Privacy
Last updated: September 7, 2026 (ACT/privacy categories clarified) · Independent BARZEL product (not affiliated with Metadata.io).
BARZEL is a private host-policy agent for AI agents running on hosts you control. This page explains what we collect for the early-access program and product communications, and how we use it.
What we collect
On barzel.dev (cloud)
- Early-access application: name, email, optional company/role, host OS, use-case description, and that you agreed to observe-first install + dual-gated ACT terms.
- Technical signals: a hashed IP and coarse request metadata for rate limiting and abuse prevention (not used for advertising).
- Onboarding / invite: invite token hashes, issue/onboard timestamps, and delivery status for private onboard links.
- Nested / debug / audit fields on applications: status history, mail queue reasons (for example
missing_AGENTMAIL_API_KEY), confirmation/invite message IDs when sent, and operator stamps such aslastInviteEmailedAt/confirmationEmailedAt. These support ops and support — not advertising. - Email: messages we send from BARZEL ops inboxes (application receipt, invite/onboard link) and replies you send back.
On your host (local install — stays on your machine)
- Policy / health: active policy hash, mode, dual-gate readiness, actuator stance.
- EDR / sensors (local): process/socket/DNS sensor heartbeats and redacted command-line samples (length-capped; env redacted when configured).
- Audit / mutation ledger: recommend vs applied vs reverted actions (quarantine, DNS sinkhole, egress) with timestamps — used for operator accountability and revert.
- Debug / state: last-good policy snapshot, resolver stub backups under the BARZEL state directory, triage recommendations. These files do not phone home by default.
How we use it
- Review and approve early-access applications.
- Send application receipts and private onboard links.
- Operate and secure the preview (rate limits, fraud/abuse signals, support).
- Improve product docs and onboarding for observe-first installs and dual-gated Guard/Fortress ACT.
We do not sell personal data, run a marketing list from EAP applications, or publish a public install URL.
Where it is stored
Application and invite records are stored in our production blob store used by barzel.dev APIs. Email is sent through AgentMail from BARZEL-operated inboxes (for example barzel-eap@agentmail.to). Host installs you run stay on your machine; BARZEL’s observe pilot does not phone home application form data from your host.
Retention
We keep early-access records while the private preview is active and for a reasonable period afterward for support and security. You can request deletion of your application by emailing barzel-eap@agentmail.to with your Application ID.
Sharing
We use infrastructure providers strictly to run the site, APIs, storage, and email (for example Vercel hosting/blob and AgentMail). We do not share EAP applicant data with third parties for their own marketing. We may disclose information if required by law or to protect the security of BARZEL or applicants.
Children
BARZEL early access is intended for adults operating technical systems. We do not knowingly collect data from children.
Contact
Privacy questions: barzel-eap@agentmail.to. Site: https://barzel.dev.