Privacy Policy.
What we collect, why we collect it, and the things D3 Edge is built never to see.
1. Introduction
This Privacy Policy explains how D3 Global, Inc. (“D3,” “we,” “us”) handles personal information in connection with D3 Edge: the ai.d3.com website, the robots.txt grader, the agent index and feed, the D3 Edge SDK and edge adapters, and the dashboard at ai.d3.com/app (together, the “Services”).
D3 Edge is a product about machine traffic. Most of what it processes is not personal information at all — it is evidence about automated clients: which agent made a request, whether it signed that request, and what purpose it declared. Two design choices shape the rest: verification runs inside your own edge rather than on our servers, and what we keep is a narrowed record of each evaluation rather than the raw request.
Where we handle personal information as part of your deployment, you are the controller and we act as your processor under your instructions. Where we handle information about our own users, prospects, and site visitors, we are the controller.
2. Information We Collect
Information you provide to us
Account and organization information. The email address you sign in with — we send a sign-in link rather than issuing a password — along with your profile, your organization and its members, the domains you register to it, your communication preferences, and the settings you configure, including the adapter keys you create. Keys themselves are stored only as hashes; a key is shown once and we cannot recover it.
Contact and interest information. What you send through the contact form or the robots.txt checker, such as your email address and the domain you asked about. We do not record your IP address on that form.
Support correspondence. What you send us when you get in touch.
Information we collect automatically
Signals your websites send us. When the SDK or adapter evaluates a request reaching your site, it sends the signals needed to tell agent traffic apart from everything else — including, but not limited to, the hostname and path requested, the IP address, and request headers such as user-agent, signature, and purpose headers. We narrow this before storing it: we do not keep the request body or the query string, and an IP address is kept only as a salted hash, or not at all where no salt is configured.
Deployment telemetry. What your adapter did with each request, key-authentication failures so you can spot a leaked or undeployed key, and — where you route origin logs to us — response sizes for the bytes-saved estimate.
Session and site information. A session token and its expiry, the IP address and user-agent of the signing-in browser, and ordinary server logs for ai.d3.com, kept briefly for security and reliability.
Information from third parties
Public registries and directories. The agent index is built from public sources — key directories, published crawler lists, and vendor-operated registries — plus our own verification. These describe software, not people.
Domain and registrar data. Where you register a domain to your organization, we use registrar and DNS records, including data available to D3 as a registrar, to confirm control and to establish a domain’s age and history.
Anti-abuse. Cloudflare Turnstile returns a pass or fail for form submissions.
3. How We Use Your Information
We use the information above to:
- provide the Services — classify traffic, publish and sign the feed, run the dashboard, and enforce the policy you configure;
- authenticate you, keep accounts secure, and investigate suspected abuse of keys or of the index;
- build agent risk profiles and agent analytics across all the organizations we serve, on an anonymized basis, so the index and the trust profiles get better for everyone;
- publish research and aggregate statistics about agentic traffic, in a form that identifies neither you, your site, nor any individual;
- respond to your enquiries, provide support, send product updates you asked for, and send service messages you cannot opt out of while you hold an account; and
- comply with law and enforce our Terms.
We do not sell personal information, share it for cross-context behavioral advertising, or use your content or your end users’ data to train models. Traffic data feeding the cross-organization profiles is anonymized first, so what those profiles describe is agent behavior — not you, your site, or any individual.
4. Legal Basis for Processing
For people in the UK, EEA, and other jurisdictions with an equivalent framework, we rely on:
- performance of a contract — operating your account and the Services;
- legitimate interests — securing the Services, preventing abuse, understanding agentic traffic at an aggregate level, and business-to-business communications, balanced against your rights;
- consent — product-update email, which you can withdraw at any time; and
- legal obligation — where retention or disclosure is required of us.
5. Sharing of Information
We share personal information only in these circumstances:
- Within your organization. Administrators can see their organization’s members, keys, analytics, and policy configuration.
- Service providers acting on our instructions — hosting and edge infrastructure, managed databases, and transactional email, currently including Cloudflare, PlanetScale, and AWS. This list is representative rather than exhaustive. We contract them to protect the data and use it only for us.
- Professional advisers, for legal, accounting, or audit work.
- Legal and safety disclosure, where required by law or necessary to protect our rights, our users, or the public. We will tell you about a request for your data unless legally prohibited.
- Corporate transactions — a merger, acquisition, or sale of assets — subject to this Policy continuing to apply.
We do not share Your Data with agent operators, and we do not tell an agent operator which of our customers is seeing its traffic.
6. Agentic Traffic Data
Traffic records are the bulk of what the Services process, so two commitments about them are worth stating on their own.
IP hashing is one-way and salted per deployment, so a stored record cannot be used to reconstruct a visitor’s address or to follow a person between deployments. We do not attempt to identify individual human visitors from this data, and using the Services for that purpose is prohibited under the Terms.
Traffic data feeds the shared index only in anonymized, aggregated form — agent behavior, carrying no identifiers of you, your site, or any individual.
7. International Transfers
We are based in the United States and our infrastructure providers operate globally, so information may be processed outside your country, including in the United States.
Where we transfer personal information out of the UK or EEA, we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the technical measures described in this Policy. Contact us for details of the safeguards applied to a particular transfer.
8. Your Rights
Depending on where you live, you may have the right to access the personal information we hold about you, correct it, delete it, restrict or object to processing, receive it in a portable format, and withdraw consent. Where we act as your processor, we refer a request concerning your deployment to you and support you in answering it.
You can exercise most of these directly: update your profile and organization in the dashboard, revoke keys, export analytics, unsubscribe using the link in any product email, and close your account.
For anything else, email privacy@d3.com. We respond within the time the applicable law allows and will not treat you differently for asking. In the UK or EEA, you may also complain to your local supervisory authority.
9. Data Retention
We keep personal information only as long as we need it:
- Account, organization, and key metadata: for the life of the account, plus a short period afterwards for disputes and legal obligations.
- Sessions: until they expire or you sign out.
- Traffic and outcome records: a rolling window sized to the analytics your plan provides, after which they are deleted or reduced to anonymized aggregates.
- Contact-form submissions and support correspondence: as long as needed to follow up, then under our ordinary business-records schedule.
- Marketing consent records: until you withdraw consent, plus a record of the withdrawal so it stays honored.
Aggregates that identify no one may be kept indefinitely.
10. Security
We hold no credentials to your infrastructure — the adapter runs in your account, deployed by you — which removes the largest category of risk before it starts. Beyond that: adapter keys are stored only as hashes, database access is least-privilege, the feed is signed and versioned so your edge can verify it before applying it, and traffic between components is encrypted in transit.
No system is perfectly secure. If a breach affects your personal information, we will notify you and the relevant authorities as the law requires.
11. Children’s Privacy
The Services are business tools, are not directed to children, and are not intended for anyone under 18. We do not knowingly collect personal information from children. If you believe a child has given us information, email privacy@d3.com and we will delete it.
12. Changes to This Privacy Policy
We may update this Policy. We will post the new version here with a fresh “last updated” date, and where a change materially affects how we handle personal information we will give notice through the dashboard or by email before it takes effect.
13. Contact Us
Privacy questions, or to exercise a right: privacy@d3.com.
D3 Global, Inc. — see d3.com for our current registered address.