).
We don't sell or rent personal data, we don't send marketing emails, and we don't use Customer Data to train machine-learning models. Evaluations call Anthropic's Claude API, which does not train on data submitted through the API.
§04Legal bases (UK GDPR Article 6)
- Contract (6(1)(b)) — to provide the Service you've signed up for.
- Legitimate interest (6(1)(f)) — security logging, abuse prevention, and running a stable service.
- Legal obligation (6(1)(c)) — retention of transaction records for HMRC.
- Consent (6(1)(a)) — for non-essential cookies/analytics.
For Customer Data we act on your documented instructions as your processor; your own lawful basis as controller covers any personal data it contains.
§05Cookies & analytics
- Essential — sign-in session and security cookies. These can't be turned off without breaking the site and don't require consent under UK PECR.
- Functional — remembers UI preferences such as dismissed help hints, stored in your browser's localStorage.
- Analytics — privacy-respecting usage and performance analytics (Vercel), loaded only with your consent.
You can change your choice any time via . Rejecting non-essential cookies leaves the Service fully functional.
§06Sub-processors
We rely on a small number of vetted third parties:
- Supabase (EU region) — database, authentication, storage.
- Vercel (USA / global edge) — application hosting, content delivery, and analytics.
- Anthropic (USA) — the Claude API that evaluates your logs and generates fixes. API data is not used for training. If you enable BYOK, these calls run through your own Anthropic account instead of ours.
- Resend (USA) — transactional and alert email.
- Stripe (Ireland / USA) — payment processing, when paid plans launch.
Each sub-processor is bound by a data-processing agreement. International transfers rely on the UK's adequacy regulations where applicable, and on Standard Contractual Clauses where not.
§07Retention
- Account data — until you delete your workspace.
- Customer Data (ingested logs) — purged automatically by plan: Free tier after 3 days, paid tiers after 30 days. Deleting a project or workspace removes its logs immediately.
- Your encrypted Anthropic key — until you remove it or delete your workspace.
- Technical logs — typically around 30 days.
- Payment records — at least 6 years where required by UK tax law, limited to what the law requires.
- Support correspondence — as long as needed to resolve and for a reasonable follow-up window.
§08Your rights
Under UK GDPR you have the right to:
- Access — a copy of the personal data we hold about you.
- Rectification — correct inaccurate data.
- Erasure — delete your data (you can delete your workspace yourself from Account).
- Portability — your data in a structured, machine-readable format.
- Restriction or objection — limit how we use your data.
- Withdraw consent — for anything processed on the basis of consent.
- Complain to the ICO (ico.org.uk) if you believe we've handled your data unlawfully.
Where a request concerns personal data inside Customer Data, the end-user should usually contact you (the controller); we'll assist you in responding. To exercise your own rights, email tom@tomphillips.uk. We aim to respond within 30 days.
§09Security
We use industry-standard practices: TLS in transit; password hashing via Supabase Auth; database row-level security so one tenant's query can never see another's data; edge redaction of common PII before logs are stored; AES-256-GCM encryption of any Bring-Your-Own Anthropic key; and least-privilege keys for third-party services. No system is perfectly secure — report any vulnerability responsibly to tom@tomphillips.uk and we won't pursue good-faith researchers.
§10Children
The Service isn't aimed at children under 18 and accounts are restricted to adults. If you believe a child has registered, please tell us.
§11Changes & contact
We may update this policy from time to time; the effective date above shows the most recent revision, and material changes will be flagged in-product. For any privacy question — access, deletion, or complaint — email tom@tomphillips.uk.