Privacy
Last updated: October 9, 2026
Visitors
No accounts, no ad trackers, no cookies set by us. We may use Cloudflare Web Analytics, which is cookieless and does not fingerprint visitors. Our host (Cloudflare) processes standard request logs (IP, user agent) for security and abuse prevention.
Indexed repositories
We index public GitHub repositories only and store derived structure (component names, counts, rule text from permission lists, hook commands with secrets redacted) plus public repo metadata (owner, name, avatar URL, stars, license, last push). We never store environment-variable values, header values or anything matching our secret patterns. Owners can opt out at any time via the opt-out form; opted-out repos and accounts are removed at the next build and excluded from future crawls.
Submissions
If you submit a rig or an opt-out request we store the repo URL, optional email, the request time and a salted hash of your IP (for rate limiting). Agent self-submissions additionally store the JSON payload you approved. We use your email only to reply about that request. Delete requests: hello@agentrigs.dev.
Newsletter
If you subscribe to The Rig Report we store your email, the signup time, where you signed up, a confirmation flag, a random unsubscribe token and a salted hash of your IP (rate limiting). We use your address only to send the newsletter; we never sell or share it. Every email has a one-click unsubscribe link, and unsubscribing stops all mail immediately.
Rig Doctor
Files you paste into the Rig Doctor are analysed in your browser and never sent to us. For a repo URL, our server fetches the public agent-config files, redacts secret-looking values and returns the result; nothing is stored. Share links contain only the summary numbers (and the repo name, if any).
Payments
Payments are processed by Stripe; we receive your name, email and payment status, never your card details.