The short version
Surehand is the controller for the data this policy covers. Contact: support@surehand.io.
We collect as little as we need. We keep a log of what our systems do with engagement data. We do not sell data.
Surehand is the controller for the data this policy covers. Contact: support@surehand.io.
We collect as little as we need. We keep a log of what our systems do with engagement data. We do not sell data.
Through this website, we collect the name and email address you give us and the process you describe in the teardown form. We also keep standard technical logs (IP address, browser type, pages visited) for security and to fix faults.
Through an engagement, we handle the business data inside its written scope, such as mail, documents and records in the systems you connect. We also keep the sealed record Gatehouse writes for each run.
We measure how this site is used so we can tell which pages help. For basic traffic counts we use Vercel Web Analytics. It sets no cookies and counts page views, the site you came from, your country and your device type. It also records how far down a page people scroll and which buttons and outbound links they press, with nothing that identifies you. Vercel Speed Insights measures page load times the same way. Neither can identify you, so both run for everyone without asking.
Google Analytics and Microsoft Clarity are not loaded today. If we add them, they load only after you accept when asked. Both set cookies, and Clarity records how pages are used, including mouse movement, clicks and scrolling. Choosing Essential only means neither is loaded, and you keep the full site.
If we add them, your choice is saved in your browser's local storage and sets no cookie. Clearing the site data asks you again, and a Cookie choices link in the footer lets you change your answer.
We use website data to reply to you, to keep the site secure and working, and to count which pages help. We use it for nothing else.
Engagement data is used to deliver the contracted service, and for nothing else. Agents act only inside their written scope. Access beyond that scope is a defect and we treat it as one.
Where our agents call model providers, only the data needed for that run is sent, inside the engagement's scope. We do not train models on your data, and the providers' API terms we use rule out training on it.
Each call counts against the run's spend limit. The sealed record logs each crossing: when it happened, which provider and why.
Website data goes to Vercel (hosting), Discord (lead notifications) and Resend (email, where enabled). Google Analytics and Microsoft Clarity are not loaded today, so they receive nothing. Engagement data goes to the model providers named in the engagement's signed manifest, under API terms that exclude training. The full list is on the trust page.
We share nothing with advertising networks or data brokers.
We disclose data to authorities only where the law requires it, and we tell you when we are allowed to.
We keep website emails while the conversation is open, then archive them, or delete them if you ask. We keep engagement data for the term the engagement states, then return or delete it. We keep sealed records for the agreed retention period. They are yours, and you receive them when the engagement ends.
You can ask what we hold about you, and ask for it to be corrected, exported or deleted. You can withdraw consent for anything based on consent.
Write to support@surehand.io. A person replies, usually inside two business days, and the request is logged.
If this policy changes in a way that matters, we update the date at the top of this page. If we are working with you, we also tell you directly.
Send any question about this page to support@surehand.io, and a person will reply.